Privacy Policy
Last updated: 14 August 2026
1. Data controller
The data controller is Dylan Cousinet (CodeByDylan / Obligia), sole trader, SIREN 944 657 600, registered office 5 allée Pierre de Serre de Saint Roman, 31400 Toulouse, France. Contact: obligia.ceo@gmail.com.
2. Data collected
- Account data: email address, password (stored only as an argon2id hash), entity name.
- Business data entered in the register: information on ICT contracts, providers, functions and identifiers (LEI/EUID). This data is confidential and processed solely on your behalf.
- Technical data: access and security logs (timestamps, events).
- Messages you send us: the name, email address and message body submitted through the contact form. Nothing is stored in our database — the message is delivered to a fixed mailbox and exists only there.
- Audience measurement: one record per public page view, containing the page path, the referring domain, and a visitor fingerprint. The fingerprint is a salted, non-reversible daily digest computed from your IP address and browser user-agent; neither the IP address nor the user-agent is stored, and the digest changes every day, so visits cannot be linked across days or back to you. No cookie is used for this. Pages inside the application are not measured.
3. Purposes and legal basis
- Service provision (performance of contract);
- Security, fraud prevention and logging (legitimate interest);
- Replying to messages you send us (legitimate interest, or steps taken at your request prior to entering into a contract);
- Measuring how the public site is used, by aggregate counts only (legitimate interest; no cookie and no identifier that persists beyond the day);
- Billing and accounting obligations (legal obligation).
4. Recipients and sub-processors
Your data is never sold. It may be processed by sub-processors strictly necessary for the service (hosting, transactional email, payment), bound by confidentiality and GDPR compliance commitments. Sub-processor list: IONOS SARL (hosting, European Union — data centre in Spain), Sendinblue SAS trading as Brevo (transactional email, France), and Stripe Payments Europe, Ltd. (payment processing, Ireland — only if billing is enabled).
5. Location and transfers
Data is hosted within the European Union. No transfer outside the EU takes place without appropriate safeguards.
6. Retention period
Register data (the business data you enter: contracts, providers, functions, identifiers) is retained for the duration of the subscription. After termination it stays exportable for 30 days, and is then deleted — as stated in section 9 of the Terms of Service.
Account data (your email address, role, sign-in timestamps) is retained for the duration of the subscription, then for up to 3 years for evidential and legal purposes. Security and access logs are deleted after 36 months. Audience-measurement records (section 2) are deleted after 13 months. These last two periods are enforced by a scheduled purge, not only stated here. Invoicing records are kept for 10 years as required by law.
Messages sent through the contact form are kept for up to 3 years from our last exchange with you, in line with the CNIL's guidance on business contact data, and then deleted. They live in a mailbox rather than in the service, so this period is applied by hand and not by the scheduled purge described above.
7. Security
Encryption in transit (TLS), password hashing (argon2id), strict per-tenant isolation enforced by the application on every request and covered by automated tests, security headers (CSP, anti-clickjacking), and access logging. Data is encrypted at rest by the hosting provider.
8. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, objection and data portability.
Two of these rights are exercisable directly from your account, without contacting us and without delay:
- Access and portability — Export my data in your account settings downloads a structured JSON file containing your account record, your organisation membership, and your own security audit trail.
- Erasure — Delete account in the same page permanently removes your account. Deleting the last account of an organisation also deletes the organisation and every register it holds.
Your register content (contracts, providers, identifiers) is the organisation's business and regulatory data rather than your personal data; it is exported in full through the register export feature. For any other right, or if you cannot access your account: obligia.ceo@gmail.com. You may also lodge a complaint with your local supervisory authority (e.g. CNIL: www.cnil.fr).
9. Cookies
The site uses only one strictly necessary cookie for authentication (session cookie, secure and httpOnly). No advertising or tracking cookies are set, and the audience measurement described in section 2 uses no cookie at all. One entry is also written to your browser's local storage (obligia_cookie_ack) to remember that you have dismissed this notice; it is read only by this site and contains no identifier. Fonts are hosted locally (no requests to third parties).