1. Controller and contact
The controller is Valentin Chmara, Entrepreneur individuel, SIREN 904 613 536, 457 route de Relevant, 01400 Châtillon-sur-Chalaronne, France. For privacy questions or to exercise your rights, contact valentin@telegram-finder.io. No data protection officer has been appointed.
2. Data we process, purposes, and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Account email, user ID, authentication and security data | Create and secure your account, authenticate you, provide support | Contract; legitimate interests in security and fraud prevention |
| Billing identifiers, plan, invoices, transaction status; card data is handled by Stripe | Take payment, administer purchases and subscriptions, accounting | Contract; legal obligations |
| Search inputs: phone numbers, emails, LinkedIn URLs, Telegram identifiers | Perform the enrichment or lookup requested | Contract with the user; where we act as controller, legitimate interests subject to the rights of the person searched |
| Saved contacts: names, company, location, identifiers, source, confidence and enrichment status | Provide contact management and enrichment features | Contract with the user; the user is responsible for its own legal basis for uploaded third-party data |
| Telegram account data: phone, username, Telegram ID, name, biography, status, last-seen data, verification, premium/scam indicators and technical access data | Return and maintain Telegram matching results; operate linked Telegram sessions where enabled | Contract; legitimate interests in providing accurate results |
| API keys, usage counters, timestamps, events, errors, IP address, browser/device and server logs | Operate the API, enforce quotas, diagnose errors, prevent abuse and secure the Service | Contract; legitimate interests in reliability and security |
| Feedback, support messages and waitlist email | Respond, improve the Service, or notify you about requested availability | Steps at your request; legitimate interests; consent where required for marketing |
| Anonymous analytics, including page activity, interactions, engagement, outbound links, scroll depth, coarse location, browser/device type, web vitals and errors | Measure and improve the website and Service | Legitimate interests in understanding and improving performance; consent only where applicable law requires it for a particular terminal operation |
Required account and payment fields are necessary to enter into or perform the contract. Without them, we cannot create the account or complete the purchase. Other fields are optional unless identified otherwise in the interface. We do not use personal data for solely automated decisions producing legal or similarly significant effects.
3. Data concerning people searched by our users
A user may submit data about another person. That data may come from the user, Telegram, LinkedIn-related input, or enrichment providers. Depending on the feature and circumstances, the user may be an independent controller and Telegram Finder may process the data on that user’s behalf, or Telegram Finder may act as controller for operating and securing the matching service. If you believe your data appears in the Service, contact us to obtain information, object, or request restriction or deletion. We may ask for proportionate evidence of identity and of the identifier concerned.
4. Recipients and processors
Access is limited to authorized persons and providers that need the data for the purposes above, including:
- Supabase — authentication, database and storage;
- Stripe — payments, billing, fraud prevention and subscription management;
- Vercel — website and server hosting, delivery and operational logs;
- Databuddy — cookieless, anonymous website analytics and performance measurement;
- Telegram — account connection and lookup features;
- Lemlist and Zeliq — contact enrichment where the relevant feature is requested.
We do not sell personal data. We may disclose data where required by law, to establish or defend legal claims, or during a business reorganization subject to appropriate confidentiality and data-protection safeguards.
5. International transfers
Some providers operate outside the European Economic Area, particularly in the United States. Transfers are protected, as applicable, by an adequacy decision (including the EU–US Data Privacy Framework for participating organizations), the European Commission’s Standard Contractual Clauses, and supplementary measures. Contact us for information about the safeguard relevant to a particular recipient and a copy of it, with commercially confidential information redacted where necessary.
6. Retention
- Account and saved-contact data: while the account is active, then deleted or anonymized after account closure, subject to backups and legal claims;
- Inactive accounts: reviewed and ordinarily deleted after two years of inactivity, after advance notice where practicable;
- One-off search and enrichment data: only for the time needed to return, secure and troubleshoot the result, unless the user saves it as a contact or it is required for fraud prevention;
- Telegram sessions and tokens: until revoked, disconnected, expired, or the account is deleted;
- Security, API and error logs: normally no longer than 12 months, unless needed to investigate an incident or legal claim;
- Anonymous analytics data: according to the Databuddy configuration and retention schedule, for no longer than 25 months;
- Support and complaint records: up to five years after closure of the request where needed to establish or defend claims;
- Invoices and accounting records: ten years to comply with French law;
- Consent or objection evidence: for the applicable limitation period.
Backup copies are isolated and deleted on the provider’s normal rotation schedule. Data may be retained longer where a legal hold applies.
7. Cookies and similar technologies
Strictly necessary storage supports authentication, security, payment flow and preferences and does not require consent. Databuddy does not set tracking cookies or create cross-site profiles. It processes anonymous usage events, immediately discards raw IP addresses after deriving country or region, and may use local or session storage for anonymous session operation. Any other non-essential terminal storage or access will be activated only after consent where required by Article 82 of the French Data Protection Act. Where consent is required, you can accept or refuse with equal ease and withdraw it at any time; refusal does not prevent access to the core Service.
8. Your rights
Subject to legal conditions, you have rights of access, rectification, erasure, restriction, objection (including to processing based on legitimate interests and at any time to direct marketing), and data portability. Where processing relies on consent, you may withdraw it at any time without affecting earlier processing. You may also define instructions concerning your data after death under French law.
Send a request to valentin@telegram-finder.io. We normally respond within one month. We may request only the information reasonably necessary to verify identity. You may lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with your local EEA supervisory authority.
9. Security
We use proportionate technical and organizational safeguards, including encrypted transport, access controls, authentication, database row-level controls, rate limiting, logging, and provider security measures. No system is completely secure; please protect your password, API key and Telegram session and report suspected compromise promptly.
10. Children and changes
The Service is not directed to children and accounts are restricted to adults. If we learn that a child provided data directly, we will take appropriate steps to delete it. We may update this Policy to reflect legal or operational changes. Material changes will be brought to account holders’ attention before they take effect where appropriate; the effective date above identifies the current version.