Privacy policy
Last updated: 2026-09-07
This policy explains what personal data Cultural Real Estate Audit collects, why, who it is shared with, and how to exercise your rights.
Who is responsible for your data?
The data controller is Editions Neftis Limited, a private company limited by shares incorporated in Ireland, registered under number 657742 (Companies Registration Office, Irlande), tax reference 3653014JH.
Registered office: Unit 3D North Point House, North Point Business Park, Old Mallow Road, Cork T23AT2P, République d'Irlande. Business address: Moulin de Sainte Catherine, 44430 La Remaudière, France.
Contact for any question about your personal data: audit@bnm-consulting.eu.
No Data Protection Officer (DPO) has been appointed: GDPR article 37 does not require one for an activity of this size, which involves neither large-scale systematic monitoring of individuals nor large-scale processing of special category data. Any question about your data should be sent to the contact above.
Account data
An account can be created in two ways: by email and password, or by signing in with Google (OAuth 2.0 / OpenID Connect).
- Email account: your email address, and a password that is never stored in clear text - only its cryptographic hash (Argon2 algorithm) is kept, which cannot be reversed back into the original password.
- Google account: your unique Google identifier (“sub”), email address, name, and profile photo, sent by Google with your consent when you sign in. No password is requested or stored for this sign-in method.
You can link both methods to the same account, or use only one, from the “My account” page.
Content you submit to us
To produce an audit, you send us the content of the property listing to be analysed: its address or public URL, the written descriptions, and the photographs of the property it contains. This content is processed only for as long as needed to produce the audit you requested.
Technical data
On every visit, we record technical data necessary for the operation and security of the service: server logs (date and time of the request, page visited, response code), IP address, browser identifier (user-agent), and the session cookie described below.
Why do we process this data, and on what legal basis?
- Creating and managing your account, authentication, providing the audit service - performance of the contract with you (GDPR article 6.1.b).
- Billing and tracking audit credits/quotas - performance of the contract (article 6.1.b).
- Service security: server logs, lockout after repeated failed logins, security headers - legitimate interest in protecting the service and its users against fraud and unauthorised access (article 6.1.f).
- Sending emails strictly necessary for the account (signup confirmation, password reset) - performance of the contract (article 6.1.b).
- Optionally signing in with Google - consent given when you click “Continue with Google” (article 6.1.a), which you can withdraw at any time by unlinking that provider from “My account” (provided you have set a password so as not to lose access to your account).
Use of artificial intelligence models
Generating audits (diagnosis, rewriting, sales brief) relies on third-party artificial intelligence models, to which we send the content you submit: written descriptions and photographs of the property. Depending on the provider used for your audit, this processing may involve transferring this data outside the European Union:
- Anthropic PBC (Claude models), United States - processing takes place in the United States; this transfer outside the European Union is governed by the standard contractual clauses adopted by the European Commission.
- Alibaba Cloud (Qwen model) - processing takes place on Alibaba Cloud's European infrastructure (eu-central-1 region, Frankfurt, Germany): your data therefore does not leave the European Union for this provider. Alibaba Cloud offers its customers an EEA Data Processing Addendum, incorporated into its master agreement, which includes the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914). As the Alibaba group's parent company is registered in China, a residual risk of access by a foreign authority cannot be entirely ruled out in principle, regardless of where the technical processing takes place. The account used in production falls under Alibaba Cloud's international master agreement (alibabacloud.com), rather than a separate mainland-China Aliyun account under different terms: this addendum therefore does apply to the processing described here.
Anthropic PBC states in its Commercial Terms of Service (“Customer Content” section) that it does not train its models on content submitted by customers through the API. Alibaba Cloud likewise states in the Model Studio FAQ that it will never use customer data to train its models. None of your content is therefore used by these providers beyond processing your request.
Other recipients
- OVH Limited (30 Old Bailey, London, EC4M 7AU, Royaume-Uni): technical host of the application and database.
- The webmaster of your own site, only if you yourself trigger the “Send to webmaster” function from an audit, at the address you entered in “My account”.
We do not sell or rent your personal data to third parties for commercial or advertising purposes.
Retention periods
- Account data (email, hashed password, Google identifier, profile details): for the entire lifetime of the account, then deleted within a reasonable period after its deletion.
- Audit content (analysed listings, photos, generated reports): for the entire lifetime of the account, unless you delete it individually; deleted along with the account.
- Server logs and technical security data: 12 months, a usual duration allowing after-the-fact security investigation without excessive retention. Automatic rotation (monthly purge, 12 months kept) is configured on the server to enforce this duration.
- Activation and password-reset tokens: limited validity (a few hours), deleted after use or expiry.
Your rights
Under the GDPR, you have the following rights over your personal data:
- right of access: obtain a copy of the data we hold about you;
- right to rectification: correct inaccurate or incomplete data;
- right to erasure: request deletion of your data, subject to legal retention obligations;
- right to portability: receive your data in a structured, commonly used format;
- right to object and right to restriction of processing, in the cases provided for by the GDPR.
To exercise these rights, write to us at audit@bnm-consulting.eu. We reply within one month, possibly extended by two months for complex requests.
If you believe your rights are not being respected, you can lodge a complaint with the lead supervisory authority, the Data Protection Commission (DPC) of Ireland (the publisher's country of establishment), 6 Pembroke Row, Dublin 2, D02 X963, Irlande (www.dataprotection.ie). If you live in another EU country, you can also contact your own country's data protection authority - for example, in France, the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (www.cnil.fr).
Cookies
This site does not use any audience-measurement, advertising or tracking cookies. Only two cookies strictly necessary for the service are set:
| Cookie | Purpose | Duration |
|---|---|---|
| uilang | Remembers the interface language chosen before signing in. | Browser session (deleted when the browser is closed) |
| sid (or the name configured for this instance) | Keeps you signed in. | Browser session; the server-side session it refers to expires after 60 minutes of inactivity and at most 12 hours after sign-in |
As these cookies are strictly necessary for the service you requested, they do not require prior consent under applicable cookie regulation.
Data security
- encrypted connections over HTTPS with an HSTS header;
- passwords hashed with Argon2, never stored in clear text;
- session cookies marked Secure, HttpOnly and SameSite;
- security headers (Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy) applied to every response;
- temporary account lockout after several consecutive failed sign-in attempts;
- strict data isolation between accounts: no user can access another account's audits.
In the event of a data breach
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the Commission Nationale de l'Informatique et des Libertés (CNIL) within 72 hours of becoming aware of it, in accordance with GDPR article 33. If the risk to you is high, we also inform you directly, without undue delay, in accordance with article 34.
Changes to this policy
This policy may be updated, in particular to follow changes to the service or to the law. The date of the last update appears at the top of this page. In the event of a substantial change, we will inform you by reasonable means (a banner on the site or an email).