Last updated: September 2026
This policy explains what personal data the REPTIK platform (the "Service") processes, why, for how long, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR) and French data protection law (Loi Informatique et Libertés).
REPTIK [legal entity name, address and registration number to be completed] is the data controller for the personal data described below.
| Data | When | Why |
|---|---|---|
| Geographic location (latitude/longitude) | When you allow location access, or scan a bracelet | Determine the mosquito/insect risk level where you are |
| NFC bracelet code (or none, if using the guest mode) | When scanning a bracelet | Distinguish bracelet visits from guest visits in usage statistics |
| IP address | Every visit | Abuse prevention (rate limiting on the risk API) and admin security logs |
| Admin login identifier | Back-office login | Restrict access to the back-office to authorised staff |
We do not ask for your name, email address, or any other directly identifying information anywhere on the public site.
Location and scan data are processed on the basis of performance of the service you request (Art. 6.1.b GDPR) — you ask "what is the risk here?", we need your position to answer. IP-based security logging relies on our legitimate interest (Art. 6.1.f GDPR) in keeping the service secure and available.
Some requests are sent directly from your browser to the following third-party services, without passing through our servers:
Our own server also receives your coordinates to look up the nearest covered risk zone. This data is not sold, rented, or used for advertising.
Scan records (position, timestamp, matched zone) are kept for statistical purposes. We recommend — and intend to apply — a retention period of 12 months, after which older records are deleted or aggregated. Admin connection logs are kept for 12 months for security purposes.
Under the GDPR, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. Because our scan records are not linked to your name or any account, we generally cannot identify which record corresponds to you specifically — if you believe a request still applies to your situation, contact us using the details below.
You also have the right to lodge a complaint with the French data protection authority, the CNIL (www.cnil.fr).
The site stores your last risk result in your browser's local storage, purely so the page can still show useful information if you lose network connection right after a scan. This data stays on your device, is never transmitted anywhere, and is not used to track you across sites.
The site is served over HTTPS. Back-office passwords are stored hashed (bcrypt), never in plain text, and every deletion in the admin back-office requires re-entering the administrator's password as a second control.
For any question about this policy or to exercise your rights: [contact email to be completed].