Privacy policy
Last updated: October 2, 2026
The French version of this page is the authoritative text, and the legal references it cites are French.
Data controller
- Controller
- Bruno SEILLIEBERT, for Norenso, a project still being set up: Norenso is not yet a registered business
- Contact
- contact@norenso.fr
In short
This page explains what information Norenso processes, where it comes from, why, how long it is kept and how to object, in each of these situations:
- we contacted you to offer your business a website;
- you asked us for a preview with the form on this website;
- you opened your client area or became a client;
- you visit the website of a business made by Norenso.
We do not sell, rent or give away any data. No information is used for advertising, and the application never sends any data to an artificial intelligence.
If we contacted you to offer you a website
Norenso looks for local businesses that have no website, or an outdated one, to offer them a website. This information was not collected from you: here is what it is, where it comes from and what we do with it.
The information we keep:
- the identity of the business: name, trading name, SIREN and SIRET numbers, activity, address, creation date and size. If you are an individual entrepreneur, the name of your business may be your own: it is then personal data, and treated as such;
- what the business publishes itself: opening hours, menu and prices, business phone and email, the address of its website and of its public social media pages, colours, logo and photos of the shopfront or products, with no recognisable person;
- the published information on the accessibility of the establishment;
- our own observations: whether the business has a website and whether it is recent, a priority score calculated from these elements, the follow-up of our exchanges and our notes.
Where it comes from:
- INSEE's SIRENE directory, the French public business register, only for establishments whose information is made public;
- OpenStreetMap, the collaborative map, and Panoramax, street photos published under a free licence;
- Acceslibre, the French public register of the accessibility of establishments;
- the website of the business, read by our tool which identifies itself as NorensoBot, and its public social media pages, viewed by us;
- Google Maps, only to find businesses and know whether they have a website: we keep only the identifier of the listing and the website address it shows, which we visit ourselves. Nothing else from Google is kept or reused in the mock-up or in our messages.
Why: to choose the businesses to offer a website to, prepare a mock-up and present it to you. The priority score is only used to decide whom to contact first; a person always decides, and this score has no other consequence for you.
Legal basis: our legitimate interest in offering our services to professionals, for a purpose related to their business (Article 6(1)(f) GDPR). We keep only what serves this offer.
The mock-up: we may make an unofficial mock-up of the website of your business. It can only be seen through a private link, is not indexed by search engines and is no longer available 90 days after its last update. We record the date each time this link is opened, without your IP address or any other information, to know whether the offer interests you.
The first contact: by email, private message on social media, letter or phone, using the business's professional contact details. Each message says who we are and where your information comes from, and gives a code specific to your business to open your client area if you wish.
Your feedback on the mock-up: from the mock-up, you can tell us without signing in whether it interests you, with an optional comment. We keep your answer, its date and the language of the page, without recording your IP address or any information about your device. It is only used to reply to you and to improve our service. Do not write any personal data in the comment. Legal basis: our legitimate interest in replying to you and improving our service (Article 6(1)(f) GDPR). Your feedback is kept and deleted together with the other information about your business.
Objecting: at any time, without giving a reason, through the “Stop contacting me” link in each message and on the mock-up, or by writing to contact@norenso.fr. The mock-up is removed at once and we do not contact you again.
To respect your objection over time, we keep in an objection list what is enough to recognise your business, its SIRET number: without this list, a new search could suggest it again.
If you asked INSEE not to make your business's information public, your business does not appear in our searches.
If you ask us for a preview
The information sent with the “Tell us about your business” form is used only to contact you about your website, in particular to send you the preview you asked for. It is not used for any other purpose.
Only the information you enter in the form is collected:
- the name and town of your business;
- your name;
- your phone number and email address, if you provide them;
- what your customers need to find on your website, among: opening hours, prices, menu, photos, directions;
- your consent to be contacted.
To protect the form against automated submissions, the Cloudflare Turnstile service checks technical signals from your browser when you send it, and your IP address is used to limit the number of requests: it stays in memory for a few minutes, without being stored.
The processing is based on your consent (Article 6(1)(a) GDPR), given by ticking the box provided in the form. You can withdraw it at any time by emailing contact@norenso.fr.
Client area and sign-in
Your account contains your email address, your name, your role (client or administrator) and the businesses you manage. To sign in, you receive a one-time code by email, valid for 10 minutes, which we only keep in a form that cannot be read back.
Each sign-in creates a session, recorded with its expiry date, the IP address and the browser used. This information is only used to keep you signed in and to secure your account. Your IP address is also used for a few minutes to limit sign-in attempts.
