Privacy Policy

1. Introduction

Georisk-AI (Adam Laroussi, SIREN 101 615 557) is committed to protecting its users' privacy in accordance with the General Data Protection Regulation (GDPR (EU 2016/679)) and the French Data Protection Act (Loi Informatique et Libertés, as amended).

Data controller: Adam Laroussi (PolitoLogos), GDPR contact: rgpd@georisk-ai.com

2. Data Collected

The table below summarises the personal data collected, their purposes, legal bases and retention periods.

CategoryDataPurposeLegal BasisRetention
User accountEmail, password (hashed), first name, last nameAccount creation, authenticationPerformance of contract (art. 6.1.b GDPR)Duration of account + 1 year after deletion
PaymentData transmitted to Stripe (never stored in clear text by Georisk-AI)Billing and subscription managementPerformance of contract (art. 6.1.b GDPR)10 years (statutory accounting obligation)
BrowsingIP address, user-agent, pages visited, timestampsTechnical operation, security, anonymised statisticsLegitimate interest (art. 6.1.f GDPR)Maximum 13 months
CommunicationEmails exchanged with supportCustomer supportPerformance of contract (art. 6.1.b GDPR)3 years
PreferencesLanguage, country watchlist, alert settingsExperience personalisationPerformance of contract (art. 6.1.b GDPR)Duration of account

3. Data Recipients

Your data may be shared with the following recipients:

  • Georisk-AI (data controller) : internal access for the purposes listed above only
  • Stripe, Inc. (payment processor) : PCI-DSS Level 1 certified, governed by the EU-US Data Privacy Framework
  • Stack Auth (authentication processor) : user account management

Georisk-AI does not sell your personal data to third parties under any circumstances.

4. Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right of access to your personal data (art. 15 GDPR)
  • Right to rectification of inaccurate data (art. 16 GDPR)
  • Right to erasure ('right to be forgotten') (art. 17 GDPR)
  • Right to restriction of processing (art. 18 GDPR)
  • Right to data portability (art. 20 GDPR)
  • Right to object to processing (art. 21 GDPR)
  • Right to withdraw consent at any time (without retroactive effect)
  • Right to lodge a complaint with the CNIL (www.cnil.fr)

To exercise these rights: send your request to rgpd@georisk-ai.com. Response within 1 month maximum.

5. Cookies

The platform uses the following cookies:

CookieTypePurposeDurationLegal Basis
Stack Auth sessionStrictly necessaryMaintaining the authentication sessionSession durationPerformance of contract
Language preference (i18next)Strictly necessaryRemembering the selected display language1 yearLegitimate interest
Anonymised statisticsAudience measurementService improvement, anonymous browsing statisticsMaximum 13 monthsLegitimate interest

No advertising cookies, no third-party trackers for marketing purposes, no retargeting. In accordance with CNIL recommendations, no complex consent banner is required for strictly necessary cookies and anonymised statistics. Navigation statistics are collected via Umami (umami.is), a privacy-friendly tool that sets no cookies, records no IP addresses, and stores data in Europe.

6. Data Security

  • TLS encryption (HTTPS) for all communications between your browser and our servers
  • Passwords hashed (via Stack Auth, secure algorithm of the bcrypt type or equivalent)
  • Two-factor authentication (2FA TOTP) mandatory for administrator accounts
  • Regular database backups
  • No disclosure of data to third parties for commercial purposes

7. Policy Updates

Georisk-AI reserves the right to modify this privacy policy. Any material change will be notified by email to users with an active account at least 15 days before taking effect.

8. GDPR Contact

For any question relating to the protection of your personal data: rgpd@georisk-ai.com

Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, 75007 Paris, www.cnil.fr