1. Data Controller
The ArtGuard service is published by DTech Innovations, sole proprietor, SIREN 982 702 052, registered seat 105 Chemin de Souleyrol, 84570 Malemort-du-Comtat, France ("ArtGuard" or "we").
ArtGuard acts as:
- Data Controller for data collected for managing its institutional site, dashboard, and Customer contractual relationship.
- Data Processor within the meaning of GDPR article 28 for data collected on behalf of its Customers when displaying disclosures on Customer Sites (see DPA).
2. Contact
Given the size of the structure (sole proprietor not subject to mandatory DPO designation under GDPR article 37), the contact for data protection inquiries is:
- Email: dtech.innovations@proton.me
- Postal address: DTech Innovations, 105 Chemin de Souleyrol, 84570 Malemort-du-Comtat, France
3. Data collected and purposes
3.1 Dashboard User data (Customers)
| Category | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Identification | Account creation, magic link authentication | Contract performance | Account lifetime + 3 years | |
| Tenant | Organization name, subscribed plan | Billing, Service delivery | Contract performance | Contract lifetime + 5 years (accounting obligations) |
| Payment | Stripe token (no card data directly stored) | Subscription management | Contract performance | Contract lifetime + legal obligations |
| Technical logs | IP, User-Agent, connection timestamps | Security, fraud prevention | Legitimate interest | 12 months |
3.2 End Visitor data (Customer Sites)
When an ArtGuard disclosure is displayed on a Customer Site, the following data is collected and processed on the Customer's behalf (who is the controller):
| Category | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Pseudonym | SHA-256 hash of IP, reduced User-Agent | Disclosure traceability (Art. 50 compliance evidence) | Customer's legitimate interest | 30/90/365 days per Customer plan |
| Event | Event type (disclosure_shown, disclosure_acknowledged), timestamp, page URL, visitor locale |
Audit trail | Customer's legitimate interest | Same |
IPs are never stored in clear text — only a SHA-256 hash. User-Agent is truncated.
3.3 No tracking cookies
The ArtGuard snippet does not drop third-party cookies and does not engage in advertising or profiling. The disclosure display and audit event submission use a direct HTTPS call with no identifying client-side persistence (except technical localStorage for an offline queue, no personal data).
4. Recipients and subprocessors
| Subprocessor | Role | Location | Transfer safeguards |
|---|---|---|---|
| Neon (neon.tech) | Postgres hosting | EU — Frankfurt (eu-central-1 AWS) | No transfer outside EU |
| Fly.io | API hosting | EU (Paris/Amsterdam/Frankfurt) | EU region configuration |
| Vercel | Dashboard hosting | USA (with EU regionalization) | EU SCC |
| Cloudflare | Snippet CDN | Global edge network | EU SCC |
| Stripe Inc. | Payments | USA | EU SCC |
| Resend | Magic link emails | USA | EU SCC |
| Sentry | Error monitoring | USA or EU per offering | EU SCC if US |
| GitHub Container Registry | Docker images | USA | EU SCC |
5. Transfers outside the EU
Transfers to non-EU subprocessors are governed, in accordance with GDPR articles 44 to 49, by:
- The European Commission's Standard Contractual Clauses (SCC) adopted by Implementing Decision (EU) 2021/914 of 4 June 2021;
- Where applicable, Data Privacy Framework (DPF) EU-US certifications (Adequacy Decision of 10 July 2023);
- A Transfer Impact Assessment (TIA) conducted in line with Schrems II case law (CJEU, 16 July 2020, C-311/18) and EDPB Recommendations 01/2020. The TIA documents the effective level of protection in the third country, the additional technical and organisational measures implemented (end-to-end encryption on all communications, systematic IP pseudonymisation, data minimisation), and concludes that protection is substantially equivalent.
A TIA summary is available to data subjects and Customers on reasoned request to dtech.innovations@proton.me.
No data is transferred to a country without adequate protection, without SCC, and without a documented TIA.
6. Data subject rights
Under GDPR and the French Data Protection Act, you have:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Objection (Art. 21)
- Portability (Art. 20)
- Post-mortem directives
To exercise these rights: email dtech.innovations@proton.me. Identity proof may be requested in case of reasonable doubt.
Response deadline: 1 month maximum (2-month extension possible for complex requests, with notice).
6.1 End Visitors
For data collected on a Customer Site as processor: ArtGuard cannot directly identify an End Visitor from pseudonymous data alone. Access/erasure requests must be addressed first to the Customer (the Customer Site operator), who is the controller. ArtGuard assists the Customer in responding within legal deadlines.
7. Complaint
Right to lodge a complaint with the CNIL (French DPA):
- cnil.fr
- 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- +33 (0)1 53 73 22 22
8. Security
Technical and organizational measures include:
- In-transit encryption: TLS 1.2+ everywhere.
- At-rest encryption: AES-256 disk (Neon).
- Authentication: magic link, 15-minute lifetime, no permanent password.
- Immutable audit trail: PostgreSQL
audit_eventappend-only with trigger refusingUPDATE/DELETE. - Multi-tenant isolation: PostgreSQL Row-Level Security.
- IP pseudonymization: systematic SHA-256 hashing.
- Minimization: only strictly necessary data is collected.
- Security updates: monthly dependency review and patching.
9. Data retention
Retention periods are listed in section 3. After expiry, data is archived (restricted access, outside production DB) for any applicable limitation period, then definitively deleted.
10. Cookies
The institutional site and dashboard may set strictly necessary cookies (session, language). No analytics or advertising cookies without prior consent.
11. Minors
The Service is not aimed at minors. Pursuant to article 7-1 of French Law no. 78-17 of 6 January 1978 as amended (Data Protection Act), the minimum age at which a minor may consent alone to data processing in information society services is 15 years in France. ArtGuard does not knowingly collect data about persons under 15 in France, nor about persons below the applicable consent threshold in their Member State (between 13 and 16 years, per GDPR article 8). Contact dtech.innovations@proton.me if such collection occurred.
11 bis. Automated decision-making and profiling
Pursuant to GDPR articles 13(2)(f) and 14(2)(g), ArtGuard expressly declares that it does not carry out any solely automated decision-making producing legal effects or significantly affecting data subjects within the meaning of GDPR article 22, nor any profiling of End Visitors or dashboard Users. Widget detection processing is strictly deterministic and performs no assessment, segmentation, scoring, or behavioural prediction.
11 ter. Source of data — indirect collection (End Visitors)
Pursuant to GDPR article 14(2)(f), when ArtGuard processes End Visitor data, that data is not collected directly from the Visitor. It is technically emitted by the End Visitor's browser upon interaction with the Customer Site (which acts as data controller), then transmitted to the ArtGuard API by the snippet for the sole purposes described in section 3.2. ArtGuard performs no enrichment from external sources.
12. Policy evolution
This Privacy Policy may evolve. Substantial changes will be notified by email and/or displayed on the site with reasonable prior notice.
13. Contact
- Email: dtech.innovations@proton.me
- Postal address: DTech Innovations, 105 Chemin de Souleyrol, 84570 Malemort-du-Comtat, France