```html Privacy Policy — Eternavitas

Preamble

Eternavitas respects the privacy of its users and is committed to protecting their personal data in accordance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679) and the amended French Data Protection Act.

1. Data Controller

Saint-Paul Mahi (trade name: Eternavitas), sole proprietor under the micro-enterprise regime (self-employed in liberal activity, BNC). SIREN: 104788187 — SIRET: 10478818700011 — APE Code: 6201Z. Headquarters address: 2 A rue Auguste Lepère, 44100 Nantes, France. Phone: +33 7 62 04 06 54. Contact: contact@eternavitas.org.

2. Data Collected

Data Purpose Legal Basis
Email address Account creation, authentication, communication Contract execution
Password (encrypted) Authentication Contract execution
User profile (gender, age range, main goal, geographic area, activity level, optional first name, optional health context) Personalization of doctrinal recommendations Explicit consent
Medical disclaimer consent (timestamp) Proof of acceptance for sensitive goals Legal obligation and legitimate interest
Conversations with the agent Request processing, service improvement Contract execution
Payment data Subscription processing Contract execution (via Stripe — Eternavitas does not store any banking data)
IP address, browser type Security, fraud detection Legitimate interest
First name and email address (Vital Assessment form, without account creation) Delivery of the Vital Assessment by email (score, tier label, personalized message) Contractual execution (art. 6.1.b GDPR) — the service consists of delivering the requested assessment
Responses to the 8 questions of the Vital Assessment, score calculated out of 16, tier assigned (1 to 4) Score calculation, personalization of tier message, anonymized aggregated analysis for service improvement Contractual execution

3. Retention Period

4. Subcontractors

Subcontractor Function Location Guarantees
Anthropic, PBC Agent response generation (API Claude) United States EU-US Standard Contractual Clauses (SCC)
Stripe Payments Europe Ltd Payment processing Ireland / United States PCI-DSS compliance, SCC
Render Services, Inc. Application hosting United States SCC
Supabase Inc. User data storage Norway (EEA) GDPR directly applicable, no transfer outside EU/EEA
Resend, Inc. Transactional email sending United States SCC

5. Transfers outside the EU

Some data is transferred to the United States (Anthropic, Render, Resend, Stripe). These transfers are governed by the standard contractual clauses adopted by the European Commission. Data stored with Supabase remains within the European Economic Area (Norway).

6. Your Rights

In accordance with the GDPR, you have the following rights regarding your data:

To exercise these rights: contact@eternavitas.org. Response within a maximum of 30 days.

For emails related to the Vital Assessment, an unsubscribe link is present at the bottom of each message. One click is enough; no justification is required. Unsubscription is processed within 48 hours.

You can also file a complaint with the CNIL: https://www.cnil.fr.

7. Cookies

Eternavitas only uses cookies strictly necessary for the operation of the service (session, authentication). No advertising or third-party tracking cookies are used. Therefore, no specific consent is required (article 82 of the French Data Protection Act, exemption for strictly necessary cookies).

8. Security

Data is stored in an encrypted manner. Communications with the server are protected by HTTPS. Passwords are hashed (never stored in plain text).

9. Contact

For any questions regarding your personal data: contact@eternavitas.org.

```