Privacy policy
This privacy policy describes how Brightmfr SAS ("Brightmfr", "we") collects, uses and protects your personal data when you use brightmfr.com. It complies with the General Data Protection Regulation (GDPR — EU Regulation 2016/679) and the French Data Protection Act.
1. Data controller
The data controller is Brightmfr SAS, a simplified joint-stock company with €50,000 share capital, registered with the Paris Trade Register under number 949 372 581, headquartered at 12 Rue de la Paix, 75002 Paris, France. Contact: contact@brightmfr.com.
2. Data collected
We collect the data you provide through our forms: full name, email address and, where relevant, phone number and region of residence. We also collect technical data (IP address, browser type, pages viewed) through cookies and similar technologies.
3. Purposes
Your data is processed in order to: respond to your requests, send you the program documentation, inform you about the available residential real-estate projects, comply with our legal obligations and measure site audience.
4. Legal basis
Processing is based on your consent (Article 6.1.a GDPR) for marketing communications and non-essential cookies, on pre-contractual measures (Article 6.1.b) for documentation delivery, and on our legal obligations (Article 6.1.c) for record keeping.
5. Retention period
Prospect data is retained for three (3) years from the last active contact. Accounting and legal records are retained for ten (10) years in accordance with the French Commercial Code.
6. Recipients
Your data is accessible to Brightmfr internal teams and to our technical processors (hosting, email, audience measurement) located within the European Union. No data is shared with third parties for commercial purposes.
7. Your rights
You have rights of access, rectification, erasure, restriction, objection, portability and post-mortem instructions. You may exercise these rights at contact@brightmfr.com. You may also file a complaint with the CNIL (3 Place de Fontenoy, 75007 Paris).
8. Security
Brightmfr implements appropriate technical and organisational measures (TLS encryption, access controls, regular backups) to protect your data against loss, alteration or unauthorised disclosure.
9. Updates
This policy may be updated to reflect legal or operational changes. The applicable version is the one published on this page.