Privacy policy
Applicable to the Workflaws site and service.
Version in force as of 6 August 2026.
This is a courtesy translation. Workflaws is published from France and the binding text is the French one: politique de confidentialité. Where the two differ, the French version prevails. The French original is also the version to rely on for any dealing with the CNIL or a French court.
This policy describes the processing of personal data carried out in connection with the Workflaws collaborative video and audio review service (the “Service”), under Regulation (EU) 2016/679 (“GDPR”) and the French Data Protection Act. It supplements the terms of sale.
1. Data controller
The data controller is Vincent Galard (EI), a sole trader operating under the business name Powerloop, registered with the Poitiers trade and companies register under number 881 670 657, established at 30 avenue de l'Europe, 86000 Poitiers, France, reachable at contact@workflaws.com.
No data protection officer has been appointed, such an appointment not being mandatory given the nature of the processing; any question about personal data may be sent to the address above.
2. Data processed
The following data are processed in connection with the Service:
- Account data: username, name or pseudonym, email address, password (stored exclusively as a bcrypt hash, never in clear text);
- Subscription and billing data: plan, billing period, invoice history, payment status. No card data is collected or stored by the publisher: card details are entered directly with Stripe;
- Content: uploaded media (video, audio), comments, annotations and associated metadata, insofar as they contain personal data;
- Technical data: activity and connection logs, IP addresses, session cookie.
Account data are necessary to enter into and perform the contract; without them, subscribing to the Service is not possible.
The contact form on the marketing site, independently of any subscription, additionally collects:
- Enquiry data: name, email address, and where applicable company, phone number, subject and plan of interest;
- Message content: the text you write, which remains yours — please do not include sensitive information in it;
- The sender's IP address, attached to the message: it is used to enforce the form's sending limit and to filter out automated submissions.
Only name, email address and message are required; the other fields are optional and serve only to let us answer more precisely.
3. Purposes and legal bases
Data are processed for the following purposes:
- Providing the Service and managing the account (creating the workspace, authentication, collaborative review features) — legal basis: performance of the contract;
- Billing and subscription management — legal basis: performance of the contract and legal obligations (accounting and tax);
- Security of the Service (logging, prevention of unauthorised access, fraud and abuse prevention) — legal basis: the publisher's legitimate interest in protecting its infrastructure and its users, and legal obligations to retain connection data;
- Service-related notifications (transactional emails: credentials, confirmations, billing alerts, contractual information) — legal basis: performance of the contract;
- Answering enquiries sent through the contact form — legal basis: your consent, collected via the form's tick box (article 6.1.a GDPR). That consent may be withdrawn at any time by writing to the address below, without affecting exchanges that have already taken place;
- Preventing automated submissions through the form (per-IP sending limit, anti-robot check) — legal basis: the publisher's legitimate interest in protecting its inbox from abuse.
No data is used for advertising or profiling, nor sold on. No decision producing legal effects is taken on the basis of automated processing.
4. Guests' data
The account holder may invite collaborators or third parties to view and comment on their projects. Those guests' data (email address, name or pseudonym, comments, logs) are processed for the same purposes and periods as the holder's. It is for the holder to inform their guests of this policy.
Furthermore, where the customer uploads to the Service content containing third parties' personal data (rushes, recordings, interviews, and the like), the customer acts as controller of those data; the publisher then acts as processor within the meaning of article 28 GDPR, on the terms of article 15 of the terms of sale.
5. Recipients and processors
Data are accessible only to the publisher and to the following processors, strictly as far as necessary for their tasks:
- Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany): hosting of the Service's servers and data, within the European Union;
- Stripe (Stripe Payments Europe Ltd, Ireland): payment processing and subscription management;
- Transactional email is sent by the publisher's own infrastructure, hosted at Hetzner.
Data may also be disclosed to authorities legally entitled to receive them, upon formal request.
6. Transfers outside the European Union
The Service's data are hosted in the European Union and are not transferred outside the EU at the publisher's initiative. Payment processing by Stripe may involve a transfer of certain transaction data to the United States (Stripe, Inc.), covered by the safeguards of chapter V GDPR (EU–US Data Privacy Framework adequacy decision and/or standard contractual clauses).
7. Retention periods
- Account and Content: for the whole term of the subscription, then sixty (60) days after its termination or expiry (the retrieval window set out in article 8.6 of the terms of sale), after which they are permanently erased;
- Accounting records and invoices: ten (10) years, as legally required;
- Activity and connection logs, IP addresses: twelve (12) months;
- Session cookie: thirty (30) days at most;
- Enquiries sent through the contact form: three (3) years from the last exchange, the usual retention period for a business contact, then deletion. An enquiry left without follow-up is deleted as soon as it is established that no answer is called for;
- The form's anti-abuse counters (hashed IP address, anti-robot tokens): one (1) hour at most, the length of the counting window.
At the end of those periods, data are deleted or irreversibly anonymised, including from technical backups once their rotation cycle expires.
8. Cookies
The marketing site sets no advertising, analytics or tracking cookie. The application uses a single session cookie, strictly necessary for authentication and for the Service to work, exempt from consent under the CNIL's guidelines. Its lifetime does not exceed thirty days. Should cookies requiring consent ever be introduced, a consent mechanism would be put in place beforehand.
9. Your rights
Under articles 15 to 22 GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability in respect of your data, as well as the right to give directions as to their fate after your death (article 85 of the French Data Protection Act).
These rights are exercised by email to contact@workflaws.com, proving your identity where there is reasonable doubt. You will receive an answer within one month, extendable by two months for complex requests, in accordance with article 12 GDPR.
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the CNIL (Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr), or with the supervisory authority of your country of residence.
10. Security
The publisher implements technical and organisational measures appropriate to the nature of the data: encryption in transit (HTTPS/TLS), passwords stored exclusively as bcrypt hashes, separation of customers' workspaces, access control, logging, and regular technical backups of the infrastructure. In the event of a data breach likely to give rise to a risk to your rights and freedoms, the CNIL and, where applicable, the individuals concerned will be informed on the terms of articles 33 and 34 GDPR.
11. Changes to this policy
This policy may be amended to reflect changes to the Service or to the applicable rules. Any substantial change is brought to your attention by email or by a visible notice at sign-in, before it takes effect. The applicable version is the one published on the site, dated at the top of the document.