Privacy policy

Last updated:

The data controller is Antoine LE BORGNE, Entrepreneur individuel, trading as Orvel, reachable at privacy@orvel.dev. Publisher identity: studio legal notice. This policy covers the Access Record service and the access.orvel.dev website.

Data we process

DataPurposeLegal basisRetention
Email addressAccount creation, magic-link sign-in, service notificationsContractLife of the account, then 3 years
IP address, browserSign-in security, rate limitingLegitimate interest30 days
Audited domains, scan resultsProviding the service, compliance file historyContractLife of the account
Entity name, published contactGenerating and publishing the accessibility statementContractWhile the statement is published
Billing dataPayment, invoices, accounting obligationsLegal obligation10 years

Scans only cover the public pages of the site you register. We collect no data about that site’s visitors. HTML snippets kept in the results are limited to the failing element.

Processors

Transfers outside the EU rely on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework. Card details are handled directly by Stripe; we never see them.

Cookies

One cookie, ar_session, strictly necessary for sign-in, valid 30 days. No analytics or advertising cookies, so no consent banner is needed.

Your rights

You can access, rectify, erase, restrict, object to and port your data. Write to privacy@orvel.dev; we answer within one month. You may lodge a complaint with your supervisory authority (in France, the CNIL, cnil.fr).

Security

Passwordless sign-in with single-use links valid 15 minutes, hashed tokens, TLS in transit, database access limited to the application and authenticated administration.