ElectroRenew
Data Protection Notice
Including our Data Processing Agreement (GDPR Art. 28)  ·  Last updated: 30 September 2026
  1. Who we are and our roles
  2. What we process and why
  3. What the verification page shows
  4. How long we keep it
  5. Sub-processors
  6. Your rights
  7. Data Processing Agreement (GDPR Art. 28)

1. Who we are and our roles

ELECTRO RENEW SAS, SIREN 938 013 240, 110 Rue de Fontenay, 94300 Vincennes, France. Contact for data protection: contact@electrorenew.fr.

We play two different roles, depending on whose data it is:

DataControllerELECTRO RENEW SAS acts as
Data about the devices a repair shop tests for its customers: IMEI, serial numbers, component serial numbers, hardware identifiers, test results and grades, and the certificates and reports built from themThe repair shop (our customer, the "tenant")Processor, acting on the shop's instructions under the agreement in section 7
Account data of our own customers: e-mail address, name, sign-in data, credit purchases and credit ledgerELECTRO RENEW SASController

If you brought a phone to a repair shop, that shop decides why and how your device's data is processed and is your first point of contact. We will pass on any request we receive about a shop's data to that shop.

2. What we process and why

2.1 On behalf of repair shops (processor)

We never read the personal content of a tested phone (contacts, messages, photos, apps). Diagnostic results that a technician does not save stay on the technician's PC and are not sent to us.

2.2 For our own purposes (controller)

Full detail, including the Android test app and our Telegram channel, is in our Privacy Policy.

3. What the verification page shows

Anyone who scans a certificate's QR code, or enters its certificate ID at electrorenew.app/verify, sees the device model and storage, its IMEI and serial number, the battery figures, the checks performed and the grade, the test date, whether an account was still signed in, and the name shown as technician.

This is deliberate: it lets a buyer confirm that the certificate matches the handset in their hand. The page is not indexed and cannot be searched or listed; it answers only to a full certificate ID. Treat a certificate ID as you would treat the IMEI itself.

The certificate is signed with ELECTRO RENEW SAS's own key. The signature shows that the record has not been altered since it was saved; it is not a third-party accreditation. See what our certificate is and isn't.

Reports created before 15 September 2026 and legacy report.html reports are not signed.

4. How long we keep it

DataRetention
Saved reports and their verification pages24 months from the test date. The date is shown on the verification page and on reports printed from the dashboard. After it, the report data is deleted and only the certificate ID and its status are kept, so a printed certificate can still be recognised as expired or revoked.
Copies of reports in a shop's dashboardUntil the shop deletes them or asks us to, and at the latest when the shop's account is closed (see section 7.9).
Account dataWhile the account exists; deleted within 30 days of a closure request, except records we must keep by law.
Purchase and invoicing records10 years (French accounting law).
Waiting list and contact messagesUntil you ask to be removed.

Deleting a report before then

5. Sub-processors

We use the following service providers. Each processes data only to provide its service to us.

ProviderWhat it does for usLocation
Supabase Inc.Database, authentication and server functions — stores accounts, reports and certificatesEU (Stockholm, Sweden)
Cloudflare, Inc.Hosting of this website and the dashboard, DNS, CDN, request routing, delivery of contact-form e-mailsEU / US (Standard Contractual Clauses)
Stripe Payments Europe Ltd.Payment processing for credit packsEU / US (Standard Contractual Clauses)
Google Ireland Ltd. (Google Workspace)Sending account e-mails (sign-up confirmation, password reset)EU / US (Standard Contractual Clauses)
GitHub, Inc.Hosting of the software installer downloads (sees your IP address when you download)US (Standard Contractual Clauses)

Recipients that act under their own terms, not as our sub-processors: eBay, only for shops that connect their own eBay account, and only the listing content the shop publishes (never an IMEI, serial number or certificate); Telegram, only for people who subscribe to our announcements channel.

We do not sell personal data and we do not use advertising or analytics services.

6. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21), and, where processing is based on consent, to withdraw that consent at any time.

For data we hold as controller, write to contact@electrorenew.fr. We answer within one month. For data about a device tested by a repair shop, contact that shop first; we assist it in answering you (section 7.8).

You may also lodge a complaint with the French data protection authority, the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr), or with the authority of the EU country where you live or work.

7. Data Processing Agreement (GDPR Art. 28)

This section forms the data processing agreement between ELECTRO RENEW SAS (the Processor) and each business customer that uses ElectroRenew or ERenewPro to test devices (the Controller). It applies automatically when the Controller accepts our Terms of Service, and prevails over them on any matter of personal-data protection. A countersigned copy is available on request.

7.1 Subject matter and duration

Processing of personal data contained in device diagnostic reports, for as long as the Controller uses the service, plus the retention period in section 4.

7.2 Nature and purpose

Receiving, storing, scoring, signing and publishing (on the verification page) diagnostic reports; keeping copies in the Controller's dashboard; printing labels; deleting reports.

7.3 Types of data and data subjects

Data: device identifiers (IMEI, serial numbers, component serial numbers, hardware addresses), device technical data, test results, grades, account-present flag, technician name or e-mail. Data subjects: the owners and prospective buyers of tested devices, and the Controller's technicians.

7.4 Instructions

The Processor processes the data only on the Controller's documented instructions — which are the configuration and use of the service as described in the Terms of Service and this notice — including for transfers outside the EU, unless EU or French law requires otherwise; in that case the Processor informs the Controller first unless the law forbids it. The Processor informs the Controller immediately if an instruction appears to infringe the GDPR.

7.5 Confidentiality

Everyone authorised by the Processor to access the data is bound by confidentiality. Access is limited to what is needed to operate and support the service.

7.6 Security measures (Art. 32)

7.7 Sub-processors

The Controller gives general authorisation to the sub-processors listed in section 5. The Processor will announce any addition or replacement by updating this page and e-mailing the account address at least 30 days in advance; the Controller may object on reasonable data-protection grounds and, failing agreement, terminate. Each sub-processor is bound by data-protection obligations equivalent to these. The Processor remains liable to the Controller for its sub-processors.

7.8 Assistance

Taking into account the nature of the processing, the Processor assists the Controller in answering data-subject requests, in meeting its security, breach-notification and impact-assessment obligations (Art. 32–36), and notifies the Controller of any personal-data breach affecting its data without undue delay after becoming aware of it.

7.9 Deletion or return at the end of the contract

When the Controller closes its account, the Processor, at the Controller's choice, returns the Controller's reports in a structured export or deletes them, within 30 days, and deletes remaining copies unless EU or French law requires storage. Verification pages of deleted reports then show them as removed.

7.10 Audit

The Processor makes available all information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates, on reasonable prior notice and subject to confidentiality.

7.11 Controller responsibilities

The Controller is responsible for having a lawful basis to test each device and save its report, for informing the device owner, and — where it erases or factory-resets a customer's device with the software — for obtaining the owner's consent beforehand (for example on its drop-off form).