Focalis Technologies S.A.S. (“Focalis,” “we,” “us”) — 12 Rue de la Paix, 75002 Paris, France — [email protected] · [email protected]
Focalis Technologies S.A.S. is the data controller for personal data collected via our website, sales and support interactions, and account administration for Focalis products (Data Pipeline, Automation Suite, Integration Layer). Where we process customer data on your behalf as part of providing the software (for example, records you send through a pipeline or automation), we act as a processor under GDPR — governed by our DPA. This Policy describes our practices as controller; the DPA governs processor activity.
Contact: Focalis Technologies S.A.S., 12 Rue de la Paix, 75002 Paris, France — Email: [email protected] — Privacy/DPA inquiries: [email protected] — Phone: +33 1 23 45 67 89.
We do not intentionally collect sensitive personal data (health, biometrics, political opinions, etc.) and you should not send such data through our products unless your use case requires it and you have a lawful basis and appropriate safeguards. Customer content sent through pipelines or automations is your data — you control it.
| Purpose | Examples | Lawful basis (GDPR) |
|---|---|---|
| Provide and support the software | Provision workspaces, deliver license keys, operate the cloud-hosted option, authenticate users, provide support and status communications | Performance of contract; legitimate interests (service reliability and support) |
| Billing and contracting | Coordinate invoicing via Dodo Payments, manage subscriptions, DPA and procurement workflows | Performance of contract; legal obligation (invoicing/records) |
| Security and compliance | Detect abuse, enforce Terms, maintain audit logs, handle incidents, comply with law | Legitimate interests; legal obligation |
| Communications | Respond to inquiries, send transactional messages (receipts, security notices, renewal reminders), product updates where you have opted in | Performance of contract; consent (for marketing updates); legitimate interests |
| Improvement | Aggregated, de-identified usage metrics to improve reliability and documentation | Legitimate interests (with minimization and aggregation) |
We do not sell personal data. We do not use personal data for automated decision-making that produces legal or similarly significant effects.
Where GDPR applies, we process personal data on the bases listed above: performance of a contract, legitimate interests (balanced against your rights — e.g., operating a secure service, communicating about it, and improving it), compliance with legal obligations, and consent where we have requested it (for example, optional marketing). You may withdraw consent at any time where it is the basis for processing — withdrawal does not affect prior lawful processing.
We share personal data only as needed to operate our business and as described here:
We require processors to handle data only on our instructions, with confidentiality, security, and data-protection commitments, and to assist us with data-subject requests and breach notification.
Current sub-processors for Focalis Systems (controller and processor activity). We notify customers of material changes at least 14 days in advance via email and/or product notice, and we maintain a versioned change log on request.
| Sub-processor | Purpose | Location | Data categories |
|---|---|---|---|
| Dodo Payments | Merchant of record: checkout, payment processing, invoicing, VAT/GST calculation and remittance, subscription management | Global (as merchant of record) | Billing contact, transaction and invoice metadata; not full card data (handled by Dodo) |
| Cloud hosting provider (EU) | Compute, storage, networking for cloud-hosted product option, backups, and operational logs | EU — Frankfurt (primary); US — Virginia (optional residency) | Account, usage, and operational logs; customer content when cloud-hosted |
| Email delivery provider (EU) | Transactional email (license delivery, receipts, security notices, support replies) | EU | Email address, message content, delivery metadata |
| Error and performance monitoring (EU) | Reliability, diagnostics, and alerting | EU | Pseudonymized logs, error traces, performance metrics |
| Support desk tooling (EU) | Customer support ticket handling and knowledge base | EU | Contact and support correspondence |
On Enterprise with self-host / VPC deployment, customer content remains in your environment and the hosting sub-processor row applies only to our control plane (license and operational coordination), not to your data plane.
Change notification: Subscribe by contacting [email protected]. If you object to a new sub-processor on reasonable data-protection grounds, contact us within 14 days — we will work with you in good faith, including offering an alternative configuration or, if no reasonable alternative exists, allowing termination of the affected service without penalty (with pro-rata refund of prepaid, unused fees).
For customers who handle personal data through our products, we offer a DPA that incorporates:
To execute the DPA, contact [email protected] or your account contact. Execution does not delay your ability to use the product — the DPA can be countersigned after purchase.
We primarily process data in the EU (Frankfurt). Where you select US residency or where a processor operates globally (e.g., Dodo Payments as merchant of record), transfers outside the EEA/UK are protected by SCCs, adequacy decisions where available, or other lawful mechanisms, plus technical measures (encryption in transit and at rest) and contractual commitments. We document transfer mechanisms in the DPA.
We apply minimization — we keep what is needed for the purpose and delete or anonymize the rest.
We apply technical and organizational measures including: encryption in transit (TLS 1.2+) and at rest (AES-256), access control with least privilege and MFA for internal access, audit logging, daily backups with tested restores, network isolation, and incident response procedures. We maintain a security overview and respond to questionnaires within one business day — contact [email protected]. No system is perfectly secure, but we treat security as a contractual commitment, not a slogan.
Depending on your jurisdiction, you may have the right to:
To exercise rights, contact [email protected] or [email protected]. We respond within 30 days (sooner where law requires). We may need to verify identity and to preserve data where law or the contract requires. Where we act as processor, we assist the controller in fulfilling requests — please direct subject requests to the controller first.
Our products and site are for business use and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it.
We may update this Policy to reflect changes in processing, law, or our products. Material changes are notified by email to account contacts and by updating the “Last updated” date above. For processor activity, DPA terms control where they conflict with a policy update.
Focalis Technologies S.A.S., 12 Rue de la Paix, 75002 Paris, France — [email protected] — Privacy/DPA: [email protected] — Phone: +33 1 23 45 67 89. For billing and invoices handled via Dodo Payments, you may also use the billing portal linked from your receipt, or contact us and we will coordinate with Dodo Payments.