Personal data register

Field Description
Data controller PopcornFX
Processing purpose Customer account management, support services, transaction processing, security, fraud detection, service improvement
Categories of data subjects Individual users
Categories of personal data First and last name, email postal and IP addresses, company name, job, country, hardware, user’s editor preferences and behavior
Legal basis for processing Contract performance (Art. 6(1)(b)), Consent (Art. 6(1)(a)), Legitimate interest (Art. 6(1)(f))
Recipients Internal team and payment service provider (Stripe)
Transfers outside the EU Not for our own processing, but payment data is managed by Stripe. Although data is hosted in the EU, access by Stripe, Inc. (US) may occur for internal purposes. In such cases, Standard Contractual Clauses (SCCs 2021) are used as the legal safeguard for international transfers.
Data retention period 2 years after last activity, then anonymized for hardware and behavioral data. Payment data is handled by the service provider as per financial regulations.
Security measures Data encryption at rest and in transit, access control, strong authentication, regular audits
Source of data Collected directly from the user via the web platform and the PopcornFX software
Automated decision-making None - decisions involving personal data are reviewed or confirmed by humans.
Data Protection Officer (DPO) Valentin Ksiezak – privacy@persistant.fr