Privacy Policy
ABDELMOUMEN ADAM, trading under the commercial name GMB Club, attaches great importance to the protection of your personal data and the respect of your privacy.
This Privacy Policy transparently informs you about the data collected, the reasons for its collection, how we use and protect it, as well as your rights. It applies to the gmb-club.com website and to the GMB Club SaaS platform.
1. Data Controller
1.1. Identity of the data controller
| Legal name | ABDELMOUMEN ADAM |
| Trading name | A2Z — GMB Club |
| Legal form | Sole proprietorship |
| SIRET | 850 996 349 00039 |
| Address | 879 Chemin de la Grotte des Fées, 83400 Hyères, France |
| [email protected] | |
| Telephone | +33 6 49 37 62 72 |
1.2. Data Protection Officer (DPO)
| Name | Adam ABDELMOUMEN |
| [email protected] | |
| Telephone | +33 6 49 37 62 72 |
2. Personal Data Collected
2.1. Website browsing
- IP address, browser type and version, operating system
- Pages visited, visit duration, date and time of connection
- Referrer URL, approximate geolocation (country, region)
- Technical, analytical and personalisation cookies (see section 11)
2.2. Account creation
- Surname, first name (or legal name), professional email address, telephone, postal address, job title
- Company name, business sector, number of locations, addresses of locations
2.3. Use of the platform
- GMB data: name, address, category, opening hours, telephone, website, photos, customer reviews, replies, performance statistics
- Generated content: AI-generated review replies, retouched photos, scheduled publications, reports, collection campaigns
- Usage data: connection logs, actions performed, preferences, frequency of use
- Imported contacts: name, email, telephone of recipients of SMS/Email/WhatsApp campaigns
- OAuth tokens: access tokens for third-party platforms, stored encrypted (AES/Fernet), never accessible in plain text
2.4. Billing and payment
Banking details are collected and processed exclusively by Stripe (PCI-DSS Level 1 certified). We never store your full banking data. We retain only the last 4 digits of the card, the expiry date and the card type.
2.5. Unified messaging (Messenger, Instagram, WhatsApp Business)
GMB Club allows its customers to manage, through a unified interface, conversations received via Facebook Messenger, Instagram Direct Messages and WhatsApp Business. In this capacity, GMB Club acts as a technical intermediary between the Meta platforms and its business customers, who remain responsible for data processing vis-à-vis their own end customers.
When an end user writes to one of our customers through these channels, we process:
- The textual content of the messages exchanged (incoming and outgoing)
- Attachments sent (photos, videos, audio, documents, GPS location)
- The public name, profile picture and account identifier on the Meta platform
- Conversation metadata (timestamps, read statuses, reply window)
Messages are processed to enable our customers to reply, to generate suggested replies via artificial intelligence (Mistral AI), and to automatically qualify the type of request (information, quote, complaint, customer service).
2.6. WordPress integration (GMB Club Connect plugin)
When a user installs the GMB Club Connect plugin on their WordPress site, we receive and store:
- The WordPress site URL and its name
- The WordPress user identifier used as the author of published articles
- Categories, tags and the list of authors of the WordPress blog (periodic synchronisation to enable selection during article creation)
- The license key generated by GMB Club, or — for the manual method — a WordPress application password (encrypted at rest, never exposed to the browser)
No WordPress data is shared with third parties outside the technical sub-processors listed in section 4.2 (hosting, OpenAI/Anthropic for article generation).
2.7. Wix integration (direct OAuth connection)
When a user connects their Wix site to GMB Club via OAuth (Settings > Website connection), we receive and store:
- The unique Wix instance identifier (
instance_id, generated by Wix) - The Wix site URL and its name
- The Wix Member identifier used as the author of published articles
- Categories, tags and the list of members of the Wix blog (periodic synchronisation to enable selection during article creation)
- OAuth Client Credentials access tokens issued by Wix (encrypted at rest, never exposed to the browser)
No Wix data is shared with third parties outside the technical sub-processors listed in section 4.2 (hosting, OpenAI/Anthropic for article generation).
