How Slaane collects, uses and protects your personal data.
Last updated: [21/11/2025]
This Privacy Policy explains how Slaane SAS and its affiliates (“Slaane”, “we”, “us” or “our”) collect, use, disclose and protect personal data when you use our booking platform (the “Platform”), or interact with us offline (including by email or phone). It describes users’ rights and how to exercise them, the legal bases for processing personal data under the EU General Data Protection Regulation (“GDPR”), and the measures we take to safeguard personal data.
This Policy applies to:
individuals who use the Platform to request or receive booking services (“Clients”);
independent concierges/bookers providing services through the Platform (“Bookers”);
visitors to our websites and mobile apps; and
other individuals whose personal data we process in connection with our business.
If you are located outside the EEA, this Policy also explains international data transfers and safeguards.
Slaane SAS
Registered at: Slaane 992 077 743
Registered office: 110 RUE de Fontenay 94300 Vincennes France
Data Protection Officer (DPO) and other data related matters: frederick@slaane.com
If you require an EU Representative under Article 27 GDPR, insert details here: frederick@slaane.com.
We collect and process personal data necessary to operate the Platform, provide services, comply with legal obligations, and improve our services. Categories include:
A. Client data
Identity: name, title, profile photo, date of birth (if required).
Contact: email, phone, postal address.
Payment & billing: payment method details, transaction history, invoices.
Service data: booking requests, preferences, messages with Bookers, ratings & reviews.
Usage data: cookies, device identifiers, IP address, browser type, geolocation where provided.
B. Booker data
Identity & credentials: name, business name, professional status (SIRET, URSSAF or equivalent), ID documents for KYC.
Financial: bank details (RIB/IBAN) for commission payments, payout history.
Service delivery records: services offered, schedules, communications, reviews.
Compliance records: contract, onboarding documentation, tax and insurance status (if provided).
C. Technical & analytics data
Device and connection data (IP address, device type, OS, browser).
Log data, error reports and performance metrics.
Cookies and similar technologies (see Section 10).
D. Special categories & derived data
We generally do not collect special categories of personal data (sensitive data). If sensitive data is supplied (e.g., health data to arrange a medical appointment), we will process only if lawful and with explicit consent or other appropriate lawful basis. We may also process derived data (aggregated or pseudonymised analytics).
We process personal data only where we have a lawful basis under the GDPR:
Performance of a contract (Art. 6(1)(b)): to provide the Platform and concierge services, billing, payouts, dispute resolution.
Legal obligation (Art. 6(1)(c)): record retention for tax, anti-money laundering (KYC), accounting and regulatory compliance.
Legitimate interests (Art. 6(1)(f)): fraud prevention, Platform improvement, security, enforcing our Terms of Service — balanced with user rights and freedoms.
Consent (Art. 6(1)(a)): for marketing communications, non-essential cookies, and other optional processing where we request consent (clear opt-in).
Vital interests or public interest only if strictly necessary and rare.
For each data category and purpose, we document the legal basis in our internal Records of Processing.
We process personal data for the following purposes:
Platform operation & service delivery. Registering accounts, matching Clients with Bookers, facilitating bookings, communications, payments and refunds, and handling cancellations.
Payment & payouts. Processing payments (we use Stripe) and paying Bookers (commission model: Slaane retains a commission as set out in the contractual terms).
KYC, fraud prevention & risk management. Identity verification, anti-fraud scoring, sanctions checks and dispute resolution.
Customer support. Responding to inquiries, handling complaints and claims, and quality control.
Marketing & commercial communications. Newsletters and offers where consented (you may opt out at any time).
Analytics & product improvement. Aggregated, pseudonymised analytics to improve Platform performance.
Legal & regulatory compliance. Retention for tax, accounting, anti-money laundering obligations and court orders.
Safety & enforcement. Protection of our users, enforcement of Terms, and prevention of misuse.
We may use automated systems (including scoring algorithms) to assist with fraud detection, trust & safety assessments, and matchmaking. Where automated decision-making produces legal or similarly significant effects on an individual, we will provide meaningful information about the logic involved, the significance and envisaged consequences, and offer the right to human review where required by law.
A formal Data Protection Impact Assessment (DPIA) has been completed for high-risk processing such as algorithmic scoring / profiling. Summary of DPIA findings and mitigations are available on request to the DPO.
We and our partners use cookies and similar technologies:
Strictly necessary cookies — required for core Platform functionality (session cookies, authentication). No consent required.
Preference and statistics (analytics) cookies — used to measure and improve performance; require user consent.
Marketing and advertising cookies — used for targeted advertising (e.g., Facebook Pixel); require opt-in consent.
Cookie consent is managed through a consent management platform (e.g., Cookiebot). You can change cookie settings at any time via the cookie banner or browser settings. More details are in our Cookie Notice (appendix).
We only share personal data with third parties when necessary and under contractual safeguards:
Payment processor: Stripe (payouts and payment processing). Stripe’s processing is governed by Data Processing Addendum and Standard Contractual Clauses (SCCs) where applicable.
