Personal data

Privacy policy

How we collect, use and protect your data when you use sarahcitta.com and related services.

1. Data controller

The controller for personal data is Sarah Charhi, publisher of sarahcitta.com.

Data contact: sarahcittapro@gmail.com.

2. Data collected

We may process in particular:

  • Identification and account data (name, username, email address and encrypted password);
  • Connection and usage data (pages viewed, device and technical logs);
  • Payment data handled by our payment provider (we do not store your card number);
  • Content you voluntarily send us (contact messages and permitted attachments).

3. Purposes and legal bases

  • Providing services (account, content access and support) — performance of the contract;
  • Billing and subscription management — performance of the contract and legal obligations;
  • Security and website improvement — legitimate interest;
  • Communications (responses to requests) — legitimate interest or performance of the contract.

4. Recipients

Data may be shared with strictly necessary technical processors (hosting provider, authentication/database provider, payment provider and email service where used), in compliance with the GDPR and under a data-processing agreement where required.

5. Retention period

Data is kept for the time needed for the stated purposes, then archived or deleted in accordance with legal obligations (for example, invoicing) and our internal retention policies.

6. Your rights (GDPR)

Within the limits set by law, you have the following rights:

  • Access, rectification and erasure;
  • Restriction of processing;
  • Objection;
  • Data portability, where applicable;
  • Withdrawal of consent where processing is based on consent;
  • To lodge a complaint with the CNIL (cnil.fr).

To exercise your rights, use the contact form or sarahcittapro@gmail.com.

7. Cookies and trackers

Cookies or similar technologies may be used for website operation, audience measurement or security. You can configure your browser to refuse some cookies, which may limit some features.

8. Transfers outside the EU

If certain processors are located outside the European Economic Area, appropriate safeguards (the European Commission’s standard contractual clauses or an adequacy decision) are put in place where required by law.

9. Updates

This policy may be updated. Its last update date may be specified here when material changes are made.