Back to home

Privacy Policy

Last updated: August 17, 2026

SQL Audit Platform audits the configuration of SQL Server instances. This policy sets out the personal data we process in doing so, why we process it, how long we keep it, and how you can exercise your rights.

1. Data controller

The service is published by Databreizh. For any question about your personal data, or to exercise your rights, write to contact@databreizh.fr

On-premises deployments: when the application is installed on your organisation's own infrastructure, your organisation is the data controller. Databreizh then has access neither to your user accounts nor to your audit data, which never leaves your infrastructure.

2. Data we process

We collect only the data the service needs to operate:

  • Account identity: email address, name, organisation. Passwords are never stored in clear text (salted hash only) and are never included in an export.
  • Display and accessibility preferences.
  • Client record: for organisations managed by a service provider, the contact's details (name, email, phone, address) and engagement notes.
  • Technical metadata about the audited SQL Server instances: name, version, configuration settings.
  • Audit results: configuration findings, scores and remediation recommendations.
  • Access and action logs (sign-ins, administrative operations), for security and traceability.

3. Purposes and legal bases

Every processing activity rests on a legal basis within the meaning of Article 6 GDPR:

  • Providing the service — performance of the contract: account creation, authentication, running audits and returning their results.
  • Security and traceability — legitimate interest: access and action logs, prevention and detection of abuse.
  • Billing and accounting — legal obligation: issuing and retaining accounting records.
  • Account-related information — legitimate interest: service notifications, licence expiry reminders, payment reminders.

4. Our role depends on the data

For account data (identity, preferences, logs) we are the data controller. For the audit data of your instances we act as a processor: your organisation remains the controller and decides how long that data is kept and when it is deleted. One important consequence follows: an individual's erasure request never deletes their organisation's audit data — it erases the individual as a person.

5. Recipients and processors

Your data is neither sold nor rented. It is accessible to authorised Databreizh staff and to a small number of technical providers, whose exhaustive list — role, data location and transfer basis — is published on the Subprocessors page and kept up to date.

  • Hosting of the application and the database: servers located in France, contracting entity established within the European Union.
  • Transactional email: invitations, password reset, service notifications.
  • Ancillary technical providers: delivery of the API documentation portal, fonts for social cards, distribution of collector releases.

PDF reports are generated on our own infrastructure with networking disabled; no data reaches a third party in the process. The endpoints of the webhooks you configure, and your single sign-on identity provider, are not our subprocessors: they act on your instruction.

See the full list of subprocessors

6. Retention periods

We apply a retention schedule per category of data:

  • User account and preferences: for the lifetime of the account, then erased at the end of a 30-day grace window.
  • Security and activity logs: a rolling 12 months, after which the actor is pseudonymised.
  • Audit data (instances, audits, findings): as agreed in the contract with your organisation, which remains the controller.
  • Accounting records and invoices: 10 years, under Article L123-22 of the French Commercial Code.
  • Proof of erasure: after a purge we keep a traceability record (technical identifier, date, volume erased) that contains no personal data.

7. Security

We implement the technical and organisational measures required by Article 32 GDPR:

  • Encryption of data in transit (TLS).
  • Encryption at rest of audit findings and personal data (AES-256-GCM), with keys held outside the database.
  • Passwords stored as salted hashes, never in clear text.
  • Strict isolation between organisations and access limited to authorised staff only.
  • Logging of access and of administrative actions.

8. Your rights

The GDPR grants you the following rights over your personal data:

  • Right of access to your data (Art. 15)
  • Right to rectification (Art. 16)
  • Right to erasure (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to data portability (Art. 20)
  • Right to object (Art. 21)

9. Exercising your rights

From your account, Settings › Privacy lets you download an export of your personal data and submit a request directly, without sending an email.

You may also send your request, stating which right you are exercising, to contact@databreizh.fr

If you are already signed in, that authentication is enough to establish your identity: proof of identity will only be requested where there is reasonable doubt.

We reply within one month of receiving the request. That period may be extended by two months for complex requests; you would be told so, with reasons, within the first month — Article 12(3) GDPR.

Some data may be retained despite an erasure request where a legal obligation requires it, invoices in particular (Article 17(3)(b) GDPR). Where that happens, we tell you which data is retained and why.

10. Cookies

We use only cookies that are strictly necessary for the service to work: the session cookie that keeps you signed in and, in on-premises deployments, the licence validation cookie. No advertising, audience-measurement or third-party tracking cookie is set, and no data is sent to an ad network or external analytics tool.

11. Complaints and contact

For any question about this policy or about how your data is processed, write to contact@databreizh.fr

You also have the right to lodge a complaint with the CNIL, the French supervisory authority: www.cnil.fr