Personal data
Privacy policy
Last updated: 6 August 2026.
This translation is provided for information; in case of discrepancy, the French version prevails.
Who decides what
Your schooldecides about its students' data: it collects it, corrects it, deletes it. It is the data controller within the meaning of the GDPR. Benford Tech acts only as a processor: it runs the tool and uses this data for nothing else — no resale, no advertising, no model training.
Benford Tech is, however, the controller for the accounts it manages itself: the platform administration accounts and school opening requests.
What is processed
- Student
- First name, last name, email, phone (optional), gender and dance level, profile photo (optional), class enrolments, confirmed and recorded attendance, plan, payments and invoices.
- Teacher or school administrator
- Name, email, encrypted password, role, speciality and hourly rate if provided, history of attendance calls made and messages sent.
- School
- Name, city, address, company ID (SIRET), billing details, identifiers of the school's Stripe account.
- Visitor
- No data. The site sets no tracker and no advertising cookie, and does not measure its audience.
Why
- Running the class : enrolling, counting places, keeping the waitlist, taking attendance, sending day-before reminders and video recaps.
- Keeping the school's books : plans, payments, numbered invoices, chasing unpaid amounts — a legal obligation for the school.
- Securing access : a password for staff, a secret personal link for the student.
The legal basis is the performance of the contract between the student and their school, and the legal obligation for invoicing. Push notifications only go out after your explicit consent in the browser, and stop when the permission is withdrawn.
Who else can access it
Nobody outside your school and the technical providers below. Schools are sealed off from one another: one school's data is never visible from another.
| Provider | Role | Location |
|---|---|---|
| Vercel | Site hosting | United States — functions run in Europe (Frankfurt) |
| Neon (AWS) | Database | European Union — Frankfurt (eu-central-1) |
| Stripe | Online payments, on behalf of each school | European Union / United States |
| Hostinger | Email delivery (invoices, reminders, access links) | European Union |
| “Continue with Google” sign-in (optional, staff and students), Drive and Photos if staff connect them | United States |
Transfers outside the European Union:the database and the site's functions run in the European Union, in Frankfurt. Vercel remains a US company with a worldwide delivery network: when a transfer outside the European Union does occur, it relies on the European Commission's standard contractual clauses, provided for in that provider's contract.
Data from Google APIs
Some optional features rely on Google APIs. The “Continue with Google” sign-in is offered to everyone — staff and students alike — on sign-in and enrolment screens, and always remains optional. Drive and Photos only concern school staff (teachers, administrators), who choose whether to connect their Google account.
- “Continue with Google” sign-in : Thempo reads the account's email address, first name and last name, to find the matching account or pre-fill enrolment forms — the fields remain editable before submission. Nothing else is accessed or stored.
- Google Drive (read-only) : when a staff member connects their Drive, Thempo only reads the folders they explicitly designate (a course's materials, a student's file) to sync their contents into the school's space. The rest of the Drive is never browsed. Thempo stores an access token, the email address of the connected account and the reference of the synced files; disconnecting Drive deletes the token.
- Google Photos (official picker) : Thempo never accesses the photo library — only the photos explicitly chosen in Google's picker are copied as course materials. Here too, disconnecting deletes the token.
Thempo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: this data serves only the features described above, is never transferred to third parties, never used for advertising, and never used to train AI models.
For how long
A student's data is kept as long as they are enrolled in their school, then deleted at their request or the school's. Invoices and payments are kept for ten years, as accounting law requires. A staff account is kept for the duration of their role.
Cookies
A single durable cookie is set, tempo_session, and only after signing in: it keeps the staff session open. Signing in with Google additionally leaves two short-lived, strictly technical cookies: a security token for the duration of the exchange with Google, and tempo_google_prefill (ten minutes) which carries the form pre-fill. All are strictly necessary to the service, which exempts them from a consent banner. No analytics cookie, no advertising tracker, no embedded social network. Students who use their personal link don't even have a cookie.
Security
Staff passwords are hashed (bcrypt) and never stored in plain text. All exchanges go through HTTPS. A student's personal link contains a random token: it is as good as a password, better not to share it. Every request checks the school of the signed-in person before answering.
Your rights
You can request access to your data, its correction, its deletion, its portability, or object to a processing operation. The fastest route is to talk to your school, which has direct control in its space. You can also write to the publisher, whose details are in the legal notice. In case of disagreement, you can refer the matter to the CNIL, the French data protection authority (cnil.fr).
