Privacy policy
Last updated: 25 April 2026
This privacy policy describes how Corely.me (SIREN 894 108 059) (hereinafter “Corely”, “we”) collects, uses and protects your personal data in connection with your use of the corely.me website and the Corely SaaS platform (hereinafter the “Service”).
This policy complies with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679; RGPD in French) and with amended French Law No. 78-17 of 6 January 1978 (loi « Informatique et Libertés »).
1. Data controller
The data controller is Corely.me (SIREN 894 108 059), whose contact details are set out in the legal notice.
For data processed on behalf of our business customers(multi-tenancy), Corely acts as a processor within the meaning of Article 28 of the GDPR. The terms are set out in our data processing agreement (DPA).
2. Data Protection Officer (DPO)
For any question regarding the processing of your data, you may contact our DPO:
- Email: contact@corely.me
- Postal address: 4, rue Copernic, 59700 Marcq-en-Baroeul, France
3. Data collected
3.1 Data you provide to us
- Sign-up: first name, last name, business email, password, organisation, country.
- Profile: telephone number, language, time zone, photo (optional).
- Billing: company name, SIRET number, EU VAT number, billing address, IBAN/BIC where applicable.
- SSO authentication: Google or Microsoft Azure AD identifier (link to your third-party account, without access to your password).
- 2FA authentication: TOTP OTP secret (encrypted).
3.2 Technical data collected automatically
- IP address, browser type and version, operating system.
- Pages visited, session duration, API requests.
- Audit logs: actions performed on the platform (creation, modification, deletion).
3.3 Data collected through third parties
- Bridge (PSD2): banking information (transactions, balances) if you enable bank synchronisation.
- Coinbase CDP: crypto addresses and balances if you enable crypto payments.
- Google / Microsoft: OAuth profile if you use SSO.
4. Purposes and legal bases
| Purpose | Legal basis | Retention period |
|---|---|---|
| Provision of the Service (account, subscription, modules) | Performance of the contract | Term of the contract + 3 years |
| Invoicing and accounting obligations | Legal obligation (Art. L123-22 of the French Commercial Code — Code de commerce) | 10 years |
| Security, fraud prevention, audit logs | Legitimate interest | 1 year (configurable up to 7 years) |
| Product communications (newsletters, updates) | Consent | Until unsubscription |
| Aggregated usage statistics | Legitimate interest | 2 years |
| Response to a contact or support request | Legitimate interest / Consent | 3 years after the last interaction |
5. Recipients of the data
Your data is accessible only to the following persons:
- Authorised Corely personnel, who are bound by a duty of confidentiality.
- Our processors (hosting, email delivery, payment) listed below.
- The competent authorities in the event of a lawful request.
Main processors
| Processor | Purpose | Location |
|---|---|---|
| OVH SAS | Infrastructure hosting | France (Roubaix) |
| Bridge SA | PSD2 bank synchronisation | France |
| Coinbase Inc. (CDP) | Crypto wallets | United States (DPF) |
| Stripe | Subscription payments | Ireland / United States (DPF) |
6. Transfers outside the EU
Your data is stored in datacenters located in France (EU). Certain processors may process data in the United States under the EU-U.S. Data Privacy Framework. No transfer is made to a third country that does not provide an adequate level of protection.
7. Your rights
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of the data concerning you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): delete your data, unless a legal obligation provides otherwise.
- Right to restriction: temporarily suspend processing.
- Right to data portability: retrieve your data in a structured format (CSV/JSON export).
- Right to object: refuse certain processing (direct marketing, profiling).
- Right to withdraw your consent at any time.
- Right to set post-mortem instructions regarding the fate of your data after your death.
To exercise these rights, contact dpo@corely.me. A response will be provided within one month (which may be extended to three months for complex requests).
If you disagree, you may lodge a complaint with the CNIL (French data protection authority — Commission nationale de l'informatique et des libertés): www.cnil.fr.
8. Security
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Passwords hashed with bcrypt (12 rounds).
- Multi-factor authentication (TOTP) available.
- Comprehensive audit logs, traceability of access.
- Encrypted daily backups, retained for 30 days.
9. Cookies
The cookies used on the website are described in our cookie policy.
10. Changes
We reserve the right to amend this policy. Any material change will be notified to you by email or via the platform at least 30 days before it takes effect.