Privacy policy

Version 1.0 — in force as of 28 July 2026.

This English text is provided for convenience. The French version is the authoritative one and prevails in case of discrepancy.

1. Who we are, and who does what with your data

Cardasoft, a French simplified joint-stock company with a sole shareholder (SASU) with share capital of €5,000, registered with the Paris Trade and Companies Register under number 107 440 471, with its registered office at 48 rue Mstislav Rostropovitch, 75017 Paris, France (“Cardasoft”, “we”), publishes the Pélio app (the “App”), a management tool for self-employed service providers.

Cardasoft acts in two distinct capacities:

Cardasoft's role per data category
DataCardasoft's roleApplicable framework
Your data as a subscribing provider (account, e-mail, credentials, subscription data)ControllerThis policy
Your clients' data that you enter into the App (contact details, appointments)Processor — you are the controllerThe data processing agreement (GDPR art. 28) annexed to the Terms

Wide table: swipe it left to see every column.

In plain terms: for your account, we are the controller and this policy applies. For your clients' data, you are the controller: we act on your instructions. Your clients exercise their rights with you; the App gives you the means to answer them.

Contact: contact@pelio.app. Cardasoft is not required to appoint a data protection officer (GDPR art. 37: no large-scale processing of special categories of data, no systematic monitoring).

2. What data, for what purpose, on what legal basis

2.1 Your data as a subscribing provider (Cardasoft = controller)

Subscribing provider data
DataPurposeLegal basis (GDPR art. 6)Retention
E-mail, hashed password, Apple or Google sign-in identifier if you use itCreate and secure your account, authenticate youPerformance of the contract (6.1.b)Lifetime of the account
Name and professional details entered in your settingsIdentify you, sign your reminder SMSPerformance of the contract (6.1.b)Lifetime of the account
Subscription data (status, dates) passed on by the app storeManage your subscription and supportPerformance of the contract (6.1.b) + legal obligation (6.1.c) for the subscription invoiceAccount + 10 years for the subscription invoice (accounting obligation)
Minimal technical logs (errors, server calls)Run the service, prevent outagesLegitimate interest (6.1.f)Limited period

Wide table: swipe it left to see every column.

2.2 Your clients' data (Cardasoft = processor)

Summary; the detail is in the data processing agreement annexed to the Terms. The retention periods below are the App's defaults; you remain the controller.

Data of the provider's clients
DataPurposeRetention
First name, surname, phone number, address, access instructions (encrypted), appointment historyClient list, scheduling of jobs3 years after the last job
Phone number, first name, date and time of the appointmentTransactional SMS remindersPhone number tied to the client record; send logs kept for 1 year (proof of sending)

Wide table: swipe it left to see every column.

No special categories of data within the meaning of GDPR art. 9 are processed. Access instructions (door code, key location) are protected by additional application-level encryption.

3. Recipients and processors

Your data is never sold, rented or shared for advertising purposes. It is accessible to Cardasoft and to the following sub-processors:

Sub-processors
Sub-processorRoleLocation
OVH SAS (OVHcloud)Server and database hosting; SMS delivery; service e-mail delivery (address confirmation, password reset)France / European Union
Apple and GooglePayment of your subscription (Cardasoft never sees your card); “Sign in with Apple / Google” if you choose itUnited States — covered by standard contractual clauses and the EU–US data privacy framework

Wide table: swipe it left to see every column.

EU hosting: your clients' data stays in France and does not leave the European Union. Only the subscription payment and, where applicable, social sign-in go through Apple or Google.

No analytics, no trackers. The App contains no third-party analytics, no advertising SDK, no advertising identifier, and performs no cross-app tracking. No “App Tracking Transparency” prompt is therefore shown on iOS.

This website sets no cookies and makes no request to any third party: no remote fonts, no external scripts, no analytics. That is why it shows no consent banner — there is nothing to consent to.

4. How long we keep the data

  • Provider account: for the duration of the subscription, then deleted — except the invoice for your subscription, kept for 10 years (accounting obligation).
  • Client list: 3 years after the last job.
  • SMS send logs: 1 year.

Exercising the right to erasure (GDPR art. 17), whether for one client or for the whole account, anonymises or deletes operational data (client list, expired SMS logs). Expired data is purged automatically. Portability (art. 20) is served by a CSV export of one client or of everything, from within the App.

One exception remains for accounting reasons: if accounting records have been issued by the App, they are kept for 10 years in isolated archival storage, out of reach of any recreated account. The invoicing module is disabled in version 1 of the App, so in practice no such record is produced while it stays disabled.

5. Deleting your account

You can delete your account directly from the App, at any time, without going through support: the function is in your settings and asks for your password to confirm. Deletion erases your data and your clients' data, and immediately revokes all your sessions.

If you no longer have access to the App, write to contact@pelio.app: we will delete the account after verifying your identity.

6. Your rights

Under the GDPR you have, over your own data (provider account), the rights of access (art. 15), rectification (art. 16), erasure (art. 17), restriction (art. 18), portability (art. 20) and objection (art. 21), as well as the right to give post-mortem instructions under French law.

To exercise them: contact@pelio.app.

Are you a client of a professional who uses Pélio? Your rights are exercised with her: she is the controller. From the App she can view, correct and erase your data and stop the SMS reminders. If you cannot reach her, write to us and we will pass it on.

Complaints: you may lodge a complaint with the French data protection authority, the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.

7. Security

We implement measures in line with GDPR art. 32: encryption in transit (TLS) and at rest, additional application-level encryption of access instructions, hosting in the European Union, per-account isolation, hashed passwords (argon2id), encrypted backups, logging. In the event of a data breach, the procedures of art. 33 and 34 apply, with notification to the CNIL within 72 hours where required.

8. Changes

This policy may be updated. Any substantial change is notified in the App or by e-mail. The version in force is dated.

Version 1.0 — 28 July 2026. Related documents: Terms and their data processing annex (GDPR art. 28).