MIABELANGUE places the utmost importance on the protection of your personal data. This policy sets out how we collect, use and protect your information when you use our web platform (hereinafter “the Platform”).
1. Data Controller
The data controller is MIABELANGUE, a simplified joint-stock company (SAS) with a share capital of 100 euros, registered with the Paris Trade and Companies Register under number 107 389 140, with its registered office at 61 rue de Lyon, 75012 Paris, France. For any question regarding your data, you can contact us at: contact@miabelangue.com.
2. Intended audience
The Platform is aimed at adults and minors alike. An account for a Student under 15 may be created by the Student themselves, but it stays closed until the holder of parental authority has confirmed their approval via a link sent to them by email. That confirmation constitutes consent to the processing of the minor's data (Article 8 GDPR, Article 45 of the French Data Protection Act); it is time-stamped and kept as evidence. The holder so confirmed is the sole contracting party.
The data we hold about the child is limited to what is necessary: first name, last name, email address, month and year of birth, level, progress and the session notes written by the teacher. We never ask for their full date of birth or their postal address. From the legal guardian we keep the email address, name and relationship declared at confirmation. The child has messaging with the teaching team; the holder of parental authority may request its contents. Legal basis: performance of the contract, and the holder's consent for children under 15.
3. What data do we collect, why, and on what basis?
We only collect data that is strictly necessary for the proper functioning of our services. For each processing activity, the legal basis under the GDPR is specified.
- Identification and account data: last name, first name, email address, and the month and year of birth. These last two are requested for every account, for one purpose only: to determine whether a legal guardian's approval is required. The day of birth is never requested. Legal basis: performance of the contract, and legal obligation as regards the protection of minors.
- Technical and security data (sessions): to secure your connection and prevent fraud, our authentication system temporarily records your IP address and the type of browser (User-Agent) used during your session. Legal basis: legitimate interest (security and fraud prevention).
- Usage and progress data: courses taken, lessons viewed, learning progress and consultation of your digital books in your library. Necessary to provide the service and allow you to resume where you left off. Legal basis: performance of the contract.
- Transaction data (purchases and subscriptions): the history of your orders, a secure customer identifier and the status of your payments. MIABELANGUE never stores your full bank details: payment processing is entirely delegated to our secure partner Stripe. Legal basis: performance of the contract, and legal obligation to retain accounting records.
- Booking data (video conferencing): when you book a lesson, we process calendar data (date, time) to generate the video conference link. Legal basis: performance of the contract.
- Communication data (newsletter): if you choose to subscribe, your email address is used to send you our news — new courses, new books, and news of Mina and Ewe. No newsletter is sent to an address we have not verified as being yours: a subscription requested from the website awaits the click of a confirmation link, while a subscription requested from “My account” relies on the address already verified for your account. Legal basis: consent, which you can withdraw at any time — an unsubscribe link is included in every mailing, and the switch remains available in “My account”.
4. Who has access to your data? (Our processors)
Your data is never sold to third parties. It is only shared with our trusted technical service providers (processors within the meaning of the GDPR), bound by contract and applying strict security standards:
- Render Services, Inc. — hosting of the web interface, the API and the database.
- Cloudflare, Inc. — secure storage of your digital book files (R2 service).
- Stripe — secure processing of card payments and subscriptions.
- Cal.com — management of calendars and bookings for video-conference lessons.
- Resend — sending our emails: transactional messages related to your account and orders (performance of the contract) and, if you have consented, the newsletter (consent).
- Axeptio — collection and management of your consent to cookies and trackers (consent management platform).
5. Data transfers outside the European Union
Some of our processors (notably Render, Cloudflare and Stripe) are established in the United States. When a transfer of your data takes place outside the European Union, it is governed by the safeguards provided for by the GDPR: either the processor’s adherence to the EU–United States Data Privacy Framework, or the signing of the standard contractual clauses approved by the European Commission. You may request a copy of these safeguards at the address indicated in section 1.
6. Retention period
We only keep your data for as long as is necessary for the purposes described above:
- Account and usage data: kept for as long as your account is active. In the event of prolonged inactivity (3 years), your account is closed; an email warns you thirty days in advance, and simply signing in resets the clock. Closing — whether you ask for it or it follows from inactivity — is an anonymisation: your name, address and photo are erased from the account, your progress, course access and remaining session credits are deleted, and only the items listed below remain, which the law requires us to keep for longer than the account itself.
