GDPR Compliance

Our commitment to personal data protection, beyond the strict legal framework.

Last updated: May 19, 2026

Data controller

The data controller is Zurab NATCHKEBIA, sole trader, SIRET 94235203000012, trading under the commercial name « Primpay ». In accordance with article 37 of the GDPR, the appointment of a Data Protection Officer is not required for this activity. The single point of contact for any question regarding data protection is reachable at privacy@primpay.fr.

Legal basis for processing

Processing is based on: (a) explicit consent of the end customer when signing up for a loyalty program (art. 6.1.a GDPR), (b) execution of the subscription contract for partner merchants (art. 6.1.b GDPR), (c) the publisher's legitimate interest in the technical security of the service — server logs (art. 6.1.f GDPR).

Categories of data processed

Identity data (first name, last name), contact data (email, phone), transaction data (visits, stamps, rewards), technical data (IP, user-agent, anonymized logs). No bank data, no health data, no sensitive data within the meaning of article 9 GDPR.

Hosting and location

All data is hosted within the European Economic Area: application servers on Vercel cdg1 region (Paris, France), database on Supabase eu-west-1 region (Ireland). No data transfer outside the EEA.

Subprocessors

The publisher uses the following subprocessors, all contractually committed by GDPR-compliant agreements: Vercel (application hosting), Supabase (database), Apple (Wallet API), Google (Wallet API), Resend (transactional email), Formspree (contact form).

Your GDPR rights

You have the following rights: access, rectification, erasure, limitation, opposition, portability, withdrawal of consent at any time. To exercise these rights, write to privacy@primpay.fr. Response guaranteed within 30 days.

Breach notification

In case of a data breach presenting a risk to your rights and freedoms, the publisher commits to notify the CNIL within 72 hours and inform you as soon as possible in accordance with article 34 of GDPR.

GDPR contact

GDPR point of contact: Zurab NATCHKEBIA — privacy@primpay.fr. You may also contact the CNIL via cnil.fr.