Privacy policy
Data controller: Tyche Informatique, 7 rue du 19 mars, Celles-sur-Durolle 63250. Personal data contact: data@tyche-info.fr.
Data processed, purposes and retention
| Data | Legal basis | Retention |
|---|---|---|
| Account (email, display name, username, hashed password) | Performance of the contract | Account lifetime, then immediate deletion |
| Projects, documents and Drive files | Performance of the contract | Until they are deleted or the account is |
| Messages and attachments (end-to-end encrypted) | Performance of the contract | Until they are deleted or the group is; 1 h to 7 days in an ephemeral channel |
| Signed-in devices (browser, last activity) | Legitimate interest (account security) | 30 days maximum |
| Project activity log | Legitimate interest (traceability of collaborative work) | 12 months |
| Security log (sign-ins, IP, browser) | Legitimate interest (security, GDPR art. 32) | 6 months |
| Organization and subscription (billing details) | Performance of the contract | Duration of the subscription |
| Client portal (name entered by the client, messages) | Legitimate interest (customer relationship follow-up) | Project duration |
| Meetings by link (title, name entered by guests) | Performance of the contract | Title: until deleted; guests' names: duration of the meeting, never stored |
| Free trial already used (encrypted fingerprint of the email address and network, never in clear) | Legitimate interest (preventing free trial abuse) | 12 months |
| Contact and demo requests (name, email, company, message) | Legitimate interest (answering the request) | 12 months |
| Questions asked to the help center assistant | Legitimate interest (answering the question) | Not kept: processed by the publisher’s AI server, then forgotten |
| Invoices | Legal obligation (art. L123-22 of the French Commercial Code) | 10 years |
| Sign-in sessions | Performance of the contract | 30 days maximum |
| Invitations sent to an email address | Legitimate interest of the inviter | 90 days without acceptance |
| Notification subscriptions | Consent (browser permission) | Until permission is withdrawn |
No data is sold, used for advertising or to train artificial intelligence models.
Security
Personal data and content are encrypted in the database (AES-256-GCM), files are encrypted on disk, messages and calls are end-to-end encrypted: even the publisher can't read your messages. Passwords are hashed (Argon2id), two-factor authentication is available and traffic goes through HTTPS.
Recipients and processors
- Hosting: Tyche Service, 15b chemin du bray, Annecy-le-vieux 74940, 07.68.79.70.91 (European Union).
- Subscription payments: Stripe, through its Link service (Stripe Technology Europe Ltd, Ireland), which sells the subscription as merchant of record and acts as controller for the payment: it receives the name, email, billing address and payment data, applies taxes and issues receipts and invoices. Socle never sees card numbers.
- Push notifications: your browser's service (Google, Mozilla, Apple or Microsoft) receives an encrypted notification that never contains the content of your messages. These services may be located outside the European Union (covered by the Data Privacy Framework or standard contractual clauses).
Calls, font and libraries go only through Socle's servers: no tracker, no third-party audience measurement.
Cookies
Socle only uses a session cookie strictly necessary for signing in, a cookie remembering your chosen language, and the browser’s local storage for your display preferences. They are exempt from consent (art. 82 of the French Data Protection Act), so no banner is needed.
Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to set directives regarding your data after your death. From the settings, you can directly download all your data, change your email and delete your account. For any other request: data@tyche-info.fr (answer within one month).
You can file a complaint with the CNIL (3 place de Fontenoy, 75007 Paris — www.cnil.fr).
Data breach
In case of a breach posing a risk to your rights, the CNIL is notified within 72 hours and you are informed as soon as possible if the risk is high.
Last updated: October 8, 2026