Aller au contenu principal

Last updated : 1 September 2026

Privacy Policy

Oprotect (a marketplace for private security missions in France) is committed to protecting your personal data. This policy explains what we collect, why, who we share it with, and your rights.

Version françaiseLegal notices & termsCookie policy

1. Data controller

The data controller is OPROTECT, a French SAS, registered office at 13 rue de Thorigny, 75003 Paris, France, 847 814 092 RCS Paris.

Privacy enquiries: contact@oprotect.com or +33 1 86 98 23 11.

2. Data we collect

Depending on how you use our website and services, we may process:

  • Identity and contact details: name, email, phone, company, address.
  • Account and authentication: credentials, session tokens, login history.
  • Quote requests and missions: guard type, dates, location, description, price estimates.
  • Commercial relationship (CRM): emails, quotes, bookings, invoicing.
  • Partner agent onboarding: company registration (SIRET), CNAPS licence, supporting documents (ID, insurance).
  • Payments: card data (number, expiry, CVC) is collected and processed exclusively by Mollie B.V. on its hosted checkout. Oprotect does not store full card numbers. A Mollie mandate identifier may be linked to your account if you opt in to save a card.
  • Analytics and advertising: cookies, ad identifiers, pages viewed, traffic source (with consent where required).
  • Technical logs: IP address, user agent, timestamps (security and operations).

3. Purposes and legal bases

We process personal data for specific purposes, under GDPR Article 6 legal bases including:

  • Contract or pre-contractual steps: handling quote requests, account creation, matchmaking, secure access links.
  • Legal obligation: accounting records, regulatory compliance (CNAPS for agents).
  • Legitimate interests: platform security, fraud prevention, service improvement, internal alerts (new leads, agent sign-ups).
  • Consent: analytics and advertising cookies (consent banner), marketing where applicable.

4. Recipients and processors

Data is accessed by authorised Oprotect staff and, where relevant, by agents or clients involved in a confirmed booking (contact details unlocked after validation).

We use GDPR Article 28 processors including:

  • Supabase — database, authentication, file storage (EU).
  • Vercel — web application hosting.
  • Brevo — transactional email delivery.
  • Google (Tag Manager, Analytics, Ads, Search Console) — analytics and campaigns, subject to consent.
  • Cloudflare — inbound email routing where applicable.
  • Mollie B.V. (Keizersgracht 126, 1015 CW Amsterdam, Pays-Bas) — online payments, marketplace holding, card mandates, and payouts to partner agencies. Mollie privacy policy: https://www.mollie.com/privacy.

5. Retention

We keep data only as long as necessary:

  • Prospects and quote requests: up to 3 years after last contact, unless you object.
  • Clients and missions: contract duration + statutory limitation and accounting periods.
  • Agent accounts: partnership duration + regulatory obligations.
  • Cookies: as stated in the consent banner.
  • Technical logs: limited period (months), longer if a security incident requires it.

6. Cookies

Strictly necessary cookies (session, security) do not require consent.

Analytics and advertising cookies are enabled only after your choice in the cookie banner. You may change your mind by clearing browser cookies or contacting us.

7. Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, objection, portability (where applicable), and withdrawal of consent.

To exercise your rights, email contact@oprotect.com. We respond within one month.

You may lodge a complaint with your supervisory authority (in France: CNIL, www.cnil.fr).

8. Security

We apply appropriate technical and organisational measures: HTTPS, role-based access, vetted hosting providers, private storage for sensitive documents (time-limited signed URLs).

Card payments run on Mollie's PCI DSS environment. Oprotect never sees the full card number.

9. International transfers

Some processors (including in the US) may process data outside the EEA. We rely on GDPR mechanisms such as Standard Contractual Clauses and supplementary measures where required.

10. Children

Our services are intended for adults. We do not knowingly collect data from children.

11. Updates

We may update this policy to reflect service or legal changes. The last updated date is shown at the top. Material changes will be communicated appropriately.

Appeler le standardDevis gratuit