GMB Club

Privacy Policy

ABDELMOUMEN ADAM, trading under the commercial name GMB Club, attaches great importance to the protection of your personal data and the respect of your privacy.

This Privacy Policy transparently informs you about the data collected, the reasons for its collection, how we use and protect it, as well as your rights. It applies to the gmb-club.com website and to the GMB Club SaaS platform.

Last updated: 28 July 2026
Version 1.6
GDPR compliant

1. Data Controller

1.1. Identity of the data controller

Legal nameABDELMOUMEN ADAM
Trading nameA2Z — GMB Club
Legal formSole proprietorship
SIRET850 996 349 00039
Address879 Chemin de la Grotte des Fées, 83400 Hyères, France
Email[email protected]
Telephone+33 6 49 37 62 72

1.2. Data Protection Officer (DPO)

NameAdam ABDELMOUMEN
Email[email protected]
Telephone+33 6 49 37 62 72

2. Personal Data Collected

2.1. Website browsing

2.2. Account creation

2.3. Use of the platform

2.4. Billing and payment

Banking details are collected and processed exclusively by Stripe (PCI-DSS Level 1 certified). We never store your full banking data. We retain only the last 4 digits of the card, the expiry date and the card type.

2.5. Unified messaging (Messenger, Instagram, WhatsApp Business)

GMB Club allows its customers to manage, through a unified interface, conversations received via Facebook Messenger, Instagram Direct Messages and WhatsApp Business. In this capacity, GMB Club acts as a technical intermediary between the Meta platforms and its business customers, who remain responsible for data processing vis-à-vis their own end customers.

When an end user writes to one of our customers through these channels, we process:

Messages are processed to enable our customers to reply, to generate suggested replies via artificial intelligence (Mistral AI), and to automatically qualify the type of request (information, quote, complaint, customer service).

2.6. WordPress integration (GMB Club Connect plugin)

When a user installs the GMB Club Connect plugin on their WordPress site, we receive and store:

No WordPress data is shared with third parties outside the technical sub-processors listed in section 4.2 (hosting, OpenAI/Anthropic for article generation).

2.7. Wix integration (direct OAuth connection)

When a user connects their Wix site to GMB Club via OAuth (Settings > Website connection), we receive and store:

No Wix data is shared with third parties outside the technical sub-processors listed in section 4.2 (hosting, OpenAI/Anthropic for article generation).

2.8. Built-in live support chat

GMB Club offers its authenticated users a built-in live support chat, available only after signing in. This is a proprietary system without chatbot or AI: messages are read and answered by a member of the GMB Club internal team.

When you open a conversation with our support, we process:

This data is used to answer your support requests, monitor service quality (response time) and keep a contextual history to make follow-up conversations smoother. It is not used for marketing and is not shared with any third party. You may permanently delete your conversation at any time from the chat widget (« Delete » button at the bottom of the window).

2.9. AI Assistant ("AI Agent")

GMB Club offers a conversational assistant ("AI Agent") that the user addresses in plain language, by keyboard or by voice. At the user's request, the assistant can read their account data (reviews, posts, statistics, articles, SEO, contacts) and perform actions, always after explicit confirmation for any sensitive action. Conversation history is kept for 30 days.

Voice messages (dictation): when the user dictates a request to the AI Agent, the audio recording is transmitted to Mistral AI for transcription, then is not kept — only the transcribed text is.

3. Purposes and Legal Bases for Processing

PurposeLegal basis
Creation and management of the user accountPerformance of contract — Art. 6.1.b
Provision and improvement of the ServicePerformance of contract — Art. 6.1.b
Billing and accounting managementLegal obligation — Art. 6.1.c
Payment processing (via Stripe)Performance of contract — Art. 6.1.b
Customer support and technical assistanceLegitimate interest — Art. 6.1.f
Improvement of AI algorithmsLegitimate interest — Art. 6.1.f (anonymised data)
Management of messaging conversations (Messenger/Instagram/WhatsApp)Performance of contract — Art. 6.1.b
AI-based qualification and reply suggestion on messagesLegitimate interest — Art. 6.1.f
AI Assistant ("AI Agent"): reading account data and performing actions at the user's request, with confirmationPerformance of contract — Art. 6.1.b / Legitimate interest — Art. 6.1.f
Operation of the built-in live support chat (replies, history, notifications)Legitimate interest — Art. 6.1.f
Sending of commercial communications / newslettersConsent — Art. 6.1.a
Statistical analysis and improvement of the serviceLegitimate interest — Art. 6.1.f (anonymised data)
Fraud prevention and securityLegitimate interest — Art. 6.1.f
Legal obligations (accounting, taxation)Legal obligation — Art. 6.1.c

