Privacy policy
Last updated: 15 July 2026
1. Who we are
Sereno, whose registered office is at 49 rue de l'Amiral Mouchez, 75013 Paris, France (RCS Paris 928 379 957), operates daas, a weather-data service available at daas.serenodata.com and api.daas.serenodata.com. Sereno is the data controller for the personal data described in this policy.
Privacy contact: privacy-daas@serenorisks.com.
2. What this policy covers
This policy explains how we process personal data when you visit daas.serenodata.com, create and use an account, call the API, or correspond with us about the service. daas is a business-to-business service; the personal data we process mostly concerns the people who administer and use customer accounts.
3. Personal data we collect
Account data: the account owner's name, email address and organisation name.
Space settings: the country, city and timezone you set, and your interface language.
Usage and technical data: API request logs (endpoints called, timestamps, volumes, response status), API-key identifiers, IP addresses and standard connection data, and the usage metrics shown in your space.
Billing data: payments are processed by Stripe; we receive transaction references, billing details and payment status, not full card numbers.
Correspondence: messages you send us, for example through the contact page or by email.
We do not knowingly collect special-category data, and the service is not directed at children.
4. Why we process it, and on what legal basis
| purpose | personal data | legal basis (GDPR) |
|---|---|---|
| creating and operating your account, providing the service, and sending service emails (verification, security, billing and important notices) | account data, settings, usage and technical data | performance of a contract, art. 6(1)(b) |
| billing, invoicing, accounting and tax records | account and billing data | performance of a contract; legal obligation, art. 6(1)(c) |
| marketing emails about daas | account owner's email | consent, art. 6(1)(a), withdrawable at any time |
| security, abuse and fraud prevention, and service integrity | usage and technical data | legitimate interest, art. 6(1)(f): keeping the service secure and reliable |
| producing aggregate, non-identifying usage statistics | usage and technical data | legitimate interest, art. 6(1)(f) |
| handling requests, claims and disputes | relevant data | legitimate interest; legal obligation where applicable |
5. Who receives the data
Within Sereno, access is limited to the people who need it for the purposes above. We use the following providers:
| provider | role | region |
|---|---|---|
| Scaleway | cloud hosting and database for the service | France |
| Scaleway transactional email | sending account and service emails | France |
| Stripe | payment processing | Ireland (Stripe Payments Europe, Ltd); transfers to the US under the EU-US Data Privacy Framework and standard contractual clauses. See the Stripe Privacy Center. |
| OpenStreetMap / Nominatim | location search when you set your city in the space | United Kingdom |
When you use the location search during signup, your search text is sent to that service through our servers; the service receives the query and our server's IP address, not yours.
We may also share data with professional advisers, and with authorities where the law requires it. We do not sell personal data.
6. International transfers
The service and its database are hosted in France, and we keep personal data in the EU where possible. The location search is operated by the OpenStreetMap Foundation in the United Kingdom, but queries reach it only through our servers: it receives the search text and our server's IP address, not yours, and nothing linking the query to you or your account. The only transfer of personal data outside the EU/EEA concerns payments: Stripe may transfer payment-related data to Stripe, LLC in the United States under the EU-US Data Privacy Framework and the European Commission's standard contractual clauses, as published on Stripe's legal pages.
7. How long we keep it
| data | retention |
|---|---|
| account data | for the life of the account, then archived for 5 years after closure for evidence purposes (statutory limitation period) |
| invoices and accounting records | 10 years, as required by French commercial law |
| API and technical logs | 12 months for security and billing purposes |
| marketing data and consent records | 3 years from last contact |
After these periods, data is deleted or anonymised.
8. Your rights
You have the right to access your personal data, to have it rectified or erased, to restrict its processing, to receive it in a portable format, and to object to processing based on legitimate interest. You may object to direct marketing at any time, and you may withdraw consent at any time without affecting the lawfulness of prior processing. Under French law, you may also give instructions on the fate of your data after your death.
To exercise these rights, write to privacy-daas@serenorisks.com or to the postal address in section 1. We may ask you to confirm your identity if there is reasonable doubt, and we respond within one month, extendable where the law allows. You may also lodge a complaint with the CNIL (cnil.fr) or with your local supervisory authority.
9. Cookies
The service uses essential session cookies only, to keep you signed in and to secure the service. These are strictly necessary and do not require consent. We do not use advertising cookies.
10. Security
We apply technical and organisational measures appropriate to the risk. These measures include encryption of data in transit (TLS) and at rest, hashed storage of passwords and API-key secrets, strict access controls following the principle of least privilege, with production access limited to the persons who need it, logging and monitoring of access to production systems, daily automated backups, and vulnerability management of our infrastructure and dependencies. No system is perfectly secure; if a breach affects your rights, we will notify you and the authorities as required by law.
11. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on individuals.
12. Changes to this policy
We may update this policy. Material changes will be notified by email or in your space, and the date above updated accordingly.