Personal Data Protection Policy

Retyc - a service by TripleStack SAS

Version 1.1 - Effective as of: 24 May 2026

Article 1 - Overview and scope

TripleStack SAS, a simplified joint-stock company (société par actions simplifiée unipersonnelle) with a share capital of €1,000, registered with the Lyon Trade and Companies Register (RCS) under number 853 010 064, with its registered office at 12 B rue du Stade - 69290 Grézieu-la-Varenne (hereinafter "TripleStack" or "Retyc"), acts as data controller for personal data collected in connection with the operation of the Retyc platform accessible at https://retyc.com (the "Platform").

TripleStack is represented by its President, Mr. Emilien Mantel.

This policy (hereinafter the "Policy") is intended to inform all users of the Platform - whether professionals (B2B customers) or individuals (B2C customers and anonymous users) - of the conditions under which TripleStack collects, processes and retains their personal data, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (hereinafter the "GDPR") and French Act No. 78-17 of 6 January 1978 on Information Technology, Files and Civil Liberties as amended (hereinafter the "LIL").

This Policy forms an integral part of the Terms of Service and Sale (Terms) of the Platform. In the event of any conflict between this Policy and the Terms, the data protection provisions of this Policy shall prevail.

The Platform distinguishes three categories of users to whom this Policy applies:

  • B2B Registered Users: natural persons using the Platform in the context of their professional activity, on behalf of a B2B customer;
  • B2C Registered Users: natural persons using the Platform for personal purposes, as consumers;
  • Anonymous Users: persons accessing the Platform without a registered account, in particular to download a shared file.

Article 2 - Data collected, purposes and legal bases

2.1 Account management and provision of Services

Data collected: first name, last name, email address, password (stored in hashed form - TripleStack has no access to the password in clear text).

Data subjects: B2B and B2C Registered Users.

Purpose: creation and management of the user account, authentication, provision of Services, management of the customer's Organisation.

Legal basis: performance of contract (Article 6(1)(b) of the GDPR).

Retention period: for the duration of the contract, then deleted immediately upon account closure, unless a legal retention obligation applies.

2.2 Management of paid subscriptions and billing

Data collected: identification data (name, first name, email address), information relating to the subscription, billing history.

Data subjects: B2B and B2C Registered Users holding a paid subscription.

Purpose: subscription management, invoice issuance, payment tracking.

Recipients: this data may be transmitted to TripleStack's accountant, acting as a sub-processor, solely for the purpose of preparing annual accounts and fulfilling legal accounting obligations.

Legal basis: performance of contract (Article 6(1)(b) of the GDPR) and compliance with legal accounting obligations (Article 6(1)(c) of the GDPR).

Retention period: billing data is retained for ten (10) years from the end of the relevant accounting year, in accordance with legal accounting obligations.

2.3 Payment processing

Data collected: TripleStack does not directly collect or store banking or payment card data. Such data is collected and processed directly by Stripe, a payment services provider acting as an independent data controller.

Data subjects: B2B and B2C Registered Users holding a paid subscription.

Purpose: secure processing of financial transactions.

Legal basis: performance of contract (Article 6(1)(b) of the GDPR).

Retention period: transaction data transmitted to Stripe is retained by Stripe in accordance with the terms of its own privacy policy, available at https://stripe.com/fr/privacy. TripleStack retains only the transaction references necessary for accounting purposes, for a period of ten (10) years.

2.4 Security and logging

Data collected: IP addresses, connection logs (date, time, browser type and version), timestamps of actions on the Platform, file metadata: size, creation and modification date, Organisation directory structure (file names and types are encrypted client-side and inaccessible to TripleStack).

Data subjects: B2B and B2C Registered Users and Anonymous Users.

Purpose: Platform security, detection and prevention of abuse, technical administration, traceability.

Legal basis: legitimate interest of TripleStack in ensuring the security and integrity of the Platform (Article 6(1)(f) of the GDPR).

Retention period: security logs are retained for twelve (12) months from collection.

2.5 Anonymised usage statistics

Data collected: aggregated and anonymised usage data (types of features used, frequency and duration of activities). This data is collected via a self-hosted analytics tool (Umami), which does not place any cookies on the user's device and does not collect any identifiable personal data.

Data subjects: B2B and B2C Registered Users and Anonymous Users.

Purpose: improvement of the Services and the Platform.

Legal basis: legitimate interest of TripleStack in improving its Services (Article 6(1)(f) of the GDPR). As this data is anonymised, it does not technically constitute personal data within the meaning of the GDPR.

Retention period: twenty-four (24) rolling months.

2.6 Support and correspondence

Data collected: email address, name, content of support exchanges.

Support tool: support is available at https://support.retyc.com. It is hosted on the same Scaleway infrastructure as the Platform (France, European Union) and uses the Retyc single sign-on (SSO) system.

