European compliance

GDPR & data protection

Last updated: 18 May 2026

This page complements our privacy policy by detailing Bourselo's compliance with the General Data Protection Regulation (EU Regulation 2016/679, "GDPR") and the Swiss Federal Act on Data Protection (FADP / nLPD) applicable to the site publisher Infinity Aurora Sàrl, whose registered office is located in Chambésy (Geneva).

1. Applied principles

2. Register of processing

ProcessingPurposeLegal basisRetention
Waiting list / pilot application Project follow-up, pilot selection, product communication Consent (Art. 6.1.a) 3 years after last contact
Project email delivery Inform subscribers of progress and launches Consent As long as subscription is active
Open/click stats (Brevo) Measure engagement, improve messaging Legitimate interest + transparency 13 months

3. Processors and transfers

Bourselo relies on two identified processors, chosen for their European compliance:

3.1 Brevo (Sib SAS)

3.2 Infomaniak Network SA

No data transfer to a third country outside the EU or Switzerland is performed.

4. Cookies and trackers

The Bourselo site uses no advertising cookies, no external analytics tracker (no Google Analytics, no Facebook Pixel) and no profiling tools.

No cookie banner is needed because no non-essential cookie is placed on your browser.

5. Data security

6. Data breach procedure

In case of a data breach likely to result in a risk to your rights and freedoms, Infinity Aurora commits to:

7. How to exercise your rights

For any request — access, rectification, deletion, portability, objection or withdrawal of consent:

Email: bonjour@bourselo.fr

Suggested subject: "GDPR request — [your name]"

We respond within a maximum of 30 days (extendable by 2 months for complex requests, with prior notice).

8. Related documents

Bourselo is a young project and we take data protection very seriously. If anything in this document raises a question, please reach out — we always reply.