Data protection · GDPR transparency

Privacy Policy

This policy sets out how Fixery® collects, uses, retains and protects personal data across its services and its client relationships.

Explicit purposes · Defined retention periods · Rights respected

Last updated: 30 May 2026

Our privacy commitment

Fixery® is committed to protecting the privacy of its users and clients. This Privacy Policy explains what information we collect, why we collect it, how we use it and what rights you have over your personal data, in accordance with the General Data Protection Regulation (GDPR).

1. Roles: data controller and data processor

The controller for the data collected on the fixery.fr website and in the course of the client relationship is:

Allan Desgranges (Fixery®)
Campus 120, Z.I. République, 120 rue du Porteau, 86000 Poitiers, France
Privacy contact email: [email protected]

Fixery® acts as the data controller within the meaning of the GDPR for the processing described below (data collected through the website and in the course of its own client relationship).

By contrast, when Fixery® accesses personal data hosted within the information systems of its business clients — in particular as part of its maintenance, managed IT and supervision services — Fixery® acts as a data processor within the meaning of Article 28 of the GDPR. That data is then processed solely on behalf of, and on the documented instructions of, the client, who remains the data controller. This processing is governed by the sub-processing clauses set out in the service agreement or by a dedicated data processing agreement (DPA), in accordance with Article 28 of the GDPR: subject matter, duration, nature and purpose of the processing, categories of data and of data subjects, confidentiality and security obligations, the framework for any further sub-processing, and the fate of the data at the end of the contract.

2. Data collected, purposes and legal bases

We collect different categories of data for specific purposes, relying on legal bases that comply with the GDPR.

a. Managing the client relationship and delivering services

  • Data collected: First name, last name, email address, phone number, company details where applicable, and the history of services subscribed (tickets, invoices, quotes, interventions).
  • Purpose: To deliver the services set out in the contract, manage the client relationship, respond to your support requests and communicate on the transactional aspects of our relationship.
  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR).

b. Billing and legal obligations

  • Data collected: Billing information (company name, postal address, contact details, breakdown of the services provided).
  • Purpose: To issue invoices, maintain proper accounting records and meet our legal and tax obligations.
  • Legal basis: Legal obligation (Article 6(1)(c) GDPR).

c. Platform security and fraud prevention

  • Data collected: IP address, connection logs, technical identifiers, device and browser information.
  • Purpose: To prevent fraud, diagnose incidents, secure our information systems and protect your data.
  • Legal basis: Legitimate interest (Article 6(1)(f) GDPR) in protecting our infrastructure and your data.

d. Marketing and informational communications

  • Data collected: First name, last name, email address, history of the commercial relationship.
  • Purpose: To send you, in a measured way, information about services similar to those already provided or about Fixery® news.
  • Legal basis: Fixery®'s legitimate interest in informing its business clients (Article 6(1)(f) GDPR), with the ability for you to object to these communications at any time.

e. Audience measurement and site improvement

  • Data collected: Aggregated and anonymised browsing data, page views, technical events (errors, performance).
  • Purpose: To improve the usability, performance and security of the site, without any individual tracking of visitors.
  • Legal basis: Legitimate interest (Article 6(1)(f) GDPR), in line with the guidance of the French data protection authority (CNIL) on audience measurement that is exempt from consent where the data is anonymised.

3. Retention periods

We keep your data only for as long as necessary for the purposes pursued, plus any applicable statutory limitation periods.

  • Client and contractual data: kept for the entire duration of the contractual relationship, then archived for a maximum of 5 years from the end of the relationship, for evidential purposes.
  • Billing and accounting data: kept for 10 years, in accordance with French legal obligations.
  • Connection and security logs: kept for a maximum of 12 months to secure the platform and prevent malicious activity.
  • Prospect data (contact form with no resulting contract): kept for up to 3 years from your last contact or from a message that remained unanswered.

Beyond these periods, data is deleted or irreversibly anonymised.

4. Recipients and processors

Fixery® does not sell, trade or transfer any of your identifiable personal data to commercial third parties. Your data may be shared only with the following recipients:

  • Staff members and providers involved in delivering the services subscribed.
  • Hosting and technical services: Automattic, Inc. / WordPress.com (website hosting) and Cloudflare, Inc. (CDN, security, acceleration and cookieless anonymous audience measurement via Cloudflare Web Analytics).
  • Professional email: Google Workspace (Google Ireland Limited).
  • Where applicable, administrative or judicial authorities when required by law.

All our processors are carefully selected for their GDPR compliance and are contractually bound by strict obligations of confidentiality, security and processing of data solely on our instructions.

Some of these providers may be located outside the European Union. In such cases, we ensure that transfers are governed by mechanisms recognised under the GDPR (for example, adequacy decisions, membership of the Data Privacy Framework, or standard contractual clauses).

5. Data security

We implement a range of technical and organisational measures to safeguard the security of your personal information. In particular, we use up-to-date encryption (TLS 1.2/1.3) to protect sensitive information transmitted online. Data at rest is also encrypted on the secure infrastructure of our cloud provider.

Access to data is strictly limited on a least-privilege basis. Only duly authorised individuals, bound by a duty of confidentiality, may access your data in the course of their duties.

6. Your rights

In accordance with the GDPR, you have the following rights over your data:

  • Right of access: You can request a copy of the data we hold about you.
  • Right to rectification: You can ask us to correct or update inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): You can request the deletion of your data, subject to our legal retention obligations.
  • Right to restriction of processing: You can ask that the use of your data be temporarily frozen in certain cases.
  • Right to object: You can object, on grounds relating to your particular situation, to certain processing based on our legitimate interest.
  • Right to data portability: You can ask to receive the data you have provided to us in a structured format.
  • Right to set post-mortem directives: You can define what happens to your data after your death.

To exercise these rights, you can contact us at: [email protected]. Where necessary, we may ask you for proof of identity in order to verify your request.

We will endeavour to respond within one (1) month of receiving your request, a period that may be extended by two (2) months where requests are complex or numerous.

If you are unable to resolve a difficulty with us, you also have the right to lodge a complaint with the competent supervisory authority, in particular the Commission Nationale de l’Informatique et des Libertés (CNIL), the French data protection authority: www.cnil.fr.

7. Cookies and similar technologies

We use only technical cookies that are strictly necessary for the proper functioning of the site (caching, security). Audience measurement is carried out on a strictly anonymous basis, with no advertising cookies, no tracking and no individual profiling.

For more information on the types of cookies used and how to configure your browser, please see our Cookie Policy.

8. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time to reflect regulatory, technical or organisational changes affecting our data processing. In the event of a substantial change, we will inform you by any appropriate means.

The "last updated" date at the top of this page lets you identify the version currently in force.

A question about your data?

For any request relating to this policy, or to exercise your rights, write to us at [email protected].