Privacy Policy
Last updated: 11 July 2026
1. Data controller
The controller of the personal data collected via the QualiFSTD application is:
Jean-Claude CHENARD, Sole Trader (Entrepreneur Individuel), SIRET 791 546 419, 1bis, Avenue Justin Maurice, 47520 Le Passage, France.
Contact: contact@qualifstd.com
2. Data collected
In the course of using QualiFSTD, the following categories of data are collected:
| Category | Examples | Purpose |
|---|---|---|
| Account data | Last name, first name, email address, password (hashed), role (ATO manager, compliance officer, instructor) | Authentication, access management |
| Organisation data | ATO name, logo, address, supervisory authority | Interface personalisation, generated documents |
| Billing data | Payment information (processed exclusively by Stripe, not stored by QualiFSTD) | Subscription management |
| FSTD usage data | Information relating to the FSTDs operated, certificates, QTG test results, reported faults, uploaded documents (photos, PDF) | The very purpose of the service: regulatory compliance monitoring |
| Technical data | IP address, connection logs, strictly necessary cookies | Security, technical operation |
3. Purposes and legal basis for processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Provision of the service (account creation, access to the Application) | Performance of the contract (art. 6.1.b) |
| Billing and subscription management | Performance of the contract / legal obligation (art. 6.1.b and 6.1.c) |
| Security and fraud prevention | Legitimate interest (art. 6.1.f) |
| Communication relating to the service (notifications, transactional emails) | Performance of the contract (art. 6.1.b) |
| Service improvement and internal usage statistics | Legitimate interest (art. 6.1.f) |
QualiFSTD does not collect or process any so-called “sensitive” data within the meaning of Article 9 of the GDPR.
4. Hosting and data location
QualiFSTD data is hosted and processed exclusively within the European Union, via the Supabase infrastructure, ensuring that no data is transferred outside the EU/EEA. The application itself is deployed on a virtual private server (VPS) at Hostinger.
No transfer of personal data is made to a third country outside the European Economic Area, unless explicitly stated otherwise. Should such a transfer become necessary (for example for a specific technical provider), it would be governed by the appropriate safeguards provided for by the GDPR (standard contractual clauses, adequacy decision).
5. Recipients of the data
Personal data is accessible:
- to authorised persons within the Customer’s organisation (according to the roles defined in the Application);
- to the Publisher, strictly to the extent necessary for the provision, maintenance and support of the Application;
- to the following technical sub-processors, acting on the Publisher’s instructions:
- Supabase (hosting of the database and file storage);
- Hostinger (hosting of the application server);
- Stripe (payment processing);
- Resend (where applicable, sending of transactional emails).
These providers use the data only in the context of the services provided to the Publisher and are subject to contractual obligations of confidentiality and security.
The data is neither sold, rented, nor transferred to third parties for commercial or advertising purposes.
6. Retention period
- Account data and FSTD usage data: retained for the entire duration of the subscription, then for a period of 30 days after termination to allow the Customer to export their data, before permanent deletion.
- Billing data: retained in accordance with the legal obligations for the retention of accounting documents (10 years).
- Technical logs: retained for a maximum period of 12 months.
7. Data security
The Publisher implements appropriate technical and organisational measures to ensure the security of personal data, in particular:
- encryption of passwords (hashing);
- secure authentication and fine-grained management of roles and permissions (Row-Level Security at the database level);
- encryption of data in transit (HTTPS/TLS);
- hosting with certified providers complying with European security standards.
8. Rights of data subjects
In accordance with the GDPR, any person whose data is processed has the following rights:
- Right of access: obtain confirmation that their data is being processed and obtain a copy of it;
- Right to rectification: have inaccurate or incomplete data corrected;
- Right to erasure: request the deletion of their data, within the limits of the legal retention obligations;
- Right to restriction of processing;
- Right to object to processing based on legitimate interest;
- Right to portability of the data provided;
- Right to withdraw consent, where the processing depends on it.
These rights may be exercised by writing to the following address: contact@qualifstd.com. A response will be provided within a maximum period of 30 days, in accordance with the GDPR.
In the event of a persistent disagreement, the data subject also has the right to lodge a complaint with the French Data Protection Authority (Commission Nationale de l’Informatique et des Libertés — CNIL) — www.cnil.fr.
9. Cookies
The Application uses only cookies that are strictly necessary for its operation (user session management, authentication). No advertising or third-party tracking cookie is placed without the prior consent of the user.
10. Modification of this policy
The Publisher reserves the right to modify this privacy policy at any time, in particular to comply with any regulatory, technical or legal development. Any substantial modification will be notified to Users by any appropriate means.
11. Contact
For any question relating to this privacy policy or to the exercise of your rights, you may contact the Publisher at the following address: contact@qualifstd.com