Skip to main content

Legal

Privacy policy

Coordinating a private stay means processing sensitive information: itineraries, physical measurements, preferences and habits. This policy sets out what is collected, why, for how long, and how to exercise your rights.

Last updated: 18 September 2026

This English text is provided for convenience only. The French version is the sole legally binding version; in the event of any discrepancy, the French text shall prevail.

01

Controller

The controller is BHM EXPORT, 82 rue Manin, 75019 Paris, France.

For any question about the processing of your data, or to exercise your rights, write to contact@praestantia-paris.com or to BHM EXPORT, 82 rue Manin, 75019 Paris, France. No data protection officer has been designated, as the nature and volume of processing do not require one within the meaning of Article 37 of the GDPR.

02

Data collected

Three categories of data are processed:

Identification data — title, surname, first name, email address, telephone number and, where applicable, the identity of any person you authorise to deal with the coordinator.

Engagement data — destinations, dates, the areas of expertise selected, the parameters of the brief, the itinerary, and the documents and correspondence relating to the file.

Sensitive profiling data — physical measurements, diets and food exclusions, habits, confidentiality requirements, itineraries. This data is collected only when the relevant area is activated, and only so far as performing the service requires.

03

Purposes and legal bases

Identification and engagement data are processed in order to take steps at your request prior to entering into a contract, and thereafter to perform that contract.

Sensitive profiling data is processed on the basis of your consent, obtained when the brief is configured. That consent can be withdrawn at any time from the settings in your client portal, without affecting the lawfulness of processing carried out beforehand.

Audit and connection logs are retained on the basis of the legitimate interests in securing the system and maintaining the traceability of operations.

04

Retention periods

A closed file is archived for the period set in the governance configuration, then deleted. Sensitive profiling data is purged automatically at the end of the inactivity period selected, independently of the retention of contractual documents.

Audit logs are retained for a defined period, at the end of which they are destroyed. The exact periods that apply are set out in the record of processing activities and will be provided to you on request.

05

Security

Communications are encrypted in transit. Sensitive profiling data is encrypted at rest using AES-256-GCM; access tokens are never stored in the clear.

Access to files is compartmented by role. Coordinators' internal operational notes are stored separately from the client file data and cannot appear in your client portal.

All sensitive operations — viewing, modification, access to a document, export, deletion — are recorded in an audit log whose integrity is protected by cryptographic chaining.

06

Recipients and processors

Your data is accessible to the coordinator assigned to your file and, where applicable, to the platform administrator.

Performing a service may require information to be passed to an operational contractor. Only the information strictly necessary to prepare and perform that service is provided. Access opened to a third party is time-stamped, limited to a defined scope, and expires automatically.

BHM EXPORT's processors are: Hostinger International Ltd, for hosting the site and for email; Neon, Inc., for the database, hosted in the Frankfurt region; Stripe, for card payments; Google, for advertising measurement, once you have consented. This list is kept up to date.

07

Hosting and transfers

The hosting infrastructure is located within the European Union. No data is transferred outside the European Union without appropriate contractual safeguards; where that occurs, details of the safeguards will be provided to you on request.

08

Your rights

You have the rights of access, rectification, erasure, restriction of processing, objection and data portability, together with the right — specific to French law — to give directions as to what becomes of your data after your death.

Two of those rights can be exercised directly from the settings in your client portal: a full export of your file in JSON and PDF formats, and the permanent deletion of your data.

You may also lodge a complaint with the competent supervisory authority.

09

Cookies

A session cookie, strictly necessary for the client portal to work, is set without consent — the regulation allows this for that purpose alone. It is protected against script access, restricted to this site, and expires when the session closes.

The site also uses one advertising measurement tag, to gauge how our campaigns perform. It loads only once you agree: until you accept, no third-party script is called and nothing is stored. Declining is as simple as accepting, and you may change your mind at any time from the footer.

No measurement data leaves this site before that consent.