Privacy Policy
Version: July 31, 2026
At Octensoft ("Ecomposable," "we," "our"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, share, and protect your data when you interact with our website, platform, and services.
It complies with the General Data Protection Regulation (GDPR) and applicable French law.
1. Scope
This Privacy Policy applies to:
- Visitors to our website and marketing pages.
- Users registered on the ecomposable Platform.
- Organizations and individuals using our Digital HQ + Operations Hub or SaaS Launchpad services.
If you use the Platform to process data on behalf of your own end users or customers (e.g., website visitors, email subscribers, support contacts), we act as a data processor for that data under your instructions. Our Data Processing Agreement (DPA) defines our respective responsibilities.
2. Information We Collect
We collect different types of data depending on how you interact with us.
2.1 From Website Visitors
- Contact forms: Name, email address, and any information you provide in your message.
- Waiting list: Name, company name, and email address to notify you of service availability.
- Cookies and tracking technologies:
- Microsoft Clarity and Microsoft Advertising: Used to analyze site usage through behavioral metrics, heatmaps, and session recordings. These data (IP addresses, mouse movements, etc.) are processed in accordance with Microsoft's Privacy Statement.
- Google reCAPTCHA: Used to prevent fraudulent activities. Google collects data (IP address, user behavior) to verify that you are human, in accordance with its Privacy Policy.
- You can configure your cookie preferences through your browser settings or our cookie consent tool.
2.2 From Registered Users
- Account information: Name, email address, company name, role, phone number (optional).
- Billing information: Payment method details, billing address, invoice data. Payment details are processed by our payment providers, not stored directly on our systems.
- Platform usage data: Access logs, login history, configuration preferences, and usage metrics necessary to operate and secure the Platform.
2.3 From Digital HQ + Operations Hub Customers
When you use the Platform to host your Digital HQ, we process data on your behalf, including:
- Your end users' data: Any personal data collected through your tools (WordPress visitors, CRM contacts, email subscribers, support tickets, etc.).
- Content and operational data: Website content, files, documents, configurations, analytics data, backups.
- Access logs and security data: IP addresses, authentication logs, and activity records for security and compliance.
All processing of this data is performed under your instructions, as documented in our DPA.
2.4 From SaaS Launchpad Customers
When you use the SaaS Launchpad to build and operate your own products, we process:
- Application data: Data generated by your applications, stored in your own databases on your cluster.
- CI/CD and infrastructure data: Repository access, build logs, deployment history, monitoring data.
- Observability data: Metrics, logs, and traces collected by the monitoring stack (Prometheus, Thanos, Grafana).
You control access to this data. We may access it only for support, maintenance, or security purposes under defined operational procedures.
3. How We Use Your Information
3.1 As Data Controller (Your Account and Relationship)
We process your personal data to:
- Respond to your requests and inquiries.
- Manage your account and provide access to the Platform.
- Process payments and issue invoices.
- Notify you of service availability, updates, or maintenance.
- Send operational communications (e.g., security alerts, billing notices).
- Improve the security, performance, and reliability of the Platform.
- Send marketing communications (only with your prior consent).
We do not use your personal data for commercial purposes without your explicit consent.
3.2 As Data Processor (Your Digital HQ and Applications)
When processing data on your behalf:
- We do so strictly under your documented instructions.
- We do not sell, rent, or share your end users' data with third parties except as described below.
- We do not use your end users' data for our own purposes.
- You remain the data controller responsible for compliance with data protection laws (including obtaining necessary consents from your end users).
4. Legal Basis for Processing
Under GDPR, we rely on the following legal bases:
- Contract: Processing necessary to fulfill our agreement with you (provide the Platform, host your tools, process payments).
- Consent: Optional processing such as marketing communications or use of non-essential cookies.
- Legitimate interest: Platform security, abuse prevention, performance optimization, and legal compliance.
- Legal obligation: Retention of financial and contractual records as required by law.
5. Sharing Your Data
We do not sell or exchange your personal information with third parties.
We share data only in the following cases:
5.1 Subprocessors
We engage subprocessors to deliver our services, including:
- Cloud infrastructure providers: AWS, GCP, Alibaba Cloud, OVH, Scaleway, and others (depending on deployment).
