Privacy policy
Effective 30 June 2026.
Contents
- 1. Introduction and scope
- 2. Data controller
- 3. Our approach: privacy by design
- 4. Definitions
- 5. What we do not collect
- 6. Location data
- 7. Querying the map
- 8. Data stored locally on your device
- 9. Contact form
- 10. Abuse prevention
- 11. Legal bases (Article 6 GDPR)
- 12. Recipients and processors
- 13. Third-party data providers
- 14. Transfers outside the European Union
- 15. Retention periods
- 16. Security
- 17. Your rights
- 18. Minors
- 19. Changes
- 20. Contact
1. Introduction and scope
This Privacy Policy explains what data the Pangée app processes, or does not process, when you use it. It applies to the mobile application as well as to the legal pages published online. Pangée is built on the principle of data minimisation: it collects only what is strictly necessary for it to function.
2. Data controller
The data controller is Staivium, publisher of the App, reachable at privacy@staivium.com for any question about your data. The processing described below is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and applicable data-protection law.
3. Our approach: privacy by design
Pangée is a consultation app. Using it requires no account, sign-up or profile. The App contains no advertising, no audience-measurement or behavioural-analytics tool, no tracking cookie and no advertising identifier. No data is collected for profiling, nor sold, rented or otherwise transferred to third parties for commercial purposes.
4. Definitions
'the App' means the Pangée mobile application; 'the Publisher' means Staivium; 'you' or 'the User' means any person using the App; 'personal data' means any information relating to an identified or identifiable natural person; 'processing' means any operation performed on such data.
5. What we do not collect
We do not collect: your name or identity, any account or password, any map-browsing history kept on our servers, any advertising identifier, any usage-analytics data, or any tracking cookie. No data feeds any marketing profile.
6. Location data
If you consent through your operating-system permission, your GPS position is used to locate you on the map. This is processed locally on your device: your position is neither stored by the Publisher nor sent to a server as such. You can withdraw this permission at any time in your device settings; the App remains usable in free-navigation mode.
7. Querying the map
When you tap the map to query a layer, or when a layer loads information around a point, the relevant coordinates and your device's IP address are sent to the corresponding public data providers (in particular IGN, BRGM, Géorisques and Hub'Eau) and to the Publisher's tile server (Cloudflare). These coordinates correspond to the point you are viewing on the map, which may not match your actual position. Processing by those third-party providers is governed by their own privacy policies.
8. Data stored locally on your device
Your usage preferences (language, favourite layers, layer order, display settings) are stored in your device's local storage so that your configuration is restored between sessions. This data does not leave your device and is not transmitted to the Publisher. It is deleted when you uninstall the App or clear its storage.
9. Contact form
When you write to us via the 'Help & contact' screen, the following are processed: the subject of your request, the content of your message, your email address and, where applicable, the image you attach. The purpose of this processing is to receive and handle your request. This information passes through the Publisher's server (Cloudflare Worker); any image is stored on Cloudflare R2; the message is delivered to the support mailbox via Resend, Inc. Your email address is used as the reply address.
10. Abuse prevention
To prevent automated submissions and abuse, the server temporarily processes the IP address from which the form is sent in order to rate-limit requests. This data is processed for security purposes only and is not used for any other purpose.
11. Legal bases (Article 6 GDPR)
Location: your consent, given through the operating-system permission, together with the Publisher's legitimate interest in providing the display feature. Querying the map: the legitimate interest of the Publisher and the User in providing and obtaining the requested information. Contact form: the Publisher's legitimate interest in responding to your request. Abuse prevention: the Publisher's legitimate interest in keeping the service secure.
12. Recipients and processors
Your contact data is accessible to the Publisher and to its technical processors, which act on its behalf and on its instructions: Cloudflare, Inc. (server hosting and image storage) and Resend, Inc. (email delivery). Distribution of the App is handled by Google Ireland Limited. No data is shared with third parties for their own commercial use.
13. Third-party data providers
Displaying and querying layers relies on third-party public data services (in particular IGN, BRGM, Géorisques, Hub'Eau / Eau France, INRAE, OpenStreetMap, Copernicus). Interacting with a layer sends a request to the relevant provider, which applies its own privacy policy. The full list of providers appears in the 'Credits & sources' screen.
14. Transfers outside the European Union
As Cloudflare, Inc. and Resend, Inc. are established in the United States, processing your contact data may involve a transfer outside the European Union. Such transfers are governed by the appropriate safeguards under Chapter V of the GDPR, in particular the standard contractual clauses adopted by the European Commission.
15. Retention periods
Contact messages and attached images: kept for as long as needed to handle your request, then for a maximum of twelve (12) months before deletion. Abuse-prevention data (IP address): retained ephemerally, for the duration of the anti-abuse check. Preferences stored locally: kept on your device for as long as the App is installed.
16. Security
Exchanges between the App, the Publisher's server and the data providers are encrypted in transit (HTTPS/TLS). The Publisher applies data minimisation, keeps no centralised database of users' personal data and restricts access to contact messages. As no system is infallible, absolute security cannot be guaranteed.
17. Your rights
Under the GDPR, you have the right of access, rectification, erasure, objection, restriction of processing and portability, as well as the right to withdraw your consent at any time. To exercise these rights, write to privacy@staivium.com or use the 'Help & contact' screen. Exercising these rights is free of charge and we respond within one (1) month. You may also lodge a complaint with the French data-protection authority (CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr).
18. Minors
The App is intended for a general audience and does not specifically target children. The contact form should not be used by anyone under the age of fifteen (15) without the consent of their legal guardians.
19. Changes
This Policy may be updated to reflect changes to the App or to applicable law. The applicable version is the one published in the App and online at the time you consult it; its effective date appears at the top of the document. In the event of a material change, we will endeavour to inform you within the App.
20. Contact
For any question about your data, write to privacy@staivium.com. For any other request, write to contact@staivium.com or use the 'Help & contact' screen.