Privacy Policy
Last updated: January 5, 2026
1. Introduction
DxLean is committed to protecting the confidentiality and security of your personal data. This privacy policy describes how we collect, use and protect your information in accordance with the General Data Protection Regulation (GDPR).
2. Data Controller
Status: Auto-entrepreneur
Name: Guerreiro Daillant Lyssandre
SIRET: 844 496 752 00024
Contact: lyssandre.gd@dxlean.eu
3. Personal Data Collected
3.1 Identification data
- Username, first name, last name
- E-mail address
- Phone number (optional)
- Profile photo (optional)
3.2 Professional data
- Department and position
- Organizational branch
- Notification preferences
3.3 Authentication data
- Azure AD authentication token (not stored, used for session only)
- Last login date
3.4 Navigation data
- Access logs (IP address, timestamp) - retained for 30 days
- Essential session cookies only
4. Processing Purposes
| Purpose | Legal basis |
|---|---|
| User account management and authentication | Performance of contract (Art. 6.1.b GDPR) |
| Management of non-conformities and quality processes | Legitimate interest (Art. 6.1.f GDPR) |
| Email notifications | Performance of contract + Consent |
| Human resources management | Performance of contract |
| Working time tracking (time clock) | Performance of contract |
| Security and traceability (logs) | Legitimate interest (IT security) |
5. Data Recipients
- DxLean technical team: Platform administration and maintenance
- Your organization's administrators: User management
- Quality team: Non-conformity processing
- Subcontractors:
- OVH (hébergement - France)
- Microsoft Azure AD (authentification - USA, clauses contractuelles types)
6. Transfers Outside the European Union
Some data may be transferred to countries outside the EU:
Microsoft Azure AD (États-Unis)
OAuth authentication protected by Standard Contractual Clauses (SCC) approved by the European Commission.
7. Retention Period
| Data type | Duration |
|---|---|
| User accounts | Contract duration + 3 years (archiving) |
| Non-conformities and quality actions | 5 years minimum (ISO 9001 standards) |
| Access logs | 30 days (automatic rotation) |
| Time tracking data | 5 years (Labour Code) |
8. Security Measures
- Mandatory HTTPS encryption (TLS 1.2+)
- Secure authentication via Azure AD (OAuth 2.0)
- Data isolation per client (separate databases)
- CSRF and XSS protection
- Role-based access control
9. Your Rights
In accordance with the GDPR, you have the following rights:
Right of access
Obtain a copy of your personal data
Right of rectification
Correct your incorrect information
Right to erasure
Request the deletion of your data
Right to portability
Retrieve your data in a structured format
Right to object
Object to certain processing activities
Right to restriction
Restrict the processing of your data
Exercise your rights
To exercise any of these rights, contact us at:
E-mail : lyssandre.gd@dxlean.eu
Response time: 1 month maximum
10. Right to Lodge a Complaint
If you believe your rights are not being respected, you have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL):
11. Cookies
DxLean uses only strictly necessary cookies for the operation of the platform (session cookies). No tracking or advertising cookies are used.
Session cookies are automatically deleted when you close your browser.
12. Modifications to this Policy
We reserve the right to modify this privacy policy at any time. Modifications will be published on this page with a new update date.
13. Contact Us
For any questions regarding this privacy policy or the processing of your data: