Privacy policy
Last updated: 22 July 2026
This policy sets out what data GetAff collects, why, how long it is kept and what rights you can exercise. It is written to be read, not to be waved at you.
Data controller
[Raison sociale à compléter], [Adresse à compléter]. Contact: [email protected].
For any question about your data, write to that address. We answer within one month.
Data we collect
Account: email address, display name and a technical identifier, provided by you or by Google at sign-in. Legal basis: performance of the contract.
Listed programs: the information you enter about your program, including a contact address that is never published. Legal basis: performance of the contract.
Analyses: the addresses of the sites you analyse and the results produced, kept so you can find them again. Legal basis: performance of the contract.
Technical logs: IP address, user agent and request timestamps, retained by the host for security and diagnostics. Legal basis: legitimate interest.
What we do not do
No advertising trackers, no social pixels, no data resale, no profiling for advertising purposes.
The only cookie we set is the session cookie, strictly necessary for sign-in to work. It does not require prior consent.
Processors
Google Cloud / Firebase: hosting, authentication and database, within the European Union.
Google Vertex AI: analysis engine. The content of pages you submit is sent to it to produce the analysis. It is not used to train any model.
Cloudflare: delivery and network protection.
Stripe: payments, if you subscribe. We never see your card number.
Retention
Account and programs: for as long as the account exists, then deleted immediately on closure.
Analyses: kept with the account, deleted with it.
Technical logs: retained by the host under its own schedule, in the order of a few weeks.
Your rights
Access, rectification, erasure, restriction, objection and portability.
Two of these are available immediately from your dashboard, without writing to us: export your data produces a complete file, delete your account permanently erases everything.
You may lodge a complaint with your national data protection authority.
Transfers outside the European Union
Hosting and the database are located in the European Union. Some processors may access data from third countries as part of their support operations, under the European Commission standard contractual clauses.
Security
Encryption in transit and at rest, database access restricted to the application service account, no direct client access, and logging of administrative actions.