Version: v2026-03
Effective: March 2026
1. Data Controller
The website https://labo-rnp.com and the member area are operated by:
LABO RNP, simplified joint-stock company (SAS), share capital €3,000
Registered office: 31 B Rue de Lorquin, 57400 Imling, France
Registration: RCS Metz — SIREN 951 755 750
GDPR contact: admin@labo-rnp.com
Legal representative: Adrien Chartier
2. Data Collected
2.1 Data provided via website forms
When you fill out the forms on the website (contact, assessment request, appointment request, newsletter signup), LABO RNP collects and processes the following information:
- your first and last name,
- your email address,
- your phone number,
- and the content of the message or information you choose to provide in the free text field.
This data is used exclusively to:
- respond to your requests and organize the necessary follow-up,
- plan and ensure the follow-up of services offered by LABO RNP,
- improve the quality of service and user relations.
Some information freely provided in the free text field may contain elements relating to your physical condition or well-being. This information is only processed with your explicit consent and solely to organize the requested assessment.
Mandatory or optional: providing your name and email address is necessary to process your request. Phone number and message content are optional. Without the mandatory data, we will not be able to follow up on your request.
2.2 Data provided by members
When you create an account on the LabO RNP member area, the following additional data is collected:
| Category | Data | Collection moment |
|---|---|---|
| Identity | First name, last name, email | Registration (magic link) |
| Professional profile | Profession, organization, city, specialties, therapeutic approach | Conversational onboarding |
| Contact details | Phone number | Member profile (optional) |
| Goals | Motivations, training objectives | Onboarding |
| Community | Messages, suggestions, published comments | Community space |
Mandatory or optional: only the email address is required to create an account (magic link authentication). All other data (professional profile, phone, objectives) is optional and can be provided gradually. You can use the member area without completing your profile, but some personalization features will be limited.
2.3 Automatically collected data
On the public website:
When browsing the site, LABO RNP uses Plausible Analytics (hosted in France by UBM Studio) to measure audience. Plausible does not set any cookies, does not collect any personally identifiable data, and does not track users across websites. The data collected is exclusively aggregated: pages visited, traffic source, device type, country.
On the member area:
| Category | Data | Purpose |
|---|---|---|
| Progress | Completed modules, scores, time spent, attempts | Training follow-up |
| Activity | Pages viewed, scroll depth, reading time | Content improvement |
| Engagement | XP, level, badges, streaks, completed quests | Gamification |
| AI Conversations | Text messages exchanged with the assistant | Path personalization |
| Notifications | Preferences (in-app, push, email) | Communication |
| Bookmarks | Saved articles, personal notes | Quick access to content |
2.4 Personalizing your experience
To provide you with the best possible learning experience, the member area uses certain information derived from your activity:
| What we do | How it works | What it brings you |
|---|---|---|
| Your personalized profile | We structure the professional information you share in your exchanges with the assistant (profession, specialties, goals) | A training path adapted to your practice |
| Assistant memory | The assistant remembers your progress and preferences | More relevant answers, without having to repeat yourself |
| Engagement tracking | We measure your overall activity (logins, modules followed) to better understand your journey | Support adapted to where you are |
2.5 Voice data
When you use the voice input feature in the member area, your audio recording is transmitted to OpenAI (Whisper) for text transcription. The audio recording is not stored on our servers or by OpenAI beyond immediate processing.
