Privacy policy
Last updated: 13 September 2026.
This policy describes how personal data is processed in the context of thebeepilot-app.fr website and theBeePilot mobile application, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act of 6 January 1978 as amended.
1. Data controller
The data controller is the site's publisher, a private individual acting in a non-professional capacity. In accordance with article 6, III, 2° of the LCEN, their personal contact details are not made public; their identity is held by the site's host. For any question about your data, a dedicated contact point is available:contact@beepilot-app.com.
Given the nature and volume of processing, appointing a Data Protection Officer (DPO) is not mandatory; the contact above remains your point of contact for any request.
2. Data collected
On this site:
- Sign-up form (waitlist): your email address;
- Contact form: your name, your email and your message;
- Technical data strictly necessary for operation and security (host connection logs).
In the application:
- Account data: email address (and sign-up information);
- Beekeeping data you enter: apiaries, hives, inspections, treatments, queens, harvests…;
- Geolocation of your apiaries, only with your consent, for the foraging weather and floral resources features.
No data is sold or transferred to third parties for commercial purposes.
3. Purposes and legal bases
- Waitlist: to inform you of the application's launch — legal basis: your consent (art. 6.1.a GDPR), revocable at any time.
- Contact form: to answer your request — legal basis: pre-contractual measures or legitimate interest (art. 6.1.b/f).
- Account and application service: to provide the service — legal basis: performance of the contract (terms of use, art. 6.1.b).
- Geolocation: mapping features — legal basis: consent (art. 6.1.a).
4. Recipients and processors
Data is only accessible to the publisher and their technical processors, who are bound by confidentiality:
- Netlify, Inc. — website hosting and form processing (Netlify Forms). Covered by a data processing agreement (DPA).
- Supabase — hosting of the account and application data, on infrastructure located in the European Union.
- Where applicable, third-party services used by the application (e.g. weather or mapping data), detailed within the application.
5. Transfers outside the European Union
Application data is hosted in the European Union. Processing of the site's forms by Netlify, Inc. may involve a transfer to the United States. This transfer is covered by the appropriate safeguards provided by the GDPR, in particular the European Commission's standard contractual clauses (art. 46 GDPR) and the provider's data processing agreement.
6. Retention periods
- Email addresses (waitlist): until launch and then until you unsubscribe, and for a maximum of 3 years from the last contact (CNIL recommendation on prospecting).
- Contact messages: for as long as necessary to handle your request, then possible archiving within legal time limits.
- Application account data: for the entire lifetime of your account, then deleted (or anonymised) after closure, subject to legal retention obligations.
7. Your rights
Under the GDPR, you have the following rights: access,rectification, erasure, restriction,objection, portability, the right towithdraw your consent at any time, and the right to setdirectives regarding your data after your death.
To exercise these rights, write to contact@beepilot-app.com. Proof of identity may be requested in case of reasonable doubt about the requester's identity.
You also have the right to lodge a complaint with the French data protection authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 —www.cnil.fr.
8. Cookies and trackers
This site uses no advertising tracking cookies nor third-party analytics tools; no prior consent is therefore required for this. Only strictly necessary elements for operation may be used. If an analytics tool is added later, your consent will be collected via a dedicated banner.
9. Security
Appropriate technical and organisational measures are implemented to protect your data (HTTPS-encrypted exchanges, hosting of application data in the European Union, restricted access). As no data transmission over the Internet can be guaranteed 100% secure, however, we cannot guarantee absolute security.
10. Minors
The service is not intended for persons under 15 without the consent of the holder of parental authority. If you believe a minor has provided us with data without such consent, please contact us so that we can delete it.
11. Changes to this policy
This policy may be modified at any time to reflect legal or service changes. The date of the last update appears at the top of this page.