Phitalys

Personal data

Privacy policy

This policy explains how Phitalys handles personal data, distinguishing the marketing website (phitalys.com) from the service (app.phitalys.com), which do not share the same GDPR role.

1. The marketing website (phitalys.com)

On the website, we only collect the data you voluntarily submit through the contact form: name, organisation, email and message.

2. The service (app.phitalys.com)

When a client organisation subscribes to the service, the organisation is the data controller and Phitalys acts as a processor under the GDPR, within a data-processing agreement (DPA).

For data processed through the service, address your rights requests to your employer (the data controller).

3. Your rights

Under Regulation (EU) 2016/679 (GDPR), you have the right to access, rectify, erase, restrict, object to and port your data. To exercise these rights regarding the website, write to contact@phishia.fr. You may also lodge a complaint with your supervisory authority.

4. Security

Data is protected in transit (TLS) and access to the service is role-controlled with logging. See our Security page for details (hosting, encryption, processing).

5. Contact

For any question about this policy: contact@phishia.fr. See also our legal notice.

Last updated: July 2026.