Privacy Policy
Politique de Confidentialité
Your Privacy Matters
This policy explains how we collect, use, and protect your personal and financial information.
Data Controller
Realite SAS, a simplified joint-stock company registered with the Paris Trade Register under number B 123 456 789, is responsible for processing your personal data in accordance with the GDPR.
1. Information We Collect
We collect different types of information to provide our services and improve your experience.
1.1 Personal Information
- Name and email address
- Account credentials and preferences
- Contact information (phone number, address)
- Payment and billing information
- Profile photo and biographical information (optional)
1.2 Financial Information
- Portfolio holdings and transactions
- Investment preferences and risk tolerance
- Financial goals and objectives
- Market data and analysis preferences
- Search history and configured alerts - This data is used only to improve your personalized experience
1.3 Technical Information
- Device information and browser data
- IP address and location data
- Usage patterns and feature interactions
- Cookies and similar tracking technologies
- Access logs and technical diagnostic data
2. How We Use Your Information
We use your information to provide, maintain, and improve our services, as well as to offer you a personalized experience.
2.1 Service Provision
- Provide portfolio tracking and analysis
- Deliver personalized financial insights via AI
- Process payments and manage subscriptions
- Provide customer support
- Personalize your dashboard and alerts
2.2 Service Improvement
- Analyze usage patterns to improve our service
- Develop new features and functionality
- Optimize performance and user experience
- Train and improve our AI models (anonymized data only)
2.3 Communication
- Send service updates and notifications
- Provide educational content and market insights
- Respond to your inquiries and support requests
2.4 Artificial Intelligence Processing
🤖 Your data may be analyzed by our AI systems to generate personalized insights. This processing is carried out securely and in compliance with GDPR.
3. Information Sharing and Disclosure
🔒 We Do NOT Share Your Financial Data
Your financial information is never shared with third parties for marketing purposes.
We may share information only in these limited circumstances:
- Service Providers: Trusted third parties who help us operate our service (under strict confidentiality agreements)
- Legal Requirements: When required by law, court order, or regulatory authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- Consent: When you explicitly consent to sharing
- AI Providers: Our AI partners (OpenAI, Anthropic) to generate personalized analyses, under strict data protection contracts
Legal Transfers
In case of a legal request, we will inform you to the extent permitted by law, unless doing so would compromise an ongoing investigation.
4. Data Security
We implement appropriate technical and organizational security measures to protect your data.
4.1 Security Measures
- AES-256 encryption of data in transit and at rest
- Secure authentication and access controls
- Regular security audits and penetration testing
- Employee training on data protection
- Continuous system monitoring and intrusion detection
4.2 Financial Data Protection
- Bank-level encryption for financial information
- Limited access on a need-to-know basis
- Regular security assessments and updates
- Compliance with GDPR and financial data protection standards
- Data backup and recovery procedures
4.3 Breach Notification
In the event of a data breach that may pose a risk to your rights and freedoms, we will notify you within 72 hours in accordance with GDPR and take all necessary steps to mitigate the damage.
5. Data Retention
We retain your data for the following periods:
- Account Data: Retained while your account is active and for 3 years after closure
- Financial Data: Retained for 7 years for regulatory compliance
- Usage Data: Retained for 2 years for service improvement
- Communication Data: Retained for 3 years for support purposes
- Login logs: Retained for 1 year in accordance with legal requirements
- Payment data: Retained for 10 years for accounting obligations
- Analytics cookies: Maximum 13 months in accordance with CNIL recommendations
- Prospecting data: 3 years after last contact
You may request deletion of your personal data, subject to legal and regulatory requirements. Some data may be retained for legitimate business purposes or legal compliance.
6. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of Access: Obtain a copy of your personal data
- Right to Rectification: Correct inaccurate data
- Right to Erasure: Request deletion of your data ('Right to be Forgotten')
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
- Right to define post-mortem directives: Define directives relating to the retention and communication of your data after your death
How to Exercise Your Rights
To exercise these rights, contact us at contact@realite.io
You also have the right to lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés) if you believe that the processing of your data does not comply with regulations.
7. Cookies and Tracking
We use cookies and similar technologies to improve your experience and analyze the use of our service.
7.1 Types of Cookies
- Essential Cookies: Required for basic service functionality
- Analytics Cookies: Help us understand usage patterns
- Preference Cookies: Remember your settings and preferences
7.2 Analytics Cookies
- Google Analytics: To measure audience and improve our services
- Performance cookies: To optimize site speed and performance
7.3 Cookie Management
- You can accept or refuse non-essential cookies on your first visit
- You can change your preferences at any time via our cookie banner or your browser settings
7.4 Retention Period
In accordance with CNIL recommendations, cookies have a maximum lifespan of 13 months. Your consent is periodically requested again.
8. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by relevant authorities
- Binding Corporate Rules where applicable
- Supplementary technical and organizational measures
🤖 AI Processing: Our services use OpenAI APIs (United States). These transfers are governed by Standard Contractual Clauses and enhanced security measures.
9. Children's Privacy
Our service is not intended for children under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected such information, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or platform notification at least 30 days before they take effect. We encourage you to review this policy periodically.
11. Contact Information
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at:
- Email: contact@realite.io
- Privacy Email: contact@realite.io
- Data Protection Officer: dpo@realite.io
- Address: 123 Financial Street, 75001 Paris, France
We commit to responding to any request relating to your personal data within one month. This period may be extended by two months if necessary, taking into account the complexity of the request.
You also have the right to lodge a complaint with the CNIL: Commission Nationale de l'Informatique et des Libertés, 3 Place de Fontenoy - TSA 80715, 75334 Paris Cedex 07, www.cnil.fr
Realite SAS - RCS Paris B 123 456 789
Last Updated: January 27, 2026
This Privacy Policy is effective as of the date above and applies to all information collected by Realite.