1. Data controller
Personal data collected via the FiftyCare Platform is processed by:
PROVIDENCE S.A.S.
11 rue de Sontay, 75016 Paris, France
RCS Paris: 911 416 501
Email: contact@fiftycare.fr
Website: www.fiftycare.fr
(hereinafter "Providence" or the "Data Controller")
2. Data collected
2.1. Account and identification data
- First and last name
- Email address
- Username and password (encrypted)
- Date of birth (for minimum age verification)
2.2. Health and wellness data
- Questionnaire responses (menopause symptoms: sleep, hot flushes, mood, energy, pain, weight)
- Wellness score and progress history
2.3. Payment data
- Payment information transmitted to payment processors (Stripe, PayPal, Apple Pay)
- Banking details are not retained by Providence.
2.4. Technical and browsing data
- IP address
- Browser and device type
- Pages visited, session duration
- Connection logs
- Cookies (see Section 8)
2.5. Communication data
- Customer service interaction history
- Notification preferences
3. Purposes and legal bases for processing
| Purpose | Legal basis |
|---|---|
| Account creation and management | Performance of contract (Art. 6.1.b GDPR) |
| Provision of Services and personalised protocols | Performance of contract |
| Processing health/symptom data | Explicit consent (Art. 9.2.a GDPR) |
| Billing and payment management | Performance of contract + legal obligation |
| Platform and Service improvement | Legitimate interest (Art. 6.1.f GDPR) |
| Sending communications and newsletters | Consent (Art. 6.1.a GDPR) |
| Platform security and fraud prevention | Legitimate interest |
| Compliance with legal and accounting obligations | Legal obligation (Art. 6.1.c GDPR) |
| Anonymised usage statistics | Legitimate interest |
4. Data recipients
4.1. Technical and service providers
- Website host: WordPress
- App host: OVHcloud
- Payment processors: Stripe, PayPal, Apple Pay
- Analytics tools: aggregated and anonymised data only
4.2. Competent authorities
Upon lawful request or court order.
4.3. No commercial resale
Providence does not sell, rent or transfer Users' personal data to third parties for commercial purposes.
5. Retention periods
| Data category | Retention period |
|---|---|
| Account data | Duration of subscription + 3 years after closure |
| Health / assessment data | Duration of subscription + 1 year after closure |
| Payment records | 5 years (legal accounting obligation) |
| Navigation / logs | 12 rolling months |
| Customer service communications | 3 years after last contact |
| Newsletter data | Until consent is withdrawn |
6. Users' rights
Under the GDPR and applicable data protection law, each User has the following rights:
- Right of access (Art. 15 GDPR): obtain a copy of personal data held
- Right to rectification (Art. 16 GDPR): correct inaccurate or incomplete data
- Right to erasure (Art. 17 GDPR): request deletion of personal data ("right to be forgotten")
- Right to restriction (Art. 18 GDPR): restrict data processing
- Right to data portability (Art. 20 GDPR): receive data in a structured, machine-readable format
- Right to object (Art. 21 GDPR): object to processing based on legitimate interest
- Right to withdraw consent: at any time, for consent-based processing
- Right to define post-mortem instructions: regarding data after death
How to exercise these rights
By email: contact@fiftycare.fr
Or by post: PROVIDENCE S.A.S. — 11 rue de Sontay, 75016 Paris, France
Providence undertakes to respond within 30 days of receiving the request. Proof of identity may be required.
Right to lodge a complaint
Users may lodge a complaint with the French data protection authority: CNIL — 3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France — www.cnil.fr — Tel.: +33 1 53 73 22 22
For Users in other EU member states, complaints may also be lodged with the competent national supervisory authority.
7. International data transfers
Data is primarily hosted and processed within the European Union (OVHcloud — France/Europe servers). Where data is transferred to third countries (e.g. via Stripe or PayPal), Providence ensures that appropriate safeguards are in place, in accordance with Articles 44 et seq. of the GDPR (standard contractual clauses, European Commission adequacy decisions).
8. Cookies
8.1. When using the Platform, cookies and trackers may be placed on the User's device.
8.2. Types of cookies used:
| Type | Purpose | Duration |
|---|---|---|
| Essential cookies | Platform operation, authentication | Session / 13 months |
| Analytics cookies | Audience measurement (anonymised statistics) | 13 months |
| Preference cookies | Storing user preferences | 13 months |
8.3. Non-essential cookies (analytics, preferences) require the User's prior consent, collected via a consent banner on first access.
8.4. Users may configure their browser to refuse cookies or be notified of their placement. Refusing certain cookies may affect Platform functionality.
9. Data security
Providence implements appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure:
- Password encryption (hashing)
- Secure HTTPS connections
- Strict internal access controls
- Regular backups
- Secure hosting (OVHcloud)
In the event of a personal data breach likely to result in a risk to Users' rights and freedoms, Providence undertakes to notify the CNIL within 72 hours and to inform affected Users without undue delay.
10. Children
The Platform is not intended for children under 13 years of age. Providence does not knowingly collect data from children under 13. If such data comes to Providence's attention, it will be deleted immediately.
11. Changes to this Privacy Policy
Providence reserves the right to modify this Policy at any time. Changes are notified to Users by email with 15 days' prior notice. The date of the last update is shown at the top of this document.
12. Contact
For any questions regarding this Policy or the protection of your personal data:
Email: contact@fiftycare.fr
Address: PROVIDENCE S.A.S. — 11 rue de Sontay, 75016 Paris, France