Privacy Policy

Last updated: 11/03/2025
This Privacy Policy explains how Seemio IOT S.A.S. collects, uses, and protects your personal data when you use our website and application. It is written in compliance with the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).

1. Data Controller

The data controller is:

Seemio IOT (in creation)
S.A.S. with capital of XXXX €
Registered office: #ADDRESS#
RCS: #RCS#
Phone: #PHONE#
Email: contact@seemio.com


If a Data Protection Officer (DPO) has been appointed, they can be contacted at: contact@seemio.com

2. Purposes of Processing

We process personal data for the following purposes:

  • Creating and managing your user account (web and mobile)
  • Connecting and synchronizing with your IoT sensors
  • Displaying, storing, and accessing sensor data (e.g., level, temperature, humidity)
  • Billing, payments, and customer relationship management
  • Technical support and customer service
  • Service maintenance, security, and improvement
  • Compliance with legal and accounting obligations

We do not perform advertising profiling or behavioral tracking.

3. Legal Bases for Processing

Data processing is based on the following legal grounds:

  • Contract performance (account management, sensor access, billing, support)
  • Legitimate interest (service security, error detection, operational continuity)
  • Legal obligation (accounting, invoicing, regulatory compliance)

4. Data Collected

We may collect and process the following categories of personal data:

  • Identification data: name, surname, email address, encrypted password, company, phone (optional)
  • Authentication data: Google OAuth identifiers, access tokens, connection logs
  • Technical data: IoT sensor IDs, transmitted measurements, timestamps, connectivity status
  • Contractual data: purchased products, subscriptions, invoices
  • Technical logs: IP address, browser type, operating system (for diagnostic purposes only)

No sensitive data is collected.

5. Data Recipients and Service Providers

Personal data is processed solely by Seemio IOT S.A.S. and its essential technical service providers:

Service Provider
Role
Location
GDPR Safeguards
Vercel Inc.
Hosting of the website and frontend
United States
Standard Contractual Clauses
Supabase Inc.
Backend, database, and API hosting
EU
GDPR compliant
Sentry (Functional Software Inc.)
Error tracking and monitoring
United States
Standard Contractual Clauses
Google LLC
Authentication via Google Auth
United States
Standard Contractual Clauses
Orange SA
IoT connectivity and gateway services
France
Processed within the EU

All providers act as data processors under Article 28 of the GDPR and process data only on behalf of Seemio IOT S.A.S.

6. Data Transfers Outside the European Union

Some providers (Vercel, Sentry, Google) are located in the United States. Transfers of personal data are governed by EU Standard Contractual Clauses (SCCs), ensuring an adequate level of protection.

7. Data Retention

Active user account
As long as the account remains active

Inactive account
3 years after last activity

IoT sensor data
Duration of the contractual relationship

Billing and accounting data
10 years (legal requirement)

Technical logs
Up to 1 year

8. Your Rights

In accordance with GDPR, you have the following rights:

  • Right of access, rectification, and erasure
  • Right to restrict or object to processing
  • Right to data portability
  • Right to lodge a complaint with the CNIL (www.cnil.fr)

You can exercise these rights by contacting: contact@seemio.com

9. Security Measures

We implement appropriate technical and organizational measures to protect your data:

  • Encrypted communications (HTTPS/TLS)
  • Secure password hashing
  • Regular backups and access control
  • Technical error logging via Sentry
  • Secure data hosting on Supabase and Vercel

10. Cookies and Tracking Technologies

Our website and applications use only strictly necessary technical cookies required for the service to function properly, including:

  • Session cookies (login and session maintenance)
  • Security cookies (Google OAuth2 authentication)

We do not use analytics, advertising, or tracking cookies. These technical cookies are exempt from user consent under CNIL and GDPR guidelines.

11. Policy Updates

This Privacy Policy may be updated at any time to reflect regulatory or technical changes. The last updated date appears at the top of this page. If significant changes occur, users will be notified.

12. Contact

For any questions regarding the protection of your personal data:

contact@seemio.com
#ADDRESS#

13. Competent jurisdiction

Any dispute relating to the use of the website, applications or services offered by Seemio IOT S.A.S. will be subject to the right French and falls under the exclusive jurisdiction of the courts of the jurisdiction of the company's head office.