Privacy Policy
Data collected, purposes, retention periods and your rights.
Courtesy translation. This English version is provided for convenience only. In the event of any discrepancy or dispute, only the French version of this document is legally binding.
01Introduction and Data Controller
toGæther is committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679) and the French Data Protection Act (loi Informatique et Libertés).
This Privacy Policy describes how we collect, use, retain and protect your personal data when you use our association management and administration platform for higher education, on the togaether.me website and in the toGaether mobile applications for iOS and Android.
Data controller:
Gaether Inc.
Société par actions simplifiée à associé unique (SASU)
9 Rue de Malabry, 92350 Le Plessis-Robinson, France
104 543 830 R.C.S. Nanterre · SIREN 104543830
Email: privacy@togaether.me
02Personal data we collect
When you use toGæther, we collect different categories of data depending on your profile (Administration, Association, Student):
2.1. Data you provide directly
- Identification data: first name, last name, email address, phone number (optional)
- Profile data: profile picture, educational institution, role (student, association member, administrator)
- Association data: association name, articles of association, legal documents, banking details (IBAN for transfers)
- Event data: titles, descriptions, dates, venues, prices, attendees
- Financial data: transactions, membership fees, expenses, budgets
2.2. Data collected automatically
- Connection data: IP address, browser type and version, time zone, operating system
- Audience measurement: pages visited, clicks on some actions, referral source, browser type and screen size, tied to a short-lived session identifier. These statistics are anonymous and not linked to your account; you can opt out at any time (see the Cookie Policy)
- Cookies and trackers: session identifiers, user preferences (see our Cookies Policy)
- Usage data: actions performed on the platform, interactions with events and associations
- Discovery account tracking: if you use a discovery ("prospect") account opened to evaluate toGæther, we record, linked to that account, the spaces viewed, the time spent per space, the actions attempted that are reserved for subscribed accounts and the browser type, in order to support you towards a subscription. This data is kept for 90 days
2.3. Payment data
Payments on toGæther are processed by HelloAsso, a French payment platform dedicated to associations. Your card details are entered on HelloAsso's secure payment page: toGæther never has access to them.
- We NEVER store full banking details (card number, CVV)
- HelloAsso collects: the card details entered on its payment page, and the payer's first name, last name and email address
- We retain only: transaction identifier, amount, date, payment status
2.4. Data received from third parties
- Authentication: if you sign in with Google (Google Sign-In), with Apple (Sign in with Apple) or through your institution's authentication service (SSO), we receive your name, your email address and, where applicable, your profile picture. With Sign in with Apple, you can choose to hide your address: we then receive a relay address assigned by Apple (ending in @privaterelay.appleid.com or @private.icloud.com), which forwards our emails to you.
2.5. toGaether mobile application for iOS and Android
In addition to the data described above, the mobile application processes the following data:
- Camera: used only at your initiative, to scan ticket QR codes at event entry checks and to take a photo (profile picture, gallery upload). QR codes are read on the device; only the photos you choose to send are transmitted to our servers.
- Photo library: photos are chosen through your system's picker; only the images you select are sent (uploads to your associations' galleries, messaging, profile picture).
- Push notifications: if you allow them, a notification token specific to your device is stored and linked to your Account. Notifications (title, text and a link to the relevant screen) are routed through Expo Push Service, then through Apple Push Notification service on iOS or Firebase Cloud Messaging on Android. You can turn them off at any time in your device settings; the token is removed from your Account when you sign out or as soon as the notification service reports it as invalid.
- Technical identifiers: on Android, notification delivery through Firebase Cloud Messaging relies on a Firebase installation identifier generated on the device.
- On-device storage: your sign-in session, your display preferences, a copy of your tickets so they can be shown offline and, for ticket checkers, scans awaiting synchronisation are stored locally; they are erased when the application is uninstalled.
- No advertising or tracking: the application contains no advertising or audience-measurement tool and does not track you across other companies' apps or websites.
- Code scanning on Android: QR code scanning relies on Google's ML Kit library, which runs on the device; Google may receive technical diagnostic data (device and application information, library performance and errors).
