Summary
We collect only what is necessary to operate Oyeba. You keep control over your data, you can export or delete it at any time. We never sell your data. Your data stays in the European Union.
1. Data collected
Data you provide
- Identity: first name, last name, email address, country, preferred language
- Profile: profile type (diaspora, coordinator, etc.), photo if you add one
- Content: everything you publish in your projects (steps, proofs, messages)
Data collected automatically
- Technical data: IP address, browser type, language, time zone
- Usage data: pages viewed, actions taken, dates and times
- Server logs: kept for 12 months maximum for security reasons
2. Purposes
We use your data to:
- Provide the service: create your account, host your projects, transmit your proofs
- Communicate with you: notifications, support, product updates
- Improve the product: aggregated and anonymized usage analysis
- Secure the service: fraud detection, abuse prevention
- Meet our legal obligations
3. Legal basis
In accordance with article 6 of the GDPR, we rely on:
- Performance of the contract (delivering the service you requested)
- Our legitimate interest (security, product improvement)
- Your explicit consent (non-essential cookies, marketing communications)
- Compliance with legal obligations (accounting, legitimate judicial requests)
4. Recipients
Your data is only accessible to:
- Yourself and the members you explicitly invite into your projects
- Our technical teams, strictly as needed to operate the service
- Our subcontractors (hosting, email sending) under GDPR-compliant contracts
We never sell or rent your data to third parties, in any form.
5. Retention period
- Account data: as long as your account is active, then 30 days after deletion
- Project content: depending on your role in the project and the owner's decision
- Technical logs: 12 months maximum
- Accounting data: 10 years (legal obligation)
6. Your rights
In accordance with the GDPR, you have the following rights, exercisable at any time:
- Access: obtain a complete copy of the data concerning you
- Rectification: correct inaccurate data
- Erasure: request the deletion of your data
- Restriction: restrict certain processing
- Portability: receive your data in a structured format (JSON)
- Objection: refuse certain processing (notably marketing)
- Complaint: with the CNIL (cnil.fr)
To exercise these rights, write to dpo@oyeba.com. We respond within 30 days.
7. Transfers outside the EU
We do not transfer your personal data outside the European Union. Should this change, we would apply the standard contractual clauses of the European Commission and inform you beforehand.
8. Cookies
See our dedicated cookie policy.
9. Contact DPO
For any question about the protection of your data, write to our Data Protection Officer:
dpo@oyeba.com
Oyeba SAS, DPO
Paris, France