Sendora Logo

Privacy Policy

At Sendora, protecting your personal data and privacy is a priority. We are committed to complying with applicable regulations, including GDPR and French data protection law.

1. Who is responsible for your data?

Sendora, the company that publishes the platform, is responsible for processing your personal data. For any questions, contact us.

2. What data do we collect?

We only collect the data necessary to create your account, use our services, and improve your experience: first name, last name, email, login information, usage statistics, and technical data (IP address, logs, cookies).

3. Why do we use your data?

  • Sending transactional emails (account confirmation, password reset, etc.)
  • Sending marketing emails to your own contacts, under your responsibility
  • Customer support and assistance
  • Improving our services and usage statistics
  • Complying with our legal obligations and fighting fraud

4. Legal basis for processing

Your data is processed on the basis of contract performance (creating and managing your account), your consent (newsletter, non-essential cookies), or our legitimate interest (security, service improvement).

5. Who has access to your data?

Your data is only accessible to Sendora's teams and our technical service providers (hosting, email delivery, analytics), strictly within the scope of providing the service. We never sell or rent your data to third parties.

6. Subprocessors and transfers outside the EU

Some data (notably emails) is processed via Amazon Web Services (AWS), which hosts the sending infrastructure. When this data is transferred outside the European Union, we ensure adequate safeguards are in place (standard contractual clauses).

7. Security

We implement appropriate technical and organizational measures to ensure the security and confidentiality of your data: encryption, access control, backups, regular audits, etc.

8. Data retention period

Your data is retained for as long as your account is active, then deleted upon request or after a period of inactivity (2 years maximum for inactive accounts). Some data may be kept longer to meet our legal obligations.

9. Your rights

In accordance with GDPR, you have the following rights: access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. To exercise your rights, contact us.

10. Cookies

We use cookies to improve your experience, measure audience, and secure the platform. You can manage your preferences in your browser or via the cookie banner.

11. Incident management

In the event of a personal data breach, we will inform you as soon as possible in accordance with regulations.

12. Changes to this policy

We may modify this policy at any time: the current version is always available on this page. You will be informed of any major change.