03Purposes of processing and legal bases
We process your personal data only for specified, explicit and legitimate purposes:
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account | Performance of the contract (Art. 6.1.b GDPR) |
| Providing the toGæther services | Performance of the contract (Art. 6.1.b GDPR) |
| Processing payments and membership fees | Performance of the contract (Art. 6.1.b GDPR) |
| Managing events and ticketing | Performance of the contract (Art. 6.1.b GDPR) |
| Generating administrative and legal documents | Legal obligation (Art. 6.1.c GDPR) |
| Transactional communications (confirmations, notifications) | Performance of the contract (Art. 6.1.b GDPR) |
| Audience measurement of the Platform (anonymous visit statistics) | Legitimate interest (Art. 6.1.f GDPR); tracker exempt from consent (Art. 82 French Data Protection Act), with a right to opt out |
| Additional audience measurement with Google Analytics (only if you accept it) | Consent (Art. 6.1.a GDPR and Art. 82 of the French Data Protection Act), which you can withdraw at any time from “Manage cookies” |
| Marketing communications and newsletters | Consent (Art. 6.1.a GDPR) |
| Fraud prevention and security | Legitimate interest (Art. 6.1.f GDPR) |
| Legal and regulatory compliance | Legal obligation (Art. 6.1.c GDPR) |
| Push notifications in the mobile application and the browser | Performance of the contract (Art. 6.1.b GDPR); display requires your permission in your device or browser settings |
| Content moderation, handling of reports and user blocking | Legitimate interest (Art. 6.1.f GDPR) and legal obligations (Art. 6.1.c GDPR) |
| Tracking of discovery (prospect) account activity to support them towards a subscription | Legitimate interest (Art. 6.1.f GDPR); right to object by email to privacy@togaether.me |
04Recipients of your data
We never sell or rent your personal data. Your data may be shared only in the following cases:
4.1. Internal services
- Authorised toGæther staff (access limited on a need-to-know basis)
4.2. Processors and technical partners
- Google Cloud (Google Cloud EMEA Limited, Ireland): application hosting (Cloud Run), the "paris" Firestore database, file storage ("to-gether-7b4e1-fr" bucket), application logs and backups, in the europe-west9 region (Paris, France)
- Google — Firebase Authentication / Identity Platform: account authentication (email and password, Google, Apple, institution SSO), processed in the United States
- Google — Firebase Cloud Messaging: routing of push notifications to browsers and Android devices, processed in the United States
- Google — Google Sign-In: signing in with your Google account, at your initiative (United States)
- Apple (United States): Sign in with Apple, at your initiative, and Apple Push Notification service (APNs) for routing notifications to iOS devices
- Expo — 650 Industries, Inc. (United States): Expo Push service, which forwards the mobile application's notifications to APNs and Firebase Cloud Messaging
- HelloAsso (France): secure collection of payments (ticketing, membership fees, donations) for associations that chose this service, under its own privacy policy
- Resend (United States): sending of transactional emails and email notifications; emails are sent from Ireland, while the account, metadata and sending logs are processed in the United States
- Optional features: when used, automatic receipt reading and assisted analysis of financial reports rely on Google Vertex AI (Gemini model, europe-west1 region, Belgium)
- Maps and addresses: OpenStreetMap France map tiles, loaded by your browser (which sends your IP address); geocoding of event and venue addresses by the OpenStreetMap Foundation's Nominatim service (United Kingdom); autocompletion of typed addresses by the French national address database (api-adresse.data.gouv.fr, French State)
- Services you connect yourself: if you or your association connect an external service (Google Drive, Google Calendar, Gmail, Google Contacts, Microsoft Outlook and OneDrive, DocuSign, Yousign, Universign), toGæther exchanges with that service only the data needed for the feature used, within the permissions granted; that service acts under its own terms
- Google Analytics (Google Ireland Limited / Google LLC): additional audience measurement, turned on only if you consent to it in the cookie panel; browsing data (pages viewed, referral source, device) that may be processed in the United States, under the EU–US Data Privacy Framework
- Sentry — Functional Software, Inc. (hosted in the European Union, Germany): reporting of technical errors on the site (error message, page, browser, version) for service reliability; no IP address, no cookies, no screen recording
All our processors are bound by contractual agreements guaranteeing the protection of your data (DPA - Data Processing Agreement). The up-to-date list of our processors is provided on request at privacy@togaether.me.
4.3. Other toGæther users
- If you create a public association or event, certain information (name, description, images) is visible to other users
- Members of your association can see your profile information (subject to your privacy settings)
- Administrators of your institution can access the data required for administrative management
4.4. Legal authorities
In the event of a judicial requisition or legal obligation, we may be required to disclose your data to the competent authorities (police, courts, tax administration, etc.).
05Data transfers outside the EU
Application data (database, files, application logs and backups) is hosted and processed in France, in Google Cloud's Paris region (europe-west9).
Some processing takes place outside the European Union, mainly in the United States: authentication (Firebase Authentication / Identity Platform), push notification delivery (Firebase Cloud Messaging, Expo Push Service, Apple Push Notification service), sign-in with Google or Apple, part of the processing carried out by Resend and, when you connect them yourself, Google, Microsoft or e-signature services.
These transfers are governed by the European Commission's adequacy decision on the EU–US Data Privacy Framework where the recipient is certified under it and, failing that, by the standard contractual clauses adopted by the European Commission, including those in Google Cloud's data processing terms (Cloud Data Processing Addendum).
