1. Who is responsible for your data?
DJIDJELLI, entreprise individuelle (EI), based in 04000 Digne-les-Bains, publishes Apportly. Data protection contact: Clarisse Djidjelli, who can be reached at clarisse@apportly.app.
Apportly acts in two distinct roles:
- Processor for the data that each customer organisation manages in its workspace: its network of referrers, referred leads, messages, contracts and commissions. The organisation is the controller for this processing and Apportly carries it out on its instructions, under the data processing agreement.
- Controller for its own relationships: user accounts and security, billing, demo and contact requests, sign-up reminders and product information, as well as the Carte app customer account described below.
If an organisation has invited you, recorded your referral or contacted you through its app, contact that organisation first: its name appears in the app, on its website and in its emails, and its own privacy policy is published on its website.
2. Data processed for customer organisations
To provide the service, Apportly hosts and processes the following for each organisation:
- Network members: identity, contact details, company, individual contract and its acceptance, commissions and rewards, messages and posts.
- Referred leads: identity, contact details, need, stages, amounts, comments and the referrer’s declaration confirming that they have informed the person.
- Organisation users: account, role, referrers they manage and action history.
The organisation determines the legal basis for this processing and informs individuals of it in its own privacy policy, which it publishes on its website before any referrer registration or invitation.
When a lead is referred and their email address is known, an information email may be sent to them on behalf of the organisation: it states who passed on their contact details, why and for how long, and contains an objection link. An objection anonymises the record and adds the person to the organisation’s objection list, which prevents any new referral concerning them.
3. Processing carried out by Apportly for its own purposes
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure your account | Name, email, password hash, second factor, sessions, IP address, browser and security logs | Performance of the contract; legitimate interest in securing the platform |
| Bill subscriptions | Organisation, payer’s email and address, subscription history and payment references | Performance of the contract; legal accounting obligation |
| Organise demos | Name, email, phone number, company, notes and chosen time slot | Pre-contractual steps taken at your request |
| Respond to contact form submissions | Name, email, company, reason and message | Legitimate interest in responding to requests received |
| Support a sign-up in progress | Business email, answers, logo, public company identity and reminders sent | Legitimate interest in facilitating a sign-up you have started |
| Inform customers about the product | Name, email and organisation | Legitimate interest for customers; consent where required by law |
| Diagnose and fix the service | Technical logs and errors, with no audience measurement tools or advertising | Legitimate interest in providing a reliable service |
When you book a demo and our calendar is connected, a Google Calendar event, with its Google Meet link, is created with your name, email, company and notes. It is deleted along with your request.
The contact form reaches us by email: it is not stored in the platform’s database.
When you start signing up, your email and answers are saved in a draft so that you can resume later. If your sign-up remains incomplete, you receive no more than two reminders; each one contains an unsubscribe link that stops them. If your workspace is created without the subscription being activated, a reminder is sent to you thirty minutes later, then a final reminder one working day later.
During sign-up, the name or SIREN number you enter is sent to the public Recherche d’entreprises directory (recherche-entreprises.api.gouv.fr), which also receives your browser’s IP address. The public information returned, such as the company name, address and directors, pre-fills the company profile.
4. Carte app
Carte is the digital loyalty card app that Apportly offers to merchants and their customers.
- Apportly is the controller for the Carte customer account and the shared app: account creation, cards held, preferences, notifications and security.
- Each merchant is the controller for the data of its loyalty programme: the card held with that merchant, points, visits, benefits and referrals. Apportly processes this data on its behalf. The merchant sees the names of the customers who hold its card.
Data processed: name, email, cards, points, visits, benefits used, referrals, notification token and agreement to receive offers from merchants, which is off by default. Legal bases: performance of the Carte terms of use, and consent for offers. This data is retained for as long as the account is open; closing the account deletes the Carte profile and the associated cards.
5. AI connector
An organisation can allow its authorised users to connect an external AI assistant compatible with the MCP protocol to its workspace. Only an owner or administrator of the organisation can authorise an assistant; each authorised user then connects their own account to it. The assistant receives the requested data: lead names, companies, stages and amounts, and the network directory, without email addresses, phone numbers or messages.
