Privacy Policy
This English version is provided for convenience. In case of discrepancy, the French version (amalyon.com/privacy) is authoritative.
Last updated: May 30, 2026 · Effective date: May 30, 2026
✓ GDPR CompliantYour privacy matters to us. This policy explains what data we collect, how we use it, and what rights you have as a data subject under the General Data Protection Regulation (GDPR).
Table of contents
1. Data Controller
The data controller for personal data collected through the amalyon Service is:
- Entity: amalyon
- Service: amalyon SaaS platform — automated GDPR compliance and web security audits
- Email: privacy@amalyon.com
2. Data We Collect
2.1 Data You Provide to Us
| Category | Data | Purpose |
|---|---|---|
| Account | Company name, email address, password (hashed) | Account creation and management |
| Payment | Billing information (processed by Stripe) | Payment processing |
| Application | WordPress URL, WooCommerce API credentials, logo, colors | Mobile app generation |
| Communications | Messages sent to our support team | Technical assistance |
2.2 Data Collected Automatically
| Category | Data | Purpose |
|---|---|---|
| Technical logs | IP address, browser type, pages visited, timestamps | Security, debugging, Service improvement |
| Cookies | Session identifier, preferences | Authentication, Service functionality |
| Usage data | Dashboard actions, build statuses | Service improvement |
We do not collect special category data within the meaning of the GDPR (health data, ethnic origin, political opinions, etc.).
3. How We Use Your Data
Your personal data is used to:
- Create and manage your account;
- Provide the Service (automated compliance and security audits);
- Process your payments;
- Send you transactional emails (order confirmation, download link, invoices);
- Contact you for technical support;
- Comply with our legal and regulatory obligations;
- Detect and prevent fraud and abuse;
- Improve and optimize the Service (aggregated, anonymized analytics).
We do not use your data for marketing purposes without your prior consent.
4. Legal Basis for Processing
| Processing Activity | Legal Basis (GDPR Art. 6) |
|---|---|
| Providing the Service and managing your account | Contract performance (Art. 6(1)(b)) |
| Payment processing | Contract performance (Art. 6(1)(b)) |
| Security logs and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations (accounting, VAT) | Legal obligation (Art. 6(1)(c)) |
| Marketing emails (if consented) | Consent (Art. 6(1)(a)) |
| Non-essential cookies (if accepted) | Consent (Art. 6(1)(a)) |
5. Sharing with Third Parties
We do not sell your personal data. We may share it with processors in the following cases:
- Stripe – Payment processing (Stripe privacy policy);
- Railway – Service and database hosting (USA, EU region available);
- SendGrid (Twilio) – Transactional email delivery (USA, covered by the Data Privacy Framework);
- Anthropic – AI processing of submitted audit data (USA, governed by EU Standard Contractual Clauses);
- Competent authorities – Upon legal or judicial request.
All our processors are bound by contractual data protection obligations compliant with the GDPR.
6. Data Retention Period
| Data Category | Retention Period |
|---|---|
| Active account data | For the entire duration of account activity |
| Closed account data | 90 days after closure, then deletion |
| Billing / accounting data | 10 years (statutory tax obligation) |
| Security logs | 12 months |
| Session cookies | Duration of the session (deleted when the browser is closed) |
| Functional cookies | 13 months maximum |
7. Cookies and Similar Technologies
7.1 What Is a Cookie?
A cookie is a small text file placed on your device when you visit a website. It allows the site to remember information about your browsing activity.
7.2 Cookies We Use
| Cookie | Type | Duration | Purpose |
|---|---|---|---|
token (sessionStorage) |
Essential | Session duration | JWT authentication |
cookie_consent |
Functional | 13 months | Remembering your cookie preferences |
7.3 Managing Cookies
You can control and/or delete cookies at any time through your browser settings. Deleting the authentication token will log you out of the Service.
8. International Transfers
Your data may be processed by our processors (Stripe, Railway, SendGrid, Anthropic) in countries located outside the European Economic Area (EEA), including the United States. These transfers are governed by Standard Contractual Clauses approved by the European Commission and/or the EU-US Data Privacy Framework, ensuring an adequate level of protection.
9. Your GDPR Rights
As a data subject, you have the following rights over your personal data:
- Right of access (Art. 15): obtain a copy of your data;
- Right to rectification (Art. 16): correct inaccurate data;
- Right to erasure (Art. 17): request deletion of your data;
- Right to restriction of processing (Art. 18): limit the use of your data;
- Right to data portability (Art. 20): receive your data in a structured format;
- Right to object (Art. 21): object to certain processing based on legitimate interest;
- Withdrawal of consent: withdraw your consent at any time (without affecting the lawfulness of processing carried out before withdrawal).
To exercise your rights, contact us at privacy@amalyon.com. We will respond within one month. If you are not satisfied with our response, you may lodge a complaint with the CNIL (cnil.fr), the French data protection authority.
10. Minors
The Service is intended for individuals aged 18 and over. We do not knowingly collect personal data from minors. If you believe a minor has provided us with data, please contact us immediately at privacy@amalyon.com.
11. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (HTTPS/TLS) and at rest;
- Passwords stored in hashed form (bcrypt);
- JWT authentication with expiration;
- Login attempt rate limiting;
- Data access restricted to authorized personnel;
- Security HTTP headers (HSTS, X-Frame-Options, CSP);
- Continuous monitoring and access logging.
In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify you within 72 hours in accordance with Article 33 of the GDPR.
12. Changes to This Policy
We may amend this policy at any time. In the event of a material change, we will notify you by email at least 30 days before it takes effect. The "last updated" date at the top of this page indicates the version currently in force.
13. Contact & DPO
For any question about this policy or to exercise your rights:
- Email: privacy@amalyon.com
- Recommended subject line: "GDPR Rights Request – [your email]"
To file a complaint with the supervisory authority: CNIL – Online complaints