Privacy Policy
Last updated: 13 July 2026 • Version: 1.0
The French version of this document prevails in case of discrepancy.
1. Data controller
Secure Layer SASU: RCS Tours 940 166 408
6 rue d'Entraigues, 37000 Tours, France
Data protection: dpo@securelayer.dev
General: support@securelayer.dev
We process your data under the GDPR (EU) 2016/679 and the French Data Protection Act.
2. Data we collect
| Data | Where | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Account identity: email, Cognito identifier, plan (tier) | AWS Cognito + DynamoDB (eu-west-3) | Authentication, account management | Contract | Life of account |
| Google sign-in (if used): identifier, email | Google (US) | Federated sign-in | Contract | Life of account |
| Content: projects, infrastructure diagrams | DynamoDB + S3 (eu-west-3) | Core product | Contract | Until you delete |
| Security answers and risk justifications (free text) | DynamoDB (eu-west-3) | Security analysis | Contract | Until you delete |
| Code generation (inputs/outputs) | Amazon Bedrock (AWS, eu-west-3) | IaC generation | Contract | Transient |
| Billing data: payment method, address, VAT number | Stripe (EU + US) | Payment | Contract + legal obligation | 10 years (tax law) |
| Telemetry: errors, performance, session recording (text masked), session identifier, tier | Amazon CloudWatch RUM (eu-west-3) | Analytics, reliability | Consent | 30 days |
| Cookie-free audience measurement: page viewed, referrer (domain), campaign (utm), language | Amazon CloudWatch Logs (eu-west-3) | Aggregate traffic statistics | Legitimate interest (Art. 82 exemption) | 13 months |
Free-text fields (risk justifications) may contain personal data if you enter it. Do not include sensitive data there.
3. Cookie-free audience measurement
We count visits to the public pages with an audience measurement tool we built ourselves, hosted on our own AWS infrastructure (eu-west-3). What is counted: the page viewed, the referring site's domain, the campaign (utm), the browser language, and a few anonymous events (for example opening the demo or starting the self-check).
The tool uses no cookie, no identifier and no browser fingerprinting. The only thing stored or read on your device is your objection flag (the sl-no-beacon key): read to honor your objection, written only if you object. Your IP address is never stored; the server may read it transiently to filter out bots, then discards it. The resulting statistics are aggregate and anonymous, produced for our exclusive use, never joined to user accounts and never shared with third parties.
This processing falls under the consent exemption for audience measurement (Article 82 of the French Data Protection Act) and our legitimate interest (GDPR Art. 6(1)(f)). Logs are kept for 13 months.
You can object
Open "Cookie Settings" in the footer and turn on the audience measurement objection. Your browser then sends nothing.
4. Subprocessors
| Subprocessor | Role | Region | Transfer outside the EU |
|---|---|---|---|
| Amazon Web Services (hosting, auth, storage, AI, telemetry) | Hosting & infrastructure | eu-west-3 (Paris) | No (intra-EU) |
| Stripe | Payments | EU + US | Yes: Standard Contractual Clauses |
| OAuth sign-in | US | Yes: Standard Contractual Clauses |
Your data is primarily processed in the EU (AWS eu-west-3); transfers to Stripe and Google are covered by Standard Contractual Clauses (SCCs).
We do not sell your personal data.
5. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, portability and objection, plus the right to withdraw consent.
How to exercise them
Email dpo@securelayer.dev with proof of identity; we respond within one month (GDPR Art. 12). Erasure and export requests are handled manually by our team.
You may lodge a complaint with the CNIL.
6. Automated processing
We automatically classify the importance of some security rules and attach your tier to telemetry; this is not solely-automated decision-making with legal effect (GDPR Art. 22).
7. Security
Data is encrypted in transit (TLS) and hosted on AWS with provider-side encryption at rest, within the European Union. Access is restricted and controlled.
In the event of a high-risk data breach we notify the CNIL within 72 hours and inform affected users (GDPR Art. 33-34).
8. Cookies
See our Cookie Policy for details and consent management.
9. Minors
The service is not intended for anyone under 15, and we do not knowingly collect their data.
10. Retention schedule
The periods below complement the "Retention" column in section 2 and document the auto-expiring technical stores, useful to understand what remains after an erasure request.
| Store | Contents | Retention |
|---|---|---|
| DynamoDB + S3 (eu-west-3) | Account, projects, diagrams, security answers | Life of account, until deletion |
| Stripe | Invoices, subscriptions (accounting obligation) | 10 years |
| DynamoDB backups (PITR): projects, idempotency, credits, generation jobs, cache (prod only) | Point-in-time recovery | 35 days |
| Application logs (CloudWatch Logs) | Lambda function logs | prod: up to 6 months (some 1 year); beta: 1 week |
| Dead-letter queues (SQS: 6, one per domain) | Failed delivery events | 14 days |
| Event archive (EventBridge) | Application events | 7 days |
| RUM telemetry (CloudWatch RUM) | Errors, performance, session recording | 30 days |
| Audience measurement logs (CloudWatch Logs) | Anonymous traffic events (no IP, no identifier) | 13 months |
| Temporary & generated files (S3) | Staging / generation outputs | 1 day (staging); 90 days (generation) |
After an erasure request, some data persists in auto-expiring backups or logs for the periods above; accounting records (Stripe invoices) are retained under a legal obligation (GDPR Art. 17(3)(b), Code de commerce L123-22).
11. Changes
We may update this policy; material changes will be notified and the "last updated" date refreshed.