This transmission is an instruction from the organisation. The assistant’s provider, often based outside the European Union, then processes this data under its own terms; the authorisation can be withdrawn at any time.
6. Webhooks and public API
On the organisation’s instructions, confirmed when each webhook is created, Apportly sends events, including the names of the lead and the contact, the programme and the amounts, to the webhook addresses it has configured. These deliveries are signed, restricted to HTTPS and reject private destinations.
The public API gives access to complete lead records, including email addresses and phone numbers, only to systems that hold one of the organisation’s API keys. The organisation chooses these recipients and is accountable for their use and their location.
7. Who can access the data?
Data is accessible to authorised Apportly personnel within the scope of their duties, to users authorised by the organisation and to the following providers, depending on the feature used. Apportly does not sell or rent personal data.
Apportly’s sub-processors for organisations’ data:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Convex | The platform’s database, files, authentication and real-time functions | All workspace data: accounts, network, leads, messages, contracts, commissions and files | European Union, eu-west-1 region (Ireland); company based in the United States | Hosting in the European Union; for any access from the United States, Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Cloudflare | Delivery and protection of the website, back office and web app | Web traffic: IP address, session cookies, URLs visited and relayed sign-in requests | Global network; company based in the United States | Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Resend | Sending transactional emails: codes, invitations, contracts, notifications and statements | Recipient address, email subject and content, including names, amounts, links and attached commission statements | United States (sending region to be confirmed) | Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Expo | Relaying notifications to iOS, building and updating the mobile apps | Device token, notification title and text; IP address during an update | United States | Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Google Firebase Cloud Messaging | Delivering notifications on Android and in the browser | Device or browser token, notification title and text; browser IP address | United States | Data Privacy Framework (to be confirmed) |
| Apple Push Notification service | Delivering notifications on iPhone and iPad | Device token, notification title and text | United States | Data Privacy Framework (to be confirmed) |
Providers for Apportly’s own processing:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Stripe | Payment and subscription management for customer organisations | Organisation name, payer’s email and address; card details are entered directly with Stripe | Ireland or the United States (to be confirmed) | Stripe is also the controller for its own payment processing; Data Privacy Framework or standard contractual clauses (to be confirmed) |
| Google Calendar, Google Meet | Scheduling demos, when the calendar is connected | Name, email, company and notes from the demo request | United States | Data Privacy Framework (to be confirmed) |
| Recherche d’entreprises (api.gouv.fr) | Identifying the company during sign-up | Name or SIREN number searched for, browser IP address | France | No transfer outside the European Union; public service that is the controller for its own processing |
| Google, GitHub | Sign-in with an existing account, when this option is offered | Sign-in identity passed on by the chosen provider | United States | Separate controllers; their own terms and safeguards apply |
Recipients that act on their own behalf, under their own terms:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Apple App Store Connect, Google Play | Publishing the organisation’s app in the app stores | Review contact (name, email, phone number), demo account and testers’ email addresses | United States | Separate controllers; their own terms and safeguards apply |
Destinations chosen and configured by each organisation:
| Recipient | Purpose | Data received | Location | Transfer safeguard |
|---|---|---|---|---|
| Webhooks | Sending events to the addresses configured by the organisation | Names of leads and contacts, programme, stages and amounts | Chosen by the organisation | Instruction from the organisation, which itself provides the legal framework for this transfer |
| Public API | Access by the organisation’s systems to its own data using an API key | Complete lead records, including email addresses and phone numbers | Chosen by the organisation | Instruction from the organisation, which itself provides the legal framework for this transfer |
| AI assistant (MCP connector) | Consultation of the workspace by the AI assistant that an authorised user approves | Lead names, companies, stages and amounts, network directory; no email addresses, phone numbers or messages | Depends on the assistant’s provider, often in the United States | Instruction from the organisation; the chosen provider applies its own terms |
Authorities, advisers or insurers may also receive data where required by law or justified by the defence of legal claims.
