This is the Privacy Policy KARTES

It was last updated on June 10, 2026

This Privacy Policy describes how ODOWA is a word. (hereinafter nous ) collects, uses, shares and protects the personal data of users of mobile applications Cards are provided. (KARTES Intervention, KARTES Nature, hereinafter the Applications), as well as associated services accessible through the site It is called kartes.io..

It complies with the General Data Protection Regulation ()The RGPD is .) and the Law on Information and Freedoms of 6 January 1978 as amended.

Identity of the controller 1.

The data processor is:

ODOWA SASU
It is located at 6 rue d'Armaillé, 75017 Paris
SIRET: 945 053 015 00018 is also available.
This is my e-mail: [email protected]

The data collected 2.

2.1 Data provided directly by the user

Category Data concerned
User account Email address, password (hashed), name, first name, phone number (optional), profile photo (optional)
Work area (workspace) Organization name, logo, settings, user role (member, administrator, owner)
Content produced in the application Photos of infrastructure elements taken from the application, entered descriptions, comments, inspection and intervention forms, electronic signatures, and voice recordings for transcription
Payment (paying offers) Billing data processed by Stripe (name, billing address). Card data never passes through our servers.

2.2 Data that is collected automatically

Category Data concerned
Location Data GPS Coordinates (latitude/longitude) when creating or viewing an element on the map, as well as for the optional team position sharing feature (Pro and higher plans, can be disabled)
Technical Data IP Address, device type, OS version (Android/iOS/Web), application version, anonymized technical identifiers
Activity Journals (audit log) Timestamped history of actions performed (creation / modification / deletion of items, interventions, inspections) with user identifier — used for traceability and security
Usage Data Pages viewed, features used, time spent, for internal statistical purposes

Purposes and legal bases 3.

Purpose Legal basis (GDPR)
User account creation and managementExecution of the contract (CGS)
Supply of application features (mapping, inspection, intervention, reporting)Contract Execution
Geolocation of elements on the mapContract Execution — the feature requires the position to function
Image analysis using artificial intelligence (AI Vision: object recognition, field suggestions)Contract execution / consent (optional feature activable)
Voice transcription by artificial intelligence (AI Voice)Consent (explicit user trigger)
AI ChatbotConsent (optional feature)
Team MessagingContract Execution
Push notifications (alerts, messages, reminders)Consent (activatable/deactivatable system authorization)
Gamification (badges, optional rankings)Contract execution — disableable by the administrator
Team Position Sharing (Pro+ Offers)Consent (activable by each member individually)
Billing and payment of the subscriptionContract execution / legal obligation (accounting)
Security, fraud prevention, traceability (audit log)Legitimate interest / legal obligation
Anonymized internal usage statisticsLegitimate Interest
Transactional communications (password reset, confirmations)Contract Execution

Permissions of the mobile applications 4.

The KARTES applications request the following system permissions on Android and iOS.All are requested contextually at the time of their first use and can be revoked at any time in the device settings.

Permission Usage justification
CameraTake photos of infrastructure elements (equipment, signage, damages) to associate them with mapped elements or with interventions/inspections.
Localization (precise and approximate)Geolocate elements when creating them on the map, display your real-time position to help you navigate on site, and optionally share your position with your team (optional feature).
MicrophoneSave AI-transcribed voice annotations to quickly enter fields without a keyboard (optional feature).
Storage / PhotosSelect existing images from the gallery to attach them to an item or an intervention.
NotificationsNotify you of relevant events (new message, assigned intervention, important alert)
InternetSynchronize data with our servers and use cloud AI features.

