Personal data
Privacy policy
Last updated: 29 July 2026.
This translation is provided for information; in case of discrepancy, the French version prevails.
Who decides what
Your schooldecides about its students' data: it collects it, corrects it, deletes it. It is the data controller within the meaning of the GDPR. Benford Tech acts only as a processor: it runs the tool and uses this data for nothing else — no resale, no advertising, no model training.
Benford Tech is, however, the controller for the accounts it manages itself: the platform administration accounts and school opening requests.
What is processed
- Student
- First name, last name, email, phone (optional), gender and dance level, profile photo (optional), class enrolments, confirmed and recorded attendance, plan, payments and invoices.
- Teacher or school administrator
- Name, email, encrypted password, role, speciality and hourly rate if provided, history of attendance calls made and messages sent.
- School
- Name, city, address, company ID (SIRET), billing details, identifiers of the school's Stripe account.
- Visitor
- No data. The site sets no tracker and no advertising cookie, and does not measure its audience.
Why
- Running the class : enrolling, counting places, keeping the waitlist, taking attendance, sending day-before reminders and video recaps.
- Keeping the school's books : plans, payments, numbered invoices, chasing unpaid amounts — a legal obligation for the school.
- Securing access : a password for staff, a secret personal link for the student.
The legal basis is the performance of the contract between the student and their school, and the legal obligation for invoicing. Push notifications only go out after your explicit consent in the browser, and stop when the permission is withdrawn.
Who else can access it
Nobody outside your school and the technical providers below. Schools are sealed off from one another: one school's data is never visible from another.
| Provider | Role | Location |
|---|---|---|
| Vercel | Site hosting | United States |
| Neon (AWS) | Database | United States — us-east-1 |
| Stripe | Online payments, on behalf of each school | European Union / United States |
| Gandi | Email delivery (invoices, reminders, access links) | France |
| “Continue with Google” sign-in, if the school uses it | United States |
Transfers outside the European Union:the site hosting and the database are located in the United States. These transfers rely on the European Commission's standard contractual clauses, provided for in these providers' contracts.
For how long
A student's data is kept as long as they are enrolled in their school, then deleted at their request or the school's. Invoices and payments are kept for ten years, as accounting law requires. A staff account is kept for the duration of their role.
Cookies
A single cookie is set, tempo_session, and only after signing in: it keeps the staff session open. It is strictly necessary to the service, which exempts it from a consent banner. No analytics cookie, no advertising tracker, no embedded social network. Students don't even have a cookie: their personal link is enough.
Security
Staff passwords are hashed (bcrypt) and never stored in plain text. All exchanges go through HTTPS. A student's personal link contains a random token: it is as good as a password, better not to share it. Every request checks the school of the signed-in person before answering.
Your rights
You can request access to your data, its correction, its deletion, its portability, or object to a processing operation. The fastest route is to talk to your school, which has direct control in its space. You can also write to the publisher, whose details are in the legal notice. In case of disagreement, you can refer the matter to the CNIL, the French data protection authority (cnil.fr).