1. Introduction
This Privacy Policy explains how GetMyMFA ("we", "us", "our") collects, uses, discloses, and protects personal data when you use our website and services accessible at https://get.mymfa.io (the "Service").
We are a company established in France and process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable French data protection laws.
2. Data controller
The data controller responsible for processing your personal data is:
GetMyMFA 649 Rue Berthelot 10120, Saint-Germain France Email: hello@mymfa.io
3. Personal data we collect
3.1 Data you provide directly
We may collect the following personal data when you use the Service:
- Email address
- Name (where applicable)
- Account credentials
- Communications sent to us (support requests, emails)
3.2 Data collected automatically
When you access the Service, we may automatically collect:
- IP address
- Browser type and version
- Device identifiers
- Pages visited and usage logs
- Date, time, and duration of visits
This data is used strictly for security, performance monitoring, and service improvement.
4. Purposes and legal bases for processing
We process personal data only where a lawful basis exists under Article 6 GDPR:
- Performance of a contract: to provide and operate the Service
- Legal obligations: compliance with applicable laws
- Legitimate interests: security, fraud prevention, service improvement
- Consent: where required (e.g. optional communications)
We do not use personal data for purposes incompatible with those listed above.
5. Cookies and tracking technologies
We use strictly necessary cookies only, which are essential for the proper functioning and security of the Service.
No advertising or non-essential tracking cookies are used. Where this changes, we will request your consent in accordance with GDPR and ePrivacy rules.
6. Data sharing and recipients
We do not sell or rent your personal data.
Personal data may be shared only with:
- Authorized service providers acting as data processors (e.g. hosting, security services)
- Public authorities where required by law
All processors are bound by GDPR-compliant data processing agreements.
7. Data storage and international transfers
Personal data is primarily processed and stored within the European Union. Where transfers outside the EU occur (e.g. infrastructure providers), appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs) or equivalent lawful mechanisms.
8. Data retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Account data: for the duration of the account
- Usage and security logs: limited retention periods
- Legal obligations: as required by law
You may request deletion of your data at any time, subject to legal retention requirements.
9. Data security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption at rest and in transit
- Access controls
- Secure hosting infrastructure
While no system is completely secure, we continuously improve our safeguards.
10. Your rights under GDPR
You have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object
- Right to data portability
You may exercise your rights by contacting hello@mymfa.io. We will respond within one month, as required by law.
You also have the right to lodge a complaint with your local data protection authority, including the CNIL in France.
11. Children's data
Our Service is not intended for children under the age required by applicable law. In France, this age is 15 years, unless parental consent is provided.
We do not knowingly collect personal data from children without appropriate consent.
12. Third-party links
Our Service may contain links to third-party websites. We are not responsible for their privacy practices and encourage you to review their privacy policies.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Changes will be published on this page with an updated revision date. Where required by law, we will notify you of material changes.
14. Contact
For any questions regarding this Privacy Policy or personal data processing, contact:
GetMyMFA Email: hello@mymfa.io
This Privacy Policy is drafted to comply with GDPR and applicable French data protection law.