Data protection

Privacy policy

In force since [DATE] · GDPR (Regulation (EU) 2016/679) and the French Data Protection Act.

This policy explains what personal data VatAtlas collects, why, on what legal basis, how long we keep it, and the rights you can exercise. It applies to this website and to our business prospecting.

1. Who is responsible for your data

Data controller: VatAtlas — [LEGAL NAME], [micro-entreprise / company], SIRET [SIRET], registered at [ADDRESS].
Contact for privacy matters: [CONTACT EMAIL].

2. What we collect, and why

DataPurposeLegal basis
Business contact details of e-commerce sellers (company name, business email, VAT number, marketplace, country) — collected from public marketplace listings and the EU VIES database. B2B prospecting: telling a company it may have an unmet VAT obligation and offering a free audit. Legitimate interest (Art. 6(1)(f) GDPR) — direct B2B marketing to professionals, in line with the French CNIL guidance on business prospecting.
Booking form: name, company, email, phone, and your three answers (countries sold in, where stock is stored, where goods come from). Preparing and holding the free audit call you request. Your consent and pre-contractual steps taken at your request (Art. 6(1)(a) and (b) GDPR).
Site measurement: IP address, page visited, referrer, and the prospect identifier carried by a personal link (the ?p= parameter), logged server-side. Measuring which prospects open our page, and securing the service. No advertising, no profiling. Legitimate interest (Art. 6(1)(f) GDPR) in a strictly necessary, privacy-friendly measurement.

3. Who receives your data

We use a small number of processors, bound by contract to act only on our instructions:

We never sell your data, and we never share it with third parties for their own marketing.

International transfers

Some processors (e.g. Smartlead, Google) may process data outside the EU. Where they do, transfers are framed by the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

4. How long we keep it

5. Your rights

Under the GDPR you may, at any time:

To exercise any of these, write to [CONTACT EMAIL]. We answer within one month. If you believe your rights are not respected, you can lodge a complaint with the French supervisory authority, the CNIL.

6. Security

Data is stored on a secured server with restricted access and encrypted connections. Access is limited to what is strictly necessary to run the service.

7. Changes

We may update this policy; the date at the top always reflects the version in force.