Privacy policy
This policy describes how NoFlyer processes personal data of professional Clients and their users (owner and admin areas), of professional contacts, and of guests who view a public property page, use the chatbot or request a Wi-Fi code.
Data controller
Processing is currently organised as part of the NoFlyer project, a French simplified joint-stock company (SAS) being incorporated, under the responsibility of its project lead and publication director, Thibaut Dabonneville. The legal entity acting as data controller will be specified once the company is registered.
Data protection contact
For any question about your personal data or to exercise your rights, contact dpo@noflyer.fr. This is the dedicated data protection contact for the NoFlyer project. Requests are handled following the documented internal procedure (see the DSAR runbook).
Data subjects
- Professional Clients and their authorised users (owner and admin areas).
- Professional contacts (commercial or support exchanges).
- Guests viewing a public property page, the chatbot or the Wi-Fi reveal.
Account data
- E-mail address and password (stored hashed), optional name, account role and status.
- Administration activity log for security and traceability purposes.
Property data and media
Descriptive property information, amenities, instructions and media uploaded by the Client for display on the public page.
Property public contact
Where the Client provides a contact intended for guests, that information is displayed on the property public page according to its settings.
Billing and subscription data
Subscription and payments are handled via the payment provider Stripe. NoFlyer does not store card numbers. The billing and subscription data needed to manage the contractual relationship is retained.
Support
Exchanges and requests sent to support are processed to answer the request and follow it up.
Public-page visits
When a public property page opens, NoFlyer performs first-party technical visit measurement from minimised data: viewed route/path, the referrer origin (domain name), locale, browser (user-agent) information, a value derived from the IP address via a salted hash, and a timestamp. The visit record keeps only a hashed IP value; the raw request address is processed transiently to derive that value and to apply security and abuse controls. No advertising tracker or third-party analytics tool is used.
Technical and security data
Minimised technical data (security events, rate limiting, diagnostics) is processed to secure the service and prevent abuse. Application logging is minimised and redacted (no secret or password is logged; IP addresses are reduced to a hashed value). Logging by the reverse proxy and hosting infrastructure is separate and remains to be verified against the operational retention policy.
Chatbot
When a guest uses the chatbot, their message is sent to the AI provider (OpenAI) together with the property's public context. Wi-Fi passwords, secrets and private owner/admin data are excluded from that context. Answers are automated and may contain errors; they do not constitute an automated decision producing a legal effect.
Wi-Fi password reveal
A property's Wi-Fi password is never shown by default nor sent to the chatbot. It is revealed only on the guest's explicit request, through a dedicated, rate-limited endpoint.
Mandatory or optional information
Depending on the flow, some information is essential and some is optional. Missing essential information prevents the corresponding purpose.
- Account creation: the email address and password are required to create and secure the account; without them, the account cannot be created. The full name is optional.
- Property public information: entered by the Client, it is optional or required depending on what the Client chooses to publish on the property page.
- Billing details: required only to subscribe to a paid plan and issue invoices; without them the payment cannot be processed.
- Support: the information needed to handle the request is expected; without it the request may not be resolvable.
- Technical visit measurement: collected automatically when a public page opens, for the purposes already described.
- Chatbot: a message is only needed when a guest chooses to use the assistant; without a message the assistant returns no answer.
- Wi-Fi password reveal: an optional action, explicitly triggered by the guest; without that action no Wi-Fi password is revealed.
Purposes
- Provide and operate the NoFlyer service and the public property pages.
- Manage accounts, subscription and billing.
- Ensure security, prevent fraud and abuse.
- Provide support and improve the service.
- Perform first-party technical visit measurement.
Legal bases
- Performance of the contract for account, subscription and billing data.
- Legitimate interest for security, abuse prevention, minimised technical data and first-party visit measurement.
- Legal and accounting obligations for the retention of billing documents.
- Consent where relevant, should any optional processing (for example a non-essential tracker) be introduced later.
Recipients and processors
NoFlyer relies on the following processors, active in the service:
- OVHcloud — hosting of the infrastructure and data.
- Stripe — payment, subscription and billing processing.
- OpenAI — contextual AI assistant limited to the property public context.
- No third-party transactional e-mail provider is currently active in the service. Introducing one (for example Brevo) will be reflected by an update to this list.
Transfers outside the European Economic Area
Some processors (notably Stripe and OpenAI) may involve processing or transfers of data outside the European Economic Area. Where applicable, such transfers are governed by appropriate safeguards such as standard contractual clauses. The exact configuration and associated safeguards are subject to ongoing verification before any full commercial opening.
Retention periods and criteria
At this pilot stage, no automatic purge based on fixed retention periods is active. Data may be deleted through the available actions, Client requests or account-closing operations, subject to applicable legal obligations. Numeric retention periods, anonymisation rules and their automation will be defined and implemented before the paid commercial launch.
The criteria below are expressed by end event and describe the target policy retained, not an automatic deletion already deployed.
- Account data (retained criterion): kept for the duration of the relationship, then for as long as needed to close the account, meet legal obligations and handle any disputes.
- Property content and media: may be deleted at the Client's request through the available actions; otherwise they are kept until the Client's account is effectively closed.
- Billing data (retained criterion): kept for the period required by applicable legal and accounting obligations.
- Support (retained criterion): kept for the time needed to handle the request, then for the archiving period needed to track it.
- Technical and security logs (target policy): kept for the time needed for security, diagnostics and abuse prevention; their numeric duration and purge will be framed by the future operational policy.
- Visit measurement (target policy): a statistical and security period that will be defined, quantified and automated by the future operational policy.
- Chatbot (target policy): messages are not intended to be kept beyond the applicable technical and security needs; no automatic deletion based on a fixed duration is active yet.
Security
NoFlyer applies technical measures such as transport encryption, password hashing, rate limiting, and application-log minimisation and redaction.
Your rights
Under the GDPR, you have rights of access, rectification, erasure, objection, restriction and portability. To exercise them, contact dpo@noflyer.fr.
Complaint to the CNIL
If you consider that your rights are not respected, you may lodge a complaint with the CNIL (the French data protection authority, www.cnil.fr).
Changes to this policy
This policy may be updated to reflect changes to the service or the legal framework. The last-updated date appears at the top of this document.