Privacy policy
Last update: 1 January 2026
This privacy policy describes how Vertexlabfr SAS ("Vertexlabfr", "we") collects, uses and protects the personal data of users of vertexlabfr.com, in compliance with Regulation (EU) 2016/679 (GDPR) and the amended French Data Protection Act.
1. Data controller
The data controller is Vertexlabfr SAS, registered with the Paris RCS under number 921 567 432, with its head office at 14 rue de la Paix, 75002 Paris, France. The Data Protection Officer can be reached at dpo@vertexlabfr.com.
2. Data we collect
We collect: identity (first and last name), contact details (email, phone), browsing data (anonymised IP address, pages visited), and any information voluntarily provided through our free audit form.
3. Purposes
Your data are processed to: respond to your audit request, propose suitable advisory services, comply with our legal and tax obligations, and improve the website. No automated profiling is performed without your explicit consent.
4. Legal bases
Processing is based on your consent (form), pre-contractual measures (audit), our legal obligations (accounting, anti-money-laundering) and our legitimate interest (site security).
5. Retention
Prospect data: 3 years from last contact. Customer data: duration of the contract + 5 years. Accounting data: 10 years (French Commercial Code). Technical logs: 12 months maximum.
6. Recipients & processors
Your data are accessible only to authorised Vertexlabfr staff and to our processors located within the European Union: OVHcloud (hosting, France), Brevo (transactional email, France) and Stripe Payments Europe (where applicable, Ireland).
7. Transfers outside the EU
No data transfer outside the European Union takes place. Our entire infrastructure is hosted within the EU.
8. Your rights
Under the GDPR, you have rights of access, rectification, erasure, restriction, portability, objection and the right to set post-mortem instructions. Exercise them at dpo@vertexlabfr.com. You may also lodge a complaint with the French CNIL (www.cnil.fr).
9. Security
We implement appropriate technical and organisational measures: TLS 1.3 encryption, ISO 27001-certified hosting, strict access control, logging, encrypted backups and a business continuity plan.
10. Updates
This policy may be updated. The version that applies is the one published on this page on the date of your visit.