If you ask for access to the area of your business without a code, we keep your request (name, email address, phone if you provide it, message and language) to check that you are indeed in charge of the business before giving you access.
This processing is necessary to prepare and perform your contract (Article 6(1)(b) GDPR). Sign-in emails are sent by Scaleway Transactional Email, in France.
Information about your business, photos and web address
In your client area, you check and change what your website shows: opening hours, menu and prices, contact details, presentation and legal notice. Each change is written to a log: who made it, when, and the old and new value. This log keeps track of what you asked us to publish, for example a price or opening hours.
The photos, logo and menu you send are used only for your website and for the files we prepare for you. Before sending a photo, you confirm that you have the right to use it and that no person can be recognised in it.
For the web address of your website, we keep the chosen domain name and the history of your choices. We look up the public information of domain name registries (availability, registrar, name servers) and check the technical settings of the address. A domain name registered for you is registered in your name, after the contract is signed.
If you create visuals in the studio of your client area (posters, stickers), we keep each visual: the template, the format, the colours and elements chosen, the texts you write, and the date and format of each download. They let you pick up and download your visuals again; the dates, opening hours and contact details they show are read from your information each time they are displayed, and downloaded files are not kept on our servers. Your visuals are deleted with the rest of your client area data.
This processing is necessary to prepare and perform your contract (Article 6(1)(b) GDPR); the change log also serves to defend our rights and yours (point (f)).
If you tell us that an upcoming feature interests you, such as creating your posters and posts, we keep your answer, its date and, if you write one, the description of the visual you would need. This information is only used to prepare that feature. Legal basis: your consent (Article 6(1)(a) GDPR). You can change or withdraw your answer at any time in your client area; otherwise it is kept like the rest of your client area data.
Updating your Google Business Profile and your Facebook page
From your client area, you can connect your Google Business Profile or your Facebook page so that Norenso updates them for you. We then keep:
- your express consent, with the version of the text you accepted and its date;
- the access keys (tokens) issued by Google or Meta, stored encrypted, which only let Norenso change what you authorised;
- the identifier and name of the Google profile or Facebook page you chose;
- a log of what was sent and when: connection, successful or failed updates, disconnection.
Why: to publish on these platforms, at your request, your opening hours, your closures (on Google only) and the address of your website, when you save your opening hours in your client area or tap “Update now”. Norenso never touches your reviews, photos, posts or messages.
Legal basis: your consent, given in your client area by ticking “I allow Norenso to make these changes for me” before connecting to the platform (Article 6(1)(a) GDPR). You can withdraw it at any time by disconnecting the platform.
Google and Meta receive the information you chose to publish. They process it for their platforms, under their own responsibility and according to their own terms and privacy policies.
You can disconnect a platform at any time with the “Disconnect” button in your client area: Norenso then asks the platform to withdraw its access and immediately deletes the tokens and the link to your profile or page. What is already published on the platform stays as it is. If you withdraw access from your Google or Facebook account, the tokens become useless and are deleted when you disconnect the platform in your client area, or together with the other data of your client area.
Signing the contract
When you sign your contract online, we record your name, your position, the email address the signing code was sent to, the time the code was sent and entered, the IP address and browser used, and the signed contract as a PDF. The code itself is only kept in a form that cannot be read back.
This information proves the signature and the content of the contract. This processing is necessary for its performance and for the defence of our rights (Article 6(1)(b) and (f) GDPR). It is kept for the whole duration of the contract, then five years after it ends, the limitation period between professionals.
Payment and invoices
Payments by card or SEPA direct debit are made on a Stripe payment page. Norenso never sees your card number or your full bank details: Stripe sends us the status of your subscription and payments, and your invoices.
Stripe also processes some of this data for its own purposes, in particular to verify the identity of its customers and prevent fraud: its own privacy policy then applies.
Legal basis: the performance of your contract (Article 6(1)(b) GDPR), and for invoices our legal obligation to keep accounting records (point (c)).
Visit statistics of your website
Once your website is online, we count its visits to show them to you in your client area: page views, clicks on useful buttons (call, directions, order, book) and where visitors come from, by broad categories. No cookie, no identifier and no IP address is stored: we only keep daily totals.
For these statistics, you are the controller and Norenso acts on your behalf, as a processor, under the data processing annex of your contract. We never use them for ourselves or to compare businesses. The visitors of your website are informed by the privacy page of that website, and you can refuse this measurement by writing to us.
