Personal data protection
Read the French version
Version 2.1 — updated 26 July 2026
1. Who is responsible for this processing
Secufor, a simplified joint-stock company registered with the Nanterre Trade and Companies Register under number 931 143 572, with its registered office at 69 rue Louise Michel, 92300 Levallois-Perret, France.
For any question about your data, or to exercise your rights : dpo[at]secufor.net. We answer at that address ; there is no need to go through the contact form.
2. What we collect, and why
The table below is exhaustive. It does not describe what we might do one day, but what the site does today.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Username, email address, password — the latter kept as a hash, never in clear text | Creating and managing your account, identifying you | Performance of the contract | For as long as your account exists |
| Password-reset token and its expiry date | Letting you regain access to your account | Performance of the contract | One hour, after which the token stops working |
| Hash of your session token, creation and last-use dates, your browser’s user agent | Keeping you signed in and spotting abnormal use | Legitimate interest (account security) | Thirty days at most, then deleted automatically. A revoked token (sign-out) is kept for a further seven days for incident investigation, then deleted. |
| Plan subscribed to, and licence key, encrypted in the database | Delivering the product you bought and verifying your licence | Performance of the contract | For the duration of the subscription |
| Proof that you accepted the T&Cs : version accepted, timestamp, and any waiver of the right of withdrawal | Establishing what you agreed to, and when | Legitimate interest (evidence) and legal obligation | Five years from the order |
| References for your subscription with our payment provider : session, customer and subscription identifiers, the plan subscribed to, the subscription status and the end date of the current period | Linking your account to your subscription, delivering your licence, ending it on cancellation, and retrieving your invoices from our provider | Performance of the contract, and legal obligation as regards accounting records (art. L123-22 of the French Commercial Code) | Ten years — the retention period for the accounting records these references give access to |
| Message sent through the contact form : first name, surname, email address and message body | Replying to you | Steps taken at your request (art. 6(1)(b)) | The message reaches us by email and is not stored in the database. It remains in our mailbox for as long as it takes to handle your request. |
| Hash of your IP address at the time of submission — the address itself is not kept | Preventing bulk automated submissions, which would get our email flagged as spam | Legitimate interest (service security) | 24 hours |
| Server technical logs, including the IP address | Security and fault diagnosis | Legitimate interest | As per our host’s policy, twelve months at most |
What we never receive : your card number, its expiry date and its security code. The amounts charged and your invoices themselves are held by our provider, not by us : we keep only the references needed to retrieve them. Payment takes place on the pages of our provider Stripe, and those details do not pass through our servers. All we receive is confirmation that a payment has been made.
Periodic signal from the extensions — allowed by the contract, no data received to date
Article 5.3.5 of the terms of use allows an Application to transmit periodically the identifier of the licensed site, the version installed and its activation status, for the sole purposes of verifying the licence and monitoring proper operation.
No Application does so today, and the table above therefore remains exhaustive. We mention it here because a contractual authorisation is not a collection, and the latter must not be discovered after the fact : on the day an Application emits this signal, its description page will say so and the table above will be completed BEFORE it goes live — retention period and legal basis included. The signal will remain disableable without any loss of functionality.
3. What we do not do
It seems just as useful to state what does not happen :
- No advertising, no targeting, no retargeting. We pass nothing to ad networks or advertising platforms.
- No profiling, and no automated decision producing effects concerning you.
- No analytics : no Google Analytics, nor any equivalent. See our cookie policy.
- No newsletter, no promotional message. The only automated email we can send you is the one that lets you reset your password, and you are the one who triggers it. If you write to us, we reply — that goes without saying, and it stops there.
- No sale, no rental, no exchange of your data.
- No collection by the plugins. WPOAuth and WPSQL run on your server and send us nothing, apart from the verification of your licence key — which contains no data about your own users.
4. Who else has access
Two providers only, each for one precise task :
- Stripe — collecting payments. Stripe gathers payment details directly from you, on its own pages.
- OVHcloud — hosting the site and the database, and delivering the password-reset email. The servers are located in the European Union.
Apart from these two providers, your data is disclosed to no one — save for a request from a judicial or administrative authority empowered to make it, with which we are bound to comply.
5. Where your data is
The data we hold is hosted in the European Union. Stripe, whose group is established in the United States, may process data outside the Union ; such transfers rely on the safeguards provided for in Chapter V of the GDPR and are described in its own privacy policy.
6. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions as to what becomes of your data after your death.
To exercise them, write to dpo[at]secufor.net. We reply within one month. If your request is complex, that period may be extended by two months ; we will tell you so within the first month.
Deleting your account : we do so within thirty days of your request. Some data must nevertheless be kept beyond that point because the law requires it : accounting records (ten years) and proof of your acceptance of the T&Cs (five years). It is then set apart and used for that purpose alone.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr. If you reside in another Member State, you may also contact your own supervisory authority.
7. How your data is protected
- The site and the API are served over HTTPS only.
- Passwords are kept as a hash, never in clear text. They cannot be recovered — not even by us.
- Licence keys are encrypted in the database.
- Session tokens are likewise never stored in clear text : the database holds only a hash, so a database leak would not allow anyone to sign in as you.
- Downloading the product is restricted to accounts holding the corresponding subscription.†
† This wording will be strengthened — “requires genuine authentication; knowing an account identifier is not enough” — once session-token verification is deployed, which is under way. We would rather promise less than we are about to deliver than the reverse.
If you find a vulnerability, our reporting procedure is set out on the Security page.
8. Cookies
This site sets no advertising, analytics or social-network cookies. The details are in our cookie policy.