Privacy policy
What we keep — almost nothing — and what you can do about it, at any time and without writing to us.
Last updated: 12 August 2026.
Details only the publisher can fill in
The identity of the data controller and the country where the data is hosted are not invented here. As long as they read “to be completed”, this policy remains incomplete with regard to articles 13 and 14 of the GDPR.
- Data controller (identity and address)
- to be completed
- Contact address for exercising your rights
- to be completed
- Data protection officer, if one has been appointed
- to be completed
- Country where the data is hosted
- to be completed
In short
- Checking water quality requires no account, and your searches never reach our servers: your browser queries Hub'Eau and the European Environment Agency directly.
- If you create an account, the only directly identifying piece of data we keep is your e-mail address.
- No advertising, no trackers, no resale and no sharing for commercial purposes.
- You can export all of your data and delete your account yourself, at any time. Deletion is immediate and final.
What we keep, and why
Only for people who create an account:
- E-mail address — to identify you when you sign in and to send you the alerts you asked for. It is the only directly identifying piece of data.
- Password — never kept as such: only an Argon2id fingerprint is stored, from which the password cannot be recovered. That is also why we cannot remind you of it, only let you choose a new one.
- Language and plan — so we write to you in your language.
- Saved places — a label you choose, the municipality, its INSEE code, the postcode and the distribution network. Never the street or the number: the municipality is enough to query Hub'Eau.
- Bathing sites followed — the identifier, name and coordinates of the public site; never yours.
- Alerts — their type, their target and the date of the last message, so we do not tell you the same thing twice.
- Sessions — a sign-in token kept in hashed form. Your IP address and your browser are kept only as a non-reversible fingerprint.
- Sign-in attempts — a non-reversible fingerprint of the IP address or of the targeted address, to slow down brute-force attacks.
- Links sent by e-mail — the fingerprint of the address confirmation or password reset link, its expiry date and whether it has been used.
What we never keep
- Name, surname, title, date of birth, telephone number.
- Precise postal address: the municipality is the finest granularity.
- Payment details: the member area is free and no payment is connected.
- A history of your searches: they do not go through our servers.
- IP addresses and browsers in the clear.
- Advertising cookies, third-party trackers, browser fingerprinting.
On what legal basis
Managing your account and sending alerts rest on the performance of the service you asked for (GDPR, article 6.1.b). Limiting sign-in attempts rests on our legitimate interest in protecting accounts (article 6.1.f).
No message is sent unless you asked for it, and every message carries an unsubscribe link that works in one click.
For how long
- Account and associated data: as long as the account exists.
- Sessions: 30 days at most, purged automatically on expiry, ten simultaneous sessions at most.
- Sign-in attempts: 24 hours.
- Password reset link: 1 hour, and it works only once.
- Address confirmation link: 24 hours, and it works only once.
- After account deletion: nothing. Erasure is physical and immediate, and it takes places, followed sites, alerts and sessions with it.
Cookies
A single cookie, named “akvido_sess”, set only when you sign in. It contains nothing but an opaque session token and is strictly necessary for the member area to work: as such, it does not require your prior consent.
No analytics, no third-party cookie, no advertising tracker. Signing out deletes this cookie.
Who receives your data
Nobody. Your data is neither sold, nor rented, nor passed on for commercial or advertising purposes.
E-mails are handed to the mail server that hosts the site's domain: no third-party sending provider is involved. The hosting country, shown at the top of this page, determines whether any transfer outside the European Union takes place; it must be specified by the publisher.
Your rights
They are exercised straight from your member area, without writing to us and without delay:
- Access and portability — the “Export my data” button returns your entire account as a JSON file.
- Rectification — you change your places, followed sites, alerts and password yourself.
- Erasure — the delete-account button erases everything, physically and immediately.
- Objection — you can switch off an alert, or use the unsubscribe link carried by every message.
The export contains neither your password fingerprint, nor your session tokens, nor the IP fingerprints: those are authentication secrets or non-reversible data.
You may also lodge a complaint with the French CNIL (www.cnil.fr) or with the data protection authority of your own country.
How your data is protected
- Passwords hashed with Argon2id: the plain password is never kept.
- Session tokens drawn at random and stored hashed; HttpOnly, Secure and SameSite cookie.
- Single-use e-mail links, hashed in the database and short-lived.
- Prepared statements throughout, and strict separation between members.
- Identical answers whether an address exists or not, so nobody can find out who is registered.
- A database account limited to Akvido's own database, with no right to alter its structure.
Minors
The service is not specifically aimed at minors and collects no information that would reveal the age of its members.
Changes
Any change to this policy is dated at the top of the page. A substantial change affecting registered members will be announced to them by e-mail.
See also: Legal notice