Home · Privacy
Privacy Policy
This policy explains which personal data Pentania processes, why, and the rights you have, in accordance with the GDPR and the French Data Protection Act.
Last updated: 11 June 2026.
1. Data controller
BrainOps (SASU), 23 rue de l'Arrivée, boîte 37, 75014 Paris — SIREN 880 077 466 R.C.S. Paris. Contact: pentania@pentania.fr.
2. Data collected
- E-mail address: for magic-link sign-in and account management.
- Account & subscription data: status (free / Premium), access source, date of last sign-in.
- Technical data: connection logs (IP address, timestamp, browser type), for security purposes.
- Transaction data transmitted by the payment provider (subscription status, billing country). Your card details are never processed or stored by BrainOps: they are handled by the payment provider.
3. Purposes & legal bases
- Providing the service and managing your account (authentication, Premium access) — basis: performance of the contract.
- Managing the subscription and billing — basis: performance of the contract and legal obligation (accounting).
- Security, fraud prevention and proper operation (logs) — basis: legitimate interest.
- Possible non-essential communications (where applicable, e.g. news) — basis: consent, withdrawable at any time.
4. Recipients & processors
Your data is not sold. It may be processed by providers acting on our behalf, governed by a data processing agreement (DPA):
- Host: OVH SAS (France, European Union).
- Payment provider (seller / Merchant of Record): Paddle (Paddle.com Market Ltd), which handles payment, billing and taxation.
- E-mail delivery: OVH SAS (MX Plan mail service), for sending sign-in links.
5. Transfers outside the European Union
Some providers may be located outside the EU. Where applicable, these transfers are governed by the appropriate safeguards provided for by the GDPR (adequacy decision or standard contractual clauses).
6. Retention periods
- Account: kept for as long as the account is active, then deleted or anonymized after a period of inactivity.
- Accounting documents / invoices: 10 years (legal obligation; kept by the payment provider).
- Technical logs: a limited duration, proportionate to security needs.
7. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to set out directives concerning the fate of your data after your death. To exercise them: pentania@pentania.fr. You may also lodge a complaint with the CNIL (cnil.fr).
8. Cookies & local storage
Pentania uses neither advertising cookies nor third-party trackers. Only strictly technical local storage is used: a session token (to keep you signed in) and your theme preference. As these elements are necessary for the operation of the service, they are exempt from prior consent. No consent banner is therefore required as it stands.
9. Security
We implement reasonable technical measures: encrypted connection (HTTPS), cryptographically signed session tokens, restricted access to data. As no method is infallible, we cannot guarantee absolute security.
10. Minors
The service is intended for an adult audience or for those who have the required consent. We do not knowingly collect data from children under 15 without an appropriate basis.
11. Changes
This policy may be updated. The applicable version is the one published on this page.