Data Protection

Last updated: July 2026

Overview

Bubex is committed to complying with the EU General Data Protection Regulation (GDPR — Regulation 2016/679), the French Data Protection Act (Loi Informatique et Libertés), and other applicable data protection laws. This page summarises your rights as a data subject and how we fulfill our obligations as a data controller.

Data controller

The data controller for personal data processed through the Bubex platform is Bubex, operated by Félicien Merlaut. You can reach our data protection contact at contact@bubex.io.

Categories of personal data

CategoryExamplesLegal basis
IdentityName, email, professional titleContract performance
AuthenticationHashed password, session tokensContract performance
Deal contentListings, interests submittedContract performance
Usage logsIP address, page views, timestampsLegitimate interest (security)
CookiesSession cookie for authenticationContract performance / consent

Data subject rights

Under GDPR and applicable French law, you have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): Obtain confirmation of whether we process your data, and a copy of that data.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your data, subject to overriding retention obligations (e.g., legal record-keeping requirements).
  • Right to restriction (Art. 18): Request that we restrict processing of your data in certain circumstances.
  • Right to data portability (Art. 20): Receive your data in a machine-readable format to transfer to another controller, where processing is based on consent or contract.
  • Right to object (Art. 21): Object to processing based on legitimate interests. We will stop unless we demonstrate compelling legitimate grounds.
  • Rights related to automated decisions: We do not make solely automated decisions that produce legal effects concerning you.

To exercise any right, contact us at contact@bubex.io. We will respond within 30 days. We may need to verify your identity before processing the request.

International transfers

Your data is processed primarily within the European Economic Area (EEA). Where sub-processors are located outside the EEA (for example, if Vercel serves requests via edge locations), appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.

Retention periods

  • Account data: retained for the duration of membership and up to 3 years after closure.
  • Deal data: 5 years from the date of posting, for potential regulatory record-keeping compliance.
  • Security logs: 12 months rolling.

Security measures

We implement appropriate technical and organisational measures including: TLS 1.2+ encryption in transit; encryption at rest for the database; row-level security policies preventing cross-member data access; restricted database access via service role credentials not exposed to the internet; and periodic review of access controls.

Supervisory authority

If you are located in France or the EEA and believe we have not handled your data in compliance with GDPR, you have the right to lodge a complaint with the relevant supervisory authority. In France, the competent authority is the CNIL (Commission Nationale de l'Informatique et des Libertés) at cnil.fr.

Contact

For any data protection enquiry or to exercise your rights, write to us at contact@bubex.io.