Privacy Policy
Estos documentos se publican en inglés, versión que prevalece. Las traducciones están en preparación.
This policy explains how REACH TECHNOLOGIES SAS ("1st Minute Lead", "we") processes personal data as data controller: data of visitors to our websites, of the persons who create and manage a client account, and of prospects.
It does not cover the data of Leads (persons who submit a form on a Client's website) or of Advisors invited to an account: that data is processed by 1st Minute Lead on behalf of the Client, as processor, under the Data Processing Agreement. For any request concerning your data as a Lead, contact the company whose website you visited; we forward to the relevant Client any request we receive directly (see §9).
1. Controller and contact
REACH TECHNOLOGIES SAS, 1 rue du Quai, 59800 Lille, France — SIREN 953 284 296.
- Privacy: privacy@1stminutelead.com
- Data Protection Officer (DPO): dpo@1stminutelead.com
2. Data we process and why
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Browsing on 1stminutelead.com | Technical server logs (truncated IP, requested pages, user agent) | Legitimate interest (security, operation) | 12 months |
| Account creation and management | First and last name, professional email, company name, country, website URL, interface language, password (stored hashed) | Contract (Terms of Use) | Life of the account + 30 days after closure |
| Email verification and security | Email, verification codes, sign-in events | Contract; legal obligation (security) | Life of the account |
| Billing and subscription | Billing identity, email, plan, invoices; card data is entered directly with Stripe and never touches our servers | Contract; legal obligation (accounting) | 10 years (accounting documents) |
| Transactional and service emails | Email, first name (verification, password reset, invitations, quota and trial notifications, onboarding tips during setup) | Contract; legitimate interest for setup tips (opt-out available) | Life of the account |
| Support and contact | Email exchanges with contact@1stminutelead.com or support@1stminutelead.com | Legitimate interest (answering you) | 3 years after last contact |
| Feature waitlist | Email, name, feature of interest, interested yes/no (collected in-app when you express interest in an upcoming feature) | Consent | 3 years or until withdrawal |
| Product usage analytics | See §3 | Legitimate interest (improving the product) | 180 days (events), 90 days (error reports) |
We do not sell personal data, we do not run third-party advertising trackers, and we send no marketing emails without a legal basis to do so.
3. Product usage analytics
The application (app.1stminutelead.com) and the "One Minute Lead" mobile application send first-party usage statistics to our own infrastructure — no third-party analytics SDK is embedded.
- What is recorded: named product events (e.g. "lead claimed", "page viewed"), screen/route, app version, operating system, language, a random device identifier and a session identifier, plus technical error reports.
- What is never recorded: the content of Leads (no name, email, phone or message of a Lead in analytics events — only internal identifiers), and full IP addresses: the IP is truncated on arrival (last byte removed in IPv4, /48 in IPv6) before storage.
- Retention: raw events are automatically purged after 180 days, error reports after 90 days.
4. Cookies and local storage
Details, including the storage used by the Script on Clients' websites, are given in the Cookie Policy. In summary:
4.1 Our own sites
- 1stminutelead.com (showcase site): no advertising or analytics cookie; at most a functional cookie storing your language preference.
- app.1stminutelead.com (application): an authentication cookie (
oml_token, essential), a random analytics device identifier inlocalStorage(oml_aid) and a session marker insessionStorage— all first-party, as described in §3.
4.2 The Script on Clients' websites
The Script places no cookie on visitors' devices. It keeps a browsing journal of the current visit in sessionStorage (erased when the tab closes), limited to the Client's website, and integrates with the Client's consent banner. This processing is carried out on behalf of the Client — see the DPA and the template Lead Information Notice.
5. Recipients and transfers
Data is accessed only by the authorized staff of Reach Technologies and by the providers listed on the Subprocessors page, each for its own function: hosting in France (Hostinger), payments (Stripe), transactional emails (Resend), mobile push notifications (Expo) and, for accounts with the Scoring module enabled, language-model providers (Groq, Anthropic).
The application infrastructure and the database are located in France. Some ancillary providers are located in the United States; those transfers are governed by the safeguards of Chapter V of the GDPR (adequacy decision — EU–US Data Privacy Framework — or standard contractual clauses), as detailed on the Subprocessors page.
6. Retention
Retention periods are listed per processing in §2. When you close your account (or when it is terminated), account data is kept for thirty (30) days — allowing reactivation and the handling of disputes — then permanently deleted; Lead Data follows the return-and-deletion terms of the DPA. Data subject to a legal retention obligation (invoices) is archived for the legal period only.
7. Security
Access to the Platform is protected by individual accounts and hashed passwords (bcrypt); sessions use signed tokens; all traffic is encrypted in transit (TLS); the database is not exposed publicly; access to production is restricted to authorized staff using key-based authentication. Web Call streams are encrypted end to end by WebRTC (DTLS-SRTP) and are neither recorded nor stored.
In the event of a personal data breach likely to result in a risk to your rights, we will notify the CNIL and, where required, the persons concerned, within the regulatory time limits.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection provided by the GDPR, and the right to define directives on the fate of your data after death (French Data Protection Act).
- By email: privacy@1stminutelead.com (or dpo@1stminutelead.com)
- We reply within one (1) month, extendable by two (2) months for complex requests.
- You may lodge a complaint with the CNIL (cnil.fr), the French supervisory authority.
9. Requests from Leads
If you submitted a form on a website using 1st Minute Lead and wish to exercise your rights, the data controller is the company whose website you visited. Any request received directly by 1st Minute Lead is forwarded to that company without delay, and we assist it in responding to you, in accordance with the DPA.
10. Changes
We may update this policy, in particular when features or providers change. The date and version at the top of this page identify the current version; material changes are notified to account holders by email.
This document is published by Reach Technologies SAS. For any question: contact@1stminutelead.com.
See also: Legal Notice · Terms of Use · Terms of Sale · DPA · Cookies · Subprocessors