3. Purposes and legal bases
3.1 Public website
| Purpose | Legal basis | Details |
|---|---|---|
| Responding to contact requests | Pre-contractual measures (Art. 6.1.b) | Contact forms, assessment and appointment requests |
| Sending newsletters | Consent (Art. 6.1.a) | Voluntary newsletter subscription |
| Audience measurement | Legitimate interest (Art. 6.1.f) | Plausible Analytics — exempt from consent (CNIL) |
3.2 Member area
| Purpose | Legal basis | Details |
|---|---|---|
| Member account management | Contract (Art. 6.1.b) | Creation, authentication, account management |
| Training follow-up | Contract (Art. 6.1.b) | Progress, completions, XP, levels |
| Transactional emails | Contract (Art. 6.1.b) | Magic link, confirmations, account notifications |
| Bookmarks and notes | Contract (Art. 6.1.b) | Content saved by the member |
| Quests and tasks | Contract (Art. 6.1.b) | Learning path gamification system |
| Community | Contract (Art. 6.1.b) | Publishing and interacting in the community space |
| In-app notifications | Contract (Art. 6.1.b) | Alerts and updates |
| AI Library (RAG) | Contract (Art. 6.1.b) | Semantic search in training content |
| Appointment booking | Contract (Art. 6.1.b) | Booking and follow-up |
| Marketing emails | Consent (Art. 6.1.a) | Newsletters, promotional offers |
| Email sequences | Consent (Art. 6.1.a) | Automated email paths |
| Push notifications | Consent (Art. 6.1.a) | Browser notifications |
| Engagement tracking | Legitimate interest (Art. 6.1.f) | Better understand your journey to adapt support |
| Follow-up coordination | Legitimate interest (Art. 6.1.f) | Ensure continuity across our tools |
| Profile personalization | Legitimate interest (Art. 6.1.f) | Adapt content to your professional practice |
| Assistant memory | Legitimate interest (Art. 6.1.f) | Allow the assistant to remember your context |
| Content improvement | Legitimate interest (Art. 6.1.f) | Identify the most useful content through reading metrics |
| Progressive path | Legitimate interest (Art. 6.1.f) | Unlock advanced content as you progress |
| Email quality | Legitimate interest (Art. 6.1.f) | Measure whether our emails are useful to you (opens, clicks) |
4. How we personalize your experience (Art. 22)
To provide you with the best possible learning and practice experience, the member area adapts to your profile and progress. Here's what that means concretely:
| What we do | How | What it changes for you |
|---|---|---|
| Adapt support | We measure your overall engagement (logins, modules followed, time spent) to know where you stand | You receive suggestions and support adapted to your pace |
| Personalize your path | The assistant retains your professional information (profession, specialties) shared in your exchanges | Content and recommendations match your practice |
| Remember your context | The assistant generates a summary of your progress so it doesn't start from scratch each time | More relevant answers, without having to repeat yourself |
What it does NOT do: these processes do not make any decisions on your behalf and have no legal effect. All members have exactly the same access to the platform, regardless of their engagement level. The sole purpose is to adapt the experience to be as useful as possible for you.
You stay in control: you can disable personalization at any time in Settings > Privacy > Disable personalization. Your member area will continue to work normally, without automatic adaptation.
5. Data recipients
Collected data is intended solely for LABO RNP's internal teams, for request follow-up and service organization.
It is neither sold nor shared with third parties for commercial purposes.
It may, where appropriate, be communicated to the following technical service providers, acting on behalf of LABO RNP:
| Processor | Role | Data concerned | Location |
|---|---|---|---|
| Supabase (AWS) | Hosting, database, authentication | All member data | EU (AWS eu-west, Ireland) |
| Resend | Email delivery | Email address, email content | USA (SCCs) |
| OpenAI | AI assistant, voice transcription, embeddings | Messages, voice recordings (transit) | USA (DPA, zero-retention) |
| Orion CRM | Customer relationship management, booking | Profile, phone, follow-up notes | France |
| LearnyBox | Training sync | Member profile | France |
| UBM Studio | Training sync | Member profile | France |
| Vercel | Frontend hosting | Navigation data | USA (HQ) / EU (hosting) — SCCs |
| Plausible Analytics (via UBM Studio) | Audience measurement | Pages visited, referrer, device (aggregated) | France |
| n8n | Workflow automation | Behavioral scoring data | Self-hosted (France) |
For transfers to the United States, Standard Contractual Clauses (SCCs) or Data Processing Agreements (DPAs) are in place in accordance with Chapter V of the GDPR.
