GDPR Compliance

We use cookies to improve your experience and provide personalized offers. You can accept, reject all, or customize your choices.

Shopping cart

Your favorites

You have not yet added any recipe to your favorites list.

Browse recipes
ESC

What are you looking for?

Privacy

At ALOLAO, we value your privacy. Here's what you need to know:

• We only collect your email address, encrypted password, and information necessary to access and receive messages.
• Your data is never sold, but it may be used by ALOLAO for promotional purposes in order to offer you personalized deals or special offers.
• Messages you send remain private and are automatically deleted from our servers 90 days after being received by the recipient..
• You can delete your account and all your data at any time.
• You’re free to enable/disable email notifications and refuse to receive future messages.
• All data is hosted in Europe, on secure and GDPR-compliant servers.

For any question or request: [RGPD contact email address]
By continuing, you accept our [Full Privacy Policy] and our [Terms & Conditions].


Privacy Policy – Recipients

This Privacy Policy (hereinafter the "Policy") aims to inform you, as a recipient user of the ALOLAO platform, how your personal data is collected, used, stored, and protected.


1. Who is the data controller?

The editor of the ALOLAO platform is responsible for processing your personal data.
Data Controller:
ALOLAO
contact@alolao.com


2. What data is collected?

We only collect data strictly necessary to use the service.

Collected Data:

  • Email address (required for access and notifications)

  • Password (encrypted, never stored in plain text)

  • QR code linked to your profile

  • Login date, message access date

  • Notification preferences (email enabled/disabled)

  • IP address (temporarily stored for security and abuse prevention)

⚠️ No sensitive or biometric data is collected.
We do not collect or store the content of received messages, which remain strictly private.


3. Purpose of data processing

Purpose

Legal basis

Creation of your user account

Consent

Access to unlocked messages via QR code

Legitimate interest

Sending email notifications (if enabled)

Consent

Securing data access

Legal obligation

Anonymous usage statistics

Legitimate interest


4. Who has access to your data?

Your data is:

  • Only processed by the ALOLAO team

  • Never sold to third parties, partners, or external platforms

Some technical providers may access data strictly for hosting or security purposes, under GDPR-compliant contracts.
Uploaded files are hosted on Backblaze.


5. How long is your data stored?

Data type

Retention period

Email address

Until account deletion

Access logs

12 months max

Anonymous technical logs

6 months

IP address

3 months max

Opt-out or unsubscribe data

3 years (legal proof)

You can request immediate deletion of your data at any time (see section 8).


6. Where is your data stored?

Where your data is stored
ALOLAO uses Backblaze B2 Cloud Storage, with servers located in the European Union (Amsterdam/Paris). This ensures your data is physically stored in the EU, under GDPR standards.

How your data is protected
– Encrypted in transit and at rest
– Access restricted only to authorized processes
– Automatically deleted once retrieved by the recipient

Legal compliance
Although our provider is a US-based company, we ensure EU storage location is used and we apply additional encryption so that even our storage provider cannot access the content of your files.


Files uploaded by the sender (messages) are permanently deleted 90 days from our platform7. Your rights

In accordance with applicable laws, you have the following rights:

  • Right of access: Know what data we hold about you

  • Right to rectification: Fix errors or outdated info

  • Right to object: Refuse non-essential processing (e.g., email notifications)

  • Right to erasure: Delete your data permanently

  • Right to restrict processing: Temporarily pause data use

  • Right to portability: Retrieve your data in readable format

📧 To exercise your rights, contact us at: [RGPD contact email]
We commit to responding within 30 days.


8. Account deactivation or deletion

You can delete your account and personal data at any time via your user space or by written request.
This action is irreversible:

  • All access is revoked

  • Preferences are erased

  • Links to received messages are permanently broken


9. Cookies and trackers

ALOLAO uses only strictly necessary functional cookies, for:

  • Managing user sessions

  • Securing the platform

  • Language settings

❌ No advertising cookies
❌ No third-party trackers
❌ No behavioral profiling


10. Policy updates

This Privacy Policy may be updated at any time, especially due to regulatory or technical changes.
Users will be notified of significant changes via email or upon next login.


11. Contact & complaints

For any question or complaint regarding data management:
📩contact@alolao.com 
You may also contact the French supervisory authority:
CNIL – www.cnil.fr