Privacy Policy
Personal data, GDPR and security
Personal data and GDPR
Association Zenyx collects and processes only the data necessary for creating and managing accounts, fulfilling orders, invoicing, support, infrastructure security, fraud prevention, compliance with legal obligations and defending its rights.
The legal basis for processing may be performance of the contract, compliance with a legal obligation, Association Zenyx's legitimate interest in securing its services and preventing abuse, or consent where required.
Categories of data
- Identification and contact information
- Billing, order and payment data
- Support tickets and communications with the team
- Technical logs, IP addresses, security traces and abuse events
- Information necessary for accounting, legal and evidentiary obligations
Retention period
The retention period varies according to the purpose: during the contractual relationship, then for the applicable statutory periods or the periods necessary for evidence, collection, security, fraud prevention and dispute management.
In the event of non-payment, service data may be permanently deleted after a usual period of 15 calendar days following suspension, with a minimum period of 7 calendar days. In the event of manual termination requested by the Customer, fraud, serious abuse or a security risk, immediate deletion may be applied where necessary.
Processors and recipients
Data may be shared with technical processors or providers necessary for the service to operate, including payment, hosting, email routing, support, security, technical analysis and accounting obligations. Association Zenyx does not sell personal data.
Data subject rights
In accordance with the GDPR (EU 2016/679), you have rights of access, rectification, erasure, restriction, objection and portability where these rights apply. These rights may be exercised by contacting [email protected] or the DPO at [email protected].
