Trust Center
Privacy by Design
Privacy by Design
At Bordermath, the protection of your data is at the heart of our architecture. We have designed every feature with a "privacy by design" approach:
- ✓Passport images never stored: uploaded photos are analyzed once and then immediately deleted. Only the extracted text is kept in your profile.
- ✓Deterministic 90/180 calculations: our Schengen compliance algorithms are transparent and verifiable.
- ✓Data minimization: we only collect what is essential to provide the service. No advertising profiling. No resale of data.
- ✓End-to-end encryption: all data is encrypted in transit (TLS 1.3) and at rest.
What we do not do
No data resale
Your travel data, itineraries and personal information are never sold, rented or shared with third parties for commercial purposes.
No advertising profiling
We do not build advertising profiles based on your destinations or nationality. No marketing cookies are used.
No arbitrary sharing with authorities
We do not share your data with migration authorities unless we are legally compelled by a court decision.
Strict minimization
We do not retain data beyond what is strictly necessary. Complete deletion on request or account closure.
Technical and Organizational Security Measures
Secure infrastructure
Our infrastructure is hosted on Vercel with Neon PostgreSQL databases in Europe. Restricted access, mandatory multi-factor authentication for the technical team.
Encryption
All communications are encrypted in transit via TLS 1.3. Data at rest in our PostgreSQL database is encrypted by the infrastructure provider (Neon).
Access controls
Least privilege principle: only technical members necessary for maintenance have access to production data, via secure and logged accesses.
Audit and monitoring
Access logging and anomaly detection via PostHog and native Vercel tools. Automatic alerts in case of suspicious activity.
Security testing
Regular review of code and dependencies to identify and correct vulnerabilities. Security updates applied as soon as available.
Compliance and Certifications
GDPR
Full compliance with the EU General Data Protection Regulation.
Security
Continuous security audit, data encryption, strong authentication.
List of Subprocessors
We work with the following subprocessors, all subject to contracts guaranteeing GDPR compliance and the security of your data:
| Sous-traitant | Finalité | Types de données | Localisation | Politique |
|---|---|---|---|---|
| Neon (PostgreSQL) | Primary database hosting | Account data, itineraries, messages | Europe (Germany / EU) | View |
| Better Auth | Authentication | Email, session tokens | Europe | View |
| Google OAuth | Social authentication | Email, name, profile image | United States | View |
| PostHog | Analytics and session replay | Usage events, session replays | United States | View |
| Resend | Transactional emails | Email address, email content | United States | View |
| Rodium AI | Ephemeral OCR processing | Images (not stored), extracted text | United States | View |
| Nominatim / OpenStreetMap | Geocoding | City names, coordinates | International | View |
| Carto / Leaflet | Map display | GPS coordinates (client) | Client | View |
| Vercel | Infrastructure hosting | All data (encrypted) | Europe | View |
Transparency and Audits
We believe in total transparency regarding the processing of your data:
- Open source (partial): the Schengen compliance calculation algorithms are available for verification.
- Incident reports: in the event of a security incident affecting your data, we undertake to notify you as soon as possible.
- Audit on request: upon justified request, we can provide additional information on our security practices.
- DPAs: we rely on the data processing agreements (DPAs) and Standard Contractual Clauses offered by our critical subprocessors; the formalization of these agreements is being finalized and further details can be provided on justified request.
Incident Reporting Procedure
If you suspect a security incident affecting your data on Bordermath (unauthorized access, potential leak, abnormal behavior), please report it to us immediately:
Support email: support@bordermath.xyz
We commit to acknowledging receipt of your report within 24 business hours and keeping you informed of the investigation progress.
How to Exercise Your Rights
In accordance with GDPR, you have several rights regarding your data. To exercise them:
For complete account deletion, you can also use the "Delete my account" function in the application settings.
- Send us a request by email to support@bordermath.xyz
- Specify your identity and the nature of your request (access, rectification, deletion, etc.)
- We will respond within a maximum of one month
Questions about our security?
Questions about our security?
Our legal and security team is available to answer your questions regarding the protection of your data.
Contact the legal teamFor any concerns, please write to support@bordermath.xyz.
Avis important : <strong class="text-navy">Important notice:</strong> Bordermath provides calculation and information tools. This document is not legal advice. Consult a qualified attorney for questions relating to your specific situation. For any concerns, please write to support@bordermath.xyz.