Capfineo
Privacy policy
Last updated : 10 September 2026
This document is a starting template whose structure follows the GDPR. It must be adapted to your actual processing activities and reviewed by legal counsel before publication.
This policy describes the data we collect, what we use it for and the rights available to you. It applies to the whole site and to our exchanges in the course of reviewing a financing application.
Data controller
The data controller is the company publishing this site, whose details appear in the legal notice. A dedicated address is provided for any question concerning your data.
Data collected
Identification and contact data (surname, first name, email, phone, address); project data (amount, term, purpose); situation data (employment status, income, housing); technical data strictly necessary for the operation and security of the site.
Purposes
To review your financing application, present it to the lending institutions you authorise, support you through to disbursement, answer your messages, and comply with our legal and regulatory obligations.
Legal bases
Your consent for the review of the application; performance of the contract for handling the file; compliance with legal obligations for retaining certain items; our legitimate interest in the security of the site.
Recipients
The lending institutions you expressly authorise, our technical providers acting on instruction, and the authorities where the law requires it. Your data is neither sold, nor rented, nor passed on for advertising purposes.
Retention periods
Application with no follow-up: 12 months. Completed file: the statutory period applicable to financing transactions, from the end of the relationship. Contact messages: 24 months.
Your rights
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time. A request sent to our privacy contact is handled within 30 days. You may also refer the matter to the competent supervisory authority.
Cookies
This site uses only the cookies strictly necessary for it to work — notably the session and cross-site request forgery protection. No advertising cookie or third-party tracker is set, and no font is loaded from an external server.
Security
Encrypted transport, compartmentalised access, logging of file consultations, and minimisation of the data collected.