Recipients and processors
Your data is intended for Norenso only. It is not sold, rented or given away. It is hosted in France by Scaleway, on servers run by Norenso. Our providers only access it for the service they provide to us, under a contract that requires this of them:
- Cloudflare, only for the anti-bot check (Turnstile) of the request form. For this check, Cloudflare also uses some signals to improve its service, as a controller;
- Scaleway, in France, which hosts this website, its database, its backups and our clients' websites, delivers and protects them (content delivery network and firewall), and manages the domain names registered in the name of our clients;
- Scaleway Transactional Email, in France, which sends sign-in and signing codes and our emails;
- Stripe, for payments and invoices;
- Sentry, if enabled, which reports technical errors in the application to us: its reports contain neither your identity, nor your cookies, nor what you type;
- ntfy, a notification tool hosted by Norenso on its Scaleway server in France, which alerts Norenso to a new request or a completed step: its notifications only contain the name of the business and the event, never a phone number or an email address. When a notification is relayed to an iPhone, the ntfy.sh service only receives a technical identifier of the notification and a fingerprint of our channel's address, which it passes on through Google (Firebase) and Apple to wake the app; neither the name of the business nor the content of the notification is sent to it;
- Anthropic, the maker of the Claude assistant, which Norenso uses with a business plan (Claude Team) to prepare mock-ups and websites. In it, we use the public information of the business and what you ask us to publish, never the data of your account (email address, sign-ins, signature, payments). With this plan, Anthropic does not train its models on our content. The application itself sends nothing to Claude.
We may also have to disclose data to an authority that lawfully requests it, such as the tax authorities or the courts.
Transfers outside the European Union
Hosting, backups and email sending stay in France, with Scaleway. Cloudflare (for the anti-bot check of the form only), Stripe, Sentry and Anthropic are American companies: some data may be processed in the United States. Depending on the provider, these transfers rely on the adequacy decision of the European Commission for companies certified under the Data Privacy Framework, or on the standard contractual clauses of the European Commission. You can get the details of these safeguards by writing to us.
Retention periods
After these periods, data is deleted, or made anonymous when only totals remain.
- Contacted businesses that do not become clients
- three years after collection or after your last contact with us, then deleted
- Objection list
- as long as needed to respect your objection, with the SIRET number only
- Mock-up openings
- 90 days after each opening
- Requests sent with the form
- three years after our last exchange, if no contract is signed
- Requests for access to the client area without a code
- one year
- Account, business information and photos, web address, change log
- during the contract, then three months after it ends, the time needed to hand over the archive of your website; without a contract, like the information of the contacted business
- Google or Facebook connection and log of updates
- tokens deleted as soon as you disconnect the platform from your client area; the rest like your account: during the contract, then three months after it ends; without a contract, like the information of the contacted business
- Signature evidence and contract
- during the contract, then five years after it ends
- Invoices and accounting records
- ten years (Article L123-22 of the French Commercial Code)
- Sign-in and signing codes
- valid for 10 minutes, then unusable
- Sign-in sessions
- until you sign out, and at most 7 days after your last visit
- Visit statistics
- 25 months, as daily totals, and deleted within thirty days after the contract ends
- Technical logs
- a few days, with automatic rotation of the server logs
- Backups
- encrypted copies of the database, kept for 30 days
Data deleted by the application also leaves the backups within the following 30 days.
Your rights
You can access your data, have it corrected or erased, ask for its processing to be restricted and object to its processing, in particular to prospecting, at any time and without giving a reason. For the data of your account and your business, you can also ask to receive it in a reusable format. When processing is based on your consent, you can withdraw it at any time. You can also set instructions about what happens to your data after your death.
To exercise these rights, email contact@norenso.fr. You will receive a reply within one month.
If you believe your rights are not respected, you can lodge a complaint with the CNIL, the French data protection authority, at cnil.fr.
Storage in your browser
The website may store three display preferences in your browser, with no personal data: the language of the website, the chosen theme (light or dark) and whether the logo animation has already played during your visit. The language is kept in a cookie, sent to the website on each visit so that it can reply in that language. The theme and the animation stay on your device.
When you sign in, a session cookie is also stored. It is strictly necessary to keep you signed in, is not used for any tracking and disappears when you sign out or at the latest 7 days after your last visit.
The request form loads the Cloudflare Turnstile service, which may use information in your browser that is strictly necessary to tell a person from a bot. Payment takes place on a Stripe page, which applies its own rules. This website uses no audience measurement tool and no advertising tracker.
Legal notice
Information about the website publisher and host is given in the legal notice.