M2Stock · FRET SOLUTIONS
Privacy policy
Which data is used, why it is used and how to exercise your rights.
Version M2STOCK-2026-10-06.2 · 6 October 2026
Translation of contractual version M2STOCK-2026-10-06.2.
1. Controller and contact
FRET SOLUTIONS, RCS Angers 795 041 045, 16, rue Saint-Vincent, 49610 Mûrs-Erigné, France, is the controller for the processing necessary to operate M2Stock. For requests concerning your data: contact@fretsolutions.fr. This contact does not imply that a data protection officer has been appointed.
Your company manages its members’ permissions. Companies receiving an enquiry are responsible for their subsequent use of the information received to handle that enquiry and any resulting business relationship.
2. Data, purposes and lawful bases
| Data | Use | Lawful basis |
|---|---|---|
| Professional identity, company, SIRET, email, telephone, permissions and hashed password. | Open accounts, authenticate users, manage teams and provide the company workspace. | Performance of the contract for customers who are natural persons; legitimate interest in providing the service and managing colleagues’ access for other people. |
| Listing characteristics, site address, geographical coordinates, photos and designated contact. | Publish and search for availability; geocode the site and display an approximate location. | Performance of the requested service and the advertising company’s legitimate interest in presenting its offer. |
| Enquiries, professional contact details, telephone-number views, favourites and alert criteria. | Connect businesses, retain useful history and send alerts that users have expressly created. | Performance of the requested service; legitimate interest in recording and securing introductions. |
| Billing address, tax information, Stripe identifiers, subscription status and invoices. | Manage subscriptions, billing, payment incidents and accounting. | Performance of the contract and statutory accounting and tax obligations. |
| Version and acceptance date of terms, signatory identifier and company. | Establish evidence of the contract and handle disputes. | Legitimate interest in establishing and defending the parties’ rights. |
| Security and administration records, reports, timestamps and limited technical information. | Protect the service, prevent abuse, moderate content and diagnose incidents. | Legitimate interest in service security; legal obligation where required by an authority’s request. |
| Selected descriptive characteristics, requested tone and text suggested by AI. | Provide writing assistance at your request and limit calls. | Performance of the optional feature requested. |
Fields marked as required are necessary for the relevant feature. Without them, that feature cannot be provided. Optional fields, photos, AI assistance, favourites and alerts remain the user’s choice. No decision producing legal effects is made solely through automated profiling.
3. What is public and what is shared
Your optional company logo is displayed publicly on its listings. A company administrator may replace or delete it from My company. File metadata is removed during upload.
Published listings, their content, photos and a rounded location are publicly accessible. The exact address entered in the address field is not displayed in public search. However, an approximate location does not guarantee that a site cannot be identified from its surroundings, description or other elements added by the advertiser.
Enquiries are accessible to their author and authorised members of the recipient company. Necessary contact details are sent to the listing’s contact person so they can respond. A telephone number may be disclosed to a signed-in, verified user who requests it. Company administrators manage their team’s access. Platform administrators have access limited to their support, security and moderation duties.
FRET SOLUTIONS does not sell your personal data. Access may be granted to a competent authority where legally required, and to our providers as needed for their services and within the applicable contractual framework.
4. Providers and location
- Application hosting: Online / Scaleway SAS (Dedibox). Declared processing region: France.
- Photo and file storage: Scaleway Object Storage (Paris, France).
- Delivery of service emails: Mailjet (Sinch).
- Stripe: payment page, billing and subscription management. Card details are entered directly with Stripe. See its privacy policy for its own processing, including fraud prevention and regulatory obligations.
- IGN Géoplateforme: resolution of the site address necessary for geographical search. The geocoding request sends this address to the service.
- OpenStreetMap: provision of map tiles. When they are displayed, the browser sends its IP address and technical information, among other data, to the tile provider. See the OpenStreetMap privacy policy.
- xAI (Grok), only when AI assistance is enabled and requested: receipt of selected capacity, availability and equipment to propose a description. Free-text fields, photos, contact details and the address are not sent. The proposal must be reviewed before publication. The request disables response storage for reuse (store=false), without guaranteeing European residency or zero retention of provider logs.
Information about international transfers and their safeguards: Application hosting, databases and file storage are in France. Stripe and xAI (Grok) may process data outside the European Economic Area, including in the United States. Their data processing agreements describe the applicable transfer safeguards, including European Commission standard contractual clauses. AI drafting sends only technical characteristics, without free-text fields or contact details. This configuration does not guarantee European residency or zero data retention at xAI..
Where a transfer outside the European Economic Area is necessary, it must be covered by an applicable GDPR mechanism, including an adequacy decision or standard contractual clauses with the necessary measures. You may request information about recipients and a copy of applicable safeguards, subject to confidential information. Providers’ operational data is also subject to the retention periods in their contractual commitments.
5. Retention periods
The periods below constitute our retention policy. Deletion requests and periodic reviews may be handled by the authorised team; they do not all rely on automatic deletion.
| Category | Period |
|---|---|
| Account and professional profile | For the duration of service use. Without an active subscription, closure after 24 months without signing in, with 30 days’ prior notice. On a closure request, deletion or anonymisation within one month, subject to the exceptions below. |
| Removed listings and associated photos | 90 days after permanent removal or closure of the company workspace, to allow recovery and handle incidents. A draft kept by an active account is not a permanent removal. |
| Enquiries and telephone-number viewing history | 12 months after creation, followed by deletion or anonymisation, except information strictly necessary for an identified dispute. |
| Favourites and alerts | Until deleted by the user or their account is closed. |
| Unaccepted invitations | The link expires after 7 days; invitation data is deleted no later than 30 days after expiry. |
| Technical AI-generation records | 90 days; M2Stock does not retain full request content in these logs. |
| Security and administration logs | 12 months, with restricted access, unless an incident requires specific evidence to be preserved. |
| Contractual evidence and documents needed to defend a right | 5 years after the end of the contractual relationship or closure of the case, in a restricted-access archive, subject to ongoing proceedings. |
| Invoices and accounting documents | 10 years from the end of the financial year concerned. |
| Backups | A maximum 30-day rotation; backups are isolated from everyday use. Deletions are reapplied after restoration. |
Litigation or a legal obligation may justify retaining certain information beyond the usual period. Only the necessary data is then isolated, with limited access and a review date. Information received by another professional may be retained by that professional for their own obligations.
6. Cookies and communications
M2Stock uses a session cookie needed for sign-in and the protection of actions. Its lifetime is limited to eight hours. No advertising tracker or marketing audience-measurement tool is installed by default. Cookies strictly necessary for the requested service do not require consent. You may delete them in your browser, which may interrupt your session.
External Stripe pages follow their own cookie information. If optional tracking features are added to M2Stock, they must be accompanied by the required information and prior choice. Security, account, contact and billing messages are service messages. Search alerts are sent only if you create them; you may delete them in your workspace. Registration does not constitute consent to marketing.
7. Security and rights
Measures include separation of company workspaces, role controls, password hashing, session protection, limits on certain actions and restricted access to administration features. Security also depends on protecting your access and on the content you choose to publish.
You may request access, rectification, erasure, restriction and portability where provided by the GDPR, and object to processing based on legitimate interests for reasons relating to your situation. Where processing is based on consent, you may withdraw it for the future. You may also provide instructions regarding your data after your death under the conditions provided by law.
Write to contact@fretsolutions.fr, identifying the account and your request. Proportionate proof of identity may be requested where there is reasonable doubt, without systematically collecting a copy of an identity document. A response is normally provided within one month; a reasoned extension is possible under the GDPR. You may lodge a complaint with the CNIL.