5. sub-processors and recipients of the data

To provide the services of the applications, we use technical subcontractors selected for their GDPR compliance:

Subcontractor Purpose Data concerned
Amazon Web Services (AWS S3) is also available.Storage of photos and uploaded filesPhotos taken from the app, profile photos, jackets
Anthropic (API Claude) is also available.AI Image Analysis (Vision), voice transcription (Voice), conversational assistantUploaded images, voice recordings, text prompts — only upon explicit user trigger
Mapbox is a mapbox.Display of mapping, address geocodingGPS Coordinates, Searched Addresses
It's called StripeProcessing of subscription paymentsName, email, billing address, card data (managed exclusively by Stripe, never by our servers)
DeepL deepLAutomatic translation of content for non-French-speaking usersText Snippets to Translate (labels, object type descriptions)
Host (API servers)Database and application server hostingUser Data Set
Transactional email servicesEmail sending (password reset, invitations, invoices)Email address, first name

No personal data is resold to third parties for commercial or advertising purposes.

Transfers outside the European Union 6.

Some of our subcontractors may process data from countries outside the European Union:

  • Anthropic (US) : transfers covered by the Standard Contractual Clauses (CCTs) of the European Commission.
  • Stripe (US/Ireland) : certified by the Data Privacy Framework (DPF) EU-USA, and CCT.
  • AWS is an AWS. : our S3 buckets are configured in region eu-west-3 (Paris) your photos and files remain stored in France.
  • Mapbox : CCT for map tile requests.

7. shelf life

Data Category Storage duration
User account (profile, credentials)As long as the account is active. Deletion upon request, or prolonged inactivity (3 years without connection)
Product content (photos, elements, interventions)As long as the workspace is active. Permanent deletion within 30 days after account or workspace deletion
Audit Logs (audit log)2 years from the event
Billing data10 years (legal accounting requirement)
Technical logs (connection, errors)Maximum 12 months
Backups30 to 90 days depending on the criticality
Data sent to AI (Anthropic)Not retained by Anthropic beyond the request (zero-retention policy for API uses)

Security of the data 8.

We implement technical and organizational measures to protect your data:

  • TLS Encryption for All Client/Server Communications
  • Hashed passwords (bcrypt algorithm) — never stored in plain text
  • JWT token authentication with limited lifetime + revocable refresh tokens
  • Strict data isolation per workspace (multi-tenant partitioning in database and cache)
  • Encrypted backups
  • Server-side Role-Based Access Control (RBAC)
  • Timestamped audit logs to track any sensitive action
  • Regular security updates for servers and dependencies

9. your rights.

In accordance with the GDPR, you have the following rights regarding your personal data:

  • Right of access : obtain a copy of your data
  • Right to rectification : correct inaccurate or incomplete data
  • Right to erasure (« right to be forgotten »): request the deletion of your data, subject to our legal obligations
  • Right to restriction of processing
  • Right of objection to processing based on legitimate interest
  • Right to data portability : receive your data in a structured and readable format
  • Right to withdraw your consent at any time for the processing based on it
  • Right to file a complaint with the CNIL (www.cnil.fr)

To exercise your rights, please contact us at This page is for [email protected]We respond within a maximum period of one month.

Deleting your account is also possible directly from the applications, in the user settings.

Children under the age of 10.

The KARTES applications are professional tools intended for infrastructure management actors (communities, enterprises, heritage managers).They are not intended for persons under 16 years of age and we do not knowingly collect data concerning minors.If you believe that a minor has provided us with data, please contact us for immediate deletion.

Cookies and tracers 11.

The mobile applications do not use third-party cookies for advertising or profiling purposes.

The kartes.io site may use cookies that are strictly necessary for operation (session, language) and, where applicable, anonymized audience measurement cookies. No advertising or cross-site tracking cookies are set.

12. Modifications to the policy

This policy may be updated to reflect technical, legal or functional developments. any substantial changes will be notified to users (notification in the application or email). the date of last update is at the top of this document.

Please contact 13.

For any questions regarding this privacy policy or the processing of your personal data:

This is my e-mail: [email protected]
Courier: ODOWA, located at 6 rue d'Armaillé, 75017 Paris