Data subjects: B2B and B2C Registered Users.

Purpose: responding to assistance requests, incident tracking, improving service quality.

Legal basis: performance of contract (Article 6(1)(b) of the GDPR) and legitimate interest of TripleStack in improving its Services (Article 6(1)(f) of the GDPR).

Retention period: support exchanges are retained for thirty-six (36) months from ticket closure.

2.7 Account and Service communications

Data collected: email address.

Data subjects: B2B and B2C Registered Users.

Purpose: sending transactional notifications relating to the account (registration confirmation, security alerts, information relating to changes to the Service or Terms).

Legal basis: performance of contract (Article 6(1)(b) of the GDPR) and compliance with legal information obligations (Article 6(1)(c) of the GDPR).

Sub-processor: communications are routed via Scaleway or Brevo (formerly Sendinblue), an email delivery provider established in France, acting as a sub-processor. Brevo may retain sending metadata (timestamp, delivery status) in accordance with its own privacy policy, available at https://www.brevo.com/fr/legal/privacypolicy/.

Retention period: for the duration of the contract, then deleted immediately upon account closure.

2.8 Anonymous Users

Data collected: IP address, date and time of download.

Data subjects: Anonymous Users accessing a shared file.

Purpose: security, abuse prevention, technical administration of the Platform.

Legal basis: legitimate interest of TripleStack in ensuring the security of the Platform (Article 6(1)(f) of the GDPR).

Retention period: twelve (12) months from collection.

2.9 File transfer recipients

Data collected: email address of recipients designated by the Customer when creating a transfer.

Data subjects: any person whose email address is entered by a Registered User as the recipient of a transfer.

Purpose: sending a transfer receipt notification; allowing the transfer owner to resend a notification.

Legal basis: legitimate interest of TripleStack and the Customer in ensuring proper receipt of transfers (Article 6(1)(f) of the GDPR).

Retention period: recipient email addresses are deleted upon expiry or deletion of the relevant transfer. They are not used for commercial prospecting or marketing purposes.

2.10 Event logging (datarooms and transfers)

Data collected: event type (download, deletion, modification, etc.), identity of the relevant Registered User, timestamp. Sensitive data associated with events (file names in particular) is stored in encrypted form and inaccessible to TripleStack.

Data subjects: B2B and B2C Registered Users with access to a dataroom or transfer.

Purpose: traceability and audit of actions performed within datarooms and transfers, in accordance with the native features of the Platform.

Legal basis: performance of contract (Article 6(1)(b) of the GDPR).

Retention period - Datarooms: event logs relating to datarooms are retained for three hundred and sixty-five (365) rolling days, or deleted entirely upon deletion of the dataroom if this occurs before the expiry of that period.

Retention period - Transfers: event logs relating to transfers are retained until deletion or expiry of the relevant transfer (maximum period of ninety (90) days). Data from expired transfers is automatically purged within four (4) hours of expiry.

Anonymous recipient tracking: when the recipient of a transfer is not logged into a Retyc account, TripleStack records a pseudonymised technical identifier, consisting of a non-reversible hash of the recipient's IP address and user-agent (browser). This identifier is used solely to distinguish downloads made by different anonymous users; it does not enable formal identification of the recipient. Legal basis: legitimate interest of TripleStack in ensuring transfer traceability (Article 6(1)(f) of the GDPR).

Dataroom log export: the Customer has access to a feature to export their dataroom logs directly from the Platform.

Article 3 - Zero-knowledge architecture and data access

The Platform is based on an end-to-end encryption architecture known as zero-knowledge: files uploaded by users to the Platform are encrypted client-side before any transfer to TripleStack's servers. TripleStack does not hold the decryption keys and therefore technically has no access to the content of stored files, nor to the encrypted metadata (file names and types).

Accordingly, the processing carried out by TripleStack as data controller relates exclusively to the metadata and account data listed in Article 2 of this Policy, and not to the content of files.

Article 4 - Recipients and sub-processors

TripleStack undertakes not to sell the personal data of its users.

Personal data may be processed by sub-processors, the complete and up-to-date list of which is available at https://retyc.com/legal/subprocessors.

For Stripe, whose servers may be located outside the European Union, TripleStack has entered into an agreement with this provider governing data transfers in accordance with the standard contractual clauses adopted by the European Commission.

Outside the cases listed above, TripleStack only discloses the personal data of its users to third parties in the following cases:

  • upon requisition by a competent administrative or judicial authority, within the limits of TripleStack's technical access capabilities in light of its zero-knowledge architecture;
  • to protect the legal rights and interests of TripleStack.

Article 5 - Transfers outside the European Union

With the exception of payment data processed by Stripe under the conditions described in Article 2.3, all personal data processed by TripleStack is hosted and processed exclusively on infrastructure located within the European Union.

