Chargement...
Chargement...
Last updated : 24 mai 2026
Parato (« we ») take the protection of your data very seriously, especially since you entrust us with health data (symptoms, medications, medical history, lab results). This policy explains what we collect, why, where it is stored, and how you retain control.
Applicable law: Regulation (EU) 2016/679 (GDPR) and French Data Protection Act (amended 2018).
Parato is published by Khalid Ksouri (sole proprietorship), contact: contact@parato.app. Full legal information is available on the Legal page.
| Category | Examples | Legal Basis |
|---|---|---|
| Identity & authentication | Email, name (optional), sessions | Performance of contract (Art. 6.1.b) |
| Medical profile | Age, sex, height, weight, medical history, allergies, medications | Explicit consent (Art. 9.2.a, sensitive data) |
| Health data | Symptoms, prepared consultations, lab results, scanned prescriptions, daily tracking | Explicit consent (Art. 9.2.a) |
| Payment | No cards stored by us — processed by Polar | Performance of contract |
| Technical | Anonymized server logs (masked IP), errors, performance | Legitimate interest (Art. 6.1.f) |
We never use your data for advertising purposes. No data is sold to third parties.
| Service | Role | Hosting |
|---|---|---|
| Supabase (PostgreSQL) | Database | EU (Frankfurt, eu-central-1) |
| Vercel | Web hosting + serverless | Multi-region (EU prioritized) |
| Vercel Analytics & Speed Insights | Analytics & performance — cookieless, no identifying personal data | EU |
| Resend | Transactional email delivery | EU |
| Sentry | Application error tracking (stacktraces). PII scrubbed before sending (emails masked, tokens redacted). No session replay, no user tracking. | EU (Frankfurt) |
| Polar | Payment processing (Merchant of Record, handles EU VAT) | EU / US |
| Fournisseurs IA (Groq, Mistral, Cerebras, Google, etc.) | AI processing — no data used to train their models | US / EU depending on provider |
| Cloudflare | CDN, DNS, DDoS protection | Multi-region |
All subprocessors are bound by contractual clauses ensuring GDPR-compliant protection. For transfers outside the EU, EU Standard Contractual Clauses apply.
In accordance with Articles 15 to 22 of the GDPR, you have the following rights at any time:
To exercise these rights: dpo@parato.app — response within 30 days maximum.
In the event of a data breach posing a risk to your rights and freedoms, the CNIL is notified within 72 hours (GDPR Art. 33), and you will be informed without undue delay (Art. 34).
If you believe your rights are not respected despite our response, you may lodge a complaint with the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07).
This policy may be updated to reflect legal or technical changes. Material changes will be notified to users by email at least 30 days before they take effect.