Privacy Policy
Version 2.0 — Effective July 1, 2026 — Publisher: KWALEAD SAS — European GDPR Compliance
1Data Controller
The company KWALEAD SAS, a simplified joint-stock company with a capital of €6,000, registered in the Créteil Trade and Companies Register (RCS) under number B 813 823 192, with its registered office located at 8 rue d'Estiennes d'Orves, 94000 Créteil (France), publisher of the Dringbell service, acts as the data controller. For any questions regarding your personal data or to exercise your rights, you can contact our Data Protection Officer (DPO) at the following email address:
2Collected Data
We only collect data that is strictly necessary to provide our connected doorbell service. The categories of processed data are divided according to your use of the platform:
For Doorbell Owners (Users)
- Account credentials: email address, name (optional), profile picture (optional).
- Configuration: public doorbell slug (e.g.,
/ring/maison-martin), greeting message, preferred language, time zone. - Notifications: cryptographic Firebase Cloud Messaging (FCM) push notification tokens.
- Activity log: call history (status, timestamp) and recorded messages (audio, video, text).
- Billing: Stripe payment data (card numbers are not stored on our servers).
For Visitors (Anonymous Users)
No data is collected without your knowledge. The data processed during a scan or a call are:
- IP address hash (irreversibly anonymized in the database for spam detection and rate-limiting).
- System information: browser User Agent (truncated, to calibrate the WebRTC stream), navigation locale.
- Interaction: content of the message (text, audio, or video) left by the visitor and name declared in the form in case of no answer.
3Purposes and Legal Bases
Your data is processed on specific legal bases to meet the following purposes:
| Purpose | Legal Basis | Description |
|---|---|---|
| Provision of the connected doorbell service | Performance of a contract (T&Cs) | Account creation, QR code generation, WebRTC stream, and message storage. |
| Billing and subscription management | Contract + Legal obligation | Payments via Stripe, regulatory accounting. |
| Spam and malicious call prevention | Legitimate interest | Hashing of visitors' IP addresses and abuse blocking. |
| Transactional emails and visit alerts | Performance of a contract | Email or push notifications "Someone is ringing". |
| Marketing communications (Dringbell) | Consent | Sending commercial offers (1-click unsubscribe). |
4Retention Period
Your data is kept only for the duration strictly necessary for the purposes pursued:
| Category | Retention Period | Details |
|---|---|---|
| Active account | For the entire duration of the subscription. | Immediate soft delete, then permanent purge within 30 days after termination request. |
| Inactive free account | 12 months without login. | Alert at the 11th month, then automatic deletion of data. |
| Visitor messages | 7, 30, 90, or 365 days. | Configurable by the owner user; daily cleanup. |
| System and audit logs | 12 months. | Automatic destruction for security reasons. |
| Financial logs (accounts) | 10 years. | Mandatory legal accounting retention for Stripe/Kwalead. |
5Hosting and Security
All data processed by Dringbell is hosted in Europe:
- The Postgres relational database is stored at Supabase (EU Frankfurt region, Germany).
- Message files (audio, video) are saved encrypted on Supabase Storage (Frankfurt, Germany).
- The Next.js front-end and back-end application runs on Vercel servers (CDG1 Paris region, France).
Platform communications are fully encrypted using HTTPS/TLS 1.3. Data isolation between households is ensured at the database level by Postgres RLS (Row Level Security) rules. Access to media files is only possible via temporary signed URLs with a validity period limited to 24 hours.
6Subprocessors
We use trusted service providers who offer all the necessary GDPR compliance guarantees:
Database and media storage (Frankfurt, Germany).
Hosting and Edge servers (Paris CDG1, France).
Secure payment and subscription processing.
Sending notification and service emails.
7Your GDPR Rights
In accordance with the GDPR, you have the following rights regarding your personal data:
- Right of access: Consult your data at any time.
- Right to rectification: Modify incorrect information from your profile.
- Right to erasure ("right to be forgotten"): Permanently delete your account.
- Right to portability: Export a structured JSON file of your data from the dashboard.
- Right to object and restriction: Object to marketing mailings or temporarily freeze processing.
To exercise these rights, write to privacy@dringbell.com. You can file a complaint with the CNIL if you feel your rights are not being respected.
8Cookies
Dringbell only uses cookies and local storage technologies essential to provide the service or respect privacy:
- Authentication: Supabase Auth session cookie (essential to keep you logged in).
- Language: Cookie
NEXT_LOCALE(essential to remember your display language preference). - Audience measurement: Google Tag Manager / Plausible. Visit statistics are anonymous and comply with the European Consent Mode v2. Audience measurement cookies are only loaded after obtaining your explicit consent via our cookie banner.