Privacy Policy
RLCore (hereinafter "we") is committed to protecting the privacy of users of its website rlcore.fr. This privacy policy describes the data we collect, how we use it, and the rights you have under the General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).
1. Data Controller
The data controller for personal data is:
RLCore — Raphaël L.
Toulon, France
Email: contact@rlcore.fr
2. Data Collected
We collect the following data:
- Identification data: last name, first name, email address
- Connection data: IP address, browser type, operating system, pages visited, date and time of connection
- Communication data: messages sent via the contact form
- Account data: information related to the creation and management of a user account on the platform (email, encrypted password, role, organization)
3. Purposes of Processing
Your data is collected for the following purposes:
- Managing contact requests and responding to inquiries
- Creating and managing user accounts on the SaaS platform
- Providing and improving our services (dashboard, analytics, CRM)
- Sending communications related to our services (with your consent)
- Statistical analysis of website traffic to improve performance
- Compliance with our legal and regulatory obligations
4. Legal Basis for Processing
The processing of your data is based on the following legal grounds:
- Your consent (Article 6.1.a GDPR): for sending commercial communications
- Performance of a contract (Article 6.1.b GDPR): for managing your account and providing our services
- Legitimate interest (Article 6.1.f GDPR): for statistical analysis and service improvement
- Legal obligation (Article 6.1.c GDPR): for retaining certain data required by law
5. Data Retention
Your data is retained for the following periods:
Contact data: 3 years from the last exchange
Account data: for the duration of the contractual relationship, then 3 years after account deletion
Connection data: 13 months in accordance with CNIL recommendations
Billing data: 10 years in accordance with legal accounting obligations
6. Data Recipients
Your data may be shared with the following recipients:
- Our internal team, strictly within the scope of their duties
- Supabase Inc. (data hosting and authentication) — servers located in the EU
- Vercel Inc. (website hosting) — with standard contractual clauses for transfers outside the EU
- Any technical service provider acting on behalf of RLCore, bound by confidentiality obligations
We never sell, rent or transfer your personal data to third parties for commercial purposes.
7. Transfers Outside the European Union
Some of our processors (Vercel) may be located outside the European Union. In such cases, data transfers are governed by standard contractual clauses approved by the European Commission (Article 46.2.c GDPR), ensuring an adequate level of protection.
8. Your Rights
Under the GDPR and the French Data Protection Act, you have the following rights:
- Right of access: obtain confirmation that data concerning you is being processed and receive a copy
- Right to rectification: request the correction of inaccurate or incomplete data
- Right to erasure: request the deletion of your data in cases provided by law
- Right to restriction: request the restriction of processing of your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to the processing of your data on legitimate grounds
- Right to withdraw consent: at any time, without affecting the lawfulness of prior processing
To exercise these rights, contact us at: contact@rlcore.fr. We will respond to your request within a maximum of 30 days.
In the event of a persistent disagreement, you may file a complaint with the CNIL (French Data Protection Authority): www.cnil.fr.
10. Data Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, modification, disclosure or destruction. These measures include: encryption of data in transit (HTTPS/TLS), password hashing (bcrypt), secure authentication via Supabase Auth, principle of least privilege with Row Level Security (RLS), and regular backups.
11. Policy Changes
We reserve the right to modify this privacy policy at any time. Any substantial changes will be notified on the website. The date of the last update is indicated at the top of this page. We encourage you to review this page regularly.
12. Contact
For any questions regarding this privacy policy or to exercise your rights, contact us:
Email: contact@rlcore.fr
Address: Toulon, France