The main purpose of this document is to provide, in a concise, transparent, clear and easily accessible format, information about the processing of personal data carried out by A3BC Group (hereinafter referred to as “A3BC Group” or “we”), so that you can understand the conditions under which your data is processed when using the TrustMe mobile application.
We are committed to fairness and transparency and therefore ensure that you are informed about how your personal data is processed through clear and appropriate privacy notices.
We collect personal data fairly and transparently. We do not collect personal data without your knowledge or without providing you with appropriate information about how and why it is collected.
When we process data, we do so for specific purposes: each data processing operation is carried out for a legitimate, specific, and explicit purpose.
For each processing operation carried out, we undertake to collect and use only data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
We ensure that data is kept up to date and implement procedures to enable the erasure or rectification of inaccurate data.
In the context with the processing of personal data for the purposes set out below, A3BC Group collects and processes the following categories of data concerning you:
The processing carried out by A3BC Group has the following purposes and legal basis:
| N° | Purposes | Sub-purposes | Legal basis |
|---|---|---|---|
| 1. | Management of user digital identity creation | TrustMe account management (creation, recovery, and deletion) | Performance of contracts and performance of pre-contractual measures taken at the request of the persons concerned |
| Management of credentials required for the user's digital identity (creation, update, and deletion) | Performance of the contract and performance of pre-contractual measures taken at the request of the persons concerned | ||
| 2. | Management of the use of digital identities created by users | Management of documents and other additional items (creation, update, and deletion) | Performance of contracts and performance of pre-contractual measures taken at the request of the persons concerned |
| Management of the proof of age | Performance of a contract and taking steps at the request of the data subject prior to entering into a contract | ||
| Management of data sharing with third parties | Consent (from Article 6 of the GDPR) | ||
| 3. | Technical data management | Performance of contracts and performance of pre-contractual measures taken at the request of the persons concerned | |
| 4. | Support and user contact | Collection and verification of phone number or email address | Performance of contracts and performance of pre-contractual measures taken at the request of the persons concerned |
| 5. | Responses to court orders and other requests from competent authorities | Legal obligations |
The recipients of your data are:
We ensure that, among these recipients, only authorized people have access to this data. A3BC Group applies a strict authorization policy that ensures that the data it processes is only transmitted to people authorized to access it.
We may transfer personal data outside the European Union in connection with the IT tools and services we use to carry out our activities.
Such transfers are only carried out after A3BC Group has implemented appropriate safeguards to protect the data, including, where applicable, entering into the Standard Contractual Clauses adopted by the European Commission to govern the resulting international data transfers.
We ensure that personal data is kept in a form that allows individuals to be identified only for as long as necessary to fulfil the purposes for which it is processed.
The retention periods we apply to your personal data are proportionate to the purposes for which it was collected.
More specifically, our data retention policy is organised as follows:
| N° | Category of data | Data details | Active storage period | Intermediate archiving |
|---|---|---|---|---|
| 1. | General personal data | Account data | Until the TrustMe account is deleted | None |
| Identification data (other than postal address) |
The shortest period between: - until the TrustMe account is deleted - 5 years from the validation of the digital identity |
The shortest period between: - 3 years from the deletion of the TrustMe account - the end of the 5-year period from the validation of the digital identity |
||
| Postal address |
The shortest period between: - until the TrustMe account is deleted - 3 months from the date of issue of the proof of address |
1 year from the end of the 3-month active period | ||
| Bank details |
The shortest period between: - until the TrustMe account is deleted - 10 years from the date of issue of the proof of bank details |
1 year from the end of the 10-year active period | ||
| 2. | Documents stored in the digital safe box | Any type of data | Until the TrustMe account is deleted | None |
| 3. | Technical data | Account activity history | Until the TrustMe account is deleted | 3 years from the deletion of the TrustMe account. |
We place particular importance on the security of personal data.
A3BC Group has implemented appropriate technical and organisational measures proportionate to the sensitivity of the personal data, with the aim of ensuring its integrity and confidentiality and protecting it against malicious intrusion, loss, alteration or disclosure to unauthorised third parties.
When we engage a sub-processor, we only disclose personal data with them after obtaining appropriate commitments and assurances regarding their ability to meet our security and confidentiality requirements.
We enter into agreements with our sub-processor in accordance with our legal and regulatory obligations. These agreements clearly define the conditions and terms under which personal data is processed and ensure compliance with applicable data protection regulations.
Cookies are subject to a Cookies Policy.
A3BC Group is particularly concerned with respecting your rights in relation to the data processing it carries out, in order to guarantee fair and transparent processing, taking into account the specific circumstances and context in which your personal data is processed.
In this regard, you have the right to confirm whether or not your personal data is being processed and, if so, you have the right to request a copy of your data and information concerning:
You have the right to ask us, as the case may be, to rectify or complete your personal data that are inaccurate, incomplete, ambiguous or expired.
You have the right to ask us to erase your personal data in the cases provided for by laws and regulations.
Please note, however, that the right to erasure is not a general right and can only be exercised if one of the reasons provided for in the applicable laws is met.
You have the right to request restriction of processing of your personal data in the cases provided for by laws and regulations.
You have the right to object, on grounds relating to your particular situation, at any time to process of your personal data which is based on the legitimate interest pursued by the controller (see clause above on the legal bases for processing).
If you exercise your right to object, we will no longer process your personal data for the processing concerned unless we demonstrate compelling legitimate grounds for the processing which must override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.
You have the right to portability of your personal data. Please note, however, that the right to data portability is not a general right.
Not all data from all processing operations are portable; the right to data portability only concerns processing carried out by automated means to the exclusion of manual or paper processing. This right is limited to processing based on your consent, on the performance of a contract or on the taking of steps prior to entering into a contract.
This right does not include derived or inferred data, which are personal data created by A3BC Group.
Where the processing of personal data we carry out is based on your consent, you have the right to withdraw your consent at any time.
We will then stop processing your personal data, but this will not affect the operations based on consent before its withdrawal.
You have the right to lodge a complaint with the CNIL (3 place de Fontenoy 75007 Paris) on the French territory without prejudice to any administrative or judicial remedy.
You have the right to give special instructions on how your personal data should be stored, erased and shared after your death. These special instructions only concern, and will be limited to, the processing carried out by us.
You also have the right, when that person will be designated by the executive branch, to give general instructions for the same purpose.
You may exercise the rights listed above by sending a request by email to dpo@a3bc.io or by post to: A3BC Group located at 1 contour de la Motte 35000 Rennes France, by proving your identity by any means.
We invite you to consult this policy on our website regularly. It may be updated at any time.
Version of the TrustMe Application Privacy Policy dated September 15, 2026