Privacy • Transparency • User Control
Privacy Policy
Effective version: 26 August 2026
Language
This policy describes the main personal-data processing activities connected with KOM-5A on the Web and, where the same services are used, in the iOS and Android applications.
It does not replace specific information displayed when a particular action requires additional disclosures. Any service-specific notice must remain consistent with this policy.
1. Controller and contact details
- For the commercial operation of KOM-5A covered by this policy, the controller presented to users is Tarik Mohammedi, individual entrepreneur (EI), trading under the commercial name NOVAK, registered under SIREN 992 548 107 and with the Lisieux Commercial and Companies Register, France.
- Published business address: 40 Route Emile Renouf, Apt. 154, 14600 Honfleur, France.
- General contact: info@kom-5a.com. Privacy contact: privacy@kom-5a.com.
- KOM-5A is the platform and service name. Persons carrying out technical or operational work do so within the operation of the service and under the authorisations granted to them.
2. Categories of data we process
- Account and identity data: account identifier, email address, username, profile information and other information you provide voluntarily.
- Content and activity: posts, products, services, media, reactions, follows, reports, messages and metadata needed to operate the features you use.
- K5A and internal-service data: identifiers and information needed for awards, transfers, quotes, commands, activations, expirations, history and controls connected with K5A Services.
- Professional and billing data: company-profile information, selected offer, order or subscription identifiers, payment status and information needed to manage PRO and ADS.
- Technical and security data: IP address where processed by our services, timestamps, requests, errors, security events, abusive attempts and technical information needed for platform stability and protection.
- Notifications: user identifier, notification token, platform and, where supplied by the device flow, device identifier, app version and associated technical timestamps.
- Support and rights requests: content of support messages, privacy requests, complaints and information needed to handle them.
3. Purposes and legal bases
- Perform the contract and provide requested features: account, publishing, chat, K5A Services, PRO, ADS and other features activated by the user — performance of a contract or pre-contractual steps where the GDPR applies.
- Secure accounts, prevent fraud and abuse, protect infrastructure, diagnose incidents and defend the rights of KOM-5A and users — legitimate interests, subject to the rights and freedoms of individuals.
- Moderate content, handle reports, enforce platform rules and respond to legal duties — contract, legitimate interests and/or legal obligation depending on context.
- Manage billing, records, accounting, tax duties and requests from competent authorities — legal obligation and performance of a contract.
- Manage optional preferences or technologies where consent is legally required — consent, which may be withdrawn at any time without affecting prior lawful processing.
- Improve reliability and usability using information that may lawfully be used for that purpose — legitimate interest or consent where the relevant technology requires it.
4. Public content, user interactions and chat
- Information a user chooses to publish may be visible to other users or publicly, depending on the selected feature.
- Private messages are processed to deliver and display the conversation to the intended participants, operate the feature and address abuse or legal duties where necessary.
- Users should avoid publishing or sending unnecessary sensitive personal data or third-party personal data without an appropriate basis.
5. K5A and service evidence
- K5A is an internal service and participation unit. K5A operations and related services require information that can identify the user, action, service, quote or command, state and elements needed for integrity, reconciliation and evidence of the service.
- Where a service requires contractual acceptance, information needed to establish the applicable version, acceptance and evidence of the transaction may be retained for service performance and for legitimate legal or compliance needs.
- This policy does not turn K5A into external financial data or a promise of monetary conversion.
6. PRO / ADS payments and Stripe
- KOM-5A uses Stripe for certain payment, subscription and billing flows. Information necessary to create and manage the payment or subscription session may be communicated to Stripe.
- Where payment is completed through the Stripe interface, card data entered into that interface is processed by Stripe under its own legal obligations and policies. KOM-5A processes the identifiers, statuses and information returned that are necessary to manage the service.
- Accounting and supporting records are retained where French law requires a specific retention period, including for applicable accounting records.
7. Security, logs, moderation and automated processing
- KOM-5A uses technical controls, logs and security rules to protect accounts, detect anomalies, limit abuse and maintain the service.
- Automated or rule-based processing may support security, ranking, content rotation, eligibility or moderation. Its role remains limited to the function described for the relevant service and applicable legal duties.
- If a process were to constitute a solely automated decision producing legal or similarly significant effects under applicable law, the additional information and safeguards required by law would be provided before use.
- This policy does not claim that device fingerprints or specific technical data are sent to an artificial-intelligence system where that has not been materially established.
