ELECTRO RENEW SAS, SIREN 938 013 240, 110 Rue de Fontenay, 94300 Vincennes, France. Contact for data protection: contact@electrorenew.fr.
We play two different roles, depending on whose data it is:
| Data | Controller | ELECTRO RENEW SAS acts as |
|---|---|---|
| Data about the devices a repair shop tests for its customers: IMEI, serial numbers, component serial numbers, hardware identifiers, test results and grades, and the certificates and reports built from them | The repair shop (our customer, the "tenant") | Processor, acting on the shop's instructions under the agreement in section 7 |
| Account data of our own customers: e-mail address, name, sign-in data, credit purchases and credit ledger | ELECTRO RENEW SAS | Controller |
If you brought a phone to a repair shop, that shop decides why and how your device's data is processed and is your first point of contact. We will pass on any request we receive about a shop's data to that shop.
We never read the personal content of a tested phone (contacts, messages, photos, apps). Diagnostic results that a technician does not save stay on the technician's PC and are not sent to us.
Full detail, including the Android test app and our Telegram channel, is in our Privacy Policy.
Anyone who scans a certificate's QR code, or enters its certificate ID at electrorenew.app/verify, sees the device model and storage, its IMEI and serial number, the battery figures, the checks performed and the grade, the test date, whether an account was still signed in, and the name shown as technician.
This is deliberate: it lets a buyer confirm that the certificate matches the handset in their hand. The page is not indexed and cannot be searched or listed; it answers only to a full certificate ID. Treat a certificate ID as you would treat the IMEI itself.
The certificate is signed with ELECTRO RENEW SAS's own key. The signature shows that the record has not been altered since it was saved; it is not a third-party accreditation. See what our certificate is and isn't.
Reports created before 15 September 2026 and legacy report.html reports are not signed.
| Data | Retention |
|---|---|
| Saved reports and their verification pages | 24 months from the test date. The date is shown on the verification page and on reports printed from the dashboard. After it, the report data is deleted and only the certificate ID and its status are kept, so a printed certificate can still be recognised as expired or revoked. |
| Copies of reports in a shop's dashboard | Until the shop deletes them or asks us to, and at the latest when the shop's account is closed (see section 7.9). |
| Account data | While the account exists; deleted within 30 days of a closure request, except records we must keep by law. |
| Purchase and invoicing records | 10 years (French accounting law). |
| Waiting list and contact messages | Until you ask to be removed. |
We use the following service providers. Each processes data only to provide its service to us.
| Provider | What it does for us | Location |
|---|---|---|
| Supabase Inc. | Database, authentication and server functions — stores accounts, reports and certificates | EU (Stockholm, Sweden) |
| Cloudflare, Inc. | Hosting of this website and the dashboard, DNS, CDN, request routing, delivery of contact-form e-mails | EU / US (Standard Contractual Clauses) |
| Stripe Payments Europe Ltd. | Payment processing for credit packs | EU / US (Standard Contractual Clauses) |
| Google Ireland Ltd. (Google Workspace) | Sending account e-mails (sign-up confirmation, password reset) | EU / US (Standard Contractual Clauses) |
| GitHub, Inc. | Hosting of the software installer downloads (sees your IP address when you download) | US (Standard Contractual Clauses) |
Recipients that act under their own terms, not as our sub-processors: eBay, only for shops that connect their own eBay account, and only the listing content the shop publishes (never an IMEI, serial number or certificate); Telegram, only for people who subscribe to our announcements channel.
We do not sell personal data and we do not use advertising or analytics services.
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object (Art. 21), and, where processing is based on consent, to withdraw that consent at any time.
For data we hold as controller, write to contact@electrorenew.fr. We answer within one month. For data about a device tested by a repair shop, contact that shop first; we assist it in answering you (section 7.8).
You may also lodge a complaint with the French data protection authority, the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr), or with the authority of the EU country where you live or work.
This section forms the data processing agreement between ELECTRO RENEW SAS (the Processor) and each business customer that uses ElectroRenew or ERenewPro to test devices (the Controller). It applies automatically when the Controller accepts our Terms of Service, and prevails over them on any matter of personal-data protection. A countersigned copy is available on request.
Processing of personal data contained in device diagnostic reports, for as long as the Controller uses the service, plus the retention period in section 4.
Receiving, storing, scoring, signing and publishing (on the verification page) diagnostic reports; keeping copies in the Controller's dashboard; printing labels; deleting reports.
Data: device identifiers (IMEI, serial numbers, component serial numbers, hardware addresses), device technical data, test results, grades, account-present flag, technician name or e-mail. Data subjects: the owners and prospective buyers of tested devices, and the Controller's technicians.
The Processor processes the data only on the Controller's documented instructions — which are the configuration and use of the service as described in the Terms of Service and this notice — including for transfers outside the EU, unless EU or French law requires otherwise; in that case the Processor informs the Controller first unless the law forbids it. The Processor informs the Controller immediately if an instruction appears to infringe the GDPR.
Everyone authorised by the Processor to access the data is bound by confidentiality. Access is limited to what is needed to operate and support the service.
The Controller gives general authorisation to the sub-processors listed in section 5. The Processor will announce any addition or replacement by updating this page and e-mailing the account address at least 30 days in advance; the Controller may object on reasonable data-protection grounds and, failing agreement, terminate. Each sub-processor is bound by data-protection obligations equivalent to these. The Processor remains liable to the Controller for its sub-processors.
Taking into account the nature of the processing, the Processor assists the Controller in answering data-subject requests, in meeting its security, breach-notification and impact-assessment obligations (Art. 32–36), and notifies the Controller of any personal-data breach affecting its data without undue delay after becoming aware of it.
When the Controller closes its account, the Processor, at the Controller's choice, returns the Controller's reports in a structured export or deletes them, within 30 days, and deletes remaining copies unless EU or French law requires storage. Verification pages of deleted reports then show them as removed.
The Processor makes available all information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, by the Controller or an auditor it mandates, on reasonable prior notice and subject to confidentiality.
The Controller is responsible for having a lawful basis to test each device and save its report, for informing the device owner, and — where it erases or factory-resets a customer's device with the software — for obtaining the owner's consent beforehand (for example on its drop-off form).