تخطي للذهاب إلى المحتوى

Privacy Policy

Version 1.0 — in force from [DATE]

1. Who we are

This policy describes how [RAISON SOCIALE], with its registered office at [ADRESSE], protects personal information on the dypsia.com platform.

Officer responsible for the protection of personal information: [NOM] — info@dypsia.com.

2. Who it applies to

This policy covers three groups of people:

  • visitors to the dypsia.com website;
  • customers and their administrators: the organisations that create a space, and the people who represent them;
  • the members and customers of our customers: for them, see section 4. It is the organisation, not Dypsia, that decides what is collected about them and how it is used.

3. What we collect and why

InformationWhy
Organisation name, country, address, city, postal codeCreate and identify the space, issue the invoices
Administrator's name and email addressManage the account, send service notifications, verify the address
PasswordAuthentication. It is stored hashed: we can neither read it nor recover it
Billing dataBilling, accounting, taxes
Technical logs: IP addresses, connection timestamps, security eventsSecurity, abuse prevention, proof that the contract was accepted, diagnosis
Emails exchanged with supportAnswering requests

We do not collect payment card numbers: payments are handled by certified providers, under their own policies.

The dypsia.com site uses only the cookies it needs to work: session, security, language preference. What a Space sets in its own browser session is governed by the Customer, who runs it.

4. The data our customers host

Each customer manages its own data in its space: members, donors, customers, suppliers, accounting entries, documents. For that information:

  • the customer is responsible for it: it is the customer who decides what is collected and why;
  • Dypsia acts on its behalf: we host and back up that data on its instructions, without consulting it or using it for other purposes;
  • each space rests on an isolated database, with no cross-access between customers;
  • if someone writes to us about data held by a customer, we direct them to that customer and let the customer know.

5. Who we share it with

We neither sell nor rent any personal information. We disclose it only:

  • to our infrastructure providers, for hosting the servers;
  • to the payment providers, for the paid plans;
  • to the authorities, where a law or a valid order requires it. We tell the person concerned where the law allows;
  • to a possible buyer, in the event of a sale or a reorganisation, the commitments of this policy being kept.

The current list of our providers is available on request at info@dypsia.com.

6. Where it is kept

Data is hosted on servers located in the European Union.

For people in Canada, it is therefore kept outside the country. We frame this communication with a written agreement with our host, guaranteeing a comparable level of protection.

For people in the European Union, the data stays in the Union. Where it is consulted from Canada for administration or support, that transfer rests on the European Commission's adequacy decision covering Canada.

7. For how long

CategoryPeriod
Active account and spaceFor as long as the contractual relationship lasts
Terminated space30 days, then permanent deletion and progressive erasure from the backups
Inactive free spaceDeleted after 120 days without a connection, warning at 90 days
Billing dataFor as long as the applicable tax limitation periods last
Technical logs12 months, except for a security incident being analysed
Unconfirmed sign-upNothing kept: nothing is recorded until the email address is confirmed

8. How we protect it

  • encrypted communications;
  • a separate database for each space, with no cross-access;
  • passwords stored hashed, never in clear;
  • encrypted configuration secrets;
  • administrative access controlled and logged;
  • regular backups with rotation;
  • the email address verified before any account is created.

In the event of a breach carrying a serious risk, we notify the competent authorities and the people concerned, and keep the register the law requires.

9. Your rights

You may see the information we hold about you, have it corrected, withdraw your consent subject to legal and contractual obligations, and challenge our compliance with our officer.

If you are in the European Union, you also have the rights to erasure, restriction, objection and portability.

To exercise them, write to info@dypsia.com. We answer within thirty days, and within one month for requests falling under the European regulation.

You may also complain to the competent authority: in Canada, the Office of the Privacy Commissioner; in the European Union, the supervisory authority of your country.

If your information is held in the space of a customer organisation because you are a member, a donor or a customer of it, send your request straight to that organisation: it alone decides on the processing. We assist it as far as our technical means allow.

10. Minors

The Dypsia account and the Spaces are meant for organisations and professionals. We do not knowingly collect information about minors in order to create an account.

11. Changes

We may change this policy at any time. The version in force is the one published on this page, with its update date. On a paid plan, changes take effect at the next renewal of the subscription; a customer who refuses them may terminate before that renewal. On the Free plan, they take effect as soon as they are published.

12. Reaching us

For any question about this policy or about your personal information: info@dypsia.com, or by post to [ADRESSE].

The French version of this policy prevails over any translation given for information.