Privacy Policy
1. Information for data subjects
Identity of the data controller
The processing of personal data is carried out by INVERT, a simplified joint-stock company (société par actions simplifiée) with a share capital of 1,000 euros, registered under the number 953 733 615 (Rennes), whose registered office is located at 23Q rue Jean-Baptiste Barré, 35000 Rennes, France (hereinafter the Publisher). For any question relating to the protection of personal data, you may write to our data-protection contact at the following address: shairelabs@proton.me.
Purposes, legal bases, categories of data and retention periods
The Publisher processes personal data for the following purposes:
- Account management and provision of the Service: the performance of a contract is the legal basis. The categories of data processed are the identity and professional contact details of users, connection data, as well as all contents deposited in the workspace. The data is retained for the entire duration of the contractual relationship. Upon the closure of a workspace, the contents are retained for thirty days and then deleted.
- Invoicing and accounting obligations: compliance with a legal obligation is the legal basis. The categories of data processed are the invoicing data and the contact details of the client company. Accounting documents are retained for ten years, in accordance with Article L123-22 of the French Commercial Code.
- Sending of transactional e-mails (address verification, password reset, notifications): the performance of a contract is the legal basis. The categories of data processed are the identity and e-mail address. The data is retained for the duration of the contractual relationship.
- Security, connection logs and fraud prevention: the legitimate interest of the Publisher is the legal basis. The category of data processed comprises connection data. The data is retained for the duration of the contractual relationship.
- Response to requests sent to the contact address: the legitimate interest of the Publisher is the legal basis. The categories of data processed are the identity, professional contact details and connection metadata. The data is retained for the time necessary to process the request.
- Connection via a Google account (at the user’s choice): the performance of a contract is the legal basis. The categories of data processed are the identity and connection data. The data is retained for the duration of the contractual relationship.
Specific commitments
No commercial prospecting, no audience measurement, no profiling, no automated decision-making, and no resale of data is carried out.
Cookies
The site places a single cookie. This cookie is strictly functional and serves solely to remember the chosen language. It is exempt from the collection of consent.
Your rights
You have a right of access, rectification, erasure, limitation, opposition, portability, as well as the right to define post-mortem directives. To exercise these rights, you may contact the address shairelabs@proton.me. The right to portability is exercised by means of the public API of the Service or, failing that, upon request sent to this address. However, when a user wishes to exercise their rights over data appearing in a Client’s workspace, they must contact that Client first, as it is the data controller. You also have the right to lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), by post at the address 3 place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, or on its website: https://www.cnil.fr.
2. Data processing agreement (Article 28 of the GDPR)
This section supplements the Terms of Use and Sale and applies to the data that the Client deposits and processes in its workspace. The Client acts in the capacity of data controller; the Publisher acts exclusively in the capacity of data processor.
Documented instructions
The Publisher processes the Client’s data solely upon the documented instruction of the latter.
Confidentiality
The Publisher guarantees that the persons authorised to process the data are committed to respecting confidentiality.
Security measures
The Publisher implements security measures including the encryption of data in transit, the isolation of workspaces, access control and logging. The data of the Service is hosted in France.
Sub-processors
The Client grants general authorisation to the Publisher to engage sub-processors. The Publisher will inform the Client in advance of any addition or replacement, allowing the Client to raise objections. List of sub-processors:
- Scaleway: hosting (application server, database, storage of attachments). Processing located in France (Paris).
- Cloudflare: content delivery network and frontline protection. Processing involving a transfer outside the European Union (governed by the Publisher’s commitment to apply standard contractual clauses).
- Stripe: payment. Processing involving a transfer outside the European Union (governed by the Publisher’s commitment to apply standard contractual clauses).
- Resend: transactional e-mails. Processing involving a transfer outside the European Union (governed by the Publisher’s commitment to apply standard contractual clauses).
- Google: authentication, only for users who choose to connect with a Google account. Processing involving a transfer outside the European Union (governed by the Publisher’s commitment to apply standard contractual clauses).
- GitHub and GitLab: code repository integration, only when the Client activates this integration in its workspace. Processing which may involve a transfer outside the European Union (governed by the Publisher’s commitment to apply standard contractual clauses).
Assistance to the Client
The Publisher assists the Client in responding to requests to exercise rights and for its obligations provided for in Articles 32 to 36 of the GDPR, within the limit of what is reasonable and the information at the Publisher’s disposal.
Notification of data breaches
The Publisher notifies the Client of any data breach without undue delay.
What happens to the data
At the end of the contract, the data is deleted. The Service does not include an export function: the Client wishing to obtain a copy constitutes it itself by means of the public API, or requests it from the Publisher, who provides it to the Client in a structured, commonly used and machine-readable format. Upon the closure of a workspace, the data is retained for thirty days to allow the Client to restore it, before being destroyed.
Audits
The Publisher makes available the information necessary to demonstrate compliance and to allow for audits. The latter are limited to a maximum of one per year, at the Client’s expense, subject to reasonable notice, without access to shared infrastructures or to the data of other clients. The Publisher may respond to them by means of documentation.
This policy is written in French. Any translation is provided for convenience; in the event of a discrepancy, the French version prevails.
Last updated