Lire cette page en français

Privacy Policy (GDPR)

Last updated: April 2026

This Privacy Policy explains how Soaria (“we”, “us”, “our”) collects and processes personal data when you use our website and platform (the “Service”).

1) Data controller

The data controller is Soaria.

Contact: contact@soaria.fr

Address: 11 avenue Paul Verlaine, 38100 Grenoble, France

2) Personal data we process

Depending on how you use the Service, we may process:

  • Account data: email, first name, last name, profile information.
  • Usage data: technical logs, IP address, session identifiers, pages viewed, navigation events.
  • Communications: messages to support and any attachments.
  • Service emails: data strictly necessary to send emails (e.g., email address, sending/deliverability metadata).
  • Billing data: payment and invoicing-related data (we do not store full payment card details).
  • Uploaded documents: documents you upload to the Service, which may include sensitive information (e.g., identity documents, financial documents, legal/HR documents, project documents).

3) Purposes and legal bases

We process personal data for the following purposes:

  • Provide the Service (account creation, access, features, support): performance of a contract.
  • Customer relationship and support: performance of a contract / legitimate interests.
  • Service security (fraud prevention, anomaly detection, security logs): legitimate interests.
  • Billing and statutory obligations: legal obligation.
  • Analytics: legitimate interests and/or consent where required by applicable rules.

4) Where your data is stored (hosting and location)

We host and store Service data in the European Union:

  • Application servers: Hetzner (Helsinki, Finland).
  • Database: Supabase (Postgres) — EU region.
  • User documents: Supabase Storage (S3-compatible) — EU region.

We aim to keep processing within the EU. If a transfer outside the EU becomes necessary, we will implement appropriate safeguards as required by the GDPR (e.g., Standard Contractual Clauses) and inform you.

5) Sensitive documents: what we do with them

Documents you upload may contain highly sensitive information (identity, financial situation, contractual information).

We process them only to:

  • allow you to store, view, organize, and share them within the Service;
  • provide platform functionality (e.g., creating/structuring deliverables based on information you submit or upload);
  • ensure Service security and continuity.

We do not have external vendors analyze your uploaded document content (no external OCR/AI vendor) beyond the hosting/storage and technical transit required to operate the Service.

6) Recipients and processors

Your data may be accessed:

  • Internally: by authorized Soaria staff, on a need-to-know basis.
  • By our processors (depending on the Service):
    • Hetzner Online GmbH (application hosting in Helsinki, Finland),
    • Supabase (database and file storage — EU region),
    • Stripe (payments),
    • Resend (transactional and service email delivery),
    • Umami (analytics).
    • GitHub (source code hosting and version control; technical data related to development and repository access).

We select providers that offer adequate safeguards and we put in place processor agreements where required.

7) Retention

We keep personal data only for as long as necessary for the purposes described above.

Unless stated otherwise, we apply the following principles (to be adjusted to your needs):

  • Account data: for the lifetime of the account, then deleted/anonymized after closure, subject to legal obligations.
  • Documents: for the lifetime of the account, then deleted after closure following a grace period [to be defined].
  • Billing data: retained as required by law (e.g., accounting).
  • Technical/security logs: retained for a limited period [to be defined] unless needed for security.

8) Security

We implement appropriate security measures, including:

  • access control and least-privilege permissions;
  • encryption in transit (HTTPS/TLS);
  • monitoring and incident prevention measures;
  • backups and recovery procedures.

We also undergo regular audits by cybersecurity experts to assess and improve our security posture.

No system is completely secure; we cannot guarantee absolute security, but we strive to reduce risks as much as possible.

9) Cookies and analytics

We may use analytics technologies to understand Service usage and improve it.

Depending on configuration, some analytics tools can operate without cookies, or may require your consent. When consent is required, we implement an information/consent mechanism.

10) Your rights (GDPR)

You have the following rights: access, rectification, erasure, restriction, objection, portability (as applicable).

To exercise your rights: contact@soaria.fr.

You may also lodge a complaint with the CNIL (France).

11) Updates to this policy

We may update this policy. The last updated date appears at the top of this page. If changes are material, we may notify you through the Service.