Contents
- Article 1 - Purpose
- Article 2 - Definitions
- Article 3 - Location of processing
- Article 4 - Protection measures
- Article 5 - Trash and intermediate retention
- Article 6 - Retention periods
- Article 7 - Backups
- Article 8 - Restitution and reversibility
- Article 9 - Deletion
- Article 10 - Transfers outside the European Union
- Article 11 - Amendments
The purpose of this policy is to inform the User, in a complete manner, of the storage locations of the data processed in connection with the Noryo service (hereinafter the "Service"), of the associated protection measures and of the retention periods applied. It supplements the Privacy Policy and the Security Policy.
Article 1 - Purpose
This policy aims to guarantee transparency as to the conditions of storage, protection, retention, restitution and deletion of the User's data.
Article 2 - Definitions
Definitions
- Storage
- the retention of data on a computer medium managed by the Publisher or its subprocessors.
- Backup
- the security copy made in order to ensure the continuity and resilience of the Service.
- Retention
- the period during which a piece of data is stored before deletion or anonymisation.
Article 3 - Location of processing
3.1 Database and application storage
Accounts, transactions and structured data are hosted by Supabase, within the European Union (Frankfurt, Germany).
3.2 Documents and files
Documents imported or received by the User are stored by Scaleway, in France (Paris).
3.3 Application hosting
The website and interfaces are hosted by Vercel, whose processing may take place in the United States and within the European Union, under standard contractual clauses.
3.4 Subprocessors Register
The complete list of providers involved in the storage and processing of data, as well as their location, is set out in the Subprocessors Register.
Article 4 - Protection measures
4.1 Encryption at rest
Imported documents are stored encrypted at rest at the storage provider.
4.2 Encryption in transit
Exchanges are encrypted by means of secure transport protocols, under the conditions described in the Security Policy.
4.3 Segregation
Strict access rules ensure that each User accesses only their own data.
4.4 Encrypted backups
Backups are protected by appropriate security measures and are accessible only to authorised persons.
Article 5 - Trash and intermediate retention
Items placed in the trash are retained for seven days before final deletion, in order to allow their possible restoration by the User. After this period, they are deleted, including from the file storage spaces.
Article 6 - Retention periods
Data is retained only for the period strictly necessary for the purposes described in the Privacy Policy, then deleted or anonymised.
| Data | Period |
|---|---|
| Account and profile | duration of the account, then erasure within thirty days |
| Financial data and transactions | duration of the account |
| Documents and files | duration of the account; trash seven days |
| Support | ninety days after closure |
| Security and audit logs | up to twelve months |
| Audience measurement | thirteen months at most |
| Accounting records | up to ten years |
Article 7 - Backups
Secure backups are made in order to ensure the continuity of the Service and the resilience of the data in the event of an incident. They are retained for a limited and rolling period, then overwritten. Backups are not used for purposes other than the restoration of the Service.
Article 8 - Restitution and reversibility
The User may export their data at any time from the Service, in readable formats (JSON, CSV or PDF), under the conditions specified on the Exercise your rights page. This option remains available, including after a paid subscription.
Article 9 - Deletion
9.1 Deletion on request
Upon deletion of the account, the data is erased within thirty days, subject to legal retention obligations.
9.2 Legal retention obligations
Certain data, in particular accounting records, may be retained beyond that period, for the sole duration imposed by law, then deleted.
Article 10 - Transfers outside the European Union
When data is stored or processed outside the European Union, transfers are governed in accordance with Article 14 of the Privacy Policy, in particular by means of standard contractual clauses or an adequacy decision.
Article 11 - Amendments
This policy may be updated. The applicable version is the one in force at the time of use of the Service.