Privacy policy
This document describes how we process your data on the privatecore.fr website, in the PrivateCore service installed on your own hardware, in the PrivateCore service we host for you, and in the mobile apps. The rules differ from one case to the next: that is what this page is about.
Preamble
PrivateCore is built on a simple principle: your data should stay with you, and when it cannot, you should know exactly where it is. This policy distinguishes four perimeters: the public marketing site, the software installed on your own hardware, the software we host for you, and the mobile apps. The rules are not the same.
The data controller is PRIVATECORE SAS, 48 rue Claude Balbastre, 34070 Montpellier, France (SIREN 103 084 018). Data protection officer: dpo@privatecore.fr.
On the privatecore.fr website
- No third-party tracking. No Google Analytics, no Meta pixel, no Hotjar, no third-party behavioural analytics.
- No cookies. The site sets no cookie at all, not even a technical one. The legacy
pc_consentcookie, set by the consent banner of earlier versions of the site, is automatically removed from your browser when you visit. - Audience measurement from server logs, without cookies or scripts. We analyse the technical logs of our own server (page viewed, date, country of origin, browser) to count visits in an aggregated and anonymised way: IP addresses are truncated in the statistics and no data is cross-referenced with third parties. This measurement sets no cookie, runs no tracking script in your browser, and everything is processed on our own server in France. Raw logs are purged after 30 days.
What the site records when you write to us
Three forms on the site collect data, each for a precise reason. None of it is sold, rented, or passed to a broker or an advertising network.
- Quote or installation request (/en/commander). The information you enter (name, company, email, phone, trade, description of your need) is recorded in the database of our own PrivateCore instance, hosted on our hardware in France. Two emails are then sent: a notification to our team and an acknowledgement addressed to you. Legal basis: pre-contractual steps taken at your request (art. 6.1.b GDPR). Retention: 3 years from the last exchange.
- Video appointment booking (available from the French pages). Your name, email address and chosen slot are recorded in our instance, and a confirmation email is sent to you. The video call is served by our own server: no Zoom, no Meet, no Teams is involved. Calls are neither recorded nor transcribed. Retention: 3 years from the appointment.
- Newsletter (site footer). Only your email address is collected, on the basis of your consent (art. 6.1.a), to receive our publications. No profiling, no open-tracking pixel. You can unsubscribe at any time by replying or writing to contact@privatecore.fr.
These emails are routed through our professional mail provider, Infomaniak Network SA (Switzerland), which processes the message for the time it takes to deliver it. Switzerland benefits from an adequacy decision of the European Commission.
On the demo instance
The demo instance reachable from the site runs on our servers and contains an entirely fictitious data set. It is reset regularly: anything you enter there is erased at the next reset. Do not enter any real data, whether yours or your customers' or your employees'.
The PrivateCore service: two hosting modes
PrivateCore is deployed in one of two ways, chosen by the customer, and our role under the GDPR is not the same in each. The chosen mode is stated on your quote and on your invoice; it can be switched in both directions at any time.
"At my place" mode: the software runs on your hardware
Your data (customers, employees, invoices, photos, messages, and so on) stays physically on your Mac. It never passes through our servers.
- No GDPR processing by default. We are not a processor within the meaning of article 28 GDPR for that data: it is never entrusted to us.
- Remote support by invitation only. When you request an intervention (fault, configuration), you explicitly enable access over Tailscale. Access is recorded in an encrypted, tamper-evident audit log you can consult at any time. During that intervention, and for its duration only, we act as a processor.
- Software updates. They are signed, cryptographically verified by your machine, and neither carry away nor read any user data.
- Backups. They stay under your control, on the medium you choose. We hold no copy of them.
"Online" mode: the software runs on our servers
If you choose this mode, your data is entrusted to us and we act as a processor within the meaning of article 28 GDPR for all of its processing. You remain the controller. The corresponding commitments are set out in our data processing agreement, available for signature on request.
- Location. Servers are rented from Scaleway SAS and located in France. No data is transferred outside the European Union.
- Isolation. Each customer gets their own instance, with its own database and its own container. There is no shared database across customers: one customer's query cannot, even in the event of an application defect, reach another customer's data.
- Encryption. Encrypted disks at rest, TLS 1.3 in transit, administration exclusively through a key-authenticated WireGuard tunnel.
- Backups. Encrypted, daily, and kept off the machine they protect: a backup that stays on the server it backs up does not protect against losing that server. Retention: a rolling 14 days, then erasure.
- Our access. We access the content of your instance only at your request, under a judicial order, or to restore service after an incident. Every access is logged and the log can be provided to you.
- Reversibility. You can export all of your data at any time from the application, or ask for your instance to be moved back to your own hardware. At the end of the contract, your data is returned to you and then erased from our servers and backups within 30 days.
