Chez NousChez Nous

Privacy policy

Last updated: September 10, 2026

⚠️ Page to finalise: this template covers the sections expected under GDPR but must be completed and validated by a lawyer or your DPO before going live, given the sensitivity of the data processed (people with disabilities, health data where applicable).

Chez Nous pays particular attention to protecting the personal data of its users, especially the residents it supports, a recognised vulnerable population. This policy explains what data is collected, why, and how it is protected.

Who is the data controller?

[TO COMPLETE] Legal name of the publisher, address, contact details of the Data Protection Officer (DPO) if appointed.

What data is collected

On this showcase site: first and last name, email, facility name and message, only when you fill in a contact or guide-request form. Within the Chez Nous application: [TO COMPLETE — detail of resident data: identity, photos, messages, connection data, and any health data where applicable].

Sensitive data and vulnerable users

Residents using the application may be people with disabilities. [TO COMPLETE] Specify whether health data within the meaning of Article 9 GDPR is processed, the legal basis relied on (e.g. explicit consent from the resident and/or their legal guardian), and the enhanced protection measures in place.

Why this data is collected

To respond to your contact or demo requests, send you the information guide you requested, and — within the application — allow residents to use the social network under the conditions set by their facility.

Legal basis and consent

[TO COMPLETE] Legal basis relied on for each processing activity (consent, legitimate interest, contract performance) and how informed consent is collected, including from legal guardians.

Retention period

[TO COMPLETE] Retention period for showcase site data and for data within the application, and how data is deleted if a facility stops using the service.

Hosting and security

Data is hosted within the European Union. [TO COMPLETE] Name of the host, technical security measures (encryption, access control) and organisational measures in place.

Recipients and subprocessors

[TO COMPLETE] List of any subprocessors (hosting, email delivery, etc.) and the GDPR contractual guarantees in place. No data is ever sold or used for advertising purposes.

Your rights

Under GDPR, you have the right to access, rectify, erase, restrict, object to, and port your data. For residents being supported, these rights may be exercised by their legal guardian. [TO COMPLETE] Concrete steps to exercise these rights and contact address.

Contact and complaints

[TO COMPLETE — DPO/GDPR contact email address]. You may also lodge a complaint with your national data protection authority.