Privacy Policy

Last updated: 22/12/2025

1. Introduction and Commitment

STRUKOV NETWORK (hereinafter the “Operator”, “We” or “Our”) attaches paramount importance to the protection of the privacy and personal data of its users (hereinafter the “Users” or “You”).

This Privacy Policy (hereinafter the “Policy”) aims to inform you in a transparent and comprehensive manner about how your personal data is collected, processed, used, stored and protected in accordance with:

  • Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (GDPR)
  • Law No. 78-17 of 6 January 1978 relating to information technology, files and freedoms, as amended
  • To any other applicable regulations regarding the protection of personal data

By using the STRUKOV NETWORK platform, you acknowledge that you have read this Policy and accept the practices described therein.

2. Data Controller

The data controller for the personal data collected on the platform is:

Name: STRUKOV NETWORK

Contact: Accessible via the platform's support page

For any questions relating to the processing of your personal data or to exercise your rights, you can contact us via our support page .

3. Personal Data Collected

3.1 Data Collected Directly

As part of your use of the platform, we collect the following categories of data:

a) Identification Data

  • First and last name
  • Email address
  • Mobile phone number
  • Unique account identifier
  • Profile picture (optional)

b) Account and Authentication Data

  • Login credentials
  • Encrypted password
  • Invitation code used during registration
  • Invitation codes generated for referrals
  • Connection and session history

c) Transactional Data

  • History of donations made and received
  • Transaction amounts
  • Dates and times of operations
  • Position in the participation tables
  • Progression and evolution within the network

d) Communication Data

  • Messages sent via the support system
  • Exchanges with customer service
  • Support tickets and their history
  • Notification preferences

3.2 Automatically Collected Data

When you use the platform, certain data is collected automatically:

  • Connection data: IP address, browser type, operating system, screen resolution
  • Navigation data: Pages visited, visit duration, navigation path, clicks made
  • Technical data: Device identifier, device type, browser language
  • Cookies and similar technologies: As described in our cookie policy

3.3 Sensitive Data

In accordance with the GDPR, we do not collect any so-called "sensitive" data (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation) except with explicit consent and specific legal requirement.

4. Purposes and Legal Basis of Processing

Your personal data is processed for the following purposes, on the appropriate legal bases:

PurposeLegal Basis
Creating and managing your user accountContract execution (General Terms and Conditions)
Authentication and access securityContract execution
Facilitating circular donations and managing the chartsContract execution
Transaction processing and financial historyContract execution and legal obligation
Customer service management and technical supportContract performance and legitimate interest
Sending service-related notificationsContract execution
Fraud prevention and anti-money launderingLegal obligation and legitimate interest
Platform improvement and statistical analysisLegitimate interest
Compliance with legal and regulatory obligationsLegal obligation
Marketing communications (with consent)Consent

You have the right to withdraw your consent at any time for processing based on this basis, without this affecting the lawfulness of processing carried out before the withdrawal.

5. Data Recipients

5.1 Internal Recipients

Your personal data is accessible internally only to authorized persons due to their functions and within the limits necessary for the performance of their duties (technical teams, customer service, administrative and financial department).

5.2 External Recipients

Your data may be shared with third parties in the following cases:

  • Technical service providers: Hosting (Supabase), payment services, email and notification services, acting as data processors within the meaning of the GDPR
  • Judicial and administrative authorities: Upon legal request or within the framework of legal obligations to communicate
  • Legal professionals: Lawyers, chartered accountants, auditors, within the scope of their duties
  • Anti-fraud agencies: In case of suspected illegal activities

5.3 No Sale or Rental

We do not sell, trade, rent, or transfer your personal data to third parties for commercial or marketing purposes without your prior explicit consent.

6. Data Transfers Outside the European Union

Your personal data is hosted and processed primarily within the European Union.

In the event that certain data is transferred to countries outside the European Union, we ensure that these transfers are carried out in accordance with the GDPR and the decisions of the European Commission, in particular by:

  • The use of standard contractual clauses approved by the European Commission
  • Transfers to countries benefiting from an adequacy decision
  • The recipient's adherence to recognized certification mechanisms

You can obtain a copy of the guarantees in place by contacting us through our support page.

7. Shelf Life

Your personal data is kept for varying periods of time depending on its nature and the purposes for which it is processed:

Data CategoryShelf Life
Active account dataFor the entire duration of your account + 3 years after closure
Transactional and financial data10 years in accordance with accounting and tax obligations
Anti-fraud data5 years from the date the account is closed
Connection history and logs1 year in accordance with regulations
Customer support data3 years from the closing date of the ticket
Cookies and trackers13 months maximum

Upon expiry of these periods, your data is securely deleted or anonymized for statistical purposes, unless there is a legal obligation to retain it for a longer period.

