seedling

Privacy Policy

Last updated: 19 April 2026

1. Who is the data controller

The data controller for Seedling is Sébastien Tang, a French micro-entrepreneur (SIREN 898 194 394) operating the service at useseedling.com from 69 avenue du Général Leclerc, 95250 Beauchamp, France. Contact: [email protected].

This Policy describes how we collect, use, and protect your personal data when you use Seedling. It applies alongside the Terms of Service.

2. Applicable law

Because the controller is established in France, processing is primarily governed by the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés). The French data-protection authority (CNIL) is our lead supervisory authority. If you are a resident of the Republic of Korea, we additionally respect the spirit of the Korean Personal Information Protection Act (PIPA) as a courtesy where it grants you stronger rights than GDPR.

3. What we collect

4. What we do not collect

We do not use tracking cookies, third-party analytics, or advertising pixels. The only cookie Seedling sets is a session cookie required to keep you signed in.

5. Legal bases (GDPR)

6. Sub-processors

We share the minimum data necessary with the following sub-processors:

We select sub-processors who provide adequate contractual and technical safeguards. We do not sell your personal data to anyone.

7. Your rights

Under PIPA and GDPR you have the right to:

To exercise any of these rights, email [email protected]. We respond within 30 days.

8. Data retention

9. International transfers

Because our sub-processors operate globally, your data may be transferred outside the European Economic Area. Where that is the case, transfers rely on Standard Contractual Clauses approved by the European Commission, on an adequacy decision covering the destination country, or on the sub-processor's binding corporate rules. Data transfers to the United States rely on the EU–US Data Privacy Framework where the sub-processor is certified.

10. Security

We protect your data with TLS in transit, encryption at rest for sensitive fields (GitHub Personal Access Tokens via AES-GCM), rate-limiting on authentication and signup endpoints, and the principle of least privilege for operator access. We regularly update dependencies and patch known vulnerabilities. No system is perfectly secure; if we discover a breach affecting your personal data, we will notify you without undue delay, and in any event within 72 hours as required by GDPR where applicable.

11. Children

Seedling is not directed to children under 16 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

12. Changes to this Policy

We may update this Policy. Material changes will be announced by email to active subscribers at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the current version.

13. Contact

Questions, requests, complaints? [email protected].