PRIVACY · GDPR

Privacy policy.

What we collect, why, how we protect it — and your rights, in full transparency.

1. Data controller

lescoursdelouise.com is published by Louise Blanck, sole proprietorship (SIREN 927 653 782 · 10, rue de la Paix, 75002 Paris), acting as data controller within the meaning of article 4.7 GDPR. Contact for any data question: bonjour@lescoursdelouise.com — WhatsApp +33 6 66 05 46 16. Reply within 30 days maximum (art. 12.3 GDPR).

2. Data collected

We only collect data that is adequate, relevant and limited to what is necessary (data minimisation, art. 5.1.c GDPR): identity (first/last name), contact details (email, phone), educational information (subject, level, goals, session reports), account data (credentials, login history), invoicing and booking data. Card payments are processed directly by Stripe: no card number is stored on our servers. No sensitive data within the meaning of article 9 GDPR is requested; if a parent spontaneously shares pedagogically useful information (e.g. dyslexia/ADHD), it is used only to adapt lessons, with their consent, and can be deleted on request.

3. Purposes and legal bases

Each processing relies on a legal basis under article 6 GDPR: (a) account, booking, lesson and invoicing management — performance of the contract; (b) replies to your requests — pre-contractual measures; (c) newsletter — consent, withdrawable at any time; (d) session reminders by email/SMS — performance of the contract; (e) audience statistics and site improvement — legitimate interest (and consent for analytics cookies); (f) invoice retention — legal obligation. No fully automated decision producing legal effects is made about you (art. 22 GDPR). No data is ever sold or rented.

4. Retention periods

Client account: duration of the relationship, then archived 3 years after last contact and deleted. Pedagogical reports: 3 years after the last session. Invoices and accounting records: 10 years (legal obligation). Newsletter: until unsubscription. Cookies and trackers: 13 months maximum. Security logs: 12 months. At the end of these periods, data is deleted or irreversibly anonymised.

5. Recipients and processors

Your data is never sold or transferred to third parties for commercial purposes. It is processed, each for its sole mission and under an article 28 GDPR data processing agreement, by: the site host (secure cloud infrastructure, data stored in the EU); Stripe (card payments); Calendly (appointments); Resend (transactional emails); Twilio (reminder and verification SMS); Google (optional Google sign-in, Google Meet videoconferencing); a consent-based analytics tool. Only Louise Blanck accesses pedagogical data.

6. Transfers outside the EU

Some processors (Stripe, Google, Twilio, Calendly, Resend) are US companies that may process data in the United States. These transfers are governed by appropriate safeguards within the meaning of articles 44 et seq. GDPR: the EU–US adequacy decision (Data Privacy Framework) for certified entities and/or the European Commission's Standard Contractual Clauses. A copy of these safeguards is available upon request at bonjour@lescoursdelouise.com.

7. Your rights

Under articles 15 to 22 GDPR you have the rights of access, rectification, erasure, restriction of processing, portability and objection (including to direct marketing, without reason). Under French law you may also set directives on the fate of your data after death. To exercise your rights: bonjour@lescoursdelouise.com — reply within 30 days. If, after contacting us, you consider your rights are not respected, you may lodge a complaint with the CNIL (www.cnil.fr).

8. Cookies and trackers

The site places: (a) strictly necessary cookies (session, authentication, language and theme preferences, cart), exempt from consent; (b) where applicable, analytics and personalisation cookies, placed only after your consent via the banner. You may withdraw or change your consent at any time via the "Manage cookies" link in the footer, or through your browser settings. Refusing non-essential cookies does not degrade access to the site. Consent validity: 6 months; maximum tracker lifetime: 13 months.

8 bis. Email open tracking (pixel)

Our emails contain a 1×1 transparent tracking pixel telling us whether a message was opened, when, and how many times. No browsing data, no mailbox content and no advertising profiling are collected; these statistics are never shared or sold. Purpose: confirming that important information (terms, lesson reminders, receipts) reaches you and avoiding unnecessary follow-ups. Legal basis: legitimate interest (art. 6.1.f GDPR). Retention: 13 months maximum (CNIL recommendation). You can opt out at any time, in one click, via the "Learn more / disable" link at the bottom of every email (/suivi-emails page), or by blocking images in your email client.

9. Security

In accordance with article 32 GDPR, appropriate technical and organisational measures are implemented: encrypted communications (TLS), database encryption at rest, passwords hashed with a robust algorithm (bcrypt), reinforced authentication, access logging, regular backups, access limited to what is strictly necessary. In the event of a data breach likely to create a high risk to your rights, you will be informed in accordance with articles 33 and 34 GDPR.

10. Minors

Client accounts are created by parents or legal representatives. Data of minor students is processed under the contract concluded with the legal representative, sole contact for exercising the child's rights. No direct marketing is sent to minors.

11. Updates

This policy may evolve, in particular in case of a change of processor or legal development. Any substantial change will be notified by email to registered users and flagged on this page. Last updated: June 2026.

DPO CONTACT

A question about your data?

bonjour@lescoursdelouise.com
Book a lessonFrom €27/hMessage