Privacy Policy

Last updated: January 26, 2026

This policy applies to the Sostenutoo website, the Sostenutoo iOS mobile application (App Store), and the Sostenutoo Android mobile application (Google Play Store).

1. Introduction

This Privacy Policy describes how Sostenutoo collects, uses, stores, and protects your personal data when you use our orchestra and musical ensemble management platform.

We are committed to protecting your privacy and processing your data in compliance with the General Data Protection Regulation (GDPR), Apple App Store requirements, and Google Play Store policies.

2. Data Controller

Sostenutoo - Micro-entreprise (sole proprietorship under French law)
Representative: Rémi Lecomte
Contact email: commerce.remilecomte@gmail.com
Support: support@sostenutoo.com

3. Data Collected

3.1 Data you provide to us

3.2 Data collected automatically

3.3 Data via Google OAuth (optional)

If you choose to sign in with Google:

We do not access any other Google data (contacts, calendar, Drive, etc.).

3.4 Data via Apple Sign In (optional)

If you choose to sign in with Apple:

Apple Sign In respects your privacy: you control which information is shared with our service. We do not access any other Apple data.

3.5 Sheet music data (PDF)

When sheet music is uploaded by orchestra administrators:

3.6 Communication data (chat and announcements)

When you use the chat and announcement features in the mobile applications:

Visibility: Messages, images, and announcements are visible only to active members of your orchestra.

Retention: Messages and images are retained indefinitely until manually deleted by their author or an administrator.

Image storage: Photos shared in chat are securely hosted on Supabase Storage (EU - Paris), in a dedicated bucket isolated per orchestra. Images are compressed upon upload to optimise performance.

3.7 Data NOT collected automatically

4. Mobile Applications — Specific Permissions

4.1 iOS Application (App Store)

The Sostenutoo iOS application may request access to:

The application does not collect and does not automatically sync your calendar or photo data. All actions are manual and initiated by you.

4.2 Android Application (Google Play Store)

The Sostenutoo Android application uses the following permissions:

Important: Photo access is strictly limited to your manual selection. The application cannot browse or access your photos without your explicit action.

5. Purposes of Processing

Purpose Legal Basis
Account creation and management Performance of contract
Access to your orchestra's programmes and sheet music Performance of contract
Event management and absence declarations Performance of contract
Email communication (invitations, notifications) Legitimate interest
Communication between members (chat and announcements) Performance of contract
Platform improvement Legitimate interest
Security and fraud prevention Legitimate interest

6. Data Sharing and Sub-processors

6.1 Within your orchestra

Administrators, coordinators, and founders of your orchestra can see:

Chat and announcements: Chat messages are visible to all active members of your orchestra. Announcements are visible based on the roles targeted by the author (all musicians, conductors only, etc.).

Other musicians cannot access your personal data (email, instrument) unless shared via chat.

6.2 Third-party processors

Service Usage Location
Supabase Database, authentication, sheet music storage 🇪🇺 European Union (Paris, France)
Netlify Website hosting 🇺🇸 United States (GDPR-compliant via contractual clauses)
Resend Transactional email delivery 🇺🇸 United States (GDPR-compliant)
Stripe Payments (orchestra subscriptions) 🇪🇺 / 🇺🇸 (GDPR and PCI-DSS compliant)

We never sell your data to third parties.

7. International Transfers

Some of our sub-processors (Netlify, Resend, Stripe) may process data in the United States. These transfers are governed by:

Your main database remains hosted in France (Paris) via Supabase.

8. Data Retention Period

Data Type Retention Period
Active account data As long as the account is active
Data after account deletion 90 days then permanently deleted
Connection logs 1 year
Support emails 5 years
Billing data (Stripe) 10 years (legal accounting obligation)
Chat messages and announcements As long as the account is active, or until manually deleted
Images shared in chat As long as the account is active, or until the message containing the image is manually deleted

8.1 Orchestra deletion

When an orchestra is deleted, all associated sheet music, events, programmes, messages, and announcements are permanently deleted.

8.2 Leaving an orchestra

When you leave an orchestra, your absence declarations for that orchestra are deleted. Your personal data (account, profile) remain intact. Your chat messages remain visible (with your name) to preserve conversation continuity, unless manually deleted before your departure.

8.3 Deleting messages and images

You can delete your own messages (text and images) at any time from the mobile application. Deleting a message containing an image permanently removes the image from storage within 24 hours. Administrators can also delete any message in case of inappropriate content.

9. Your Rights Under the GDPR

In accordance with the GDPR (General Data Protection Regulation — EU Regulation 2016/679) and the French Loi Informatique et Libertés (French Data Protection Act), you have the following rights:

To exercise your rights: Send an email to support@sostenutoo.com with the subject line "GDPR — [Your request]".
We will respond within 7 business days.

10. Data Security

We implement the following measures:

11. Cookies and Local Storage

We only use cookies and local storage that are strictly necessary:

No tracking, advertising, or analytics cookies are used.

Note: Google Analytics may be added in the future with a consent option.

12. Protection of Minors

Sostenutoo is a service designed for managing orchestras and musical ensembles. There is no age restriction for using the service, as it does not collect sensitive data and is used in a supervised educational and cultural context (music schools, conservatories, amateur orchestras).

If you are a parent or legal guardian and wish to obtain information about your child's data, please contact us at support@sostenutoo.com.

13. Data Breach

In the event of a data breach likely to result in a risk to your rights and freedoms, we commit to:

14. Changes to This Policy

This policy may be updated. In the event of a substantial change:

15. Contact and Complaints

For any questions about this policy:

Email: support@sostenutoo.com

To file a complaint with the supervisory authority:

CNIL — Commission Nationale de l'Informatique et des Libertés (French Data Protection Authority)
3 Place de Fontenoy - TSA 80715 - 75334 Paris Cedex 07
www.cnil.fr

← Back to home