Privacy Policy

Last updated: June 8, 2026Effective date: June 8, 2026

1. Data Controller

The controller of the personal data collected via the Bordermath service is:

Bordermath

Service operated by Régis KIKI

Contact: support@bordermath.xyz

Note : Bordermath is an independent service operated by Régis KIKI, who acts as the data controller. For any question regarding your personal data, contact Régis KIKI at support@bordermath.xyz. A postal contact address can be provided on written request to that address.

2. Categories of Data Collected

We collect and process only the data strictly necessary to provide our services:

Identity and account data

Email address, display name (optional), profile image (if Google sign-in).

Travel data

Passport nationality country, passport type, planned destinations (cities, countries, arrival/departure dates), GPS coordinates of destinations (calculated then stored), purpose of travel.

Data extracted from documents

When you use the passport analysis feature: issuing country, document type, expiration dates (if visible). Important: the image itself is analyzed and then immediately deleted; only this textual information is retained.

AI chat messages

Content of conversations with the planning assistant, associated with your trip session.

Usage and technical data

Interaction events (clicks, page views, features used), session identifiers, IP address (anonymized for analytics), User-Agent, preferred language.

3. Purposes and Legal Bases of Processing

We collect and process only the data strictly necessary to provide our services:

PurposeData ConcernedLegal Basis
Provision of the planning serviceTravel data, itineraries, passport dataContract performance
OCR analysis of travel documentsDocument images (transient), extracted textExplicit consent
Authentication and securityEmail, session tokens, IPLegitimate interest
Product improvement and analyticsUsage events, session replaysConsent
Error tracking (security and stability)Technical exceptions, masked contextLegitimate interest
Communications (onboarding, support)Email, conversation contentContract performance

4. Subprocessors and Data Transfers

We use the following subprocessors for certain features of our service. Each subprocessor is subject to a contract guaranteeing compliance with GDPR and the security of your data.

Sous-traitantFinalitéTypes de donnéesLocalisationPolitique
Neon (PostgreSQL)Primary database hosting (destinations, trips, messages)Account data, itineraries, GPS coordinates, chat messagesEurope (Germany / EU countries)View
Better AuthAuthentication and session managementEmail, session tokens, User-Agent, IP (transient)Europe (via your Vercel infrastructure)View
Google OAuthSocial authentication (optional)Email, name, profile image (if consented)United StatesView
PostHogProduct analytics and session replayUsage events, session replays, distinct_id, User-AgentUnited States (PostHog US cloud hosting)View
ResendTransactional email sending (onboarding, notifications)Email address, email contentUnited StatesView
Rodium AITransient OCR processing of passport/visa imagesDocument images (ephemeral, not stored), extracted textUnited StatesView
Nominatim / OpenStreetMapGeocoding of destinations (city → coordinates)City names, GPS coordinatesInternational (OpenStreetMap Foundation)View
Carto / LeafletClient-side map displayDestination GPS coordinates (display only, no third-party storage)Client (your browser)View
VercelHosting and deployment of the infrastructureAll application data (encrypted in transit and at rest)Europe (selected Vercel region: eu-west)View

5. International Data Transfers

Some of our subprocessors are located in the United States. For these transfers, we have implemented the following safeguards in accordance with GDPR:

  • Standard Contractual Clauses (SCC): We rely on the European Commission's Standard Contractual Clauses and/or the Data Processing Agreements (DPA) offered by our US subprocessors (Google, Resend, PostHog, Rodium AI) to frame these transfers.
  • Additional measures: Encryption of data in transit (TLS 1.3) and at rest, pseudonymization of user identifiers in analytics tools, limited retention periods.
  • User control options: You can accept or decline analytics cookies at any time via the consent banner or the 'Cookie preferences' link in the footer of every page.

For any questions regarding these transfers, contact us at support@bordermath.xyz.

6. Retention Periods

Trips and itinerariesUntil deleted by the user or account closure
Extracted data (OCR)Same duration as the associated trips
Chat messagesUntil trip or account deletion
Better Auth sessions30 days after expiration
Analytics data (PostHog)In accordance with PostHog policy (up to 1 year)
Technical backupsUp to 30 days

7. Your Rights (GDPR)

In accordance with the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

To exercise these rights, send us a request by email to support@bordermath.xyz specifying your identity and the nature of your request. We will respond within a maximum of one month.

If you believe your rights are not being respected, you have the right to lodge a complaint with the CNIL (French Data Protection Authority) or the data protection authority of your country of residence.

Right of access

Obtain a copy of your personal data that we process.

Right to rectification

Request correction of inaccurate or incomplete data.

Right to erasure

Request deletion of your data under certain conditions ("right to be forgotten").

Right to portability

Receive your data in a structured format and transfer it to another service.

Right to object

Object to processing based on legitimate interest (analytics, marketing).

Right to restriction

Request restriction of processing in certain circumstances.

8. Cookies and Trackers

Our site uses cookies and similar technologies for the following purposes:

We do not use any cookies for marketing or advertising purposes. You can configure your browser to refuse cookies, but this may affect certain features of the service.

Analytics cookies (PostHog) are only set after your explicit consent via the banner shown on your first visit. You can change or withdraw this consent at any time, as easily as you gave it, via the 'Cookie preferences' link in the footer of every page.

Independently of this consent, we keep a minimal error-tracking mechanism active (capturing technical exceptions, with all inputs and text masked) on a legitimate-interest basis, in order to keep the service secure, stable and free of malfunctions. This mechanism does not record your browsing for advertising or audience-measurement purposes.

Cookie / TrackerPurposeTypeDuration
better-auth.sessionAuthentication and session maintenanceNecessary30 days
ph_* (PostHog)Analytics and session replayAnalytics1 year
NEXT_LOCALELanguage preferenceNecessary1 year

9. Data Security

We implement appropriate technical and organizational measures to protect your data against any unauthorized access, modification, disclosure or destruction:

  • Encryption: All data is encrypted in transit via TLS 1.3 and at rest in our database.
  • Access controls: Access strictly limited to the technical team members who require this data for maintenance. Multi-factor authentication mandatory for infrastructure access.
  • Audit and monitoring: Access logging and anomaly detection via our Vercel infrastructure and PostHog.
  • Security testing: Regular review of code and dependencies to identify and fix vulnerabilities.
  • Training: Team awareness of security and data protection best practices.

10. Data Breach Notification

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we undertake to:

  • Notify the CNIL (or competent authority) within 72 hours after detection.
  • Inform you directly without undue delay if the breach presents a high risk to your rights, unless technical and organizational measures have been taken to mitigate this risk.

11. Modifications to the Policy

We may update this Privacy Policy at any time to reflect changes in our practices or regulations. Changes will take effect upon publication on this page.

For material changes, we will notify you by email or in-app notification. We encourage you to consult this page regularly to be aware of any changes.

12. Contact and Data Protection Officer

For any questions regarding this policy, the exercise of your rights or the protection of your personal data, contact us:

Email:

support@bordermath.xyz

Note : Data protection requests are handled directly by Régis KIKI, who operates Bordermath and acts as the data controller, at support@bordermath.xyz. No dedicated Data Protection Officer has been appointed at this stage. A postal contact address can be provided on written request.

For any concerns, please write to support@bordermath.xyz.

Avis important : <strong class="text-navy">Important notice:</strong> Bordermath provides calculation and information tools. This document is not legal advice. Consult a qualified attorney for questions relating to your specific situation. For any concerns, please write to support@bordermath.xyz.