8. Cookies, local storage and preferences
- KOM-5A has a preference mechanism distinguishing necessary, preferences, analytics and marketing categories. Optional categories are presented as separate choices.
- The consent choice is stored locally in the browser with a version and timestamp so that the user preference can be remembered.
- Strictly necessary technologies may operate without consent where permitted by law. Optional technologies, where used and subject to consent, must respect the user choice.
- Technical details, purposes, durations and providers are described in the Cookies & Device Storage page when published and must remain aligned with actual behaviour.
9. Notifications
- If a user enables notifications, KOM-5A processes the tokens and technical metadata needed to send and manage them.
- Depending on channel and operating system, delivery may involve Apple, Google or Expo notification infrastructure.
- Invalid, disabled or replaced tokens may be deleted or disabled according to the service operation.
10. Recipients and service providers
- Authorised personnel or persons who need access to operate, secure or support the service.
- Clerk for authentication and account management where those functions are used.
- Stripe for relevant payment, subscription and billing flows.
- Google Cloud and infrastructure providers used to host or operate technical services.
- Apple, Google, Expo or other notification infrastructure when the user enables the relevant notifications.
- Professional advisers, specialist providers, authorities or courts where necessary, proportionate or legally required.
- Other users where the user chooses a feature involving publication, a transaction or communication with them.
- KOM-5A does not sell personal data as a standalone product to third parties.
11. International transfers
- Some providers may process data from several countries depending on the service, configuration and their infrastructure.
- Where a third-country transfer requires safeguards under the GDPR or Swiss FADP, the applicable mechanism depends on provider and destination: adequacy decision, appropriate contractual safeguards or another legally available mechanism.
- KOM-5A does not make a blanket statement that every transfer uses one single mechanism. Specific information available about providers and safeguards may be requested from privacy@kom-5a.com where required by law.
12. Retention
- Account, profile and content: for the time needed to operate the account and, after closure, for the period needed to close operations, meet legal duties or defend rights.
- Contracts, acceptances, K5A Services, subscriptions and commercial operations: for the time needed to perform and evidence the service, reconcile operations, handle complaints and comply with applicable limitation periods.
- Accounting records and invoices: for the period required by French accounting and tax law where applicable.
- Security logs: for a period proportionate to the security purpose, with longer retention possible for incidents, investigations, fraud, disputes or legal obligations.
- Notification tokens: while needed for the notification service or until invalidated, disabled or replaced, subject to legitimate security needs.
- Local preferences: until changed or cleared by the user, or until the preference version expires or is replaced.
- Where immediate deletion is not possible or legally appropriate, relevant data may be isolated, restricted, deleted or anonymised according to purpose and legal duties.
13. Account deletion
- KOM-5A provides an account-deletion path using the secured Clerk account centre for sensitive identity operations.
- Deleting the authentication account does not necessarily mean immediate erasure of every local record: certain data may be disabled, quarantined or retained where needed for security, fraud prevention, contractual evidence, accounting or other legal obligations.
- Data that no longer has a purpose or lawful retention basis must be deleted or anonymised in accordance with applicable rules.
14. Your rights
- Right of access and, where provided by law, to obtain a copy of personal data.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure in the circumstances provided by law.
- Right to restriction and right to object where the legal requirements are met.
- Right to data portability where the GDPR provides it.
- Right to withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint with the CNIL in France, the FDPIC in Switzerland or another competent supervisory authority, as applicable.
- KOM-5A may request information strictly necessary to verify identity before acting on a rights request.
15. Minors
- KOM-5A’s current product rule sets a minimum age of 16 for normal account creation and use, subject to mandatory rules that may apply.
- This product rule is separate from jurisdiction-specific thresholds governing consent to certain personal-data processing.
- If KOM-5A learns that an account or processing involving a minor does not comply with applicable requirements, appropriate measures will be taken, which may include restriction, verification or appropriate deletion.
16. Changes to this policy
- This policy has a fixed effective date. It is not deemed to change every day.
- Material changes are versioned and may be notified in-product or through another appropriate channel.
- An editorial correction must not be presented as a material change to rights or processing activities.
17. Contact and requests
- Privacy and rights requests: privacy@kom-5a.com.
- General questions: info@kom-5a.com.
- Legal questions: legal@kom-5a.com.
- To help us process a request, describe it precisely and avoid sending identity documents unless KOM-5A asks for them through a proportionate and secure process.
Policy version: PRIVACY-2026-08-26