Privacy Policy
1. Data Controller
The controller of the personal data collected via the Bordermath service is:
Bordermath
Service operated by Régis KIKI
Contact: support@bordermath.xyz
Note : Bordermath is an independent service operated by Régis KIKI, who acts as the data controller. For any question regarding your personal data, contact Régis KIKI at support@bordermath.xyz. A postal contact address can be provided on written request to that address.
2. Categories of Data Collected
We collect and process only the data strictly necessary to provide our services:
Identity and account data
Email address, display name (optional), profile image (if Google sign-in).
Travel data
Passport nationality country, passport type, planned destinations (cities, countries, arrival/departure dates), GPS coordinates of destinations (calculated then stored), purpose of travel.
Data extracted from documents
When you use the passport analysis feature: issuing country, document type, expiration dates (if visible). Important: the image itself is analyzed and then immediately deleted; only this textual information is retained.
AI chat messages
Content of conversations with the planning assistant, associated with your trip session.
Usage and technical data
Interaction events (clicks, page views, features used), session identifiers, IP address (anonymized for analytics), User-Agent, preferred language.
3. Purposes and Legal Bases of Processing
We collect and process only the data strictly necessary to provide our services:
| Purpose | Data Concerned | Legal Basis |
|---|---|---|
| Provision of the planning service | Travel data, itineraries, passport data | Contract performance |
| OCR analysis of travel documents | Document images (transient), extracted text | Explicit consent |
| Authentication and security | Email, session tokens, IP | Legitimate interest |
| Product improvement and analytics | Usage events, session replays | Consent |
| Error tracking (security and stability) | Technical exceptions, masked context | Legitimate interest |
| Communications (onboarding, support) | Email, conversation content | Contract performance |
4. Subprocessors and Data Transfers
We use the following subprocessors for certain features of our service. Each subprocessor is subject to a contract guaranteeing compliance with GDPR and the security of your data.
| Sous-traitant | Finalité | Types de données | Localisation | Politique |
|---|---|---|---|---|
| Neon (PostgreSQL) | Primary database hosting (destinations, trips, messages) | Account data, itineraries, GPS coordinates, chat messages | Europe (Germany / EU countries) | View |
| Better Auth | Authentication and session management | Email, session tokens, User-Agent, IP (transient) | Europe (via your Vercel infrastructure) | View |
| Google OAuth | Social authentication (optional) | Email, name, profile image (if consented) | United States | View |
| PostHog | Product analytics and session replay | Usage events, session replays, distinct_id, User-Agent | United States (PostHog US cloud hosting) | View |
| Resend | Transactional email sending (onboarding, notifications) | Email address, email content | United States | View |
| Rodium AI | Transient OCR processing of passport/visa images | Document images (ephemeral, not stored), extracted text | United States | View |
| Nominatim / OpenStreetMap | Geocoding of destinations (city → coordinates) | City names, GPS coordinates | International (OpenStreetMap Foundation) | View |
| Carto / Leaflet | Client-side map display | Destination GPS coordinates (display only, no third-party storage) | Client (your browser) | View |
| Vercel | Hosting and deployment of the infrastructure | All application data (encrypted in transit and at rest) | Europe (selected Vercel region: eu-west) | View |
5. International Data Transfers
Some of our subprocessors are located in the United States. For these transfers, we have implemented the following safeguards in accordance with GDPR:
- Standard Contractual Clauses (SCC): We rely on the European Commission's Standard Contractual Clauses and/or the Data Processing Agreements (DPA) offered by our US subprocessors (Google, Resend, PostHog, Rodium AI) to frame these transfers.
- Additional measures: Encryption of data in transit (TLS 1.3) and at rest, pseudonymization of user identifiers in analytics tools, limited retention periods.
- User control options: You can accept or decline analytics cookies at any time via the consent banner or the 'Cookie preferences' link in the footer of every page.
For any questions regarding these transfers, contact us at support@bordermath.xyz.
6. Retention Periods
7. Your Rights (GDPR)
In accordance with the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
To exercise these rights, send us a request by email to support@bordermath.xyz specifying your identity and the nature of your request. We will respond within a maximum of one month.
If you believe your rights are not being respected, you have the right to lodge a complaint with the CNIL (French Data Protection Authority) or the data protection authority of your country of residence.
Right of access
Obtain a copy of your personal data that we process.
Right to rectification
Request correction of inaccurate or incomplete data.
Right to erasure
Request deletion of your data under certain conditions ("right to be forgotten").
Right to portability
Receive your data in a structured format and transfer it to another service.
Right to object
Object to processing based on legitimate interest (analytics, marketing).
Right to restriction
Request restriction of processing in certain circumstances.
9. Data Security
We implement appropriate technical and organizational measures to protect your data against any unauthorized access, modification, disclosure or destruction:
- Encryption: All data is encrypted in transit via TLS 1.3 and at rest in our database.
- Access controls: Access strictly limited to the technical team members who require this data for maintenance. Multi-factor authentication mandatory for infrastructure access.
- Audit and monitoring: Access logging and anomaly detection via our Vercel infrastructure and PostHog.
- Security testing: Regular review of code and dependencies to identify and fix vulnerabilities.
- Training: Team awareness of security and data protection best practices.
10. Data Breach Notification
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we undertake to:
- Notify the CNIL (or competent authority) within 72 hours after detection.
- Inform you directly without undue delay if the breach presents a high risk to your rights, unless technical and organizational measures have been taken to mitigate this risk.
11. Modifications to the Policy
We may update this Privacy Policy at any time to reflect changes in our practices or regulations. Changes will take effect upon publication on this page.
For material changes, we will notify you by email or in-app notification. We encourage you to consult this page regularly to be aware of any changes.
12. Contact and Data Protection Officer
For any questions regarding this policy, the exercise of your rights or the protection of your personal data, contact us:
Email:
Note : Data protection requests are handled directly by Régis KIKI, who operates Bordermath and acts as the data controller, at support@bordermath.xyz. No dedicated Data Protection Officer has been appointed at this stage. A postal contact address can be provided on written request.
For any concerns, please write to support@bordermath.xyz.
Avis important : <strong class="text-navy">Important notice:</strong> Bordermath provides calculation and information tools. This document is not legal advice. Consult a qualified attorney for questions relating to your specific situation. For any concerns, please write to support@bordermath.xyz.