Cloud hosting & infrastructure: Google Cloud Platform (or other designated provider) for hosting, backups and infrastructure.
Email & communication providers: (e.g., SendGrid, Twilio) for transactional emails and SMS.
Analytics & performance: (e.g., Google Analytics) when consent is provided.
Legal & compliance service providers: external counsel, auditors, fraud prevention services, tax advisors.
Law enforcement or judicial authorities where required by law.
A current list of subprocessors, their purposes and locations is maintained and available on request. We execute written contracts with subprocessors imposing GDPR-equivalent obligations.
Personal data may be processed outside the European Economic Area (EEA), including countries that do not have an adequacy decision (e.g., United States). Where transfers occur, we implement appropriate safeguards such as:
EU Standard Contractual Clauses (SCCs) approved by the European Commission; and/or
Adequacy decisions where applicable; and/or
Additional technical, contractual and organisational measures (encryption, access controls).
For transfers to service providers located in the US (e.g., Stripe, Google), SCCs or equivalent safeguards are in place. Details about transfers and safeguards are available from the DPO.
We retain personal data only as long as necessary for the purposes listed and in compliance with applicable law. Typical retention periods:
Account data and service records: 3 years after last activity (or as required by legitimate interest/contract).
KYC and onboarding documents for Bookers: 5 years after end of contractual relationship (anti-fraud/AML obligations).
Payment and financial records: 10 years for tax and accounting obligations.
Support tickets and communications: retention based on operational need (generally 3 years).
Logs and security monitoring: retained for security and forensic purposes (generally 6–24 months depending on type).
We anonymise or delete data when retention periods expire unless continued retention is required by law.
We implement state-of-the-art technical and organisational measures appropriate to the risk, including:
Encryption of sensitive personal data at rest and in transit (industry standard such as AES-256 / TLS).
Access controls and role-based permissions; multi-factor authentication for employee access.
Regular security testing and vulnerability assessments (penetration testing).
Logging, monitoring and incident response procedures.
Employee training and confidentiality agreements.
In the event of a personal data breach, we will notify supervisory authorities (e.g., CNIL) within 72 hours when required, and affected individuals where there is a high risk to their rights and freedoms.
Under GDPR, individuals have the following rights (subject to legal conditions and exceptions):
Right of access to the personal data we hold about you (Art. 15).
Right to rectification of inaccurate or incomplete data (Art. 16).
Right to erasure (“right to be forgotten”) in certain circumstances (Art. 17).
Right to restriction of processing (Art. 18).
Right to data portability to receive a copy of data in a structured, commonly used machine-readable format (Art. 20).
Right to object to processing based on legitimate interests or direct marketing (Art. 21).
Right not to be subject to solely automated decisions with legal or similarly significant effect; right to human intervention, explanation and contestation where applicable (Art. 22).
Right to withdraw consent at any time for processing that relies on consent.
To exercise a right, contact: dpo@slaane.com or send mail to [Company address]. Provide a copy of an identity document and specify the request. We respond within one month, which may be extended by two months for complex requests; we will inform you of any extension.
We will not charge a fee for standard requests; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse them.
If you are dissatisfied with our response, you have the right to lodge a complaint with a supervisory authority. In France: CNIL (Commission Nationale de l’Informatique et des Libertés). Contact details: www.cnil.fr.
Our Platform is not intended for children under the age of 16 (or the applicable age of consent in your country). We do not knowingly collect personal data from children below that age. If you believe we have collected data from a minor, contact us and we will delete it where appropriate.
We may update this Privacy Policy to reflect changes in our practices or legal obligations. Where changes are material, we will inform registered users by email at least 30 days prior to the change, and we will publish the updated date at the top of this Policy.
15. Annex — Practical Details (templates & operational notes)
A. Subprocessor register (example entries)
Stripe, USA — Payment processing — SCCs in place.
Google Cloud, EU/US — Hosting & backups — SCCs / adequacy measures.
Cookie management provider (e.g., Cookiebot), EU — Consent management.
(Full register maintained and available on request.)
B. Record of Processing (high level)
Processing activity: Booking & payment processing — lawful basis: contract.
Processing activity: KYC checks — lawful basis: legal obligation.
Processing activity: Marketing — lawful basis: consent.
C. Data Protection Impact Assessment (DPIA)
A DPIA has been prepared covering:
Automated scoring & profiling for fraud detection and trust assessment;
International transfers to non-EEA subprocessors;
Storage of KYC documents.
Summary of mitigation measures: limited access, encryption, retention minimisation, monitoring and review cycles. Full DPIA summary available on request.
Data Processing: Bookers acknowledge and consent that Slaane acts as Data Controller for platform operations and may share Bookers’ personal data with payment processors and necessary subprocessors.
KYC & Identity Documents: Bookers must provide identity documents and financial details; Bookers authorize Slaane to process these and to retain them for compliance.
Security & Confidentiality: Bookers shall maintain confidentiality and will not transfer or disclose Client personal data except through the Platform’s authorised flows.
Compliance: Bookers warrant to comply with local tax & labour obligations and to provide accurate professional status information.