REGULATORY INFORMATION

Personal data protection (GDPR)

This policy explains what personal data Phenisys processes, why it is processed, how long it is retained and the rights available to users.

Data controller and contact

Phenisys SAS (“Phenisys”), a French simplified joint-stock company with share capital of €22,692, registered under SIREN number 539 060 327 with the Lyon Trade and Companies Register, whose registered office is located at 61 Cours de la Liberté, 69003 Lyon, France, represented by Christophe Nétillard, acts as the controller of the personal data collected.

For any request concerning personal data: contact@phenisys.com

Data collected and purposes of processing

Phenisys processes only the data submitted through messaging services or contact forms: telephone number, first and last name, photographs and message content.

Where other data is provided through another channel, it is processed under the same data protection requirements.

This data is used exclusively to automate exchanges, handle user requests automatically or manually, including through a conversational agent, and provide user support.

No processing is carried out for commercial, advertising or marketing purposes.

Retention, hosting and security

Collected data is deleted no later than one month after receipt. It is not intended to be retained beyond this period.

The data is hosted exclusively in France on a secure private server operated by OVHcloud.

Access is restricted to authorised Phenisys employees and protected by strong multi-factor authentication (MFA). No other third party or processor has access to this data.

Your data protection rights

Under the GDPR, every user has the right to access, rectify and erase their data, restrict its processing, receive it in a portable format and object to its processing.

You can exercise these rights by writing to contact@phenisys.com.

Breaches, transfers and policy updates

In the event of a personal data breach or suspected breach, Phenisys will notify the CNIL within 72 hours in accordance with applicable requirements, inform affected individuals where there is a high risk to their rights and freedoms, and take the necessary steps to identify, remedy and prevent the incident.

No user data is transferred, exchanged or shared with third parties in France or abroad, except where required by law following an explicit and substantiated request from the competent French authorities.

This policy may be updated to reflect regulatory and technical developments. Users will be informed of any material change.

Last updated: 20 March 2025.

Personal data protection (GDPR) | Phenisys | Phenisys