Last updated: May 17, 2026
This policy describes how Trublion processes personal data collected in the context of the Trublion Service, which includes:
Trublion, a simplified joint-stock company with a share capital of 4,000 euros, registered with the Paris Trade and Companies Register under number 102 547 221, with its registered office at 15 cité Falguière, 75015 Paris, is the controller of personal data collected via the surfaces described in the introduction.
General contact: contact@trublion.co Personal data contact: dpo@trublion.co
Trublion has not formally designated a Data Protection Officer (DPO) within the meaning of Article 37 of the GDPR, as it is not required to do so. The function of data protection contact point is fulfilled by the legal representative, reachable at dpo@trublion.co.
The Trublion mobile application is designed to operate without account creation and without collection of identity. The following data is collected:
Aggregated usage statistics (for example, the total number of views of a publication, without any link to an identified device) may be calculated for audience measurement and Service improvement purposes. These statistics do not allow the identification of any particular reader.
No email address, no telephone number, no surname, and no directly identifying data are collected from readers.
The following data is collected in the context of the contractual relationship:
Trublion carries out commercial prospecting activities targeting independent bookshops that are not yet clients. In this context, the following data is collected from public sources (websites, professional directories):
These data concern legal entities and generic professional contact details. They are subject to specific processing as described in section 3.
| Purpose | Data subjects | Legal basis |
|---|---|---|
| Operation of the Service (display of publications, subscriptions, favourites, feed) | Readers | Performance of contract (Art. 6.1.b GDPR) |
| Transmission of the reader's first name to the bookshop for book interest notifications | Readers and booksellers | Performance of contract (Art. 6.1.b GDPR) |
| Sending push notifications | Readers | Consent (Art. 6.1.a GDPR) |
| Authentication and access to the bookseller web application | Booksellers | Performance of contract (Art. 6.1.b GDPR) |
| Billing, direct debit, debt collection | Booksellers | Performance of contract and legal obligation (Art. 6.1.b and 6.1.c GDPR) |
| Retention of contractual consent evidence | Booksellers | Legal obligation (Art. 6.1.c GDPR) |
| Security, fraud prevention, audit | Readers and booksellers | Legitimate interest (Art. 6.1.f GDPR) |
| Anonymised usage statistics | Readers and booksellers | Legitimate interest (Art. 6.1.f GDPR) |
| B2B commercial prospecting targeting independent bookshops | Prospective booksellers | Legitimate interest (Art. 6.1.f GDPR), with immediate right to object |
| Processing of content reports | Reporters and booksellers | Legal obligation (Art. 6.1.c GDPR, Articles 16 and 17 of the Digital Services Act) |
Personal data is neither sold, nor transferred, nor used for third-party advertising purposes. It may be disclosed to the following recipients:
| Sub-processor | Role | Location |
|---|---|---|
| Scalingo SAS | Application hosting and PostgreSQL database | France (region osc-fr1, sovereign infrastructure) |
| Mollie B.V. | Payment provider and SEPA mandate management | Netherlands (EU) |
| Brevo (Sendinblue SAS) | Sending of transactional emails (magic link, notifications, invoices) | France and European Union |
| WonderPush SAS | Sending push notifications to readers | France |
| Plausible Analytics | Audience measurement without cookies or personal data | European Union (Estonia) |
| MaxMind | GeoLite2 database (IP-to-region resolution), downloaded locally to Trublion servers | No data transfer |
Each sub-processor is bound to Trublion by a data processing agreement compliant with Article 28 of the GDPR.
Trublion may be required to disclose data to public or judicial authorities in the context of legal requests (request from the judicial authority, from the authority competent under the Digital Services Act, namely Coimisiún na Meán (Ireland's Digital Services Coordinator under the DSA), from the supervisory authority competent under the GDPR, namely Data Protection Commission (DPC, Ireland), or from the tax authorities).
The first name provided by a reader when notifying their interest in a book is transmitted to the relevant bookshop, solely for the purpose of informing the bookshop in view of a possible visit by the reader to the shop. This transmission takes place in the context of the performance of the contract concluded between Trublion and the reader (Article 6.1.b of the GDPR). It does not constitute a reservation, an order, or any contractual commitment between the reader and the bookshop.
All data is hosted and processed within the European Union. No structural transfer outside the EU takes place in the context of the Service.
In accordance with the General Data Protection Regulation (GDPR), every individual has the following rights:
As the application is designed to operate without identification, readers exercise their rights via a dedicated form accessible at /suppression-donnees or by email to dpo@trublion.co. Readers are invited to provide the technical identifier of their device (available in the application settings) so that Trublion can identify the relevant data. In the absence of this information, Trublion may be materially unable to process the request, in accordance with Article 11 of the GDPR.
Booksellers may exercise their rights directly from the bookseller web application (export, rectification) or by email to dpo@trublion.co. Upon termination of the contract or at the bookseller's request, Trublion proceeds with the anonymisation of the bookseller's data: the email address and telephone number are deleted, the trade name is replaced by a generic label, and the bookshop's status is set to "closed". Invoices are retained due to the legal obligation to maintain accounting records (10 years).
Independent booksellers listed in the Trublion database for prospecting purposes or for presentation within the bookseller community (non-client booksellers whose profile may be publicly displayed with minimal content) may at any time request the removal of their profile and all data relating to them. This request may be submitted via the "Request deletion" link present on each relevant profile, or by email to dpo@trublion.co. This objection is exercised pursuant to Article 21 of the GDPR and results in the deletion of the profile and the cessation of all prospecting communications as soon as possible.
Any person who considers that their rights are not being respected may lodge a complaint with the competent supervisory authority, namely Data Protection Commission (DPC, Ireland), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland, dataprotection.ie. Such a complaint may also be addressed to the supervisory authority of the European Union Member State in which the person resides, works, or believes the infringement has occurred, in accordance with Article 77 of the GDPR.
The trublion.co website uses only cookies that are strictly necessary for the operation of the Service (bookseller authentication session, language cookie). These cookies do not require the collection of prior consent.
No advertising cookies or profiling trackers are placed by Trublion. Certain providers integrated into the Service (in particular WonderPush for push notifications, or Mollie for the payment page) may place their own cookies on their respective domains, in accordance with their own privacy policies.
Upon first opening the application, the reader's IP address is read on a transient basis in order to suggest bookshops in their region. The resolution relies on a GeoLite2 database (MaxMind) downloaded to Trublion's servers, without any call to a third-party service concerning the reader. The IP address is neither retained nor associated with a device identifier.
The reader may at any time enable precise geolocation from their phone settings in order to benefit from distance-based sorting. This choice may be revoked at any time.
Trublion implements appropriate technical and organisational measures to protect data: encryption of communications (HTTPS / TLS), magic link authentication with no stored password, restricted access to the database and logging of administrator access, sovereign hosting in France with Scalingo, regular database backups.
In the event of a data breach likely to result in a risk to the rights and freedoms of the individuals concerned, Trublion will notify the competent supervisory authority, namely Data Protection Commission (DPC, Ireland), within 72 hours in accordance with Article 33 of the GDPR, and will where applicable inform the individuals concerned in accordance with Article 34.
Trublion reserves the right to amend this policy. Material changes are brought to the attention of booksellers via the bookseller web application (re-consent banner). For readers, minor changes take effect upon publication; material changes are communicated within the application where technically possible.
Previous versions are archived by Trublion for evidentiary purposes.
Automatic translation. In case of discrepancy, the French version shall prevail.