- Version
- 1.0 · Effective 2026-08-11
- Owner
- privacy@depozza.eu
- Review cycle
- Annual
- Mapped controls
- GDPR art. 5(1)(e), 15, 17, 20 · ISO 27001 A.5.33–A.5.34
Retention periods
- Account and profile data: kept while the account is open, then deleted on request or when the account is closed.
- Bookings, invoices and payout records: kept for the statutory accounting period required by French law (10 years), because we cannot lawfully delete them earlier.
- Identity-verification data: kept only as long as needed to evidence the check, then minimised to the verification result.
- Messages and dispute evidence: kept while the related booking or dispute can still be contested, then deleted.
- Security and audit logs: kept for up to 12 months for investigation purposes.
Your rights, in the product
Signed-in users can export a machine-readable copy of their data and request account deletion directly from Settings — no email ticket is required. Deletion removes profile, listing and message content; records we must keep for tax or legal-defence reasons are retained in a restricted form and are no longer used for any other purpose.
Data minimisation
- Exact addresses are only revealed to a counterparty once a booking is confirmed; search shows an approximate area.
- We do not sell personal data and do not use it for third-party advertising.
- We do not collect health data, and no special-category data is required to use Depozza.
Making a request
Any access, rectification, portability, restriction or erasure request can be sent to privacy@depozza.eu. We answer within one month, as required by the GDPR, and may ask you to confirm your identity before acting.
Questions about this document
privacy@depozza.euThis document states Depozza SAS's own policy. It is not a certification, an audit report or a legal guarantee.