Privacy policy
Last updated: 28 July 2026
How Puwapi collects, uses and protects personal data.
This English version is provided for convenience only. The French version is the legally binding text and prevails in the event of any discrepancy.
1. Who we are and what data we collect
The data controller is GHARSALLI Abdurahmen (EI), 13 Rue de la Fraternité, 69150 Décines-Charpieu, France. Any question about your data may be sent to contact@puwapi.com.
Data collected when creating an account
- Email address - required: it identifies your account and is how we reach you. Without it, the account cannot be created.
- Password - required, stored as a cryptographic hash and never in plain text. Without it, signing in is impossible.
- First and last name - optional: they personalise the interface and the messages we send you. Leaving them out has no effect on access to the service.
If you choose to sign up or sign in using a Google, Apple or Microsoft account, that provider sends us your email address and, where applicable, your name. We never receive your password.
Data collected while using the service
- Activity data: sign-ins, actions performed in your workspace, and the IP address and browser associated with them (audit log)
- Data you enter into the service yourself (customers, appointments, documents, messages): Puwapi then acts as a processor on your behalf, under the data processing agreement
- Billing data: Puwapi never stores a payment card number, which is handled directly by Stripe
Data collected when you write to us
The contact form on this site sends nothing to our servers: it opens your email client with a pre-filled message that you send yourself. We then receive whatever you chose to write, and keep it for as long as it takes to handle your request.
2. Site analytics
To know which pages of the site are being read, we record — without placing any tracker on your device — the page visited, the display language, the page that brought you here (referrer), your browser and operating system, the date and time, and a non-reversible cryptographic fingerprint of your IP address; the address itself is never stored. That fingerprint only serves to roughly tell two visits apart and cannot identify you or follow you from site to site.
This measurement rests on our legitimate interest in understanding our own site's audience in order to improve it. It is confined to our own pages, no data is passed to a third party, and records are deleted no later than 13 months after collection. You may object to it by writing to contact@puwapi.com or by enabling your browser's “Do Not Track” signal.
3. Why we use this data
| Purpose | Legal basis |
|---|---|
| Creating and managing your account, providing the subscribed service | Performance of the contract (art. 6(1)(b)) |
| Issuing invoices and keeping accounts | Legal obligation (art. 6(1)(c); French Commercial Code art. L. 123-22) |
| Keeping the service secure, detecting and preventing abuse and fraud | Legitimate interest (art. 6(1)(f)): protecting the service, our customers' data and our own against unauthorised access. Security data is used for no other purpose. |
| Measuring site traffic in order to improve it | Legitimate interest (art. 6(1)(f)): understanding which pages meet visitors' needs. Processing without trackers, without a persistent identifier and without disclosure to any third party, which keeps the impact on your privacy to a minimum. |
| Sending service emails (confirmations, invoices, alerts) | Performance of the contract (art. 6(1)(b)) |
| Telling our customers about service changes and our offers | Legitimate interest (art. 6(1)(f)) for our customers, where the products are similar to those subscribed; consent (art. 6(1)(a)) otherwise. Every message carries an unsubscribe link. |
4. Who has access to your data
Your data is never sold, rented or shared with ad networks. Only the following have access:
- The Puwapi team: access strictly limited to what support, operations and security require, and logged.
- The processors listed below, who act on our instructions alone.
| Processor | Role and location |
|---|---|
| Contabo GmbH | Hosting of servers and databases - Germany (European Union). |
| Scaleway | Storage of files uploaded to the service - France (European Union). |
| Stripe | Payment and billing processing - European Union and United States. |
| deSEC | DNS record management for our own domains - Germany (European Union). |
| Hostinger | Registrar and DNS hosting for domain names purchased by our customers from within the service - European Union. |
| Anthropic | Processing of content submitted to the service's artificial intelligence features - United States. That content is not used to train any model. |
| Google, Apple, Microsoft | Authentication, only if you choose to sign in with one of those accounts - United States. |
This list is kept up to date. Any addition or replacement of a processor is notified to subscribers under the data processing agreement.
