Privacy

Privacy policy

This policy explains how Piano Académie handles personal data through its client and teacher portals, mobile applications and related services.

Effective and last updated: 7 August 2026

1. Who is responsible for your data?

The main controller is PIANO ACADEMIE, a French simplified joint-stock company (SAS), SIREN 828 051 417, SIRET 828 051 417 00032, whose registered office is at 1 rue de Richelieu, 75001 Paris, France.

Depending on the service contracted or invoiced, PIANO ACADEMIE SERVICES, a French simplified joint-stock company (SAS), SIREN 828 163 865, SIRET 828 163 865 00011, 19 rue de la Pompe, 75116 Paris, France, may also act as controller.

Privacy contact: contact@piano-academie.com — telephone: +33 1 86 47 60 88.

2. Data we process

Depending on your role and use of the service, we may process the following categories:

  • identity and contact details: first and last name, date of birth, email address, telephone number, postal address, country, language and time zone;
  • account, authentication, family, student and legal-representative information, and an optional profile or student photograph;
  • teaching and operational information: courses, timetables, bookings, attendance, teachers, locations, educational or internal notes, communications and support requests;
  • commercial and accounting information: offers, subscriptions, packs, credits, purchases, invoices, payment status and masked payment-method information;
  • technical and security information needed to operate the service, including connection data and, if you enable notifications, an application push token linked to your account.

3. Why and on what legal basis?

We process data only for identified purposes and on the following legal bases:

  • performance of a contract or pre-contractual steps: creating and administering accounts, courses, bookings, subscriptions, credits, messages and customer support;
  • legal obligations: invoices, accounting records, tax obligations and responses to competent authorities;
  • our legitimate interests: securing the service, preventing fraud, maintaining and improving operations, and sending service information where permitted;
  • your consent where it is specifically required, in particular for optional communications or features. You may withdraw it at any time without affecting earlier lawful processing.

4. Required and optional information

Fields marked as required are necessary to create the account, manage the contractual relationship, book a service or meet a legal obligation. If they are not provided, the relevant service may not be available.

Optional information, such as a student photograph, marketing choices and push notifications, can be omitted or disabled without preventing access to the core service.

5. Who receives the data?

Access is limited to authorised Piano Académie staff and, only where necessary for their duties, assigned teachers. We also use service providers acting under our instructions or under their own legal responsibilities.

  • hosting, maintenance, email and SMS delivery providers;
  • Stripe for eligible adult subscriptions and PayPlug for school and family payments;
  • Zendesk when you use customer support;
  • Apple Push Notification service (APNs) when notifications are enabled;
  • accounting, legal and public authorities where disclosure is required by law.
  • We do not sell personal data and do not use the applications for advertising tracking.

6. Payments

Payment details are entered and secured directly by the relevant payment provider. Piano Académie does not store the full card number or card security code. We retain only the information needed to track the transaction, such as its status, reference, provider and, when available, a masked description of the payment method.

7. International transfers

Some technical providers may process data outside the European Economic Area. Where this occurs, the transfer is based on an adequacy decision, the European Commission's Standard Contractual Clauses or another safeguard permitted by data-protection law.

8. How long do we keep data?

We keep personal data only for as long as needed for the relevant purpose:

  • account and teaching data: for the active contractual relationship, then for the period needed to handle requests and legal claims;
  • contracts and evidence relating to disputes: generally up to five years after the end of the relationship, subject to applicable suspension or interruption rules;
  • invoices and accounting records: ten years, as required by French law;
  • prospect and optional marketing data: up to three years after the last contact or consent, unless you object earlier;
  • support, security and technical records: only for the operational or security period for which they are needed;
  • push tokens: until notifications are disabled, the token becomes invalid or the account is deleted.

9. Children and families

For a child, the account and required information are supplied or managed by a parent or legal representative. The information is used only for teaching, booking, safety, communication and administration of the school's services.

10. Your rights

Subject to the applicable conditions, you may request access, correction, deletion, restriction, objection and portability, and withdraw consent at any time. You may exercise these rights from the relevant account features or by emailing contact@piano-academie.com. We may ask for information needed to verify your identity.

If you believe your rights have not been respected, you may lodge a complaint with the French data-protection authority, the CNIL: www.cnil.fr.

11. Account deletion and contractual commitments

A deletion request can be started from the client account. Deleting an account does not cancel a subscription, a payment obligation or any other commitment to the school. The request may therefore be deferred while an active commitment or an ongoing service requires the account to perform the contract.

Once the applicable commitments have ended and operational requests have been completed, access is disabled and data is deleted or anonymised, except for information that must be retained to comply with accounting, tax, contractual or legal obligations.

12. Cookies, support and notifications

The web service uses only the session, authentication, security and preference technologies needed to operate. The Zendesk support widget may use its own technical components when opened. We do not use advertising cookies in the mobile applications.

Push notifications are optional. You can refuse or disable them at any time in your device settings. Disabling them does not prevent service emails required for your bookings, payments or contractual relationship.

13. Security and updates

We apply organisational and technical measures appropriate to the nature of the data, including role-based access, secure connections, authentication controls, backups and provider oversight. No system can guarantee absolute security, but suspected incidents are assessed and handled in accordance with applicable law.

This policy may be updated to reflect changes to the service, providers or law. The current version and its effective date are always available on this page.