8. Transfers outside the European Union
Application data and files are hosted in the European Union, with Convex, in the eu-west-1 region (Ireland). The providers listed above may process data in the United States or another third country. Each transfer relies on the EU-US Data Privacy Framework where the provider is certified under it, or on the European Commission’s standard contractual clauses; the note “to be confirmed” indicates that a check with the provider is in progress.
You can obtain a copy of the applicable safeguards by writing to clarisse@apportly.app.
9. How long is data retained?
| Data | Retention period |
|---|---|
| User account | Until the account is closed |
| Expired sessions, invitations and verification codes | Deleted 30 days after expiry |
| Security logs (audit) | 12 months |
| Workspace activity history | 36 months |
| Lead lost or closed unsuccessfully | Anonymised 36 months after its last activity; the organisation can choose between 12 and 60 months |
| Won lead, commissions, contracts and commission statements | Retained for the duration of the organisation’s subscription; the organisation exports what it must keep for its accounting |
| Contracts, acceptances and commission statements of a closed account | Archived with restricted access for 5 years, the general limitation period, then destroyed |
| Objection list (hashes of the email address and phone number) | Retained for as long as the organisation exists, so that the objection remains effective |
| Deactivated notification devices | Deleted 90 days after deactivation |
| In-app notifications | 90 days |
| Email sending log | 30 days |
| Feedback messages | 24 months |
| An organisation’s workspace after its subscription ends | 90-day reversibility period, with export and email reminders, then automatic deletion of the workspace |
| Sign-up drafts and their reminders | Deleted 6 months after the last activity |
| Demo requests | 24 months, together with the corresponding calendar event |
| Requests received through the contact form | The time needed to handle the request in our mailbox, then no more than 3 years after the last exchange |
| Invoices and accounting records | 10 years where French accounting rules apply |
| Carte customer account | Until the account is closed |
Data may be retained longer in intermediate archives where required by a legal obligation, litigation or the defence of a right. At the end of the applicable period, it is deleted or anonymised.
10. How is data protected?
The main measures are hosting of the data in the European Union, isolation of each workspace checked server-side on every request, encryption of exchanges, storage of passwords, codes and API keys as hashes only, encryption of sensitive secrets, two-factor authentication required for platform administrators and workspace managers, an audit log of sensitive operations and rate limiting on public entry points. The details are set out in the data processing agreement.
Within messaging spaces, users can report a message or its author, block that author and later unblock them. Blocking prevents new direct exchanges between the two accounts and hides the blocked author’s content from the user concerned. Authorised organisation administrators have a queue for handling reports.
No measure eliminates all risk. In the event of a personal data breach, Apportly alerts the organisation concerned no later than 48 hours after becoming aware of it and, for its own processing, notifies the CNIL and informs the individuals concerned where required by law.
11. What are your rights?
Depending on the processing and its legal basis, you may request access, rectification, erasure, restriction or portability, or object to certain uses. You may withdraw consent at any time without affecting processing already lawfully carried out.
For data managed by an organisation, contact that organisation first; if you contact Apportly, your request is forwarded to the organisation without delay. For Apportly’s own processing, write to clarisse@apportly.app with details of your request and information allowing us to identify you. Proof of identity is requested only where there is reasonable doubt.
If you have been referred to an organisation, you can object to any further contact using the link in the information email or by writing to that organisation.
You can close your account from the app or the portal’s Account page. If you can no longer sign in, use the dedicated account deletion page, which is accessible without signing in.
You can also lodge a complaint with the CNIL through its online complaints service.
12. Use by minors
The back office and the organisations’ apps are intended for professional use and do not target minors. Organisations must not create a programme intended to collect minors’ data without a specific assessment, appropriate information and an authorisation mechanism that complies with applicable regulations.
13. Changes to this policy
The policy may change with the product, providers or regulations. The date at the top identifies the current version. Any material change concerning an active account is communicated appropriately.
Reference sources
Official references used to keep this page up to date.