Privacy policy

We take your privacy seriously. Here is how we process your data, in compliance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.

1. Data controller

The controller of the personal data collected on Erasly is the company GEOSECURITY (GS).

  • Company: GEOSECURITY (GS), SAS — SIREN 941 426 363
  • Registered office: 8 rue André Bauchant, 37550 Saint-Avertin, France
  • GDPR contact: hello@erasly.eu

2. Data we collect

We only collect data necessary to run the service:

  • Email, first name, last name, date of birth (at sign-up — date of birth is used solely to verify the legal minimum age to access the service; legal basis: legitimate interest and legal obligation)
  • Password (encrypted, never visible to us)
  • Profile: home university, host city and school, dates, photo, bio, interests, languages
  • Messages exchanged with other users, likes, matches
  • Reviews you post about cities and schools, feedback you send via the feedback form
  • Reports and blocks of other users (moderation)
  • Audience-measurement data (usage events, anonymous identifier, session recording) — only if you have given consent via the cookie banner
  • Technical connection and email-delivery logs (timestamp, partial IP), kept for security and legal compliance

3. Purposes of processing

Your data is only used to:

  • Help you match with other Erasmus students
  • Send you email notifications (matches, messages, daily digest)
  • Moderate the platform and ensure its security (handling reports, blocks, suspensions)
  • Measure aggregate usage of the service and improve features — only with your consent (analytics cookies)

We never sell or share your data with third parties for commercial purposes.

4. Legal bases

Each processing relies on a legal basis set out in Article 6 of the GDPR:

  • Performance of the contract — account creation, matching, messaging, posting reviews: without this data the service cannot operate.
  • Consent — optional notification emails, certain non-essential cookies (where applicable). You may withdraw consent at any time.
  • Legitimate interest — service security, fraud and abuse prevention, feature improvement based on aggregated data.
  • Legal obligation — retention of certain technical data (connection logs) required by French law.

5. Sub-processors

Erasly relies on the following sub-processors, all contractually bound to comply with the GDPR:

  • Supabase Inc. (United States, data stored in EU region — Frankfurt) — database and authentication.
  • Vercel Inc. (United States) — website hosting, edge network.
  • Resend (United States) — transactional email delivery.
  • PostHog Inc. (EU regional instance — eu.i.posthog.com) — audience measurement, usage events and session recording. Enabled only with your consent (cookie banner).
  • o2switch (France) — DNS and email management for the erasly.eu domain.

Transfers outside the EU. Where sub-processors are located outside the European Economic Area (Vercel, Resend, Supabase as a US organisation), transfers are framed by the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), ensuring a level of protection equivalent to the GDPR. PostHog is used on its EU instance and analytics data remains within the European Economic Area.

6. Your rights (GDPR)

Under Articles 15 to 22 of the GDPR you have the following rights:

  • Access — view all your data from your profile or request a copy from us.
  • Rectification — change your information at any time.
  • Erasure — delete your account from settings; all your data is erased immediately.
  • Portability — request a structured export of your data by email.
  • Objection — object to a processing based on legitimate interest, unsubscribe from notification emails.
  • Restriction — request the restriction of a processing (for example if you contest the accuracy of the data).
  • Withdrawal of consent — withdraw at any time a consent previously given, with no retroactive effect.

To exercise a right: hello@erasly.eu. We respond within one month.

CNIL complaint. You have the right to lodge a complaint with the French data protection authority (CNIL — www.cnil.fr) if you consider that your rights are not respected.

7. Retention periods

Your data is kept for periods strictly necessary to the purposes of processing:

  • Active account — data retained while the account is active and used.
  • Deleted account — all personal data is erased immediately, except for public content (reviews) that may be kept in anonymised form in the community's interest, and a few strictly technical residual traces (moderation audit, security logs).
  • Contact emails — messages received at hello@erasly.eu (support, GDPR requests) retained for up to 12 months after the last exchange.
  • Analytics data — PostHog events and session recordings retained according to PostHog's default settings (typically 12 months), erased immediately if you withdraw your consent.
  • Technical logs — retained for 12 months to meet legal obligations and security needs.

8. Cookies and trackers

Erasly uses strictly necessary cookies to operate the service: session, authentication, language preference, cookie-consent choice. These cookies do not require prior consent according to the CNIL guidelines.

Erasly also uses analytics trackers (PostHog) to measure usage of the service, identify pages that cause friction and improve the experience. These trackers include an anonymous identifier, usage events and a session recording (replay). They are activated only with your explicit consent, collected via the cookie banner on first visit. You can withdraw consent at any time by clearing the site's storage in your browser.

We do not use any advertising cookies or profiling for commercial purposes.

9. Data protection officer

GEOSECURITY (GS) has not appointed a mandatory DPO within the meaning of Article 37 GDPR (the company does not carry out large-scale processing of sensitive data). For any data protection question, the single contact point is hello@erasly.eu.

10. Contact

For any privacy question or to exercise a right, write to us at hello@erasly.eu.

Last updated: 6/8/2026