Data controller

The data controller is GELMIX (see the Legal notice). You can write to bonjour@baza.fr.

Data processed

The service processes only the data necessary for it to work:

Minimisation

No real name or first name, no postal address and no identity document are requested: only the data necessary for account security and adulthood verification is collected.

Purposes and legal bases

Processing relies on the following legal bases:

Geolocation

Your position is recorded only with your explicit consent. It is never shown: no exact coordinate or address is displayed, neither to you nor to other members.

Other members see only a rounded distance (a multiple of 100 m), computed on the server side. ‘Discreet’ mode fully hides your position (no distance shown).

Withdrawing consent immediately erases your position: no position is kept after withdrawal.

Private messages and private media

Messages exchanged privately — text as well as photos — are never read or automatically moderated: they fall under the confidentiality of correspondence. They are accessible only to the participants in the conversation.

Photos sent in messaging are never passed to any moderation or analysis service. They are compressed and refused if they contain metadata (EXIF/GPS) — technical protections only.

The same rule applies to the photos in your private albums and to group messages: none of this content is analysed automatically or passed to any external analysis service. It is served only to the people you have authorised, through an authenticated address, and is neither public nor indexable.

Profile photo: automated moderation then human review

The profile photo is PUBLIC: it is the only photo subject to automated moderation, before any publication. The image is passed to OpenAI for analysis — first to a classification service, then, if necessary, to an image analysis model. If the analysis is unavailable, the photo is refused: no photo is ever published by default.

Where the refusal concerns content, the photo is never published but may be kept temporarily in a private area so that a member of the moderation team can review it. If it is accepted, it becomes your profile photo; if it is refused, the file is deleted. Without a human decision, it is automatically destroyed at the latest 3 days after it was submitted.

A photo refused because there is a doubt as to whether the person shown is a minor never enters that queue: it is destroyed immediately.

Profile certification (optional)

Certification is a VOLUNTARY step: you alone can request it, and the service works fully without it. It consists in taking a photo of yourself there and then, with your phone camera, reproducing a code shown on screen for a limited time.

That photo is passed to OpenAI for a single question: does it show a real, sharp, properly lit and properly framed face? It is NEVER compared with your profile photo, involves NO identity facial recognition, NO identity document, NO video and NO location data (image metadata is refused). Certification attests to a level of confidence; it does not guarantee a member’s civil identity.

If the analysis accepts the photo, your profile is certified and the photo is NOT kept. If it refuses it, you are told the reason and the photo is NOT kept. If it leaves a doubt, the photo is kept in a private area so that an authorised person can review it, then automatically destroyed when the retention period ends (3 days by default, 30 days at most). Only the result (certified or not) is visible to other members.

Push notifications

Push notifications are optional and work only with your permission, granted to your browser. When you enable them, the service records the subscription address supplied by your browser, the associated public encryption keys, a hashed fingerprint of the browser and the platform type — never your phone number, your email or your position.

The content of a notification is MINIMAL: an event type, the sender’s nickname, the conversation identifier and, where applicable, your total number of unread messages. The text of your messages NEVER appears in it, nor does any photo.

That content is encrypted according to the Web Push standard: the notification service of your browser (provided by your browser or system vendor) delivers the message without being able to read it. You can disable notifications at any time; the subscription is then deleted.

Recipients and processors

Your data is neither sold nor used for advertising purposes. It is passed only to the strictly necessary technical processors:

Transfers outside the European Union

The servers hosting the service and your data are located within the European Union (Germany).

Two processing operations involve a provider established outside the European Union: moderation of the public profile photo and, if you request it, analysis of the certification photo, both entrusted to OpenAI, a company established in the United States. These transfers are strictly limited to the image concerned and to that sole purpose: neither your messages, nor your messaging photos, nor your private albums, nor your position are transferred.

Delivery of push notifications, if you enable them, goes through the notification service of your browser or system, which may be established outside the European Union; the payload transmitted is encrypted and cannot be read by that service.

For any question about the safeguards framing these transfers, write to bonjour@baza.fr.

Retention periods

Your rights (GDPR)

You have the rights of access, rectification, erasure, restriction, objection and portability over your data. You can exercise them through the Contact page.

You may also lodge a complaint with the CNIL (cnil.fr).

Security

Exchanges with the service are encrypted in transit. Sessions are revocable (logging out invalidates the token). Verification codes are never stored in clear text.

Your password is not encrypted: it is HASHED (scrypt function, with a unique salt per password). A hash is not reversible — nobody, ourselves included, can recover your password from what is stored.

Photos are stored outside any public folder and are served only to authorised people (you for your profile photo, the participants for a messaging photo, authorised members for a private album).

Cookies and local storage

The service does not use advertising cookies. Only storage strictly necessary for it to work is used (session, display preferences).

If audience-measurement tools were to be added, they would be the subject of dedicated information and, if required, a prior consent banner.

Minors

The service is forbidden to minors. Any ‘Presumed minor’ report is handled as a priority and leads to deletion of the account if minority is confirmed.