Privacy policy

Last updated: 22 July 2026

This policy explains how ABA-INSTITUT (SAS, 47 route de la Grange aux Moines, 78460 Choisel, France — "we") processes personal data in connection with the Watch'n'Learn service: the watchnlearn.eu website, the web application and the iOS application ("the Service"). It applies in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).

Data controller: ABA-INSTITUT — contact: caroline@abainstitut.fr.

What data do we process?

Your account. Email address, username, password (stored only in hashed form — we never know your password), chosen language, subscription plan and access end date.

The children you work with — first names only. You can create child profiles to track their progress. We apply strict data minimisation: only a first name or nickname is accepted — the Service rejects and never stores a surname. For each child we record that first name, the list of chosen work series and exercise results (number of attempts and stars). No photos, videos, dates of birth or any other information about the child are collected. This data is visible only to the account holder, is never shared or sold, and is never used for profiling or advertising.

Payment. Payments are processed by Stripe. Your card number never passes through our servers; we keep only the Stripe customer ID, the chosen plan and the subscription status.

Technical data. Server logs from our hosting provider (IP addresses, timestamps), for security and to keep the Service running properly.

Why, and on what legal basis?

ProcessingLegal basis
Account, access to series, tracking children's progressPerformance of the contract
Billing and accountingLegal obligation
Transactional emails (welcome, password reset)Performance of the contract
Security, abuse prevention, technical logsLegitimate interest

Children's data is entered by the parent or professional working with them, under that adult's responsibility; it is used only to show them the child's progress.

Who handles this data?

We use the following processors, each bound by a data processing agreement:

  • Vercel Inc. (United States) — application hosting;
  • PingCAP / TiDB Cloud — database, hosted in the European Union (Frankfurt, Germany);
  • Stripe — payments and billing;
  • Resend — sending transactional emails;
  • Cloudflare — delivery of teaching content (exercise images, sounds and videos), which contains no personal data.

Where a processor is located outside the European Union (United States), the transfer is covered by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. No data is sold or passed to third parties for advertising purposes.

How long do we keep it?

  • Account, child profiles and progress: deleted immediately when you delete your account ("Delete my account" button on the Account page), and no later than 2 years after your access ends (end of a subscription or of an unrenewed trial).
  • Billing data: kept for 10 years, as required by French accounting rules.
  • Technical logs: a short period set by the hosting provider (a few weeks).

Cookies and local storage

The Service uses no advertising, analytics or tracking cookies — which is why there is no cookie banner. Only the following are used:

  • a strictly necessary session cookie (wnl_token) to keep you signed in;
  • your browser's local storage for offline use (downloaded content, preferences, sync queue).

Stripe's payment pages, on Stripe's own domain, apply Stripe's cookie policy.

Your rights

You have the rights of access, rectification, erasure, portability, restriction and objection over your data.

  • Immediate erasure: use "Delete my account" on the Account page — the account, child profiles and all progress are permanently deleted and any subscription is cancelled.
  • Other requests: write to caroline@abainstitut.fr; we reply within one month at most.
  • You can lodge a complaint with the CNIL (cnil.fr) or, in the Netherlands, with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Security

End-to-end encrypted connections (HTTPS), hashed passwords (bcrypt), a session cookie inaccessible to scripts (httpOnly), and restricted database access hosted in the European Union. In the event of a data breach likely to pose a risk to your rights, we will notify the CNIL within 72 hours and inform you in accordance with the GDPR.

Changes

We may update this policy; the date of the last update appears at the top of the page. If we make a substantial change, users will be informed in the application or by email.