Privacy and Data Protection Policy

Version 2.1 – Revision Date: April 8, 2026

Article 1: Identification of the Data Controller and the DPO

The company ZeitMeister (hereinafter « the Platform »), with its registered office located at Immeuble Cœur Défense, 110 Esplanade du Général de Gaulle, 92400 Courbevoie, France, acts as the Data Controller within the meaning of Regulation (EU) 2016/679 (GDPR). To ensure the security of your information, a Data Protection Officer (DPO) has been appointed and can be reached at the following address: [email protected].

Article 2: Categories of Data Collected

In the context of operating its artificial intelligence and analytical services, ZeitMeister collects the following categories of data:

  • Identity Data: Name, first names, date of birth, nationality, and copy of official identity documents (KYC framework).
  • Contact Data: Verified email address, active mobile phone number, residential address, and proof of address.
  • Technical and Telemetry Data: IP addresses, device identifiers, browsing data, connection logs, and metadata resulting from interaction with our AI models.
  • Financial Data: Information on the origin of funds and digital wallet addresses, in accordance with anti-money laundering (AML-CFT) obligations.

Article 3: Legal Bases and Purposes of Processing

The processing of your data is carried out on the legal bases provided by Art. 6 of the GDPR:

  • Contract Performance: Account infrastructure management and provision of analytical services.
  • Compliance with Legal Obligations: Compliance with French financial regulations and AMF/Tracfin directives.
  • Legitimate Interest: Securing the platform against cyberattacks, fraud prevention, and optimization of AI algorithms.
  • Consent: For sending marketing communications and the use of non-essential trackers.

Article 4: Data Security and Encryption

ZeitMeister implements enterprise-level security protocols:

  • AES-256 Encryption: For data storage at rest.
  • TLS 1.3 Transport: Encryption of all data flows between the User and our servers.
  • Physical Protection: Hosting on highly secured infrastructures located within the European Economic Area (EEA).

Article 5: Retention and Archiving

  • Active Data: Retained for the entire duration of the contractual relationship.
  • Legal Archives: Retained for a period of five (5) years after account closure to meet legal and regulatory limitation obligations.
  • Cookies:Maximum lifespan of 13 months.

Article 6: Exercise of Your Rights

In accordance with the GDPR, you have the right to access, rectify, erase, limit, port, and object. These rights can be exercised by contacting the DPO at [email protected]. You also have the right to lodge a complaint with the CNIL (www.cnil.fr).

🇬🇧 English