- Health data. The "Online" mode does not accept personal health data: hosting it on behalf of a third party requires the French "Hébergeur de Données de Santé" certification (art. L.1111-8 of the public health code), which PrivateCore SAS does not hold to date. Healthcare professionals use the "At my place" mode, where data never leaves their practice.
On the PrivateCore Manager mobile apps (iOS / Android)
The PrivateCore Manager mobile apps (published on Apple's App Store and the Google Play Store) are clients that connect exclusively to their user's PrivateCore instance, whether it sits at their place or is hosted online, over a private encrypted channel.
- No collection by the app itself. All communication happens directly between the app and the user's instance. The app sends no business data (scheduling, staff, till, customers, invoices) to any third-party service.
- Local storage on the device, encrypted. The app only stores an authentication token (iOS Keychain / Android Keystore), an offline cache of the schedule and the team (encrypted at rest), and your interface preferences. None of this ever leaves your phone.
- Permissions requested. Camera (QR code scanning: ticketing, vouchers), Face ID / Touch ID (biometric authentication at launch), Push notifications (critical alerts issued by your instance, routed through Apple Push Notification or Firebase Cloud Messaging depending on the platform: only the notification token, never business content).
- No tracking, no analytics, no advertising. No third-party SDK (Firebase Analytics, Mixpanel, Sentry, Amplitude, Crashlytics) is embedded in the apps. No advertising identifier (IDFA / GAID) is read. No behaviour is measured or transmitted.
- Deletion. Uninstalling the app wipes the local cache from the phone. The data in your instance stays managed from its administration interface.
On the built-in artificial intelligence
PrivateCore's AI features (assistant, drafting, document reading, transcription, search) run on models installed on your instance, through Ollama. Concretely:
- No text, document, photo, message or recording you hand to the assistant is sent to a third-party AI provider.
- Your data trains no model, neither ours nor anyone else's.
- Should a feature ever rely on a remote AI service, it would be disabled by default, announced as such in the interface, and subject to your explicit activation.
Our processors and recipients
The list below is exhaustive as of the date this page was updated. Any addition is notified to the customers concerned before it goes live.
- Scaleway SAS (France): hosting of "Online" mode instances. No data at all for customers in "At my place" mode.
- Infomaniak Network SA (Switzerland): routing of our professional and transactional emails (acknowledgements, appointment confirmations, invoices).
- Cloudflare, Inc. (United States): tunnel serving the privatecore.fr website. Sees only TLS-encrypted traffic, stores neither content nor personal data.
- Apple Inc. and Google LLC: routing of push notifications to the mobile apps. Receive the device token and the alert title, never business content.
- Our payment provider: handling of SEPA direct debits and card payments for subscription billing (identity, bank details, amounts). We do not retain your bank details.
No other recipient. We do not sell, rent or trade any data.
Your GDPR rights
Under articles 15 to 22 of the General Data Protection Regulation, you have rights of access, rectification, erasure, portability, restriction and objection over the data we hold about you.
To exercise them, write to dpo@privatecore.fr. We answer within one month. If your request concerns data entered in the PrivateCore instance of one of our customers (for instance your customer record at a restaurant that uses PrivateCore), address it to that customer: they are the controller, and we cannot answer in their place.
Retention periods
- Requests sent from the site and contact emails: a rolling 3 years from the last exchange, then purged.
- Appointments booked online: 3 years from the appointment.
- Newsletter subscription: until you unsubscribe, then purged within 30 days.
- Web server technical logs (privatecore.fr): 30 days, then automatically purged. Only aggregated, anonymised statistics are kept beyond that.
- Remote intervention logs: 90 days, then irreversibly purged.
- Backups of "Online" mode instances: a rolling 14 days.
- Data of a hosted customer, after termination: returned, then erased within 30 days.
- Billing records (subscription): 10 years, as required by French accounting law.
Transfers outside the European Union
The instances we host are located in France: our customers' data is subject to no transfer outside the European Union. Two ancillary processing operations leave the EU, and neither ever carries business data:
- Switzerland (Infomaniak, email): a country recognised as offering an adequate level of protection by a decision of the European Commission.
- United States (Cloudflare for the site tunnel, Apple and Google for push notifications): covered by the European Commission's standard contractual clauses. Cloudflare sees only encrypted traffic; Apple and Google receive only a device token.
Security and breach notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the CNIL within 72 hours and inform the individuals concerned without undue delay. For our hosted customers, notice reaches them within 48 hours of detection, so that they can carry out their own notification.
Data protection officer contact
For any question about this policy or your rights, contact our DPO at dpo@privatecore.fr.
Supervisory authority
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL): www.cnil.fr.
Ready to take back control?
A bespoke install, an answer from the founder, and a Mac Mini you buy yourself or we deliver configured.