Trust Center

Last updated: June 8, 2026Effective date: June 8, 2026

Privacy by Design

Privacy by Design

At Bordermath, the protection of your data is at the heart of our architecture. We have designed every feature with a "privacy by design" approach:

  • Passport images never stored: uploaded photos are analyzed once and then immediately deleted. Only the extracted text is kept in your profile.
  • Deterministic 90/180 calculations: our Schengen compliance algorithms are transparent and verifiable.
  • Data minimization: we only collect what is essential to provide the service. No advertising profiling. No resale of data.
  • End-to-end encryption: all data is encrypted in transit (TLS 1.3) and at rest.

What we do not do

🚫

No data resale

Your travel data, itineraries and personal information are never sold, rented or shared with third parties for commercial purposes.

🚫

No advertising profiling

We do not build advertising profiles based on your destinations or nationality. No marketing cookies are used.

🚫

No arbitrary sharing with authorities

We do not share your data with migration authorities unless we are legally compelled by a court decision.

🚫

Strict minimization

We do not retain data beyond what is strictly necessary. Complete deletion on request or account closure.

Technical and Organizational Security Measures

Secure infrastructure

Our infrastructure is hosted on Vercel with Neon PostgreSQL databases in Europe. Restricted access, mandatory multi-factor authentication for the technical team.

Encryption

All communications are encrypted in transit via TLS 1.3. Data at rest in our PostgreSQL database is encrypted by the infrastructure provider (Neon).

Access controls

Least privilege principle: only technical members necessary for maintenance have access to production data, via secure and logged accesses.

Audit and monitoring

Access logging and anomaly detection via PostHog and native Vercel tools. Automatic alerts in case of suspicious activity.

Security testing

Regular review of code and dependencies to identify and correct vulnerabilities. Security updates applied as soon as available.

Compliance and Certifications

🇪🇺

GDPR

Full compliance with the EU General Data Protection Regulation.

🛡️

Security

Continuous security audit, data encryption, strong authentication.

List of Subprocessors

We work with the following subprocessors, all subject to contracts guaranteeing GDPR compliance and the security of your data:

Sous-traitantFinalitéTypes de donnéesLocalisationPolitique
Neon (PostgreSQL)Primary database hostingAccount data, itineraries, messagesEurope (Germany / EU)View
Better AuthAuthenticationEmail, session tokensEuropeView
Google OAuthSocial authenticationEmail, name, profile imageUnited StatesView
PostHogAnalytics and session replayUsage events, session replaysUnited StatesView
ResendTransactional emailsEmail address, email contentUnited StatesView
Rodium AIEphemeral OCR processingImages (not stored), extracted textUnited StatesView
Nominatim / OpenStreetMapGeocodingCity names, coordinatesInternationalView
Carto / LeafletMap displayGPS coordinates (client)ClientView
VercelInfrastructure hostingAll data (encrypted)EuropeView

Transparency and Audits

We believe in total transparency regarding the processing of your data:

  • Open source (partial): the Schengen compliance calculation algorithms are available for verification.
  • Incident reports: in the event of a security incident affecting your data, we undertake to notify you as soon as possible.
  • Audit on request: upon justified request, we can provide additional information on our security practices.
  • DPAs: we rely on the data processing agreements (DPAs) and Standard Contractual Clauses offered by our critical subprocessors; the formalization of these agreements is being finalized and further details can be provided on justified request.

Incident Reporting Procedure

If you suspect a security incident affecting your data on Bordermath (unauthorized access, potential leak, abnormal behavior), please report it to us immediately:

Support email: support@bordermath.xyz

We commit to acknowledging receipt of your report within 24 business hours and keeping you informed of the investigation progress.

How to Exercise Your Rights

In accordance with GDPR, you have several rights regarding your data. To exercise them:

For complete account deletion, you can also use the "Delete my account" function in the application settings.

  1. Send us a request by email to support@bordermath.xyz
  2. Specify your identity and the nature of your request (access, rectification, deletion, etc.)
  3. We will respond within a maximum of one month

Questions about our security?

Questions about our security?

Our legal and security team is available to answer your questions regarding the protection of your data.

Contact the legal team

For any concerns, please write to support@bordermath.xyz.

Avis important : <strong class="text-navy">Important notice:</strong> Bordermath provides calculation and information tools. This document is not legal advice. Consult a qualified attorney for questions relating to your specific situation. For any concerns, please write to support@bordermath.xyz.