2.8. Built-in live support chat
GMB Club offers its authenticated users a built-in live support chat, available only after signing in. This is a proprietary system without chatbot or AI: messages are read and answered by a member of the GMB Club internal team.
When you open a conversation with our support, we process:
- Your Firebase identifier, email address and display name (already collected for authentication)
- The textual content of messages exchanged with our team
- The technical context at the moment of the exchange: active sphere and bubble, subscription plan, URL of the page where the chat was opened, browser user-agent, interface language
- If you enable support notifications (Web Push): the notification endpoint issued by your operating system (Apple, Google or Mozilla), an opaque identifier, and the encryption keys required to deliver messages
This data is used to answer your support requests, monitor service quality (response time) and keep a contextual history to make follow-up conversations smoother. It is not used for marketing and is not shared with any third party. You may permanently delete your conversation at any time from the chat widget (« Delete » button at the bottom of the window).
2.9. AI Assistant ("AI Agent")
GMB Club offers a conversational assistant ("AI Agent") that the user addresses in plain language, by keyboard or by voice. At the user's request, the assistant can read their account data (reviews, posts, statistics, articles, SEO, contacts) and perform actions, always after explicit confirmation for any sensitive action. Conversation history is kept for 30 days.
Voice messages (dictation): when the user dictates a request to the AI Agent, the audio recording is transmitted to Mistral AI for transcription, then is not kept — only the transcribed text is.
3. Purposes and Legal Bases for Processing
| Purpose | Legal basis |
|---|---|
| Creation and management of the user account | Performance of contract — Art. 6.1.b |
| Provision and improvement of the Service | Performance of contract — Art. 6.1.b |
| Billing and accounting management | Legal obligation — Art. 6.1.c |
| Payment processing (via Stripe) | Performance of contract — Art. 6.1.b |
| Customer support and technical assistance | Legitimate interest — Art. 6.1.f |
| Improvement of AI algorithms | Legitimate interest — Art. 6.1.f (anonymised data) |
| Management of messaging conversations (Messenger/Instagram/WhatsApp) | Performance of contract — Art. 6.1.b |
| AI-based qualification and reply suggestion on messages | Legitimate interest — Art. 6.1.f |
| AI Assistant ("AI Agent"): reading account data and performing actions at the user's request, with confirmation | Performance of contract — Art. 6.1.b / Legitimate interest — Art. 6.1.f |
| Operation of the built-in live support chat (replies, history, notifications) | Legitimate interest — Art. 6.1.f |
| Sending of commercial communications / newsletters | Consent — Art. 6.1.a |
| Statistical analysis and improvement of the service | Legitimate interest — Art. 6.1.f (anonymised data) |
| Fraud prevention and security | Legitimate interest — Art. 6.1.f |
| Legal obligations (accounting, taxation) | Legal obligation — Art. 6.1.c |
Consent
For processing based on consent (analytical cookies, commercial communications), you may withdraw this consent at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Data Recipients
4.1. Authorised personnel
Your data is accessible internally only to team members strictly authorised in the context of their duties (support, billing, development).