06Data retention periods
We retain your personal data only for as long as necessary for the purposes for which it was collected:
| Type of data | Retention period |
|---|---|
| Active account data | For the entire duration of your registration |
| Inactive account data | 3 years after the last login, then deletion |
| Financial and accounting data | 10 years (legal obligation - French Commercial Code) |
| Associations' legal documents | 10 years after dissolution of the association |
| Connection logs | 1 year (legal obligation - LPM) |
| Audience measurement | Session identifier: until the tab is closed; events: 13 months; aggregated statistics: 24 months |
| Commercial prospecting data | 3 years after last contact or withdrawal of consent |
| Discovery account tracking | 90 days |
Once these periods expire, your data is either permanently deleted or irreversibly anonymised.
07Security and protection of your data
We implement robust technical and organisational measures to ensure the security of your personal data:
Technical measures
- SSL/TLS encryption (HTTPS) for all communications
- Encryption of sensitive data in the database
- Authenticated sessions limited to 2 days and revoked when access rights are lost
- Automatic daily backups
- Request rate limiting, logging of sensitive actions and security alerts
- Isolation of production environments
Organisational measures
- Restricted data access (least privilege principle)
- Security and GDPR training for our teams
- Strengthened password policy
- Data breach management procedures
- Regular security audits
- Confidentiality clauses in contracts
In the event of a data breach likely to result in a risk to your rights and freedoms, we undertake to inform you as soon as possible and to notify the CNIL within 72 hours, in accordance with Article 33 of the GDPR.
08Your rights over your personal data
In accordance with the GDPR and the French Data Protection Act, you have the following rights over your data:
✓ Right of access (Art. 15 GDPR)
You can obtain a copy of all the personal data we hold about you
✓ Right to rectification (Art. 16 GDPR)
You can correct inaccurate or incomplete data directly from your account or by contacting us
✓ Right to erasure / "right to be forgotten" (Art. 17 GDPR)
You can request the deletion of your data, unless we have a legal obligation to retain it (e.g. invoices)
✓ Right to restriction of processing (Art. 18 GDPR)
You can ask us to temporarily freeze the processing of your data in certain situations
✓ Right to data portability (Art. 20 GDPR)
You can retrieve your data in a structured, machine-readable format (JSON, CSV, PDF)
✓ Right to object (Art. 21 GDPR)
You can object to some processing, in particular direct marketing (newsletter unsubscribe), audience measurement ("Manage cookies" button) and tracking of discovery accounts (by email to privacy@togaether.me)
✓ Right to withdraw your consent (Art. 7 GDPR)
Where processing is based on your consent, you can withdraw it at any time
✓ Right to set post-mortem directives (Art. 85 LIL)
You can set instructions regarding the fate of your data after your death
How to exercise your rights?
To exercise any of these rights, you can:
- Go to your toGæther account settings
- Send us an email at privacy@togaether.me
- Write to us at: Gaether Inc., 9 Rue de Malabry, 92350 Le Plessis-Robinson, France
We will respond within 1 month at most (extendable to 3 months for complex requests). Proof of identity may be requested to verify your identity.
Deleting your account
You can request the deletion of your Account and your personal data at any time:
- in the mobile application: Settings › Data, then press and hold the "Delete my account" button;
- on the website: Settings › Data;
- or by following the procedure described on the Account deletion page, available without signing in.
Deletion takes effect after a period of 30 days, during which you can cancel the request from the application or the website. It covers your Account and your personal data.
Accounting records linked to your Account (transactions, paid membership fees) are kept in anonymised form for the legal retention period (10 years), in accordance with section 6.
Right to lodge a complaint with the CNIL
If you believe your rights are not being respected, you can lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL):
CNIL - 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
Phone: +33 1 53 73 22 22
Website: www.cnil.fr
10Protection of minors
toGæther is intended for higher-education students. In accordance with the Terms of Use:
- use of toGæther is restricted to persons aged at least 15; we do not knowingly collect data about persons under 15;
- if you are between 15 and 18 years old, you declare, when creating your Account, that you have the consent of your legal representative;
- if we learn that an Account belongs to a person under 15, we may suspend or delete it; a legal representative can report this to us at privacy@togaether.me.
11Changes to this policy
We may amend this Privacy Policy to reflect changes in our services, in legislation or in our practices.
In the event of a substantial change, we will inform you by email and/or by notification on the platform at least 30 days before the changes take effect.
The current version is always available on this page, together with its last update date.
12Contact us
For any question regarding this Privacy Policy or the exercise of your rights:
Email: privacy@togaether.me
Post: Gaether Inc. — Data Protection Department
9 Rue de Malabry, 92350 Le Plessis-Robinson, France
Data Protection Officer (DPO): dpo@togaether.me
Version 2.2 - Last updated: September 25, 2026
Document compliant with the GDPR (EU 2016/679) and the French Data Protection Act (loi Informatique et Libertés)