6. Retention periods
6.1 Public website data
| Data type | Duration | Trigger |
|---|---|---|
| Contact forms | 730 days (2 years) | Submission date |
| Navigation data (Plausible) | Aggregated only | No individual data |
In case of a completed service, data necessary for contract execution and administrative follow-up is retained for the applicable legal period (five years for civil and accounting liability).
6.2 Member data
| Data type | Duration | Trigger |
|---|---|---|
| Member account and profile | Activity duration + 2 years | Last login |
| Training progress | Activity duration + 2 years | Last login |
| Transactional emails | 1 year | Send date |
| Marketing consent | Until withdrawal | Member action |
| Personalization data (profile, memory, engagement) | Activity duration | Account deletion or personalization opt-out |
| Reading metrics | Activity duration | Account deletion |
| Email statistics | 1 year | Send date |
| Voice data | Not stored | Immediate processing |
7. Your rights
In accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act of January 6, 1978 (amended), you have the following rights:
7.1 Website visitors
| Right | How to exercise it |
|---|---|
| Access (Art. 15) | By email to admin@labo-rnp.com |
| Rectification (Art. 16) | By email to admin@labo-rnp.com |
| Erasure (Art. 17) | By email to admin@labo-rnp.com |
| Objection (Art. 21) | By email to admin@labo-rnp.com |
7.2 Member area members
| Right | How to exercise it |
|---|---|
| Access (Art. 15) | Settings > Privacy > Export my data |
| Rectification (Art. 16) | Settings > Profile (direct modification) |
| Erasure (Art. 17) | Settings > Danger zone > Delete my account |
| Restriction (Art. 18) | Settings > Danger zone > Deactivate my account |
| Portability (Art. 20) | Settings > Privacy > Export (JSON format) |
| Objection to personalization (Art. 21) | Settings > Privacy > Disable personalization |
| Marketing consent withdrawal | Settings > Notifications > Marketing toggle OR unsubscribe link in each email |
You can also exercise your rights by email to admin@labo-rnp.com. A response will be provided within a maximum of one month (Art. 12.3).
In case of dispute, you can file a complaint with the CNIL:
- Online: https://www.cnil.fr/fr/plaintes
- By mail: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
8. Member account deletion
Deleting your account follows a two-phase process:
- Deletion request: your events and community contributions are anonymized immediately (identifier removed). Your account is deactivated.
- 30-day grace period: you can cancel the deletion from the login page. After this period, all your data is permanently deleted (hard delete).
Permanent deletion covers: profile, progress, events, conversations, bookmarks, notifications, badges, push subscriptions, quests, reading history, and the authentication account.
9. Cookies and trackers
| Cookie/tracker | Purpose | Legal basis | Duration |
|---|---|---|---|
sb-* (Supabase) | Authentication session | Contract | Session |
theme | Theme preference (light/dark) | Contract | 1 year |
| Plausible Analytics | Audience measurement | Legitimate interest | No cookie set |
Plausible Analytics is a privacy-friendly audience measurement solution. It does not set any cookies, does not collect any personally identifiable data, and does not track users across websites. The instance is hosted in France by UBM Studio. In accordance with CNIL recommendations, Plausible can operate without prior consent as it is configured in consent-exempt mode (no cookies, no fingerprinting, aggregated data only).
No advertising or third-party tracking cookies are used.
10. Data security
LABO RNP implements appropriate technical and organizational measures to protect your data against loss, misuse, unauthorized access, or disclosure:
- Encryption in transit (TLS/HTTPS) and at rest (AES-256 via AWS)
- Per-user data isolation (Row Level Security)
- Passwordless authentication (magic link) — no password storage
- Email verification for account deletion
- Automatic purge of deleted accounts
- Only authorized personnel within the company can access data as part of their duties
11. Changes to this policy
This privacy policy may be modified to reflect changes in regulations or LABO RNP practices. The update date is indicated at the top of the page.
Any substantial modification will be communicated to members by email and/or in-app notification. In case of a major change in required consent, a new acceptance will be requested upon your next login.
The current version is always available on this page.
Last updated: March 2026 — Version v2026-03
