Data protection policy
This policy describes how WyndPath protects personal data, both its own customers' data and the data that passes through the API on their behalf. It complements the privacy policy, which covers website visitors, and the data processing agreement, which is contractual.
1. Who is responsible for what
WyndPath acts in two distinct roles, and that distinction governs everything that follows.
- Controller for its own customers' and visitors' data: account, billing, usage logs, audience measurement on the public website.
- Processor within the meaning of Article 28 GDPR for any personal data contained in the pages you ask us to fetch. In that case you are the controller: you decide which URLs are called, for what purpose, and how long you keep the data.
2. Data passing through the API
When you call the API, WyndPath fetches a publicly accessible page and returns it to you. That page may contain personal data (a seller's handle, a city, a phone number published by its author). Three principles apply to this content.
- We do not keep page content. The response is passed to you and then discarded. It is written neither to disk nor to a database, and is never indexed, used to train models, or resold.
- We keep technical metadata for billing and diagnostics: timestamp, domain, requested URL, engine used, status, latency, credits spent. These logs are deleted automatically after 90 days.
- We do not access content outside a reported technical incident, and never without your knowledge.
One consequence must be understood: we cannot answer an access or erasure request concerning data you collected, because we no longer hold it. Such a request must be addressed to you directly.
3. Data we process for our own purposes
- Account
- Email address, hashed password, creation date, acquisition source. Retention: lifetime of the account, then 12 months.
- Usage
- Request logs described in section 2. Retention: 90 days. Daily aggregated counters are kept for billing.
- Billing
- Billing identity, amounts, invoices. Retention: 10 years, accounting obligation.
- Support
- Email exchanges. Retention: 3 years from the last contact.
- Audience
- Audience measurement on the public website only, never inside the console. Details and opt-out in the privacy policy.
4. Security
The following measures are in place and verifiable:
- encryption in transit on every entry point, including the API and the console;
- authentication by API key, revocable at any time, each key bound to a single account;
- console sign-in protected by a one-time code sent by email;
- strict isolation of sessions and credentials between customer accounts: a browsing session established for one account is never reused for another;
- encryption of the credentials you entrust to us for targets requiring authentication;
- server access restricted to the managing director, by key, without passwords;
- encrypted backups with tested restore;
- logging of administrative access.
5. Sub-processors
We rely on the following providers, and on them alone, to deliver the service:
| Provider | Country | Role | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Allemagne | Hébergement des serveurs et des bases de données | UE |
| Webshare Software Company | États-Unis | Fourniture des adresses IP de sortie (proxys) | CCT |
| Stripe Payments Europe, Ltd. | Irlande | Paiement des abonnements et facturation | UE / CCT |
| Brevo SAS | France | Envoi des e-mails transactionnels (code de connexion, factures) | UE |
| Cloudflare, Inc. | États-Unis | Protection anti-robot du formulaire, acheminement des e-mails entrants | CCT / DPF |
| Google Ireland Limited | Irlande | Mesure d'audience du site public (hors console) | UE / CCT |
Any addition to this list is published on this page before it goes live. You may object to it under the conditions of Article 6 of the data processing agreement.
6. Transfers outside the European Union
The servers running the service are located in Germany. The exit IP addresses on offer cover France, Belgium, Germany, Spain and the United Kingdom. Two providers are established in the United States: those transfers are covered by the European Commission's standard contractual clauses and, where the provider is certified, by the Data Privacy Framework. No fetched page content is stored with these providers, whose role is limited to network routing.
7. Personal data breach
In the event of a personal data breach, we inform the affected customers without undue delay and no later than 48 hours after discovery, stating the nature of the incident, the categories of data involved, the likely consequences and the measures taken. Where WyndPath acts as controller, the French supervisory authority (CNIL) is notified within 72 hours under Article 33 GDPR.
8. What we expect from you
Our compliance depends in part on how you use the service. By using the API, you undertake to:
- have a legal basis for the collection you carry out, and inform data subjects where the law requires it;
- not collect data falling under Article 9 GDPR (health, opinions, sexual orientation, biometric data) or data relating to minors;
- only collect pages accessible without authentication or circumvention of a technical access restriction, and comply with the terms of the sites concerned;
- not build profiles of natural persons nor resell personal contact details obtained through collection;
- limit your own retention to what is necessary.
Failure to comply may lead to suspension of the account, under the conditions set out in the terms of use.
9. Exercising your rights
You have rights of access, rectification, erasure, restriction, objection and portability over the data we process as controller. Deletion of your account can be requested at any time at [email protected] and takes effect within 30 days, except for accounting records we are required by law to keep. You may also lodge a complaint with the CNIL.
10. Contact
- Controller
- SARL Jérémy Devos, 15 rue Louis Seigneur, 59170 Croix, France
- Company number
- 939 628 038
- Contact
- [email protected]
Given its size and the nature of its activity, WyndPath is not required to appoint a data protection officer. Requests are handled directly by the managing director.