Privacy policy
Last updated:
The data controller is Antoine LE BORGNE, Entrepreneur individuel, trading as Orvel, reachable at privacy@orvel.dev. Publisher identity: studio legal notice. This policy covers the Access Record service and the access.orvel.dev website.
Data we process
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address | Account creation, magic-link sign-in, service notifications | Contract | Life of the account, then 3 years |
| IP address, browser | Sign-in security, rate limiting | Legitimate interest | 30 days |
| Audited domains, scan results | Providing the service, compliance file history | Contract | Life of the account |
| Entity name, published contact | Generating and publishing the accessibility statement | Contract | While the statement is published |
| Billing data | Payment, invoices, accounting obligations | Legal obligation | 10 years |
Scans only cover the public pages of the site you register. We collect no data about that site’s visitors. HTML snippets kept in the results are limited to the failing element.
Processors
- Railway: Application hosting and database (USA).
- Stripe: Payments, invoices and subscriptions (USA / Ireland).
- Resend: Transactional email (sign-in links) (USA).
Transfers outside the EU rely on the European Commission’s standard contractual clauses and, where the provider is certified, on the EU–US Data Privacy Framework. Card details are handled directly by Stripe; we never see them.
Cookies
One cookie, ar_session, strictly necessary for sign-in, valid 30 days. No analytics or advertising cookies, so no consent banner is needed.
Your rights
You can access, rectify, erase, restrict, object to and port your data. Write to privacy@orvel.dev; we answer within one month. You may lodge a complaint with your supervisory authority (in France, the CNIL, cnil.fr).
Security
Passwordless sign-in with single-use links valid 15 minutes, hashed tokens, TLS in transit, database access limited to the application and authenticated administration.