Personal data
Privacy policy
This policy explains how Phitalys handles personal data, distinguishing the marketing website (phitalys.com) from the service (app.phitalys.com), which do not share the same GDPR role.
1. The marketing website (phitalys.com)
On the website, we only collect the data you voluntarily submit through the contact form: name, organisation, email and message.
- Purpose: to answer your request (demo, quote, question).
- Legal basis: your voluntary step and our legitimate interest in handling inbound sales requests.
- Recipients: the Phitalys team only. No sharing, no resale to third parties.
- Retention: for as long as needed to handle your request, then at most 24 months in the prospect database, unless you ask for deletion.
- Analytics: aggregated statistics via GoatCounter, self-hosted on our EU servers — no cookies, no advertising ID, no cross-site tracking. Page views, referrer and country only; no IP address is stored.
- Cookies / trackers: the website uses Google Analytics (GA4) for audience measurement. Purpose: traffic statistics. Legal basis: your consent (banner — denied by default, Accept/Refuse with equal weight); it can be withdrawn at any time via “Manage cookies” in the footer. Processor: Google Ireland Ltd. Retention: measurement data kept 14 months; anonymised IP; no advertising purpose. Without consent, no GA4 tracker is set. The theme preference remains strictly functional local storage.
2. The service (app.phitalys.com)
When a client organisation subscribes to the service, the organisation is the data controller and Phitalys acts as a processor under the GDPR, within a data-processing agreement (DPA).
- Minimisation: the service reads metadata and volumes of Microsoft 365 presence and usage — never the content of communications (no email body, no meeting subject, no file).
- Group protection: teams of fewer than five people are masked in aggregates.
- Traceability: named access is logged.
- Opt-in: advanced analysis modules (including detection) are off by default; enabling them is the client's responsibility, who must inform employees and consult the works council where applicable.
- Retention: raw events are purged according to the client-set retention (90 days by default).
For data processed through the service, address your rights requests to your employer (the data controller).
3. Your rights
Under Regulation (EU) 2016/679 (GDPR), you have the right to access, rectify, erase, restrict, object to and port your data. To exercise these rights regarding the website, write to contact@phishia.fr. You may also lodge a complaint with your supervisory authority.
4. Security
Data is protected in transit (TLS) and access to the service is role-controlled with logging. See our Security page for details (hosting, encryption, processing).
5. Contact
For any question about this policy: contact@phishia.fr. See also our legal notice.
Last updated: July 2026.