5. Transfers outside the European Union
Hosting of servers, databases and files is entirely located within the European Union (Germany and France). Three types of processing may nonetheless involve a transfer to the United States:
| Transfer | Safeguard |
|---|---|
| Stripe - payment and billing data | European Commission Standard Contractual Clauses, together with the provider's technical and organisational measures. |
| Anthropic - content submitted to the artificial intelligence features | European Commission Standard Contractual Clauses. These features are optional: not using them is enough to avoid any transfer on this basis. |
| Google, Apple, Microsoft - third-party account authentication | Standard Contractual Clauses or an adequacy decision depending on the provider. This sign-in method is optional: creating an account with an email address and password involves no transfer. |
You can obtain a copy of the safeguards covering these transfers on request to contact@puwapi.com. No other transfer outside the European Union takes place.
6. Retention periods
| Data | Retention |
|---|---|
| Active user account | Until the account is deleted |
| Data after cancellation | 30 days (read-only), then deletion |
| Invoices and accounting records | 10 years (legal obligation) |
| Audit and security logs | 12 months |
| Site analytics | 13 months |
| Messages received through the contact form | 3 years from the last exchange |
| Mail data | Duration of the subscription + 30 days |
| Unsolicited job applications | 2 years from the last contact |
7. Automated decisions and profiling
Puwapi takes no decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. We carry out no scoring, no advertising segmentation and no profiling of our visitors or customers.
The service does, however, offer our subscribers analytics and artificial intelligence features that they may apply to their own data (a customer-relationship health indicator, for instance). In that case the subscriber is the controller of that processing: it is for them to inform the individuals concerned and to determine its legal basis. Puwapi acts only as a processor.
8. Your rights
Under the GDPR, you have the following rights:
- Access: confirm whether your data is being processed and obtain a copy of it
- Rectification: have inaccurate or incomplete data corrected
- Erasure: request deletion of your data, subject to our legal retention obligations
- Objection: object to processing based on our legitimate interest, in particular site analytics and marketing
- Portability: receive the data you provided to us in a structured, machine-readable format
- Restriction: have processing frozen while a challenge is resolved
- Withdrawal of consent: where processing rests on your consent, withdraw it at any time, without affecting what was done beforehand
- Post-mortem directives: give directions on what should happen to your data after your death and appoint someone to carry them out (article 85 of the French Data Protection Act)
For marketing, withdrawal takes one click on the unsubscribe link at the bottom of every message. For all other rights, write to contact@puwapi.com or to GHARSALLI Abdurahmen (EI), 13 Rue de la Fraternité, 69150 Décines-Charpieu, France.
Exercising these rights is free of charge. We reply within one month of receiving your request, extended to three months where it is complex or where requests are numerous — you are then told so, with reasons, within the first month. We may ask for further information where there is reasonable doubt as to your identity, without ever systematically requiring identity documents. If our reply does not satisfy you, you may lodge a complaint with the CNIL - 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
9. Security
We put the following measures in place, appropriate to the risk:
- hosting within the European Union, on dedicated infrastructure;
- encryption of all communications (HTTPS, TLS 1.2 minimum, TLS 1.3 by default); obsolete versions of the protocol are refused;
- encryption at rest of mail data (AES-256);
- passwords stored as cryptographic hashes, never in plain text, and temporary account lockout after repeated failed sign-ins;
- data partitioned by organisation: one customer's data is never reachable from another's account;
- named accounts, rights granted by role, administration access restricted to those who need it;
- logging of sign-ins and sensitive actions;
- encrypted daily backups of databases and files, with periodic restore testing.
Two-factor authentication on administration access is being rolled out and will be available during August 2026; this page will be updated when it goes live.
10. Changes
This policy may be updated. The date of the last change is shown at the top of the page. In the event of a substantial change, active subscribers are notified by email 30 days before it takes effect.