Privacy Policy
Personal data protection — Oursbl.eu SAS and associated services
1. Purpose and scope
Oursbl.eu SAS is committed to protecting privacy and personal data. This policy explains what data we collect, why we collect it, how long we keep it, who we share it with and what your rights are.
It applies to:
- the oursbl.eu website and its subdomains;
- our commercial, contractual and support interactions;
- the services we publish and operate: Muppy, Manganese, Sunray and Odizy.
It is written in accordance with the General Data Protection Regulation (EU Regulation 2016/679, the “GDPR”) and French Act No. 78-17 of 6 January 1978 as amended.
The website's legal notice is available on the Legal notice page.
2. Who is responsible for your data?
OURSBL.EU S.A.S., a simplified joint-stock company with share capital of €1,500, registered with the Grenoble Trade and Companies Register under SIREN 844 900 332, with registered office at 1472 route de la Croix de May, 38160 Saint-Sauveur, France.
Contact for any data protection matter: [email protected] — +33.6.85.21.89.51.
Controller or processor?
This distinction is key to understanding our obligations:
- We act as a controller for data we collect on our own behalf: website visitors, prospects, customers, partner contacts, job applicants and administration accounts for our services.
- We act as a processor, within the meaning of Article 28 GDPR, for data our customers host or process in the environments we operate for them (application databases, Manganese environments, Muppy instances, directories protected by Sunray, Odizy projects). We access such data only on the customer's documented instructions, for operations, support or security purposes. These activities are governed by a data processing agreement (DPA) signed with the customer, who remains the controller and the point of contact for data subjects.
3. What data do we process?
We only collect data that is necessary for the purposes described in section 4.
3.1 Website visitors
- Anonymous or pseudonymous audience measurement data (pages viewed, referrer, device type, country) — see section 6 on cookies.
- IP address and web server technical logs, for security and troubleshooting purposes.
3.2 Contact form and sales enquiries
- Identity and contact details: first name, last name, email address, phone number, company, job title.
- Message content: subject and body of the enquiry.
- Technical data attached to the submission: IP address, user agent, timestamp (anti-spam and proof of the request).
3.3 Customers and prospects
- Business contact details of the people we deal with.
- Contract and billing data: quotes, orders, contracts, invoices, payments.
- Relationship history: correspondence, support tickets, meeting notes.
3.4 Users of our services (Muppy, Manganese, Sunray, Odizy)
- Account data: login, name, business email, organisation, role and permissions.
- Authentication data: password hashes, SSH public keys, WebAuthn/passkey credentials, access tokens. We never store passwords in clear text.
- Activity and security logs: sign-ins, IP addresses, administrative actions, system events, operational and monitoring metrics.
- Billing and resource consumption data.
3.5 Data we do not seek
We do not knowingly collect special categories of data within the meaning of Article 9 GDPR. Our websites and services are not intended for children under 16 and we do not knowingly collect their data.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answering enquiries sent through the contact form or by email | Pre-contractual steps at the data subject's request / legitimate interest |
| Issuing quotes, entering into and performing contracts, invoicing | Performance of a contract |
| Providing, operating, monitoring and maintaining subscribed services | Performance of a contract |
| Securing our systems, preventing fraud and abuse, keeping logs | Legitimate interest / legal obligation |
| Measuring website audience in aggregate form | Legitimate interest (cookieless, tracker-free measurement) |
| B2B prospecting and information about our services | Legitimate interest, with a right to object at any time |
| Sending email communications to non-business individuals | Consent |
| Complying with accounting, tax and legal obligations | Legal obligation |
| Handling job applications | Pre-contractual steps / consent |
Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
5. How long do we keep your data?
| Category | Retention period |
|---|---|
| Contact enquiries with no follow-up | 3 years from the last contact |
| Prospects and professional networks | 3 years from the last contact |
| Contracts and related documents | Term of the contract, then 5 years (limitation period) |
| Accounting records and invoices | 10 years (Article L.123-22 of the French Commercial Code) |
| Service user accounts | Term of the contract, then deletion or anonymisation within 3 months |
| Sign-in and security logs | 12 months maximum |
| Website audience statistics | Aggregated data, kept for 13 months |
| Backups | Automatically purged according to the rotation policy of the relevant service |
| Unsuccessful job applications | 2 years from the last exchange |
Once these periods have elapsed, data is irreversibly deleted or anonymised. Data entrusted to us by customers under a service contract follows the retention period set out in the relevant contract and DPA.
