Skip to content

Privacy policy

Generic document to be validated by legal counsel before commercial use.

Generic document to be validated by legal counsel.

Controller and processor

Each customer lodge is the controller of its members' data. The publisher of Tuileur acts as a processor and only processes data on the Customer's instructions.

Data processed

Members' identity and contact details, degree and office history, attendance, documents, treasury operations, candidate files. Membership of a lodge is sensitive data (GDPR article 9): it is never shared or used for any purpose other than providing the Service.

Security

TLS encryption in transit, encryption at rest, application-level encryption of the most sensitive fields (emergency contacts, diets, candidate notes, inquiry reports), strict isolation per lodge, audit log, encrypted backups.

Hosting

Data is hosted in the European Union. Technical providers (hosting, transactional email, payments) are listed in the Data Processing Agreement.

Retention

Data is kept for the duration of the subscription and 90 days after it ends. Rejected candidate files are purged according to the period set by the lodge (2 years by default).

Data subject rights

Members exercise their rights (access, rectification, erasure, portability, objection) with their lodge. The publisher assists the Customer in handling these requests.

Cookies

The Service only uses strictly necessary cookies (session, display preferences). No advertising trackers.