- Billing data: kept for 10 years, in accordance with our legal accounting and tax obligations.
- Security data (session logs): kept for a maximum period of 12 months.
- E-mail delivery log: for each message sent from the Platform, we keep a technical record for 12 months — the type of message, its status, your address in masked form, the internal reference of the item concerned (invoice, lesson, subscription) and, where delivery failed, the reason for the refusal passed on by our delivery provider. It exists to answer the question "did that message actually go out?". Neither the subject nor the content of the message is recorded.
- Newsletter delivery register: when a campaign goes out, we keep the list of its recipients and the status of each send — sent, or refused and for what reason — for 12 months. This register first serves to resume an interrupted send without writing twice to the same person, then to answer the question "did that letter actually go out?". After that period these entries are deleted; only the text of the campaign remains, with no recipients at all.
- Built-in messaging: messages are kept for as long as your account is active; voice messages are automatically deleted 12 months after they are sent (see section 11).
- Newsletter: your address, the language in which you were reading the site and the proof of your consent (date of the request and date of the confirmation, IP addresses recorded by our servers at those two moments, browser declared at the time of the request, place on the site from which the subscription was requested, version of the wording accepted) are kept for as long as you remain subscribed. A subscription that is never confirmed is deleted after 30 days — consent that was never given is not kept. On unsubscribing, the technical items (IP addresses, browser) are erased immediately; we then keep only your address, the dates and the version of the wording, for three years, so as to be able to demonstrate that your consent had indeed been obtained and that your withdrawal was indeed carried out — after which this record is deleted. If you subscribe again later, the date of your previous withdrawal is kept for three years from that withdrawal, then erased. This retention is independent of your account: closing your account does not unsubscribe you, and unsubscribing does not close your account.
- Parental consent: retained for the lifetime of the account, then five years after its closure, in order to prove that consent was obtained (article 7.1 GDPR).
7. Security of your data
We implement appropriate technical and organisational measures to protect your data: encryption of communications (HTTPS/TLS), storage of passwords in hashed form, restriction and compartmentalisation of access to the administration area, logging of connections and regular backups.
8. Your rights (GDPR)
In accordance with the GDPR and the French Data Protection Act, you have the following rights over your data at any time:
- Right of access and portability: obtain a copy of the data we hold about you.
- Right to rectification: correct inaccurate information from your personal area.
- Right to erasure (“right to be forgotten”): request the permanent deletion of your account and your data.
- Right to object and to restriction: refuse or restrict certain processing (for example commercial communications).
- Right to withdraw your consent: at any time, for processing based on it, without affecting the lawfulness of processing already carried out.
To exercise these rights, send us an email at contact@miabelangue.com. We will handle your request within one month of receiving it, possibly extended by two months for complex requests. Finally, you have the right to lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr).
9. Cookies and trackers
The Platform uses cookies and local storage items that are strictly necessary for its operation: keeping your login session and remembering your shopping cart. Exempt from consent under the regulations, they are placed as soon as you arrive.
Any other cookie or tracker that is not strictly necessary (for example for audience-measurement purposes) is only placed after your consent has been obtained. This consent is collected and managed through a dedicated banner provided by our partner Axeptio: you can grant, refuse or withdraw it at any time, purpose by purpose, without affecting access to the essential features of the Platform.
10. Changes to this policy
We may need to update this policy. The date of the last update appears at the top of the document. In the event of a substantial change, we will inform you by an appropriate means.
11. Built-in messaging
The Platform offers a built-in instant messaging service (one-to-one conversations between a student and a teacher, and group discussions linked to a course), intended exclusively for educational follow-up. The data processed in this context is as follows:
- Content of exchanges: text and voice messages, together with their timestamps and delivery and read receipts. Legal basis: performance of the contract.
- Participants' identity: in group conversations, only your first name and your role (student or teacher) are visible to other participants. Your e-mail address and phone number are never displayed or shared with other members.
- Voice messages: audio files are hosted by our partner Cloudflare (R2 storage), governed by its data processing agreement (DPA). They are automatically deleted 12 months after being sent; the conversation then shows the mention “voice message expired”.
Exchanges are encrypted in transit (HTTPS and WSS). Messages are kept for as long as your account is active; if the account is deleted, they are anonymised, i.e. permanently dissociated from your identity. The content of your conversations is never analysed for commercial or advertising purposes, and is never sold or passed on to third parties.
