Privacy policy
How your data is collected, processed, and stored. Updated April 2026.
1. Controller
The controller for your personal data under Article 4(7) GDPR is:
- Yann Lephay (Entreprise individuelle)
- 53 avenue Charles de Gaulle, 57530 Courcelles-Chaussy, France
- SIREN 899 650 204
- Email: [email protected]
No Data Protection Officer is appointed (not required under Article 37 GDPR for this scale of processing).
2. Data we collect
Email address (for the receipt and magic link), the declaration data you enter in the wizard (addresses, financial values), and payment metadata from Stripe. We do not collect your ELSTER credentials.
3. Where it is stored
PostgreSQL hosted in the EU. TLS 1.3 in transit. Encryption at rest. Backups retained 30 days. We keep paid declarations for seven years as required by § 147 AO, then delete automatically.
4. Subprocessors
Stripe (payments), Resend (transactional email), Cloudflare (DNS and email routing), Anthropic (AI assistant — only your question text is sent, no personally identifiable information).
5. Your rights
Under Articles 15–21 GDPR you can request access, correction, deletion, portability, or objection at any time. Email [email protected]with your request. You also have the right to lodge a complaint with a supervisory authority — for users in France, the CNIL (cnil.fr); for users in Germany, your Land's Datenschutzbeauftragter.