Legal

Privacy Policy

Last updated: 25 June 2026

This Privacy Policy explains how Charles Tour (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you use our public website and connected workspace (the “Service”). It is designed to comply with the EU General Data Protection Regulation (GDPR) and applicable national laws.

1. Data controller

Codfert Ventures (SIREN 942321324), 15 route d'Avignon, 13210 Saint-Rémy-de-Provence, France, publisher of the Charles Tour Service.

Full publisher identity, contact details, and hosting information are set out in our Legal Notice: https://charlestour.com/en/legal-notice.

For any question about your personal data or your rights: contact@charlestour.com.

2. Scope

This policy applies to marketing site visitors, account holders, invited organization members, and users of the /space workspace (planning, team, documents, and optional Charles Bot mail connection).

It does not cover third-party websites or services we link to (for example Google’s sign-in page when you connect Gmail).

3. Data we process

Depending on how you use the Service, we may process the following categories of data:

  • Account and identity data: name, email address, technical identifiers, password (stored hashed).
  • Tour-related professional data: organization, role, dates, venues, contacts, travel, hotels, documents and attachments you import or enter.
  • Mail connection data (Charles Bot, optional — Gmail OAuth or IMAP): connected mailbox address, metadata and content of messages analyzed read-only to detect tour-relevant confirmations, related attachments, encrypted tokens or credentials. Nothing is added to planning without your explicit approval.
  • Technical data: server logs, IP address, browser type, timestamps, security and diagnostic events.
  • Support and correspondence: emails exchanged with our team.

4. Purposes of processing

We use your data for the following purposes:

  • Provide, maintain, and improve the Service (authentication, collaboration, planning, imports).
  • Deliver features you request, including mail sync and assisted extraction of travel information.
  • Secure the Service, prevent fraud, and handle incidents.
  • Send transactional communications (account validation, password reset, team invitations).
  • Comply with legal obligations and respond to competent authorities.
  • Measure aggregated usage and fix issues, while respecting your rights.

5. Legal bases

Under the GDPR, our processing relies in particular on: performance of a contract or pre-contractual steps (account creation, Service delivery); our legitimate interests (security, product improvement, support); your consent where required by law (for example Gmail OAuth or non-essential cookies); compliance with legal obligations.

6. Recipients and subprocessors

Your data is accessible to authorized members of our team, strictly on a need-to-know basis.

We use service providers acting as processors (hosting, transactional email, Gmail OAuth, mapping, CDN). Detailed hosting information is available in our Legal Notice: https://charlestour.com/en/legal-notice.

These providers process your data only on our documented instructions and under data protection agreements where required.

We do not sell your personal data.

7. Retention periods

Account data is kept for the duration of your contractual relationship, then archived or deleted according to legal obligations and legitimate proof needs.

Ingested mail messages and attachments are subject to a configurable retention policy on our servers; after the defined period they are removed from active systems.

Technical logs are kept for a limited time, proportionate to security and diagnostic purposes.

8. Security

We implement appropriate technical and organizational measures: encryption of sensitive secrets (including mail OAuth tokens), access control, environment separation, backups, monitoring.

No measure provides absolute security. If a breach is likely to affect your rights, we will notify authorities and, where required, affected individuals in accordance with applicable law.

9. Your rights

Subject to GDPR conditions, you have rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw consent at any time where processing is consent-based.

To exercise your rights, email contact@charlestour.com. We may request reasonable proof of identity.

You may also lodge a complaint with your local supervisory authority (in France: CNIL, www.cnil.fr).

10. Cookies and similar technologies

Our site and app may use cookies or local storage strictly necessary for operation (session, appearance preferences, language).

When non-essential cookies or analytics are introduced, we will collect your prior consent through a compliant banner and update this policy.

11. Transfers outside the European Union

Some subprocessors may process data outside the European Economic Area. In that case we ensure appropriate safeguards (EU Standard Contractual Clauses, adequacy decisions, or equivalent measures).

12. Minors

The Service is aimed at live entertainment professionals and is not intended for persons under 16. We do not knowingly collect data from minors.

13. Changes to this policy

We may update this policy to reflect changes to the Service or the law. The last updated date appears at the top. For material changes, we will notify you by an appropriate means.

14. Contact

Questions about this policy or your personal data: contact@charlestour.com.