1. Data Controller
The data controller for personal data collected on coqworking.fr is:
SECIVDA SAS
12 place du Coq, 82000 Montauban, France
SIRET: 919 389 551 00012
Email: [email protected]
Phone: +33 9 78 80 03 46
Protection of your personal data
Last updated: 2026-07-28
The data controller for personal data collected on coqworking.fr is:
SECIVDA SAS
12 place du Coq, 82000 Montauban, France
SIRET: 919 389 551 00012
Email: [email protected]
Phone: +33 9 78 80 03 46
We only collect data strictly necessary for providing our services:
Booking form: name, email address, phone number, company (optional), address (optional), message (optional).
Resident area: name, email address, password (stored as a bcrypt cryptographic hash, never in plain text).
Online payment: banking data is processed exclusively by Stripe (https://stripe.com/privacy). We do not store any banking data on our servers.
Cookies: a technical language preference cookie (NEXT_LOCALE) and a consent cookie (cookie_consent). No advertising cookie, no third-party tracker.
Audience measurement: we use Umami, hosted on our own servers (stats.secivda.cloud). It records pages viewed, referring page, device type and an approximate geographic area (city or region), with no advertising cookie and without sending anything to a third party. This measurement lets us check the site works properly and stays active for all visitors; it cannot identify you.
Detailed journey analysis (subject to your agreement): if you accept it in the consent banner, we measure the steps completed in the booking and luggage forms, along with the reason for any failure (for example “slot unavailable”). Only categories are sent: never your name, email address, phone number or the content of your messages. You may refuse at any time, with no impact on your use of the site.
Your data is processed for the following purposes:
Management of coworking space, office, and meeting room bookings.
Sending confirmations, notifications, and reminders related to your bookings by email.
Management of resident accounts and their attendance.
Invoicing and accounting.
Responding to your contact requests.
Measure site audience and the quality of the booking journey, in order to verify the site works properly and fix points where visitors get stuck.
The processing of your data is based on the following legal grounds:
Contract performance: processing bookings and payments (Article 6.1.b GDPR).
Legal obligation: retention of invoices and accounting documents (Article 6.1.c GDPR).
Legitimate interest: website security and fraud prevention (Article 6.1.f GDPR).
Audience measurement: legitimate interest (GDPR art. 6.1.f) in verifying the site works properly. Detailed journey analysis: your consent (art. 6.1.a), collected via the banner and revocable at any time.
Your personal data is strictly confidential and is only shared with the following processors for service delivery:
Stripe Inc. (secure payment) - PCI DSS Level 1 certified.
Brevo (formerly Sendinblue) (transactional emails) - Servers in the European Union.
OVHcloud (hosting) - Servers in France.
Pennylane (invoicing) - Servers in the European Union.
ntfy (internal push notifications) - Self-hosted on OVHcloud server in France.
No data is sold, rented, or shared with third parties for commercial or advertising purposes.
Audience measurement data: no external recipient. The solution is hosted on our own infrastructure, in France, and no data is sent to any third-party service.
Booking data: 3 years from the last booking.
Invoicing data: 10 years (legal accounting obligation).
Resident accounts: duration of subscription + 1 year after termination.
Contact data: 1 year from the last interaction.
Security logs: 12 months.
Audience measurement data: 25 months maximum.
We implement the following technical and organizational measures to protect your data:
HTTPS/TLS encryption on all communications.
Passwords hashed with bcrypt (never stored in plain text).
Signed JWT tokens for authentication.
SQL injection protection via Prisma ORM.
CSRF, XSS, and rate limiting protection on APIs.
HTTP security headers (CSP, HSTS, X-Frame-Options).
Isolated Docker containers with restricted privileges (no-new-privileges).
Automated daily encrypted backups with 30-day retention.
Restricted data access (principle of least privilege).
Under the General Data Protection Regulation (EU 2016/679), you have the following rights:
Right of access: obtain a copy of your personal data.
Right to rectification: correct inaccurate or incomplete data.
Right to erasure: request deletion of your data (right to be forgotten).
Right to restriction: temporarily restrict the processing of your data.
Right to data portability: receive your data in a structured, machine-readable format.
Right to object: object to the processing of your data on legitimate grounds.
To exercise these rights, write to our data protection officer at: [email protected], or by post at SECIVDA SAS, 12 place du Coq, 82000 Montauban, France.
We will respond to your request within a maximum of 30 days.
Your data is hosted exclusively on servers located in France (OVHcloud) and within the European Union.
The only processor located outside the EU is Stripe Inc. (United States), which ensures an adequate level of protection through Standard Contractual Clauses approved by the European Commission and its Data Privacy Framework (DPF) certification.
If you believe that the processing of your data does not comply with regulations, you may file a complaint with:
CNIL - Commission Nationale de l'Informatique et des Libertés
3 place de Fontenoy - TSA 80715 - 75334 Paris Cedex 07, France
https://www.cnil.fr
SECIVDA SAS - SIRET : 919 389 551 00012 - RCS Montauban
12 place du Coq, 82000 Montauban - TVA : FR49919389551