Privacy policy
Version 1.0 — in force as of 28 July 2026.
This English text is provided for convenience. The French version is the authoritative one and prevails in case of discrepancy.
1. Who we are, and who does what with your data
Cardasoft, a French simplified joint-stock company with a sole shareholder (SASU) with share capital of €5,000, registered with the Paris Trade and Companies Register under number 107 440 471, with its registered office at 48 rue Mstislav Rostropovitch, 75017 Paris, France (“Cardasoft”, “we”), publishes the Pélio app (the “App”), a management tool for self-employed service providers.
Cardasoft acts in two distinct capacities:
| Data | Cardasoft's role | Applicable framework |
|---|---|---|
| Your data as a subscribing provider (account, e-mail, credentials, subscription data) | Controller | This policy |
| Your clients' data that you enter into the App (contact details, appointments) | Processor — you are the controller | The data processing agreement (GDPR art. 28) annexed to the Terms |
Wide table: swipe it left to see every column.
In plain terms: for your account, we are the controller and this policy applies. For your clients' data, you are the controller: we act on your instructions. Your clients exercise their rights with you; the App gives you the means to answer them.
Contact: contact@pelio.app. Cardasoft is not required to appoint a data protection officer (GDPR art. 37: no large-scale processing of special categories of data, no systematic monitoring).
2. What data, for what purpose, on what legal basis
2.1 Your data as a subscribing provider (Cardasoft = controller)
| Data | Purpose | Legal basis (GDPR art. 6) | Retention |
|---|---|---|---|
| E-mail, hashed password, Apple or Google sign-in identifier if you use it | Create and secure your account, authenticate you | Performance of the contract (6.1.b) | Lifetime of the account |
| Name and professional details entered in your settings | Identify you, sign your reminder SMS | Performance of the contract (6.1.b) | Lifetime of the account |
| Subscription data (status, dates) passed on by the app store | Manage your subscription and support | Performance of the contract (6.1.b) + legal obligation (6.1.c) for the subscription invoice | Account + 10 years for the subscription invoice (accounting obligation) |
| Minimal technical logs (errors, server calls) | Run the service, prevent outages | Legitimate interest (6.1.f) | Limited period |
Wide table: swipe it left to see every column.
2.2 Your clients' data (Cardasoft = processor)
Summary; the detail is in the data processing agreement annexed to the Terms. The retention periods below are the App's defaults; you remain the controller.
| Data | Purpose | Retention |
|---|---|---|
| First name, surname, phone number, address, access instructions (encrypted), appointment history | Client list, scheduling of jobs | 3 years after the last job |
| Phone number, first name, date and time of the appointment | Transactional SMS reminders | Phone number tied to the client record; send logs kept for 1 year (proof of sending) |
Wide table: swipe it left to see every column.
No special categories of data within the meaning of GDPR art. 9 are processed. Access instructions (door code, key location) are protected by additional application-level encryption.
3. Recipients and processors
Your data is never sold, rented or shared for advertising purposes. It is accessible to Cardasoft and to the following sub-processors:
| Sub-processor | Role | Location |
|---|---|---|
| OVH SAS (OVHcloud) | Server and database hosting; SMS delivery; service e-mail delivery (address confirmation, password reset) | France / European Union |
| Apple and Google | Payment of your subscription (Cardasoft never sees your card); “Sign in with Apple / Google” if you choose it | United States — covered by standard contractual clauses and the EU–US data privacy framework |
Wide table: swipe it left to see every column.
EU hosting: your clients' data stays in France and does not leave the European Union. Only the subscription payment and, where applicable, social sign-in go through Apple or Google.
No analytics, no trackers. The App contains no third-party analytics, no advertising SDK, no advertising identifier, and performs no cross-app tracking. No “App Tracking Transparency” prompt is therefore shown on iOS.
This website sets no cookies and makes no request to any third party: no remote fonts, no external scripts, no analytics. That is why it shows no consent banner — there is nothing to consent to.
4. How long we keep the data
- Provider account: for the duration of the subscription, then deleted — except the invoice for your subscription, kept for 10 years (accounting obligation).
- Client list: 3 years after the last job.
- SMS send logs: 1 year.
Exercising the right to erasure (GDPR art. 17), whether for one client or for the whole account, anonymises or deletes operational data (client list, expired SMS logs). Expired data is purged automatically. Portability (art. 20) is served by a CSV export of one client or of everything, from within the App.
One exception remains for accounting reasons: if accounting records have been issued by the App, they are kept for 10 years in isolated archival storage, out of reach of any recreated account. The invoicing module is disabled in version 1 of the App, so in practice no such record is produced while it stays disabled.
5. Deleting your account
You can delete your account directly from the App, at any time, without going through support: the function is in your settings and asks for your password to confirm. Deletion erases your data and your clients' data, and immediately revokes all your sessions.
If you no longer have access to the App, write to contact@pelio.app: we will delete the account after verifying your identity.
6. Your rights
Under the GDPR you have, over your own data (provider account), the rights of access (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20) and objection (art. 21), as well as the right to give post-mortem instructions under French law.
To exercise them: contact@pelio.app.
Are you a client of a professional who uses Pélio? Your rights are exercised with her: she is the controller. From the App she can view, correct and erase your data and stop the SMS reminders. If you cannot reach her, write to us and we will pass it on.
Complaints: you may lodge a complaint with the French data protection authority, the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
7. Security
We implement measures in line with GDPR art. 32: encryption in transit (TLS) and at rest, additional application-level encryption of access instructions, hosting in the European Union, per-account isolation, hashed passwords (argon2id), encrypted backups, logging. In the event of a data breach, the procedures of art. 33 and 34 apply, with notification to the CNIL within 72 hours where required.
8. Changes
This policy may be updated. Any substantial change is notified in the App or by e-mail. The version in force is dated.
Version 1.0 — 28 July 2026. Related documents: Terms and their data processing annex (GDPR art. 28).