Privacy policy — working draft
This is a draft written by a non-lawyer and it is not a compliant privacy notice as it stands. It exists so that a privacy specialist reviews a structured document describing what the system actually does, rather than a blank page. Section 12 lists what must be settled before publication.
terms.md§20.6 and §20.7 already record two of those questions: cross-border transfer to Thailand alongside GDPR and the Thai PDPA, and the ten-year retention promise against data minimisation.Base language EN; the FR version must be a full translation, not a summary.
1. Who is responsible for your data
The controller is the Suradeed entity named at the head of your quote and on your invoice, whose registration details and registered office are given there and in the legal notice on this site.
The partner law firm engaged on your dossier is a separate controller for the legal work it performs and signs. It is not our processor: it owes you its own professional duties, and it decides what its file must contain.
Build note, not a clause: the entity changes at the migration recorded in
structure.md. It is read fromlib/config/and never written into this document.
2. What we collect, and why
Everything below is collected because the service cannot be delivered without it. We do not build profiles, we do not advertise, and we do not sell data.
When you ask for a price
- your name, email address, country and preferred language;
- what you tell us about the property: a label, the property type, the ownership route, the title grade, the region, an address or area, an optional listing link and an optional indicative purchase price.
Those property answers are the ones the published price grid is applied to. You are asked to confirm they are accurate because the fixed price depends on them.
When you pay
- the payment session identifier, the amount, the currency and whether the payment was live or a test;
- the version and digest of the disclosure you acknowledged before paying.
We never see or store your card number. The payment page is operated by Stripe and card details are entered there, not here.
While the verification runs
- the documents you upload, and the result of the malware scan run on each one;
- messages exchanged about the dossier;
- an audit trail of the actions taken on the dossier, kept so that who did what, and when, can be established later.
Because you have an account
- sign-in sessions, including the IP address and browser reported at sign-in, kept so a session can be recognised and revoked.
3. Why we are allowed to process it
- Performance of your contract, for everything needed to scope, price, route, carry out and deliver the verification.
- Our legitimate interest in keeping the platform secure and available: the malware scan on uploads, the audit trail, rate limiting, and error monitoring.
- A legal obligation, for invoicing and accounting records.
- The establishment or defence of legal claims, for the retained file.
4. Who else sees it
The partner law firm engaged on your dossier sees the dossier and its documents. That is the point of the service.
Our processors, who act only on our instructions:
- Cloudflare — hosting, database, document storage and PDF rendering;
- Stripe — payment processing;
- Resend — transactional email, including your sign-in links;
- Sentry — error monitoring.
We do not sell your data and we do not share it for advertising.
5. Where it goes
The platform runs on Cloudflare's network. The partner law firm is in Thailand, so a dossier concerning an EU resident is read there.
Open point, and a real one. The safeguard relied on for that transfer has to be identified and documented — standard contractual clauses, an adequacy finding, or a derogation for the performance of a contract you asked for. This is
terms.md§20.6 and it is not settled.
6. How long we keep it
Documents and the verification file are kept for ten years. That is a deliberate commercial promise, stated on your receipt: a certificate is worth little if the file behind it has been deleted by the time anyone questions it.
Account and billing records are kept for as long as required by accounting and limitation rules.
Open point. A ten-year custody promise and the data-minimisation principle have to be reconciled explicitly, and the PDPA applies alongside the GDPR. This is
terms.md§20.7.
7. Your rights
You can ask for access to your data, correction of it, erasure, restriction of processing, portability, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time.
Two honest limits:
- erasure does not extend to what we must keep to invoice you, to meet accounting duties, or to defend a claim;
- the partner firm decides what its own professional file must contain, and those requests are made to the firm.
You can complain to your supervisory authority. In France that is the CNIL.
8. Automated decisions
The price you are offered follows a published grid applied to the facts you declare. It is a rule, not a profile, and it produces one of two outcomes: a fixed price, or a review by a person. Nothing about you is inferred, and nothing is scored.
9. Cookies and measurement
The site uses only the cookies needed to keep you signed in and to keep the service secure. There is no advertising and no cross-site tracking.
We measure how the public pages are used with Cloudflare Web Analytics. It counts page views and page-speed measurements. It sets no cookie, stores nothing in your browser, builds no profile and cannot follow you to another site. There is nothing here to consent to and nothing to opt out of, because nothing about you is retained — which is why this notice describes it plainly rather than putting a banner in front of it.
Open point. This must be verified against what is actually set in the browser before publication, not asserted.
10. Security
Uploaded documents are scanned for malware and quarantined until they pass. Access to a dossier is decided by role, and every action on it is recorded. Sign-in is by one-time link; staff accounts additionally require a second factor.
11. How to reach us
[To be completed: postal address of the controller, a contact email address for privacy requests, and whether a data protection officer is appointed and must be named.]
12. What must be settled before publication
Written down so nothing here is mistaken for a completed document.
- The controller's identity and address, and whether a DPO is required and appointed.
- The transfer to Thailand: which safeguard, documented how, and what is said about it here.
terms.md§20.6. - Ten-year retention against data minimisation, and the PDPA alongside the GDPR.
terms.md§20.7. - Controller or joint controller with the partner firm. This document says separate controllers; that follows from
terms.md§20.2 and must be confirmed with it, not separately. - The processor list verified against what is actually deployed, with a data processing agreement in place for each.
- The cookie claim in §9 verified against the browser, and a banner added if anything non-essential is set.
- Retention periods stated as durations for each category, rather than the two given here.
- WhatsApp, if commercial conversations continue there: whether those messages sit inside these undertakings, and what is told to a prospect about it.
terms.md§20.14. - The Thai PDPA notice requirements, which are not identical to the GDPR's and may require their own text for the firm's processing.