Privacy policy
This page describes how Bizleen collects, processes and protects your personal data. We apply the General Data Protection Regulation (GDPR, EU 2016/679) and the amended French Loi Informatique et Libertés. The French version is the legal reference.
1. Data controller
Bizleen is a service operated by Dan Nutu EI, which is the
data controller.
SIRET 83515065700012.
137 Rue des Landes, 78400 Chatou, France.
Contact: rgpd@bizleen.com
Institutional site: mindvisionstudio.com
2. Data we collect
2.1 Account data
- Email address: to create your account, identify you, and send you service messages (address confirmation, password reset).
- Password: it is never kept in plain text. All we keep is an irreversible fingerprint of it, computed with a hashing function known to resist brute-force attacks. Nobody here can read your password back.
- Email verification status (verified or not).
- Account creation date.
2.2 Content you publish (card available at /@your-handle)
- Professional identity: first name, last name, title, company, tagline, monogram, card number.
- Contact details you choose to display: phone, contact email, website, location, links to your social networks.
- Images you upload: profile photo, logo, custom background, photos of your venue, plus a PDF document (menu, brochure) where applicable.
- For a venue page: description, address, opening hours, menu and prices, services, events, frequently asked questions, testimonials.
- Chosen appearance: visual theme and accent colour.
- If you enable other languages: the translations of the matching fields.
- If you link your Google listing: the average rating and the number of reviews (never the text of the reviews), and the coordinates derived from your address to display the location map.
These data are public by design: your card is accessible to anyone who knows the URL. That is the point of the service. Do not enter sensitive data.
2.3 Subscription and payment
- If you take out a paid plan, the payment is handled by Stripe. Your card number is entered on Stripe's side: we never see it and never store it.
- On our side, we keep the plan you subscribed to, the state of the subscription, its renewal date, and the customer and subscription references Stripe sends us, so we can give you access to what you paid for.
- Stripe separately collects, on its own account and for its own legal obligations, the billing information it needs (name, address, country, payment method).
2.4 Messages sent from a public card
When a card offers a contact form, the visitor who uses it sends us their name, email address and message. That message is forwarded by email to the card holder, who can reply to the visitor directly. The holder's email address is never displayed on the card. We do not keep the content of these messages once they have been forwarded.
2.5 Booking and map, loaded from another site
Some cards display a booking module provided by StaffClock and a location map provided by OpenStreetMap. Neither of those comes from our servers: the visitor's browser fetches them directly from the provider, and therefore hands it their IP address, exactly as when they visit any other page.
- Booking: the module is only loaded when the visitor opens the booking window. As long as nobody taps the button, nothing is requested from StaffClock and no IP address reaches it. What is then entered in that form (identity, contact details, booking details) goes to StaffClock and is processed by it for the venue: it does not travel through our servers, we never see it and we never store it. On our side we only record that a booking button was tapped, with no visitor identifier (see 2.6).
- Location map: it loads when it comes into view, and at that point hands the visitor's IP address to OpenStreetMap. It sets no cookie, and all we send it is the coordinates of the point to display.
2.6 Technical data and card view statistics
- IP address: used to limit sign-in, sign-up and message sending attempts, in order to protect accounts against automated attacks. Kept for 24 hours at most, then erased.
- Session: once you are signed in, a technical cookie keeps your session open for 30 days from your last visit; after that it expires and you sign in again.
- Language preference: a cookie remembers for one year the language you pick with the FR/EN switcher.
- Card view statistics: every time a public card is displayed and every time one of its buttons is tapped (phone, email, website, directions, menu, vCard, booking), we record the date, the approximate country reported by the network, where the visit came from (QR code, direct link, social network), the language the card was displayed in, the language of the visitor's device as their browser declares it (without the region: "fr", "es"), and, if it appears in the address, the campaign label. No visitor identifier is recorded: these statistics cannot recognise a person from one visit to the next. They are visible to the card holder.
2.7 Internal alert to the publisher
Bizleen is published by one person. To know that an account has just been created or that a subscription has just changed, the publisher receives an alert on his Telegram messaging app. It is sent to him and to nobody else.
- On sign-up: first name, last name, email address and, when that address is not from a consumer provider, its domain; the handle of the card created, the language of the form filled in, the date and time, and a link to your record in our administration tool.
- On a subscription change (new subscription, change of plan, cancellation, failed payment): email address, plan before and after the change, billing frequency, number of monthly payments already collected, date and time.
This processing rests on the legitimate interest of the publisher in knowing what is happening on his service and being able to react quickly: it is not necessary to perform the contract, and you can object to it by writing to us. Telegram is established outside the European Union (see section 4).
