Module
Module
Home
SIGN IN

Privacy Policy

Last updated: January 5, 2026

Also consult our Legal Notice

1. Introduction

DxLean is committed to protecting the confidentiality and security of your personal data. This privacy policy describes how we collect, use and protect your information in accordance with the General Data Protection Regulation (GDPR).

2. Data Controller

Status: Auto-entrepreneur

Name: Guerreiro Daillant Lyssandre

SIRET: 844 496 752 00024

Contact: lyssandre.gd@dxlean.eu

3. Personal Data Collected

3.1 Identification data

  • Username, first name, last name
  • E-mail address
  • Phone number (optional)
  • Profile photo (optional)

3.2 Professional data

  • Department and position
  • Organizational branch
  • Notification preferences

3.3 Authentication data

  • Azure AD authentication token (not stored, used for session only)
  • Last login date

3.4 Navigation data

  • Access logs (IP address, timestamp) - retained for 30 days
  • Essential session cookies only

4. Processing Purposes

Purpose Legal basis
User account management and authentication Performance of contract (Art. 6.1.b GDPR)
Management of non-conformities and quality processes Legitimate interest (Art. 6.1.f GDPR)
Email notifications Performance of contract + Consent
Human resources management Performance of contract
Working time tracking (time clock) Performance of contract
Security and traceability (logs) Legitimate interest (IT security)

5. Data Recipients

  • DxLean technical team: Platform administration and maintenance
  • Your organization's administrators: User management
  • Quality team: Non-conformity processing
  • Subcontractors:
    • OVH (hébergement - France)
    • Microsoft Azure AD (authentification - USA, clauses contractuelles types)

6. Transfers Outside the European Union

Some data may be transferred to countries outside the EU:

Microsoft Azure AD (États-Unis)

OAuth authentication protected by Standard Contractual Clauses (SCC) approved by the European Commission.

7. Retention Period

Data type Duration
User accounts Contract duration + 3 years (archiving)
Non-conformities and quality actions 5 years minimum (ISO 9001 standards)
Access logs 30 days (automatic rotation)
Time tracking data 5 years (Labour Code)

8. Security Measures

  • Mandatory HTTPS encryption (TLS 1.2+)
  • Secure authentication via Azure AD (OAuth 2.0)
  • Data isolation per client (separate databases)
  • CSRF and XSS protection
  • Role-based access control

9. Your Rights

In accordance with the GDPR, you have the following rights:

Right of access

Obtain a copy of your personal data

Right of rectification

Correct your incorrect information

Right to erasure

Request the deletion of your data

Right to portability

Retrieve your data in a structured format

Right to object

Object to certain processing activities

Right to restriction

Restrict the processing of your data

Exercise your rights

To exercise any of these rights, contact us at:

E-mail : lyssandre.gd@dxlean.eu
Response time: 1 month maximum

10. Right to Lodge a Complaint

If you believe your rights are not being respected, you have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL):

CNIL

3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

www.cnil.fr

11. Cookies

DxLean uses only strictly necessary cookies for the operation of the platform (session cookies). No tracking or advertising cookies are used.

Session cookies are automatically deleted when you close your browser.

12. Modifications to this Policy

We reserve the right to modify this privacy policy at any time. Modifications will be published on this page with a new update date.

13. Contact Us

For any questions regarding this privacy policy or the processing of your data:

  • lyssandre.gd@dxlean.eu
Legal Notice Privacy Policy Contact
© 2026 DxLean
Home Modules Contact

Navigation

Information

Contact Legal Notice Confidentialité

DxLean

Please wait, do not close this page.