8. Security and Data Protection

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, including:

8.1 Technical Measures

  • Encryption of data in transit (HTTPS/TLS protocol) and at rest
  • Pseudonymization and anonymization where possible
  • Strict access controls and enhanced authentication
  • Firewalls, intrusion detection and prevention systems
  • Regular backups and business continuity plans
  • Continuous monitoring and access logging

8.2 Organizational Measures

  • Training and raising awareness among staff regarding data protection
  • Access management policy and the principle of least privilege
  • Security Incident Management Procedures
  • Confidentiality clauses in employment and service contracts
  • Regular security audits

8.3 Notification of Violations

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will inform you as soon as possible in accordance with Article 34 of the GDPR, and notify the competent supervisory authority (CNIL) within 72 hours of discovering the breach.

9. Your Rights Regarding Your Personal Data

In accordance with the GDPR and the French Data Protection Act, you have the following rights regarding your personal data:

Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, to access that data and obtain a copy of it.

Right to Rectification (Article 16 GDPR)

You can request the correction of inaccurate or incomplete data concerning you.

Right to Erasure / “Right to be Forgotten” (Article 17 GDPR)

You can request the erasure of your personal data in certain circumstances, subject to legal obligations to retain it.

Right to Restriction of Processing (Article 18 GDPR)

You can request the restriction of the processing of your data in certain situations (contestation of accuracy, unlawful processing, etc.).

Right to Data Portability (Article 20 GDPR)

You have the right to receive your data in a structured, commonly used and machine-readable format, and to transmit it to another data controller.

Right to Object (Article 21 GDPR)

You can object at any time to the processing of your data for reasons relating to your particular situation, where the processing is based on legitimate interest.

Right to Withdraw Your Consent

For processing based on your consent, you can withdraw it at any time.

Right to Define Post-Mortem Directives (Article 85 LIL)

You can set guidelines regarding the retention, deletion and communication of your personal data after your death.

How to Exercise Your Rights

To exercise your rights, you can contact us:

  • Via our support page
  • By sending us a letter accompanied by a copy of your identity document

We undertake to respond to your request within one (1) month of receiving it. This period may be extended by two (2) months depending on the complexity of the request.

Right of Complaint

If you believe your rights have not been respected, you have the right to lodge a complaint with the National Commission for Information Technology and Civil Liberties (CNIL):

CNIL

3 Place de Fontenoy - TSA 80715

75334 PARIS CEDEX 07

Telephone: 01 53 73 22 22

Website: www.cnil.fr

10. Cookies and Similar Technologies

Our platform uses cookies and similar technologies to improve your experience, analyze service usage, and personalize content.

10.1 Types of Cookies Used

  • Strictly necessary cookies: Essential for the platform to function (authentication, security)
  • Performance cookies: These allow us to analyze site usage and improve its performance.
  • Functional cookies: Remember your preferences and choices

10.2 Cookie Management

You can configure your browser at any time to accept or reject cookies. Disabling certain cookies may affect the platform's functionality.

Cookies are stored for a maximum of 13 months in accordance with the recommendations of the CNIL.

11. Minors

Our service is intended for adults. We do not knowingly collect personal data from minors under the age of 18.

If you are a parent or legal guardian and you discover that your minor child has provided us with personal data without your consent, we encourage you to contact us immediately so that we can delete this data.

12. Links to Third-Party Sites

Our platform may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies when you leave our platform.

13. Changes to the Privacy Policy

We reserve the right to modify this Privacy Policy at any time to reflect changes in our practices, our service, or applicable regulations.

Any substantial modification will be notified to you by email or by notification on the platform at least thirty (30) days before it comes into effect.

The date of the last update is indicated at the top of this Policy. We encourage you to check this page regularly to stay informed about our data protection practices.

14. Applicable Law and Jurisdiction

This Privacy Policy is governed by and construed in accordance with French law.

Any dispute relating to the interpretation or execution of this Policy shall be subject to the exclusive jurisdiction of the French courts, subject to mandatory rules of territorial jurisdiction.

Contact - Data Protection Officer

For any questions relating to this Privacy Policy or to exercise your rights, you can contact our dedicated data protection department:

STRUKOV NETWORK

Data Protection Service

Contact: Via our support page

We are committed to handling your request diligently and confidentially, respecting your rights and applicable regulations.

By using the STRUKOV NETWORK platform, you acknowledge that you have read and understood this Privacy Policy and accept the practices described therein regarding the collection, use and protection of your personal data.