← Back

Privacy Policy

Last updated June 14, 2026

PRIVACY POLICY Last updated: June 2026 Propaler SAS ("Propaler", "we", "us", or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect information relating to users of our platform (app.propaler.com) and our website (propaler.com). This policy complies with the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679. 1. DATA CONTROLLER The data controller is: Propaler SAS Contact: privacy@propaler.com 2. DATA WE COLLECT 2.1 Account Data (Users / Subscribers) When you create a Propaler account, we collect: - First name and last name - Email address - Phone number (for Certified Agreement verification) - Company name (optional) - Payment information (processed by Stripe — Propaler does not store card details) 2.2 Usage Data We automatically collect certain technical information when you use the Service: - IP address - Browser type and version - Operating system - Pages visited and time spent - Actions performed within the platform 2.3 Proposal Tracking Data (Prospect Data) When a prospect opens a proposal shared via Propaler, we collect: - IP address - Device type and browser - Opening timestamp - Time spent on each page of the document - Number of revisits This data is collected on behalf of the Propaler user (the "controller") who shared the proposal. Propaler acts as a data processor with respect to prospect data. 2.4 Certified Agreement Data When a prospect signs a Certified Agreement, we collect: - First name and last name - Email address - Phone number - IP address - Timestamp of signature - Device fingerprint This data constitutes the audit trail of the agreement and is retained for ten (10) years. 3. PURPOSES AND LEGAL BASIS FOR PROCESSING | Purpose | Legal Basis | |---------|-------------| | Account creation and authentication | Performance of contract | | Billing and payment processing | Performance of contract | | Proposal tracking and analytics | Legitimate interest (providing the core service) | | Certified Agreement audit trail | Legal obligation / Legitimate interest | | Customer support | Legitimate interest | | Product improvement and analytics | Legitimate interest | | Marketing communications (newsletter) | Consent | | Legal compliance | Legal obligation | 4. DATA RECIPIENTS Your data may be shared with the following categories of recipients: - **Stripe**: Payment processing - **Vercel**: Hosting and infrastructure - **Supabase**: Database and authentication - **Twilio**: SMS verification (for Certified Agreements) - **Email service provider**: Transactional and marketing emails All our sub-processors are contractually bound to process data solely on our instructions and in compliance with applicable data protection law. Where sub-processors are located outside the EEA, appropriate safeguards (such as Standard Contractual Clauses) are in place. 5. DATA RETENTION | Data Category | Retention Period | |--------------|-----------------| | Account data | Duration of account + 3 years after deletion | | Proposal tracking data | 3 years from collection | | Certified Agreement audit trail | 10 years | | Billing records | 10 years (legal obligation) | | Marketing consent records | 3 years from last interaction | 6. YOUR RIGHTS Under the GDPR, you have the following rights with respect to your personal data: - **Right of access**: You may request a copy of the personal data we hold about you. - **Right of rectification**: You may request correction of inaccurate data. - **Right of erasure**: You may request deletion of your data, subject to legal retention obligations. - **Right to restriction of processing**: You may request that we restrict processing of your data in certain circumstances. - **Right to data portability**: You may request your data in a structured, machine-readable format. - **Right to object**: You may object to processing based on legitimate interest, including direct marketing. - **Right to withdraw consent**: Where processing is based on consent, you may withdraw it at any time. To exercise any of these rights, please contact us at: privacy@propaler.com You also have the right to lodge a complaint with your local supervisory authority. In France, this is the CNIL (www.cnil.fr). If you are located in another EU member state, you may contact your national data protection authority. 7. COOKIES We use cookies and similar technologies on our website and platform. For full details, please refer to our Cookie Policy. 8. SECURITY Propaler implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. These measures include: - Encryption of data in transit (TLS/HTTPS) - Encryption of data at rest - Access controls and authentication - Regular security reviews No method of transmission or storage is 100% secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by the GDPR. 9. INTERNATIONAL TRANSFERS Propaler's infrastructure involves service providers located outside the European Economic Area (EEA), including in the United States. All such transfers are governed by appropriate safeguards in accordance with GDPR requirements (Standard Contractual Clauses or equivalent). 10. CHILDREN The Propaler Service is intended for professional use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. 11. CHANGES TO THIS POLICY We may update this Privacy Policy from time to time. Material changes will be notified to you by email or via an in-app notice. The updated policy will be effective from the date indicated at the top of this document. 12. CONTACT Data Protection contact: privacy@propaler.com Propaler SAS — France