6. Cookies and audience measurement
The oursbl.eu website sets no advertising cookies, no third-party cookies and no social network trackers. We use neither Google Analytics nor any advertising network, and we never sell data.
Audience measurement relies on an open-source solution that we host ourselves on our own infrastructure, in Europe. It works without cookies and without any persistent identifier: measurements are aggregated and cannot identify you or track you across websites. No data is sent to any third party. Accordingly, and in line with the French data protection authority's guidance on exempt audience measurement solutions, no consent banner is required.
Only strictly necessary cookies may be set when using our authenticated applications (session cookie, language preference). These are exempt from consent.
7. Who has access to your data?
Your data is intended for authorised staff of Oursbl.eu SAS, within the limits of their duties. It is never sold, rented or traded.
It may be disclosed to:
- our technical processors, strictly as required to deliver the service;
- our usual advisers (accountant, lawyer, statutory auditor);
- administrative or judicial authorities, where required by law.
Main processors
| Processor | Role | Location |
|---|---|---|
| OVHcloud | Server and infrastructure hosting | European Union |
| Scaleway | Server and infrastructure hosting | European Union |
Each processor is selected for its security and confidentiality guarantees, acts solely on our documented instructions and is bound by a contract compliant with Article 28 GDPR. An up-to-date list of processors is available on request at [email protected].
8. Where is your data hosted?
Digital sovereignty is at the heart of what we do. Our services and the data associated with them are hosted within the European Union, with European operators, and are not subject to extraterritorial access legislation.
We carry out no transfer of personal data outside the European Union in our ordinary course of business. Should such a transfer become necessary, it would be made to a country covered by a European Commission adequacy decision or framed by appropriate safeguards under Article 46 GDPR (standard contractual clauses), and this policy would be updated accordingly.
9. How do we protect your data?
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- encryption of communications (TLS) across all our websites and services;
- isolation of environments and databases per customer;
- strong authentication for administrative access (SSH keys, WebAuthn passkeys via Sunray);
- access rights managed on a least-privilege basis;
- logging, monitoring and alerting of access and security events;
- regular backups with tested restore procedures;
- timely security patching and ongoing security maintenance.
Where we process health data or other sensitive data on behalf of a customer, we apply particular vigilance and host such data on our own servers, within the framework set out in the contract.
We maintain a record of processing activities, both as a controller and as a processor, in accordance with Article 30 GDPR.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the CNIL within 72 hours and inform the data subjects where the risk is high, in accordance with Articles 33 and 34 GDPR.
10. Your rights
Under the GDPR you have the following rights:
- Access: obtain confirmation that your data is processed and receive a copy of it.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: request deletion of your data, within the limits of our legal obligations.
- Restriction: request that processing be temporarily suspended.
- Objection: object to processing based on our legitimate interest, and at any time to direct marketing.
- Portability: receive the data you provided to us in a structured, machine-readable format.
- Withdrawal of consent at any time, where processing is based on consent.
- Post-mortem instructions: define what happens to your data after your death.
To exercise these rights, write to [email protected] or by post to Oursbl.eu SAS, 1472 route de la Croix de May, 38160 Saint-Sauveur, France. We may ask for proof of identity where there is reasonable doubt about who you are. We reply within one month, extendable by two months for complex requests.
If you use a service we operate on behalf of one of our customers, please send your request directly to that customer, who is the controller. We will assist them in handling it.
You also have the right to lodge a complaint with the CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.
11. Changes to this policy
This policy may change to reflect developments in our services, our processors or the regulatory framework. The date of the latest update appears at the top of this page. In case of a material change, we inform the data subjects concerned by appropriate means.
Any question about this policy: [email protected].