Privacy & GDPR
GDPR-compliant privacy policy (EU Regulation 2016/679).
Data Controller
Foot Exchange SAS — privacy@foot-exchange.com
Data Collected
Foot Exchange collects the following data:
- Identification data: last name, first name, email, profile picture
- Professional data: FIFA license, affiliated club, status, mandate history
- Connection data: IP address, connection logs, device type
- Payment data: handled exclusively by our certified payment provider
- Communications: messages exchanged via the internal messaging system
Purposes of Processing
| Purpose |
Legal basis |
| User account management |
Performance of a contract |
| Personal identity verification |
Performance of a contract |
| Mandate generation and archiving |
Performance of a contract |
| Platform improvements |
Legitimate interest |
| Sending notifications and newsletters |
Consent |
| Compliance with legal obligations |
Legal obligation |
Data Retention Period
- Active account data: subscription duration + 3 years
- Generated mandates: 10 years (legal obligation)
- Connection data: 12 months
- Payment data: 5 years (accounting obligation)
Data Sharing
Foot Exchange never sells your data to third parties. Data may be shared with:
- Technical service providers (hosting, payment) under confidentiality agreements
- Competent authorities upon legal request
Your Rights
In accordance with the GDPR, you have the following rights:
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure: delete your data (subject to conditions)
- Right to data portability: receive your data in a structured format
- Right to object: object to certain processing activities
- Right to restriction: restrict the processing of your data
To exercise these rights: privacy@foot-exchange.com. Response time: within 30 days maximum.
If you are not satisfied with the response, you may lodge a complaint with the CNIL: www.cnil.fr.
Cookies
The platform uses technical cookies required for operation (session, authentication). Anonymous analytics cookies may be used to improve the experience, with your prior consent.
You can manage your cookie preferences at any time from the application settings or your browser.
Security
Foot Exchange implements technical and organizational measures to protect your data: encrypted communications (TLS), secure storage, strict access control, and strong authentication.
In the event of a personal data breach likely to result in a risk to your rights, you will be notified within 72 hours in accordance with the GDPR.