Skip to main content

Privacy policy

Last updated: [DATE]

Data controller

[COMPANY NAME], [ADDRESS]. Contact: [DPO EMAIL]

Data collected

We collect the following data: email address, last name, first name, organization, function, phone number. For each of your active sessions we also record browser and device information, so you can recognise and revoke your own sessions. This data is necessary for creating and managing your account.

Processing purposes

Your data is used for: managing your user account, authentication, sending transactional emails (activation, password reset), account security (letting you review and revoke your own active sessions, and review and disconnect the third-party applications authorized on your account), and action traceability (activity log).

Legal basis

The processing of your data is based on the performance of a contract (Art. 6(1)(b) GDPR) for account management, and on legitimate interest (Art. 6(1)(f) GDPR) for the activity log and for the session metadata used to secure your account.

Retention period

Your account data is retained as long as your account is active. Session metadata (browser and device) is deleted together with the session it belongs to: when you revoke it, when you sign out, or when it expires after the inactivity period. Upon deletion, your data is anonymized. Activity logs are retained for 3 years.

Processors

We use Brevo (Sendinblue SAS, France) for sending transactional emails. A Data Processing Agreement (DPA) is in place.

Your rights

You have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data. To exercise these rights, contact [DPO EMAIL]. We will respond within 30 days.

Complaint

If you believe that the processing of your data is not compliant, you may lodge a complaint with the relevant supervisory authority.