Document being finalized — the final version will follow company incorporation.
Privacy Policy — KeepAlive
Last updated: September 8, 2026 · Version: draft
This policy describes the processing of personal data carried out as part of the KeepAlive mobile application (iOS and Android) and its associated backend service, published by KEEP ALIVE and available at keep-alive.fr. It is drafted in accordance with Regulation (EU) 2016/679 ("GDPR" / "RGPD") and the French Data Protection Act ("loi Informatique et Libertés") No. 78-17 of 6 January 1978, as amended.
The KeepAlive service is a complementary crisis-management and remote-assistance service. It does not replace and never substitutes for public emergency services (15 / 17 / 18 / 112).
1. Identity of the data controller
The data controller within the meaning of Article 4(7) of the GDPR is:
- KEEP ALIVE, a simplified joint-stock company — company in the process of incorporation, not yet registered
- Registered office / SIREN: [to be completed upon incorporation]
- Contact:
contact@keep-alive.fr
KEEP ALIVE has chosen to appoint an outsourced Data Protection Officer (DPO), given the sensitivity of the data processed (geolocation of people in danger). The provider has not yet been designated; in the meantime, any inquiry can be sent directly to the address above.
2. Data collected and legal bases
| Category | Detail | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Identity and account | Name, email, phone, password (stored protected), subscription plan | Performance of contract (6.1.b) |
| "Proxis" trusted network | Name, phone and/or email of trusted contacts designated by the user, notified during an alert | Performance of contract (6.1.b) |
| Geolocation | GPS position, collected only during an active alert — no location tracking outside an alert | Consent (6.1.a) + vital interests (6.1.d) — Art. 9-2-c for the related sensitive data |
| Media / capture | Audio recording, optionally video, and the associated transcript, captured only when an alert is triggered | Consent (6.1.a) + vital interests (6.1.d) |
| Payment data | Billing and subscription data; card data is processed directly by our payment provider, KEEP ALIVE does not retain card details | Performance of contract (6.1.b) + accounting obligations (6.1.c) |
| Minimal technical data | Device identifier, technical logs strictly necessary for the operation and security of the service | Legitimate interest (6.1.f) |
No data is collected for advertising, commercial profiling, or resale. KEEP ALIVE does not process data for automated decision-making producing legal effects on the person.
Note on third-party data ("proxis" network): contact details for designated trusted contacts are supplied by the person adding them; it is their responsibility to inform those contacts. KEEP ALIVE informs proxis, at their first solicitation, of the data concerning them and their rights.
3. Purposes
- Provide the service — account, alert button, proxis network, subscription management.
- Handle an alert — verification, remote support, transmission to the proxis network and, where applicable, to public emergency services.
- Audio capture and, where applicable, video during an alert, based on the voluntary triggering of the alert button.
- Manage payments and billing.
- Ensure service security and fraud prevention.
4. Retention periods
| Data | Period |
|---|---|
| Media and GPS positions | ≤ 90 days |
| Closed alerts (handled with no further action) | 90 days |
| Escalated alerts | 365 days |
| Dismissed alerts (false alarm, cancellation) | 7 days |
| Customer records (account, subscription, billing) | 3 years |
Upon expiry of these periods, data is deleted or anonymized, subject to longer retention periods required by applicable regulation (accounting obligations in particular).
5. Recipients and processors
Data is never sold, rented, or shared for commercial purposes. It may be shared, strictly as necessary, with the following recipients:
- SMS delivery for alerts and notifications, via a specialized provider.
- Email delivery for service notifications, via a self-hosted mail server.
- Payment processing, via an online payment provider (Stripe).
- Hosting of all service data: self-managed infrastructure, target France (OVHcloud).
- Apple / Google — technical delivery of push notifications to devices.
- Transcription service for audio captured during an alert, on self-hosted infrastructure (no third-party subprocessor).
Internally, access to data is limited to those who need it to carry out their duties, in particular the operators handling alerts.
6. Transfers outside the European Union
The service is designed to host data in France / the European Union. In principle, no data transfer takes place outside the EU. Two points remain to be documented precisely with the relevant providers: the technical delivery of push notifications (Apple / Google) and the configuration used with the payment provider, which may transit through infrastructure outside the EU depending on the applicable contractual safeguards (Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework).
7. Rights of data subjects
- Right of access to data (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to object to processing based on legitimate interest (Art. 21)
- Right to data portability (Art. 20)
- Right to set post-mortem directives (Art. 85 of the French Data Protection Act)
Procedure: substantiated request to contact@keep-alive.fr. Reply within one month (extendable by two months in case of complexity, Art. 12.3 GDPR). Complaints can be filed with the CNIL (French Data Protection Authority) — 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07 — www.cnil.fr.
8. Data security
KEEP ALIVE implements technical and organizational measures proportionate to the sensitivity of the data processed, notably:
- Encryption of data, in transit and at rest.
- Access segregation, limited to authorized personnel on a need-to-know basis.
- Minimization: only the data necessary for each purpose is collected (no geolocation outside an alert).
- Sovereign hosting, in France / the European Union.
- Regular review of security measures and access.
For security reasons, this policy does not detail the service's technical architecture. In the event of a data breach likely to result in a risk to the rights and freedoms of individuals, KEEP ALIVE notifies the CNIL within the timeframes required by the GDPR and informs affected individuals where the regulation requires it.
9. Cookies and trackers
The mobile application uses no cookies or advertising tracking technology. The keep-alive.fr website uses no third-party advertising-tracking analytics cookie; any future audience measurement will be self-hosted and compliant with CNIL guidelines on cookies exempt from consent.
10. Eligibility
In accordance with the Terms of Use, account creation is reserved for adults with legal capacity to contract, or a duly authorized representative of a legal entity (B2B subscription).
11. Impact assessment and changes
Given the nature of the data processed (geolocation of people in danger, data potentially relating to health during a capture), a Data Protection Impact Assessment (DPIA) is required and has been initiated.
This policy may be updated, in particular to reflect a change in the service, its processors, or applicable regulation. Any substantial change is notified in the application and/or by email prior to taking effect.
12. Contact & supervisory authority
- Data controller: KEEP ALIVE —
contact@keep-alive.fr - CNIL — 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07 — www.cnil.fr — +33 (0)1 53 73 22 22