Personal data
Privacy policy
This policy explains what personal data Noxaryn processes, why it is processed, which providers are involved and how to exercise your rights.
Last updated: 8 August 2026
Data controller
Noxaryn determines the purposes and means of the processing carried out through noxaryn.org. For any privacy question or to exercise your rights, contact hello@noxaryn.org.
Data we process
- Account data: email address, authentication identifier and information required to manage your session.
- Project and business data: business name, contact details, website information, content and choices provided to deliver the service.
- Technical and security data: IP address, technical logs, browser information and events required to operate and secure the service.
- Support communications: content of requests sent to Noxaryn and information required to handle them.
Purposes and legal bases
- Create and manage your account, project and relationship with Noxaryn: performance of pre-contractual steps and the contract.
- Provide, maintain and secure the service, prevent abuse and diagnose incidents: Noxaryn’s legitimate interest in providing a reliable and secure service.
- Comply with accounting, tax, judicial or regulatory requirements: legal obligation where applicable.
- Send optional communications requiring your approval: consent where that legal basis is required.
Recipients and providers
Data is accessible to authorised persons at Noxaryn and, only where required to provide the service, to our technical providers.
- Supabase: authentication, database and backend services.
- Vercel: hosting and delivery of the web application.
- Google: OAuth authentication only when you choose to sign in with Google.
Transfers outside the EEA
Some international providers may process data outside the European Economic Area. Where required by the GDPR, such transfers must rely on an appropriate legal mechanism, such as an adequacy decision or Standard Contractual Clauses together with the necessary safeguards.
Retention periods
Noxaryn keeps personal data only for as long as necessary for the relevant purpose and then for any retention period required or permitted by law. Data linked to an active account or project is kept for the duration of the relationship; accounting records and supporting documents are retained for the applicable statutory periods; technical and security logs are kept for a period proportionate to their purpose.
Your rights
Depending on the processing involved, you may request access, rectification, erasure, restriction or portability of your data, or object to certain processing. Where processing is based on consent, you may withdraw it at any time. Contact: hello@noxaryn.org. You may also lodge a complaint with the French data protection authority (CNIL).
Security and updates
Noxaryn implements technical and organisational measures designed to protect data against unauthorised access, loss, alteration or disclosure. This policy may be updated when features, providers or applicable requirements change.