Obligia Back to site

Privacy Policy

1. Data controller

The data controller is Dylan Cousinet (CodeByDylan / Obligia), sole trader, SIREN 944 657 600, registered office 5 allée Pierre de Serre de Saint Roman, 31400 Toulouse, France. Contact: obligia.ceo@gmail.com.

2. Data collected

3. Purposes and legal basis

4. Recipients and sub-processors

Your data is never sold. It may be processed by sub-processors strictly necessary for the service (hosting, transactional email, payment), bound by confidentiality and GDPR compliance commitments. Sub-processor list: IONOS SARL (hosting, European Union — data centre in Spain), Sendinblue SAS trading as Brevo (transactional email, France), and Stripe Payments Europe, Ltd. (payment processing, Ireland — only if billing is enabled).

5. Location and transfers

Data is hosted within the European Union. No transfer outside the EU takes place without appropriate safeguards.

6. Retention period

Register data (the business data you enter: contracts, providers, functions, identifiers) is retained for the duration of the subscription. After termination it stays exportable for 30 days, and is then deleted — as stated in section 9 of the Terms of Service.

Account data (your email address, role, sign-in timestamps) is retained for the duration of the subscription, then for up to 3 years for evidential and legal purposes. Security and access logs are deleted after 36 months. Audience-measurement records (section 2) are deleted after 13 months. These last two periods are enforced by a scheduled purge, not only stated here. Invoicing records are kept for 10 years as required by law.

Messages sent through the contact form are kept for up to 3 years from our last exchange with you, in line with the CNIL's guidance on business contact data, and then deleted. They live in a mailbox rather than in the service, so this period is applied by hand and not by the scheduled purge described above.

7. Security

Encryption in transit (TLS), password hashing (argon2id), strict per-tenant isolation enforced by the application on every request and covered by automated tests, security headers (CSP, anti-clickjacking), and access logging. Data is encrypted at rest by the hosting provider.

8. Your rights

Under the GDPR you have the right of access, rectification, erasure, restriction, objection and data portability.

Two of these rights are exercisable directly from your account, without contacting us and without delay:

Your register content (contracts, providers, identifiers) is the organisation's business and regulatory data rather than your personal data; it is exported in full through the register export feature. For any other right, or if you cannot access your account: obligia.ceo@gmail.com. You may also lodge a complaint with your local supervisory authority (e.g. CNIL: www.cnil.fr).

9. Cookies

The site uses only one strictly necessary cookie for authentication (session cookie, secure and httpOnly). No advertising or tracking cookies are set, and the audience measurement described in section 2 uses no cookie at all. One entry is also written to your browser's local storage (obligia_cookie_ack) to remember that you have dismissed this notice; it is read only by this site and contains no identifier. Fonts are hosted locally (no requests to third parties).