1. Who we are (Data Controller)
European Trader is the data controller for personal data collected through the Promptissimo service.
- Company registered with R.C.S. Paris (France), number 109 279 836
- Registered office: 173 rue de Courcelles, 75017 Paris, France
- Data Protection contact: [email protected]
2. What data we collect
2.1 Data you give us directly
- Account data: first name, last name, email address, password (encrypted), profile picture (optional);
- Billing data: billing address, company name, VAT number, Company Number (if applicable);
- Payment data: processed entirely by Stripe β we never see or store your card details;
- Communications: the content of any email, message or support request you send us;
- Community content: posts, comments and contributions in the community space.
2.2 Data collected automatically
- Usage data: pages visited, modules completed, search queries, time spent;
- Technical data: IP address (truncated), browser, OS, device type;
- Cookies: see our Cookie Policy for details.
3. Why we use your data (Legal Bases)
| Purpose | Legal basis | Retention |
|---|---|---|
| Provide the Service (account, content access) | Contract performance | Duration of subscription + 30 days |
| Billing & payment | Contract + legal obligation | 7 years (HMRC requirement) |
| Send service emails (welcome, billing, updates) | Contract performance | Duration of subscription |
| Send marketing emails | Consent (opt-in) | Until you unsubscribe |
| Analytics & service improvement | Legitimate interest | 25 months (aggregated) |
| Respond to your requests | Legitimate interest | 3 years |
| Fraud prevention & security | Legitimate interest + legal obligation | As needed |
4. Who has access to your data (Processors)
We share your data only with carefully selected service providers acting as data processors:
- Stripe Payments Europe Ltd (Ireland) β payment processing;
- Brevo (France) β transactional & marketing emails;
- Amazon Web Services (Ireland) β hosting (Frankfurt region for EU/UK data);
- Plausible Analytics (Germany) β privacy-friendly analytics;
- Intercom (Ireland) β customer support chat (only if you initiate a conversation).
All processors are bound by data processing agreements (Article 28 UK GDPR) and offer appropriate safeguards. None of them sell or use your data for their own purposes.
International transfers
Most of our processors are based in the EU/EEA, which is covered by an adequacy decision. Where transfers outside the UK or EU occur (e.g. to the US via Stripe), they are governed by Standard Contractual Clauses approved by the ICO.
5. Your rights (UK GDPR)
You have the following rights regarding your personal data:
- Right of access β request a copy of the data we hold about you;
- Right to rectification β correct inaccurate or incomplete data;
- Right to erasure ("right to be forgotten") β request deletion of your data, subject to legal retention requirements;
- Right to restrict processing β limit how we use your data in certain situations;
- Right to data portability β receive your data in a machine-readable format;
- Right to object β object to processing based on legitimate interest, including marketing;
- Right to withdraw consent β withdraw consent at any time (without affecting prior processing);
- Right not to be subject to automated decision-making β we do not use automated decision-making with legal effects.
To exercise any of these rights, email [email protected]. We will respond within one month (extendable to three months for complex requests, with explanation).
6. Right to complain
If you believe we have not handled your data appropriately, you can lodge a complaint with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint
We'd encourage you to contact us first so we can try to resolve any concern directly.
7. Security
We implement appropriate technical and organisational measures to protect your data, including:
- TLS 1.3 encryption for all data in transit;
- AES-256 encryption at rest;
- Passwords hashed with bcrypt (never stored in plain text);
- Two-factor authentication available for all accounts;
- Daily encrypted backups, retained for 30 days;
- Strict access controls based on need-to-know;
- Regular security audits and penetration testing.
In the unlikely event of a personal data breach affecting your rights, we will notify the ICO within 72 hours and inform you directly if the breach is likely to result in a high risk.
8. Children
The Service is not intended for persons under 18. We do not knowingly collect personal data from minors. If you are a parent/guardian and believe your child has provided personal data, please contact us so we can delete it.
9. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified to you by email at least 30 days before they take effect.
10. Contact
For any question about this policy or how we handle your data:
European Trader
Data Protection contact
173 rue de Courcelles,
75017 Paris, France
Email: [email protected]