Privacy policy
Last updated:
Courtesy translation. Only the French version of this document has legal effect. It is the one that binds the parties, and the one a court would read. This translation is provided to help you understand it — where the two differ, the French text prevails.
This policy describes the processing of personal data carried out byCOMPANY NAME, acting as controller for its own customers’ data, and as processor for the data contained in the messages its customers receive.
1. Two roles, which must not be confused
Controller for account data: identity, email address, billing information, connection logs. Those processing activities are described below.
Processor for the content of the messages you receive in your test inboxes. We determine neither the purposes nor the means: you remain the controller. Those activities are governed by the data processing agreement.
2. Data processed, purposes and legal bases
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address, name, hashed password | Account creation and security | Performance of the contract | Life of the account, then 30 days |
| Company name, address, VAT number, payment method | Billing and accounting obligations | Legal obligation | 10 years (French Commercial Code) |
| Connection and API call logs | Security, abuse detection, usage-based billing | Legitimate interest | 12 months |
| IP address and user agent, on sign-up, on organization creation and at each sign-in | Detection of fraudulent sign-ups and abuse | Legitimate interest | 12 months |
| Content of messages received in inboxes | Provision of the testing service | Processing on behalf of the customer | Retention configured by the customer (1 to 90 days) |
| Website audience statistics | Aggregated audience measurement | Legitimate interest, no cookie or identifier | 24 months, aggregated |
The connection data listed above is used for observation only:no automated decision — refusing a sign-up, restricting or suspending an account — is made from it, within the meaning of Article 22 GDPR. It is read by a person, and serves to ask a question rather than to answer one on someone’s behalf.
3. Cookies
The public website sets no audience measurement or advertising cookie, and therefore displays no consent banner. The application uses a single session cookie, strictly necessary for authentication.
4. Recipients and sub-processors
The full list, with location and the nature of the data transmitted, is published on theData sovereignty page and updated on every change. Only one sub-processor may involve a transfer outside the European Union: Stripe, for payment, framed by the standard contractual clauses.
5. Security
- Encryption in transit (TLS) and at rest (volumes and object storage).
- API keys stored hashed, never readable in clear after creation.
- Two-factor authentication available on every plan.
- Data isolation per organisation, at both application and database level.
- Logging of administrative access.
6. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability. These rights are exercised with hello@facteur.eu, with a response within one month. You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, 75007 Paris.
7. Data protection officer
TO BE APPOINTED IF REQUIRED — an appointment is not mandatory for an organisation of this size processing these categories of data, but it must be reassessed as soon as customers from regulated sectors arrive.