Any transfer to a third country is governed by appropriate safeguards within the meaning of Chapter V of the GDPR, and in particular by the standard contractual clauses of the European Commission.

Article 6 - Security

TripleStack implements appropriate technical and organisational measures to ensure the security and confidentiality of its users' personal data, including:

  • end-to-end encryption of files using a zero-knowledge architecture;
  • encryption of communications using the TLS protocol;
  • storage of passwords in hashed form (TripleStack has no access to passwords in clear text);
  • exclusive hosting on infrastructure located within the European Union;
  • strict access controls, limited to authorised personnel;
  • access logging and monitoring procedures;
  • regular and secure backups.

In the event of a personal data breach likely to result in a high risk to the rights and freedoms of the persons concerned, TripleStack undertakes to inform the affected persons without undue delay, in accordance with Article 34 of the GDPR.

Article 7 - Cookies and trackers

7.1 Strictly necessary cookies

The Platform uses only cookies that are strictly necessary for its operation, in particular for managing user sessions and storing browsing preferences. These cookies do not require prior consent from the user.

7.2 Audience measurement tool

The Platform uses Umami, a self-hosted analytics tool hosted on Scaleway infrastructure in France. This tool does not place any cookies on the user's device, does not collect any identifiable personal data, and processes data in a fully anonymised manner. It therefore does not fall within the consent regime applicable to analytical cookies.

7.3 No advertising or third-party cookies

No third-party cookies for advertising, targeting or behavioural tracking purposes are placed on the devices of Platform users.

Article 8 - Minors

The Platform is intended for adults who are capable of entering into binding obligations in accordance with the legislation of the country in which the user is located. TripleStack does not knowingly collect personal data concerning minors under the age of fifteen (15).

If TripleStack becomes aware that a minor under the age of fifteen (15) has created an account without the consent of their legal representative, it will delete the account and associated data without undue delay.

Article 9 - Rights of data subjects

In accordance with the GDPR and the LIL, users have the following rights in respect of their personal data:

  • Right of access (Article 15 of the GDPR): to obtain confirmation that data concerning them is being processed, as well as a copy of such data and information on the processing modalities;
  • Right of rectification (Article 16 of the GDPR): to obtain the correction of inaccurate or incomplete data;
  • Right to erasure (Article 17 of the GDPR): to obtain the deletion of their data, in the cases provided for by the GDPR;
  • Right to restriction of processing (Article 18 of the GDPR): to obtain restriction of processing in the cases provided for by the GDPR;
  • Right to data portability (Article 20 of the GDPR): to receive their data in a structured, commonly used and machine-readable format, and to transmit it to another data controller;
  • Right to object (Article 21 of the GDPR): to object at any time to the processing of their data based on TripleStack's legitimate interest;
  • Right to withdraw consent: to withdraw their consent at any time, without the withdrawal affecting the lawfulness of processing carried out before the withdrawal;
  • Right to issue post-mortem instructions (Article 85 of the LIL): to issue instructions regarding the fate of their data after their death.

Important - exercise of rights after account closure: upon account deletion, as the data is irreversibly deleted or anonymised immediately at closure, any request for access, rectification or portability received after such closure cannot be fulfilled, due to the technical impossibility of doing so. This limitation is an inherent consequence of the immediate deletion policy and the zero-knowledge architecture of the Platform.

To exercise any of these rights, users may address their request to TripleStack:

  • By email: privacy@retyc.net;
  • By post: TripleStack SAS, 12 B rue du Stade, 69290 Grézieu-la-Varenne, France.

The request must be accompanied by a copy of a valid identity document. TripleStack undertakes to respond within one (1) month of receiving the request, a period which may be extended by two (2) months in the event of complexity or a large number of requests, with prior notice to the user.

Users may also lodge a complaint with the Commission Nationale de l'Informatique et des Libertés ( CNIL): https://www.cnil.fr/fr/plaintes.

Article 10 - Data protection contact

For any questions relating to the protection of personal data, users may contact TripleStack at: privacy@retyc.net.

Article 11 - Amendments to this Policy

TripleStack reserves the right to amend this Policy at any time, in particular to comply with any regulatory, case law or technical developments, or to reflect changes to the Platform and Services.

In the event of a material amendment, users will be informed at least fifteen (15) days before the new version comes into force, by email or notification on the Platform. The version in force is the one accessible on the Platform at the time of consultation.

Article 12 - Language

In the event of any conflict or inconsistency between the provisions of the different language versions of this Personal Data Protection Policy, the French version shall prevail.

Article 13 - Contact

For any questions or complaints regarding this Policy:

  • By email: privacy@retyc.net;
  • By post: TripleStack SAS, 12 B rue du Stade, 69290 Grézieu-la-Varenne, France.