Legal

Privacy Policy

Effective from 1 April 2026 Β· Version 1.0

πŸ‡ͺπŸ‡Ί Your data stays in Europe. All Flatly servers are hosted in Germany (Frankfurt), within the European Union, in compliance with the GDPR.

1

Data Controller

The data controller for personal data collected through the Flatly app and flatly.fr website is:

For any questions about how your data is handled, please contact us at the address above.


2

Data We Collect

2.1 Data you provide

DataWhen collectedRequired
Email addressAccount creationYes
Password (hashed)Account creationYes
UsernameProfile settingsNo
Profile pictureProfile settingsNo
Review content (text, ratings)Publishing a reviewYes (to publish)
Verification documents (lease, bill)Optional review verificationNo
Questions and answersQ&A systemNo

2.2 Data collected automatically

DataPurpose
IP addressSecurity, abuse prevention
Session identifierAuthentication
Address page viewsImpact statistics (anonymised)
Helpful votes on reviewsCommunity feature

πŸ”’ Reviews are published anonymously. Your identity is never publicly displayed on Flatly.


3

Purposes and Legal Bases

PurposeLegal basis (GDPR)
Managing your user accountContract performance (Art. 6.1.b)
Publishing and moderating reviewsContract performance (Art. 6.1.b)
Sending transactional emails (account confirmation, review status)Contract performance (Art. 6.1.b)
Fraud and abuse preventionLegitimate interests (Art. 6.1.f)
Legal compliance (Decree 2017-1436, LCEN)Legal obligation (Art. 6.1.c)
Anonymised usage statisticsLegitimate interests (Art. 6.1.f)

Flatly does not send marketing emails without prior explicit consent, and never sells data to third parties.


4

Retention Periods

DataRetention
User account and profile dataUntil account deletion + 30 days
Published reviewsFor the life of the Service, or until deletion on request
Verification documentsUntil moderation decision, then deleted
Security logs (IP, sessions)Maximum 12 months
Transactional emailsResend history: 90 days

Deleting your account results in the irreversible anonymisation of your published reviews (reviews remain visible but are no longer linked to your identity) and the deletion of all other personal data.


5

Who Receives Your Data

Your data is shared only with the technical sub-processors strictly necessary to run the Service:

Sub-processorRoleLocation
SupabaseDatabase, authentication, storageπŸ‡©πŸ‡ͺ Frankfurt, Germany (EU)
ResendTransactional email deliveryπŸ‡ΊπŸ‡Έ United States (SCCs)
Google (Places API)Address search and normalisationπŸ‡ΊπŸ‡Έ United States (SCCs)
Vercelflatly.fr website hostingπŸ‡ΊπŸ‡Έ United States (SCCs)

Flatly never sells, rents, or shares your personal data with third parties for commercial, advertising, or any other purposes.


6

Transfers Outside the EU

Some of our sub-processors (Resend, Google, Vercel) are based in the United States. These transfers are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46 of the GDPR.

Data stored in our primary database (Supabase) remains exclusively in Germany.


7

Your Rights

Under the GDPR (Articles 15–22), you have the following rights:

πŸ‘οΈ

Access

Get a copy of your data

✏️

Rectification

Correct inaccurate data

πŸ—‘οΈ

Erasure

Delete your account and data

⏸️

Restriction

Limit certain processing

πŸ“¦

Portability

Receive your data in a readable format

🚫

Objection

Object to certain processing

To exercise these rights, email hello@flatly.fr. We will respond within 30 days.

You also have the right to lodge a complaint with the CNIL (France's data protection authority, cnil.fr) if you believe your rights are not being respected.

If you are based outside France, you may also contact your local supervisory authority within the EU.


8

Cookies and Trackers

The Flatly mobile app does not use cookies in the traditional sense.

The flatly.fr website uses only:

  • Strictly necessary technical cookies (session, security) β€” exempt from consent requirements;
  • No advertising or third-party tracking cookies.

Flatly displays no advertising and does not engage in behavioural tracking for commercial purposes.


9

Security

Flatly implements the following technical and organisational measures to protect your data:

  • Encrypted communications via HTTPS/TLS;
  • Hashed passwords (never stored in plain text);
  • Database-level access control via Row Level Security (RLS);
  • Verification documents stored in a private, publicly inaccessible bucket;
  • Restricted admin access.

In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be notified as soon as possible in accordance with Article 34 of the GDPR.


10

Changes to This Policy

Flatly reserves the right to update this policy at any time. For material changes, you will be notified by email with 30 days' notice.

The current version is always available at flatly.fr/en/privacy.html.


11

Contact

  • Email: hello@flatly.fr
  • Data controller: Maxime Huot
  • Response time: Maximum 30 days

Questions about your data?

We handle every request within 30 days, no exceptions.

Write to hello@flatly.fr