Privacy Policy
Last updated: 25 July 2026
This Privacy Policy describes how METIS SAS ("we", "us", "our") collects, uses, and protects your personal information when you use DPP-Tool (the "Service"). Contact: [email protected].
1. Data Controller
METIS SAS, 120 Chemin de Ceinture, 13400 Aubagne, France. SIRET: 991 555 574 00011.
2. Data Collected
We collect the following personal data:
- Account data: email address, name, company name (optional), date of last sign-in
- Product data: product information you enter to generate Digital Product Passports
- Usage data: pages visited, features used (with your consent via Google Analytics 4)
- Technical data: IP address, browser type, device type (for security and performance)
- Sign-in protection data: a counter of failed sign-in attempts, held against a one-way hash of the email address and of the IP address. The address and the email themselves are never written to this counter, and it is erased on a successful sign-in.
- Security alerts: when repeated failed sign-ins trip a threshold, we record the event together with the network the attempts came from — the address truncated to /24 (IPv4) or /48 (IPv6), never the full address.
- Password reset: a one-way hash of the reset link, valid one hour, single use.
- Two-factor authentication (only if you enable it): the shared secret used to check your codes, and one-way hashes of your ten recovery codes.
We do not collect payment card data. All payment processing is handled securely by Stripe.
3. Purpose of Data Processing
Your data is processed for the following purposes:
- Providing the DPP-Tool service and generating Digital Product Passports
- Managing your user account and subscription
- Sending transactional emails (account confirmation, password reset, security notifications, subscription updates)
- Improving the Service through anonymous usage analytics (with consent)
- Ensuring the security and integrity of the platform — in particular detecting and blocking attempts to guess passwords, and letting you protect your account with a second factor
Legal basis: contract performance (Art. 6(1)(b) GDPR), legitimate interest (Art. 6(1)(f)) — which is the basis for the sign-in protection and security alerts described above — and consent for analytics (Art. 6(1)(a)).
4. Data Sharing
We do not sell your personal data. We share data only with:
- Stripe: payment processing (PCI DSS compliant)
- o2switch: hosting provider (data stored in France)
- Brevo: delivery of our transactional emails — account confirmation, password reset, security notifications. Brevo receives the recipient address and the message content. Note that Brevo rewrites links in the messages it sends for click tracking, which means the links you click in our emails pass through Brevo.
- Supabase: the database that receives our security alerts. It never receives your email address, your name or your full IP address — only the truncated network described in section 2, and the fact that a threshold was crossed.
- Cloudflare: traffic delivery and protection in front of the website
- Google Analytics 4: anonymous usage statistics (with your consent only)
5. Data Retention
- Active accounts: data is retained for the duration of your account
- Closed accounts: you can close your account yourself from your dashboard settings. It takes effect immediately — your published passports go offline. Your data is then permanently deleted 30 days later, in our database and in our backups, and cannot be recovered.
- Sign-in attempt counters: kept for 15 minutes of activity, and swept from disk after 24 hours at the latest
- Password reset links: one hour, or until used
- Two-factor unlock requests: 72 hours, or until cancelled or carried out
- Server logs: automatically deleted after 12 months
6. Data Security
We implement appropriate technical and organizational measures:
- HTTPS/TLS encryption for all communications
- Bcrypt password hashing (cost factor 12)
- Protection against password guessing: attempts are capped per account and per network, and blocked temporarily beyond that
- Optional two-factor authentication (TOTP), with single-use recovery codes
- CSRF token protection on all forms
- SQL injection prevention via prepared statements
- Security headers, including a Content-Security-Policy that only allows scripts we have signed for that page
- Uploaded documents stored outside the web root and served only after an ownership check
- Data stored on EU-based servers (France)
7. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access: obtain a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Restriction: limit processing of your data
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interest
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the French data protection authority (CNIL): www.cnil.fr.
8. Cookies
We use the following cookies:
- Essential cookies: session management (PHPSESSID) — required for the Service to function
- Analytics cookies: Google Analytics 4 — only activated with your explicit consent via our cookie banner. No analytics script is loaded and no analytics cookie is set before you accept.
- Preference cookies: cookie consent choice (cookie_consent) — to remember your preferences
You can change or withdraw your choice at any time using the Cookie settings link in the footer of every page. Withdrawing consent is as easy as giving it: your analytics cookies are deleted immediately.
9. International Transfers
Your account and product data is stored and processed in France (EU), at o2switch.
Some of our providers may process data outside the EU. When using Google Analytics 4 (with consent), some data may be processed in the US under EU-US Data Privacy Framework safeguards. Our security alerts are stored with Supabase; because we cannot guarantee where that data is held, we deliberately send it nothing that identifies you — no email address, no name, no full IP address.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of significant changes via email.