4.2. Sub-processors and technical providers
| Sub-processor | Service provided | Location |
|---|---|---|
| Firebase (Google) | User authentication; Firebase Cloud Messaging for push notification delivery (Android, web) | United States |
| Google Business Profile API | Management of listings, reviews, publications | United States |
| YouTube Data API v3 (Google) | Publishing videos and Shorts to the user's YouTube channel, on their behalf | United States |
| OpenAI | Generation of review replies, SEO articles | United States |
| Anthropic (Claude) | Conversational AI assistant (AI Agent), business-context distillation, technical monitoring | United States — Standard Contractual Clauses / Data Privacy Framework |
| Google Gemini (Imagen) | Image generation for articles | United States |
| Perplexity AI | Content research for articles | United States |
| DataForSEO | SEO keyword research | United States |
| Sweego | Sending of acquisition SMS | France |
| Meta (Facebook / Instagram / WhatsApp) | Social media publications, WhatsApp sending, transit of incoming and outgoing messages via Messenger / Instagram DM / WhatsApp Business | United States |
| Mistral AI | Reply suggestions, message qualification, and transcription of voice messages (AI Agent dictation) | France (EU) |
| Social media publications | United States | |
| Social media publications | United States | |
| TikTok (ByteDance) | Social media publications | Singapore / China |
| Snapchat (Snap Inc.) | Social media publications | United States |
| Stripe | Payment processing (PCI-DSS Level 1) | United States |
| Hostinger | Main VPS hosting (including the live support chat and the outgoing email infrastructure), SMTP emails | Germany (EU) |
| Apple Push Notification Service (Apple Inc.) | Transit of support push notifications to Apple devices. Relay service: content is end-to-end encrypted (Web Push), never stored in clear by the provider | United States |
| Mozilla Push Service (Mozilla Foundation) | Transit of support push notifications to Firefox browsers. Relay service: content is end-to-end encrypted (Web Push), never stored in clear by the provider | United States |
| Wix.com Ltd | API for article publishing and review embed (direct OAuth integration from GMB Club). Safeguards: GDPR compliance via their Data Processing Addendum, policy available at wix.com/about/privacy-policy | Israel |
4.3. Legal authorities
We may transmit data to the competent authorities in the event of a judicial request or legal obligation.
5. Access to Google APIs (Google Business Profile, YouTube)
GMB Club accesses certain data from your Google account, only with your explicit authorisation via OAuth, in order to provide the features you enable: managing your Google Business Profile listings, and publishing videos and Shorts to your YouTube channel on your behalf (scope youtube.upload).
GMB Club's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only use this data for the user-visible features you have enabled, we do not sell it and we do not transfer it to third parties for advertising purposes.
You can revoke this access at any time from within the application (by disconnecting the relevant network) or from your Google account security settings.
6. Data Transfers Outside the European Union
Several sub-processors are located outside the European Union (United States, Singapore). These transfers are framed by:
- Standard Contractual Clauses (SCC) approved by the European Commission
- Data Privacy Framework (DPF) for certified providers
- PCI-DSS Level 1 certification for Stripe
You may obtain a copy of the safeguards in place by contacting our DPO: [email protected]
7. Data Retention Periods
| Data category | Duration | Justification |
|---|---|---|
| Active account data | Duration of subscription | Performance of contract |
| Data after termination | 30 days | Possibility of reactivation, then deletion |
| OAuth tokens | Revoked upon termination | Security |
| WordPress integration data (GMB Club Connect plugin) | Retained as long as the plugin remains connected. Uninstallation = is_connected set to false within 24h, full deletion within 30 days | Performance of contract |
| Wix integration data (OAuth connection) | Retained as long as the connection remains active. Revocation of the connection = is_connected set to false within 24h, full deletion within 30 days | Performance of contract |
| Accounting and tax data | 10 years | Legal obligation (French Commercial Code) |
| Connection and security logs | 12 months | Security and fraud prevention |
| Message content and attachments (Messenger/Instagram/WhatsApp) | 90 days | Operational duration to process customer requests |
| Conversation metadata (timestamps, statuses) | 12 months | Anonymised statistical analysis |
| Active live support chat conversations | As long as relevant to the case; deletable at any time from the widget | Legitimate interest, support continuity |
| Closed live support chat conversations | 12 months after closing (automatic weekly purge) | Reference if the topic is reopened |
| Technical logs of reply-by-email | 90 days | Technical traceability and anti-spam |
