Privacy Policy
Last updated: 14 July 2026
This English version is provided for convenience only; in case of any discrepancy, the French version shall prevail.
SAVEPNP, a French SAS registered with the Créteil Trade and Companies Register under No. 912 784 030, with its registered office at 25 rue Camille Blanc, 94400 Vitry-sur-Seine (hereinafter "we", "our"), publisher of the Seogard platform, is committed to protecting the privacy of its users in accordance with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and the French Data Protection Act of 6 January 1978 as amended.
1. Data controller
SAVEPNP (trade name: Seogard)
25 rue Camille Blanc, 94400 Vitry-sur-Seine, France
Créteil Trade and Companies Register 912 784 030 — SIRET 912 784 030 00021
Email: [email protected]
2. Data collected
2.1 Registration data
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Email address | Authentication, communication, alerts | Performance of the contract | Account lifetime + 3 years |
| Password (bcrypt-hashed) | Authentication | Performance of the contract | Account lifetime |
| Organization name | Account identification | Performance of the contract | Account lifetime + 3 years |
| Acceptance of the Terms of Use / Terms of Sale (date + version) | Proof of contractual consent | Legal obligation | 5 years after the end of the contract |
2.2 Billing data
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Stripe customer ID | Billing and payment | Performance of the contract | Contract term + 10 years (accounting obligation) |
| Invoice history | Billing, accounting | Legal obligation | 10 years |
Note: card data (card number, CVV) is never stored on our servers. It is processed exclusively by Stripe (PCI-DSS Level 1 certified).
2.3 Technical crawl data
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| URLs of crawled pages | SEO monitoring | Performance of the contract | Account lifetime |
| HTML snapshots (SSR/CSR) | Regression detection | Performance of the contract | Rolling 12 months |
| Alerts and history | Regression tracking | Performance of the contract | Rolling 12 months |
2.4 Browsing data
| Data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Authentication cookies (JWT) | Session maintenance | Performance of the contract | 7 days (access) / 30 days (refresh) |
| Analytics data (Umami) | Anonymous usage statistics | Legitimate interest | 24 months |
| Session recording (PostHog) | Understand journeys and friction points | Consent | 1 month |
3. Sub-processors
We use the following sub-processors, all GDPR-compliant:
| Sub-processor | Purpose | Data location |
|---|---|---|
| MongoDB Atlas | Database | EU (Ireland / Belgium) |
| Hetzner | Crawl servers | EU (Germany / Finland) |
| Railway | Application hosting | EU / US |
| Stripe | Payment and billing | EU / US (PCI-DSS) |
| Resend | Transactional email delivery | US |
| Umami | Analytics (self-hosted, no third-party cookies) | EU (Germany — our VPS) |
| PostHog | Session replay and journey analytics (after consent) | EU (PostHog Cloud EU) |
For transfers outside the EU, the European Commission's Standard Contractual Clauses (SCCs) are in place.
4. User rights
In accordance with the GDPR, you have the following rights:
- Right of access (Art. 15): obtain a copy of your personal data
- Right to rectification (Art. 16): correct inaccurate data
- Right to erasure (Art. 17): request the deletion of your data
- Right to data portability (Art. 20): receive your data in a structured format
- Right to restriction of processing (Art. 18): restrict the use of your data
- Right to object (Art. 21): object to the processing of your data
To exercise your rights, contact us at: [email protected]. We will respond within a maximum of 30 days.
In case of disagreement, you may lodge a complaint with the CNIL (the French Data Protection Authority): www.cnil.fr
5. Security
We implement the following technical and organizational measures:
- HTTPS encryption (TLS 1.3) for all communications
- Password hashing with bcrypt (cost factor 12)
- Signed JWT tokens with automatic rotation
- Database access restricted by IP and authentication
- Logging of access and security events
- Daily automatic backups
6. Cookies
See our Cookie Policy for details of the cookies used.
7. Changes
We may amend this policy at any time. Users will be informed by email of any substantial change. The version in force is always accessible on this page.
8. Contact
Data Protection Officer: [email protected]