Consent

For processing based on consent (analytical cookies, commercial communications), you may withdraw this consent at any time without affecting the lawfulness of processing carried out before withdrawal.

4. Data Recipients

4.1. Authorised personnel

Your data is accessible internally only to team members strictly authorised in the context of their duties (support, billing, development).

4.2. Sub-processors and technical providers

Sub-processorService providedLocation
Firebase (Google)User authentication; Firebase Cloud Messaging for push notification delivery (Android, web)United States
Google Business Profile APIManagement of listings, reviews, publicationsUnited States
YouTube Data API v3 (Google)Publishing videos and Shorts to the user's YouTube channel, on their behalfUnited States
OpenAIGeneration of review replies, SEO articlesUnited States
Anthropic (Claude)Conversational AI assistant (AI Agent), business-context distillation, technical monitoringUnited States — Standard Contractual Clauses / Data Privacy Framework
Google Gemini (Imagen)Image generation for articlesUnited States
Perplexity AIContent research for articlesUnited States
DataForSEOSEO keyword researchUnited States
SweegoSending of acquisition SMSFrance
Meta (Facebook / Instagram / WhatsApp)Social media publications, WhatsApp sending, transit of incoming and outgoing messages via Messenger / Instagram DM / WhatsApp BusinessUnited States
Mistral AIReply suggestions, message qualification, and transcription of voice messages (AI Agent dictation)France (EU)
LinkedInSocial media publicationsUnited States
PinterestSocial media publicationsUnited States
TikTok (ByteDance)Social media publicationsSingapore / China
Snapchat (Snap Inc.)Social media publicationsUnited States
StripePayment processing (PCI-DSS Level 1)United States
HostingerMain VPS hosting (including the live support chat and the outgoing email infrastructure), SMTP emailsGermany (EU)
Apple Push Notification Service (Apple Inc.)Transit of support push notifications to Apple devices. Relay service: content is end-to-end encrypted (Web Push), never stored in clear by the providerUnited States
Mozilla Push Service (Mozilla Foundation)Transit of support push notifications to Firefox browsers. Relay service: content is end-to-end encrypted (Web Push), never stored in clear by the providerUnited States
Wix.com LtdAPI for article publishing and review embed (direct OAuth integration from GMB Club). Safeguards: GDPR compliance via their Data Processing Addendum, policy available at wix.com/about/privacy-policyIsrael

4.3. Legal authorities

We may transmit data to the competent authorities in the event of a judicial request or legal obligation.

5. Access to Google APIs (Google Business Profile, YouTube)

GMB Club accesses certain data from your Google account, only with your explicit authorisation via OAuth, in order to provide the features you enable: managing your Google Business Profile listings, and publishing videos and Shorts to your YouTube channel on your behalf (scope youtube.upload).

GMB Club's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only use this data for the user-visible features you have enabled, we do not sell it and we do not transfer it to third parties for advertising purposes.

You can revoke this access at any time from within the application (by disconnecting the relevant network) or from your Google account security settings.