| Email reply tokens | 30 days after expiry | Security and replay protection |
| Browsing cookies | 13 months maximum | CNIL (French data protection authority) recommendation |
| Prospecting data (newsletter) | 3 years without interaction | Legitimate interest, CNIL recommendation |
| Anonymised data (statistics) | Unlimited duration | No longer allows identification |
8. Data Security
Technical measures
- Encryption: SSL/TLS for all communications (HTTPS), AES/Fernet encryption of OAuth tokens, encryption of backups
- Authentication: Firebase Auth, SHA256-hashed API keys, 2FA available, principle of least privilege
- Infrastructure: firewall, intrusion detection, automated backups, regular updates, API rate limiting, partitioning per Bulle (business location)
- Payments: no banking data stored on our servers — Stripe PCI-DSS Level 1
- Live support chat: access restricted to a whitelist of agents (3 Firebase identifiers); push VAPID private key stored on disk in mode 600; inbound email webhooks signed with HMAC SHA-256; outgoing emails sent from
inbound.gmb-club.comvia a self-hosted Postfix server on our VPS; Web Push messages end-to-end encrypted, never readable in clear by transit services (APNs, FCM, Mozilla Push)
Organisational measures
- Mandatory confidentiality and security clauses with all sub-processors
- Procedure for notifying the CNIL within 72 hours in the event of a data breach
- Direct notification of the persons concerned in the event of high risk
9. Your Rights Over Your Personal Data
In accordance with the GDPR, you have the following rights:
| Right | Article | Description |
|---|---|---|
| Access | Art. 15 | Obtain confirmation that your data is being processed and receive a copy of it |
| Rectification | Art. 16 | Correct your inaccurate or incomplete data |
| Erasure | Art. 17 | Request the deletion of your data (subject to legal conditions) |
| Restriction | Art. 18 | Restrict the processing of your data in certain cases |
| Portability | Art. 20 | Retrieve your data in a structured format (CSV, JSON, XML) |
| Objection | Art. 21 | Object to processing based on legitimate interest or to direct marketing |
| Withdrawal of consent | Art. 7 | Withdraw your consent at any time for processing based on it |
| Post-mortem directives | Art. 85 LIL | Define directives regarding your data after your death |
Limit of the right to erasure
This right does not apply where retention is necessary to comply with a legal obligation (e.g., accounting data retained for 10 years).
10. How to Exercise Your Rights
- By email: [email protected]
- By telephone: +33 6 49 37 62 72
- By post: ABDELMOUMEN ADAM — DPO, 879 Chemin de la Grotte des Fées, 83400 Hyères
Please attach a copy of a valid identity document. Response within 1 month maximum (extendable by 2 months in case of complexity). The exercise of your rights is free of charge.
11. Right to Lodge a Complaint with the CNIL
If you consider that the processing of your data constitutes a breach of the GDPR, you have the right to lodge a complaint with the CNIL.
| Website | www.cnil.fr |
| Address | CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 |
| Telephone | 01 53 73 22 22 |
Contact us first
We invite you to contact us directly before referring the matter to the CNIL, so that we may address your concerns as swiftly as possible.
12. Cookies and Trackers
A cookie is a small text file placed on your device when visiting a website. It enables recognition of your browser and the storage of certain information.
| Type | Examples | Duration | Consent |
|---|---|---|---|
| Strictly necessary | Session, authentication, security (CSRF), language preference | Session / 12 months max | Not required |
| Analytical | Google Analytics or equivalent (anonymised IPs) | 13 months max | Required |
| Personalisation | Display mode, language, interface settings | 12 months max | Required |
| Social media / advertising | Facebook Pixel, LinkedIn Insight Tag (if integrated) | Variable | Required |
Manage your preferences
- Chrome:
chrome://settings/cookies - Firefox:
about:preferences#privacy - Safari: Preferences → Privacy
- Edge:
edge://settings/privacy
Your consent is retained for 13 months maximum, after which a new banner will be presented to you.
13. Minors' Data
Our service is not intended for persons under 18 years of age. We do not knowingly collect personal data relating to minors. If you are a parent or legal guardian and believe that your child has provided us with data, please contact us immediately: [email protected]
14. Policy Amendments
We reserve the right to amend this Policy at any time. In the event of a substantial modification, you will be notified by email, by a notification at the next login and by a banner on the website. Continued use of the service constitutes acceptance.
15. Contact — DPO
| DPO | Adam ABDELMOUMEN |
| [email protected] | |
| Telephone | +33 6 49 37 62 72 |
| Post | ABDELMOUMEN ADAM — DPO, 879 Chemin de la Grotte des Fées, 83400 Hyères, France |
| Hours | Monday to Friday, 9:00 – 18:00 (excluding public holidays) |
| Response time | 72 business hours maximum |
Associated legal documents
Legal notice — Terms of Use (CGU) — General Terms and Conditions of Sale (CGV)