2.8 Legal bases
| Processing | Legal basis (GDPR art. 6) |
|---|---|
| Creating your account, publishing and hosting your card | Performance of the contract (6.1.b) |
| Service emails (address confirmation, password reset) | Performance of the contract (6.1.b) |
| Subscriptions, payments and invoicing | Performance of the contract (6.1.b) and legal accounting obligations (6.1.c) |
| Protecting accounts against automated attempts | Legitimate interest in keeping the service secure (6.1.f) |
| Forwarding a message received through the contact form | Legitimate interest of the visitor and of the holder in getting in touch (6.1.f) |
| Card view statistics, with no visitor identifier | Legitimate interest of the holder in measuring the audience of their card (6.1.f) |
| Displaying the booking module and the location map, loaded from a third party | Legitimate interest of the holder in offering booking and a map on their card (6.1.f) |
| Internal alert to the publisher on a sign-up or a subscription change | Legitimate interest of the publisher in following the activity of his service (6.1.f) |
| The publisher stepping into an account, for support and maintenance | Legitimate interest in helping a customer and keeping the service running (6.1.f) |
| Google Analytics audience measurement | Consent (6.1.a), revocable at any time |
3. Cookies
The following cookies may be set (audience measurement cookies only after your consent):
| Name | Purpose | Duration | Type |
|---|---|---|---|
mvc_session | Keep your session open after sign-in | 30 days after your last visit | Strictly necessary (technical cookie, not readable by the scripts on the page, sent only over an encrypted connection) |
mvc_locale | Remember your chosen language (FR or EN) | 1 year | Preference (non-sensitive) |
mvc_admin_return | Let the publisher return to his own session after a support visit to an account (see section 4) | 4 hours | Strictly necessary |
mvc_invite | Hold on to an invitation to co-edit a card while you sign in or create an account | 1 hour | Strictly necessary |
mvc_demo_<card id> | Keep browsing an unpublished card opened with a private link, without going back through the link on every page | 30 days | Strictly necessary |
mvc_demo_seen_<card id> | Avoid counting the same opening of a private link several times. Contains no visitor identifier | 30 minutes | Strictly necessary |
_ga, _ga_<measurement id> | Google Analytics: distinguish visitors and keep session state (audience measurement) | 13 months | Audience measurement, set only after consent |
That list is complete: these are the only cookies the site sets. Only the audience measurement ones ask for your consent. All the others are strictly necessary to the service you have just asked for, or remember a choice you have just made: they require no consent and cannot follow you on any other site.
We use no advertising cookies and we never resell data. For audience measurement of our site and our public cards we use Google Analytics 4. These cookies are set only after your explicit consent through the banner ("Accept" button). If you decline, no Google script is loaded and no data is sent to Google. Your choice is stored locally by your browser (it is not a cookie) and you can change it at any time with the button below.
4. Sub-processors and recipients
We only call on the providers the service needs to run. Each one only accesses the data it needs for the task it is given. The last line of this list, StaffClock, is the exception: it is not a provider working for us but a third-party service processing on its own account. It is named here because data reaches it.
- Cloudflare (Cloudflare, Inc., United States / Cloudflare Switzerland GmbH, Switzerland): hosting the site, keeping account and card data, storing the images and documents you upload, protection against attacks. Cloudflare's network is worldwide: your data may be processed outside the European Union, covered by the standard contractual clauses. Cloudflare policy.
- Stripe (Stripe Payments Europe, Ltd., Ireland / Stripe, Inc., United States): collecting subscription payments and handling invoicing. Receives your email address as well as the billing and payment details you enter on its side. Stripe policy.
- Resend (Resend, Inc., United States): delivering our emails (address confirmation, password reset, invitation to co-edit a card, forwarding a message received through the contact form). Receives the recipient address and the content of the message. Resend policy.
- Anthropic (Anthropic PBC, United States): machine translation of your content and reading a menu you photograph, only when you trigger the feature yourself. Receives the text or the image to process, never your sign-in credentials. Anthropic policy.
- Google (Google Ireland Limited, Ireland / Google LLC, United States): first, audience measurement through Google Analytics 4, only after your consent (page views, approximate country and device type); second, if you link your business listing, sending the name and the address of that business so the listing can be found and its average rating and number of reviews read. Transfers outside the EU are framed by the standard contractual clauses and the Data Privacy Framework. Google policy.
