Personal data

Privacy policy

Last updated: 6 August 2026.

This translation is provided for information; in case of discrepancy, the French version prevails.

Who decides what

Your schooldecides about its students' data: it collects it, corrects it, deletes it. It is the data controller within the meaning of the GDPR. Benford Tech acts only as a processor: it runs the tool and uses this data for nothing else — no resale, no advertising, no model training.

Benford Tech is, however, the controller for the accounts it manages itself: the platform administration accounts and school opening requests.

What is processed

Student
First name, last name, email, phone (optional), gender and dance level, profile photo (optional), class enrolments, confirmed and recorded attendance, plan, payments and invoices.
Teacher or school administrator
Name, email, encrypted password, role, speciality and hourly rate if provided, history of attendance calls made and messages sent.
School
Name, city, address, company ID (SIRET), billing details, identifiers of the school's Stripe account.
Visitor
No data. The site sets no tracker and no advertising cookie, and does not measure its audience.

Why

  • Running the class : enrolling, counting places, keeping the waitlist, taking attendance, sending day-before reminders and video recaps.
  • Keeping the school's books : plans, payments, numbered invoices, chasing unpaid amounts — a legal obligation for the school.
  • Securing access : a password for staff, a secret personal link for the student.

The legal basis is the performance of the contract between the student and their school, and the legal obligation for invoicing. Push notifications only go out after your explicit consent in the browser, and stop when the permission is withdrawn.

Who else can access it

Nobody outside your school and the technical providers below. Schools are sealed off from one another: one school's data is never visible from another.

ProviderRoleLocation
VercelSite hostingUnited States — functions run in Europe (Frankfurt)
Neon (AWS)DatabaseEuropean Union — Frankfurt (eu-central-1)
StripeOnline payments, on behalf of each schoolEuropean Union / United States
HostingerEmail delivery (invoices, reminders, access links)European Union
Google“Continue with Google” sign-in (optional, staff and students), Drive and Photos if staff connect themUnited States

Transfers outside the European Union:the database and the site's functions run in the European Union, in Frankfurt. Vercel remains a US company with a worldwide delivery network: when a transfer outside the European Union does occur, it relies on the European Commission's standard contractual clauses, provided for in that provider's contract.

Data from Google APIs

Some optional features rely on Google APIs. The “Continue with Google” sign-in is offered to everyone — staff and students alike — on sign-in and enrolment screens, and always remains optional. Drive and Photos only concern school staff (teachers, administrators), who choose whether to connect their Google account.

  • “Continue with Google” sign-in : Thempo reads the account's email address, first name and last name, to find the matching account or pre-fill enrolment forms — the fields remain editable before submission. Nothing else is accessed or stored.
  • Google Drive (read-only) : when a staff member connects their Drive, Thempo only reads the folders they explicitly designate (a course's materials, a student's file) to sync their contents into the school's space. The rest of the Drive is never browsed. Thempo stores an access token, the email address of the connected account and the reference of the synced files; disconnecting Drive deletes the token.
  • Google Photos (official picker) : Thempo never accesses the photo library — only the photos explicitly chosen in Google's picker are copied as course materials. Here too, disconnecting deletes the token.

Thempo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements: this data serves only the features described above, is never transferred to third parties, never used for advertising, and never used to train AI models.

For how long

A student's data is kept as long as they are enrolled in their school, then deleted at their request or the school's. Invoices and payments are kept for ten years, as accounting law requires. A staff account is kept for the duration of their role.

Cookies

A single durable cookie is set, tempo_session, and only after signing in: it keeps the staff session open. Signing in with Google additionally leaves two short-lived, strictly technical cookies: a security token for the duration of the exchange with Google, and tempo_google_prefill (ten minutes) which carries the form pre-fill. All are strictly necessary to the service, which exempts them from a consent banner. No analytics cookie, no advertising tracker, no embedded social network. Students who use their personal link don't even have a cookie.

Security

Staff passwords are hashed (bcrypt) and never stored in plain text. All exchanges go through HTTPS. A student's personal link contains a random token: it is as good as a password, better not to share it. Every request checks the school of the signed-in person before answering.

Your rights

You can request access to your data, its correction, its deletion, its portability, or object to a processing operation. The fastest route is to talk to your school, which has direct control in its space. You can also write to the publisher, whose details are in the legal notice. In case of disagreement, you can refer the matter to the CNIL, the French data protection authority (cnil.fr).