Protection of your personal data - GDPR Compliance
Last updated: February 2026
MMG VTC is committed to protecting the privacy and personal data of its customers. This privacy policy explains how we collect, use, store and protect your personal information in accordance with the General Data Protection Regulation (GDPR) and French data protection law.
Data controller:
We only collect data necessary to provide our VTC transport services:
We do NOT collect:
Your personal data is used only for the following purposes:
Legal basis: Contract performance (Article 6.1.b of GDPR)
Legal basis: Contract performance and legitimate interest
Legal basis: Legal obligation (accounting) and contract performance
Legal basis: Legitimate interest (Article 6.1.f of GDPR)
Legal basis: Legal obligation (Article 6.1.c of GDPR)
Your personal data is accessible only to the following persons and services:
All our service providers are GDPR compliant and located in the European Union or have appropriate guarantees.
Your data may be communicated to competent authorities only in case of legal obligation (judicial requisition, tax audit, etc.).
We NEVER sell your personal data to third parties.
Your data is retained only for the period necessary for the purposes for which it was collected:
| Data Type | Retention Period | Justification |
|---|---|---|
| Booking data | 3 years after the ride | Claims and disputes management |
| Accounting data (invoices) | 10 years | Legal obligation (Commercial Code) |
| Contact data (prospects) | 3 years without interaction | Commercial prospecting |
| Technical cookies | 13 months maximum | CNIL recommendation |
| Analytics cookies | 13 months maximum | CNIL recommendation |
Automatic deletion: At the expiration of these periods, your data is automatically deleted from our systems.
We implement appropriate technical and organizational measures to protect your personal data:
Payments are processed by Stripe, certified PCI DSS Level 1 (highest security standard). We NEVER store your banking data.
In accordance with GDPR, you have the following rights regarding your personal data:
You can request a copy of all personal data we hold about you.
You can request correction of inaccurate or incomplete data.
You can request deletion of your personal data, unless we have a legal obligation to retain it (e.g., invoices).
You can request restriction of processing of your data in certain cases.
You can receive your data in a structured, machine-readable format.
You can object to processing of your data for reasons relating to your particular situation.
You can withdraw your consent at any time (cookies, newsletter, etc.).
To exercise your rights, contact us:
Response time: We undertake to respond within a maximum of 1 month.
ID proof: For security reasons, we may ask for a copy of your ID.
Our site uses cookies to improve your browsing experience.
These cookies are necessary for the site to function and do not require consent.
These cookies require your prior consent.
You can modify your cookie preferences at any time:
Cookies are retained for a maximum of 13 months (CNIL recommendation).
Your personal data is primarily stored and processed in the European Union.
Some service providers may be located outside the European Union:
All transfers outside the EU are governed by appropriate guarantees in accordance with GDPR (Standard Contractual Clauses, Privacy Shield, etc.).
If you believe your rights are not being respected, you can lodge a complaint with the CNIL:
We reserve the right to modify this privacy policy at any time to reflect changes in our practices or for legal reasons.
Notification: In case of substantial modification, we will inform you by email or via a notification on the site.
Last update date: February 2026
For any questions regarding this privacy policy or the use of your personal data, contact us:
Response time: We undertake to respond to your requests within a maximum of 1 month.