- OpenStreetMap Foundation (OpenStreetMap Foundation, United Kingdom): two distinct uses, not to be confused. First, converting the published address of your venue into coordinates, done once from our servers: only that address, already public on your page, is sent. Second, displaying the map on the public card: that one is loaded by the visitor's browser, which hands their IP address to OpenStreetMap (see 2.5). OSMF policy.
- Telegram (Telegram FZ-LLC, Dubai, United Arab Emirates): delivering the internal alerts described in 2.7, to the publisher of the service and to him alone. Receives the content of those messages, so your name and your email address. The United Arab Emirates are covered by no adequacy decision from the European Commission: this transfer outside the European Union is limited to those alerts, and you can object to it. Telegram policy.
- StaffClock (staffclock.app): the booking module displayed on the cards that enable it. It is not a sub-processor: StaffClock processes on its own account and on the venue's whatever the visitor enters in the booking form, as well as the IP address the browser hands it when loading the module. We receive neither that information nor the booking.
The publisher's access to your account. An administration feature lets the publisher open your workspace as you see it, to help you out or handle a request. It is reserved to the publisher of the service and is only used for support and maintenance.
No data is sold, shared for advertising purposes, or handed over to a third party outside those named above, all of which are necessary for the service to run or for a feature you have enabled.
5. Retention periods
- Account, card and published content: for as long as your account exists. Immediate deletion on request (see section 6).
- Session: 30 days without a visit, then automatic deletion.
- Sign-in attempt log (IP address): 24 hours at most, purged automatically.
- Links sent by email: an address confirmation link is good for 24 hours, a password reset link for 1 hour, and each one works only once. After that the link is worth nothing; the record standing for it is erased as soon as you ask for a new link, and in any case along with your account.
- Invitations to co-edit a card: 14 days. After that the link no longer works, and the invitation, which carries the invited person's email address, is erased the next time an invitation is sent or accepted.
- Messages received through a contact form: not kept once forwarded to the card holder.
- Internal alerts to the publisher (see 2.7): the message stays in his Telegram conversation until he deletes it.
- Card view statistics: kept for as long as the card exists, and deleted along with it.
- Subscription data: for the duration of the subscription, then for as long as our accounting and tax obligations require.
- Backups: our host keeps technical backups on its own cycles; they cannot be consulted on request.
6. Your rights
Under the GDPR (articles 15-22) and the French Loi Informatique et Libertés, you have the following rights:
- Access and portability: download a complete JSON export of your data from your Account page ("Download my JSON export" button).
- Rectification: change your data at any time in your dashboard.
- Erasure (right to be forgotten): delete your account
instantly from your Account page (Danger
zone). Deleting it also deletes your card, your content, your statistics,
your sessions and every one of your files: profile photo, logo,
background, photos of the venue, event posters, photos of the menu items,
PDF document, along with the images the service built from yours (contact
thumbnail, signature QR code). Gone too are the log of your calls to the
artificial intelligence features, the invitations to co-edit that carried
your email address, and the traces of your sign-in attempts. Your handle
becomes available again.
One condition only: as long as a subscription is running, deletion is refused. Cancel it first, then delete the account. We prefer those two clear steps to an account deletion that would decide on its own to stop a subscription you are paying for. - Withdrawal of consent: for audience measurement, change your choice with the button in section 3, at any time and without giving a reason.
- Objection: deleting the account is equivalent.
- Restriction: to restrict without deleting, contact us.
- Complaint: you can file a complaint with the CNIL (cnil.fr), the French data protection authority.
We answer any request sent to rgpd@bizleen.com within one month, in accordance with article 12 of the GDPR.
7. Security
- Your password is never kept in plain text and cannot be read by anyone, including us.
- Traffic between your browser and the site is encrypted end to end by HTTPS.
- The cookie that keeps your session open is not readable by the scripts on the page and is only sent over an encrypted connection.
- Sign-in, sign-up and message sending attempts are limited in number, to slow down automated attacks.
- The files you upload are checked before being accepted: only certain image and document formats are allowed, within the size limits the editor reminds you of at upload time. We check what the file really is, not just its extension.
- Sensitive actions (changing your password or your email address, deleting your account) require you to enter your password again.
No online service is infallible. Should a data breach be likely to create a risk to your rights, we will notify the CNIL and, if the risk is high, we will inform you directly, in accordance with articles 33 and 34 of the GDPR.
8. Minors
The service is not intended for minors under 16. If you are a parent or guardian and a minor has created an account, contact us for immediate deletion.
9. Changes
This policy may be updated. The last update date is shown at the top of the page. For substantial changes, we will notify you by email.
10. Contact
For any question about your personal data: rgpd@bizleen.com.