6. Data Transfers Outside the European Union

Several sub-processors are located outside the European Union (United States, Singapore). These transfers are framed by:

You may obtain a copy of the safeguards in place by contacting our DPO: [email protected]

7. Data Retention Periods

Data categoryDurationJustification
Active account dataDuration of subscriptionPerformance of contract
Data after termination30 daysPossibility of reactivation, then deletion
OAuth tokensRevoked upon terminationSecurity
WordPress integration data (GMB Club Connect plugin)Retained as long as the plugin remains connected. Uninstallation = is_connected set to false within 24h, full deletion within 30 daysPerformance of contract
Wix integration data (OAuth connection)Retained as long as the connection remains active. Revocation of the connection = is_connected set to false within 24h, full deletion within 30 daysPerformance of contract
Accounting and tax data10 yearsLegal obligation (French Commercial Code)
Connection and security logs12 monthsSecurity and fraud prevention
Message content and attachments (Messenger/Instagram/WhatsApp)90 daysOperational duration to process customer requests
Conversation metadata (timestamps, statuses)12 monthsAnonymised statistical analysis
Active live support chat conversationsAs long as relevant to the case; deletable at any time from the widgetLegitimate interest, support continuity
Closed live support chat conversations12 months after closing (automatic weekly purge)Reference if the topic is reopened
Technical logs of reply-by-email90 daysTechnical traceability and anti-spam
Email reply tokens30 days after expirySecurity and replay protection
Browsing cookies13 months maximumCNIL (French data protection authority) recommendation
Prospecting data (newsletter)3 years without interactionLegitimate interest, CNIL recommendation
Anonymised data (statistics)Unlimited durationNo longer allows identification

8. Data Security

Technical measures

Organisational measures

9. Your Rights Over Your Personal Data

In accordance with the GDPR, you have the following rights:

RightArticleDescription
AccessArt. 15Obtain confirmation that your data is being processed and receive a copy of it
RectificationArt. 16Correct your inaccurate or incomplete data
ErasureArt. 17Request the deletion of your data (subject to legal conditions)
RestrictionArt. 18Restrict the processing of your data in certain cases
PortabilityArt. 20Retrieve your data in a structured format (CSV, JSON, XML)
ObjectionArt. 21Object to processing based on legitimate interest or to direct marketing
Withdrawal of consentArt. 7Withdraw your consent at any time for processing based on it
Post-mortem directivesArt. 85 LILDefine directives regarding your data after your death

Limit of the right to erasure

This right does not apply where retention is necessary to comply with a legal obligation (e.g., accounting data retained for 10 years).

10. How to Exercise Your Rights

Please attach a copy of a valid identity document. Response within 1 month maximum (extendable by 2 months in case of complexity). The exercise of your rights is free of charge.

11. Right to Lodge a Complaint with the CNIL

If you consider that the processing of your data constitutes a breach of the GDPR, you have the right to lodge a complaint with the CNIL.

Websitewww.cnil.fr
AddressCNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Telephone01 53 73 22 22

Contact us first

We invite you to contact us directly before referring the matter to the CNIL, so that we may address your concerns as swiftly as possible.

12. Cookies and Trackers

A cookie is a small text file placed on your device when visiting a website. It enables recognition of your browser and the storage of certain information.

TypeExamplesDurationConsent
Strictly necessarySession, authentication, security (CSRF), language preferenceSession / 12 months maxNot required
AnalyticalGoogle Analytics or equivalent (anonymised IPs)13 months maxRequired
PersonalisationDisplay mode, language, interface settings12 months maxRequired
Social media / advertisingFacebook Pixel, LinkedIn Insight Tag (if integrated)VariableRequired

Manage your preferences

Your consent is retained for 13 months maximum, after which a new banner will be presented to you.

13. Minors' Data

Our service is not intended for persons under 18 years of age. We do not knowingly collect personal data relating to minors. If you are a parent or legal guardian and believe that your child has provided us with data, please contact us immediately: [email protected]

14. Policy Amendments

We reserve the right to amend this Policy at any time. In the event of a substantial modification, you will be notified by email, by a notification at the next login and by a banner on the website. Continued use of the service constitutes acceptance.

15. Contact — DPO

DPOAdam ABDELMOUMEN
Email[email protected]
Telephone+33 6 49 37 62 72
PostABDELMOUMEN ADAM — DPO, 879 Chemin de la Grotte des Fées, 83400 Hyères, France
HoursMonday to Friday, 9:00 – 18:00 (excluding public holidays)
Response time72 business hours maximum

Associated legal documents

Legal noticeTerms of Use (CGU)General Terms and Conditions of Sale (CGV)