- SMTP providers: AWS SES, SendGrid, or equivalent for email delivery.
- Monitoring and analytics: Microsoft Clarity, Google reCAPTCHA.
- Payment processors: For handling billing and transactions.
- Support and communication tools: For internal operations.
All subprocessors are bound by contractual data protection obligations (GDPR-compliant DPAs). A current list is available on request.
5.2 Legal Obligations
We may disclose your data when required by law, court order, or regulatory authority.
5.3 Security and Enforcement
We may share data to protect the security, integrity, or rights of the Platform, its users, or third parties (e.g., to prevent abuse, fraud, or malicious activity).
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you and ensure continued protection under these Terms or an equivalent privacy framework.
5.5 Third-Party Tools on Your Digital HQ
Tools deployed on your Digital HQ (WordPress, CRM, analytics, etc.) may include integrations, plugins, or third-party services configured by you. These services may process data under their own privacy policies. You are responsible for ensuring compliance.
6. Data Storage and Retention
6.1 Storage Location
- We store data primarily in EU-based data centers to ensure GDPR compliance.
- For customers with APAC requirements, we may store data in Alibaba Cloud regions under appropriate safeguards.
- You can specify your preferred region at the time of deployment.
6.2 Retention Periods
- Marketing and website data: Up to 24 months after your last interaction, unless deleted earlier.
- Account and billing data: Retained for the duration of your subscription plus 10 years for legal and fiscal obligations.
- Platform usage and logs: Retained for a maximum of 12 months, unless required longer for security or legal reasons.
- Customer Digital HQ data: Retained as long as your subscription is active, plus 30 days after termination for backup and export purposes. After that, data is deleted or anonymized unless retention is required by law.
You may request earlier deletion of your data, subject to legal retention obligations.
7. Your Rights (GDPR)
You have the following rights regarding your personal data:
- Right of access: Request a copy of the personal data we hold about you.
- Right of rectification: Correct inaccurate or incomplete information.
- Right to erasure ("right to be forgotten"): Request deletion of your data, subject to legal and contractual retention obligations.
- Right to restriction: Request that we limit how we process your data.
- Right to data portability: Receive your data in a structured, commonly used format.
- Right to object: Object to processing based on legitimate interest or direct marketing.
- Right to withdraw consent: Revoke consent at any time for processing based on consent (e.g., marketing).
To exercise any of these rights, contact us at contact@octensoft.com.
If you believe our processing of your personal data violates applicable law, you have the right to file a complaint with the French data protection authority (CNIL).
8. Security
We implement robust technical and organizational measures to protect your data, including:
- Encryption in transit (TLS) and at rest.
- Strict access controls and role-based authentication.
- Web Application Firewall (WAF) and threat monitoring.
- Automated backups and disaster recovery.
- Regular security audits and vulnerability management.
- Continuous staff training on data protection and security.
For Digital HQ customers, you are responsible for securing your own credentials, managing user access within your tools, and configuring security settings in accordance with your needs.
9. Data Portability and No Lock-In
A core principle of Ecomposable is that you own your data. We are committed to:
- Providing easy, structured data export for all tools on your Digital HQ.
- Using open standards and formats wherever possible.
- Avoiding proprietary traps or formats designed to make leaving difficult.
Data export tools are available within the Platform. For siloed deployments, full database exports are supported on request.
10. International Transfers
Data may be transferred between regions or countries for operational reasons (e.g., multi-cloud deployments, subprocessors).
Where data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions, where applicable.
- Encryption and access restrictions.
11. Children's Data
Our services are not directed to children under 16. We do not knowingly collect data from children under this age. If we become aware that we have done so, we will take steps to delete such data.
12. Changes to This Policy
We may update this Privacy Policy to reflect legal, technical, or business changes.
- Material changes will be notified to active users via email and published on this page at least 30 days before they take effect.
- Your continued use of the Platform after the effective date constitutes acceptance of the updated policy.
13. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:
Octensoft
128 rue de la Boétie
75008 Paris, France
Email: contact@octensoft.com