Privacy policy
Last updated: 7 October 2026
1. Who is responsible for your data
AWACLOUD, a French SAS with a share capital of €33,964, 23 ter rue Jean Pinault, 28300 Jouy, France, RCS Chartres 822 982 971, publisher of the websites awacloud.com and awaforge.eu, is the controller of the processing described below.
Contact for any question about your data: privacy@awacloud.com. AWACLOUD has not appointed a data protection officer; this address serves as the point of contact.
2. What we do not collect
2.1. On our websites. The websites set no cookies, use no trackers or third-party audience measurement tools, and do not keep visitors' IP addresses. We may count the number of pages viewed, in aggregate, without cookies, IP addresses or any data that could identify a visitor. Simply visiting the websites involves no collection of personal data.
2.2. In our demos. The online demos run entirely in your browser: the files you open in them are not sent to us.
2.3. In our software. Our libraries run on your systems or those of your users and send us no data: no telemetry, no usage data. We carry out no processing on behalf of our customers in this respect.
3. The data we process, why, on what legal basis, and for how long
| Processing | Data | Purpose | Legal basis | Retention period |
|---|---|---|---|---|
| Correspondence — messages received at our contact, sales, support and awaforge addresses | email address; identity and job title if you provide them; content of the exchanges | answering your request, following it up, providing support | legitimate interest in answering requests; pre-contractual steps or contract, as the case may be | 3 years after the last exchange |
| Security reports — coordinated disclosure address | email address, content of the report | handling the vulnerability and keeping a record of it | legitimate interest in the security of our software and its users | 5 years |
| Customers and contracts — quotes, order forms, invoicing, annual statement for the commercial licence | identity and business contact details of the people we deal with; billing data | entering into and performing the contract, invoicing | contract; legal obligation (accounting) | term of the contract, then 10 years for accounting records |
| Applications: job applications, partners, sponsors, free education and research licences | identity and business contact details, content of the application | assessing the application | pre-contractual steps | duration of the application, then 2 years |
| Business prospecting by email — professionals, for offers related to their activity | professional identity and job title, business email address, organisation, history of exchanges | presenting our offers to you | legitimate interest | 3 years after the last contact without a positive response |
| "Notify me" list — people who asked for it on our websites | email address, date of sign-up | notifying you when new products or features arrive | consent | until you withdraw your consent |
| Exercise of your rights | identity, email address, subject of the request, response | handling your request and keeping proof of it | legal obligation | until we respond to your request; the response is then kept as proof for the applicable limitation period; any proof of identity requested is deleted once the request has been granted |
Prospecting: where your data comes from. When we contact you without you having written to us first, your contact details are business contact details that have been made public or obtained from third parties. You can always object to our messages, without giving a reason, by a simple means stated in each of our messages: a reply to that message, or an email to privacy@awacloud.com. Your objection applies to all our future messages.
"Notify me" list. Signing up is voluntary: you sign up by clicking the button provided for this purpose on our websites. You can unsubscribe at any time by replying "stop" to any of our messages, or by writing to newsletter@awacloud.com or privacy@awacloud.com.
Mandatory data. The data requested to draw up a quote, an order form or an invoice is necessary to enter into the contract; without it, the contract cannot be concluded. Other exchanges are optional.
We process no sensitive data, make no automated decisions and carry out no profiling. We do not sell or rent your data.
4. Who has access to it
- authorised AWACLOUD staff, within the limits of their duties;
- Proton AG (Switzerland), the host of our email, acting as our processor: it hosts all messages exchanged with our email addresses;
- our accounting providers (bookkeeping and chartered accounting, established in France), who receive only the documents needed for the accounts and the year-end closing;
- our approved platform for electronic invoicing;
- public authorities, upon a lawful request.
No data is entrusted to any other provider.
5. Transfers outside the European Union
Our email is hosted in Switzerland by Proton AG. Switzerland benefits from an adequacy decision of the European Commission (Decision 2000/518/EC): this transfer requires no additional safeguard. We make no other transfer outside the European Union.
When you interact with our projects on third-party platforms (GitHub, npm), those platforms process your data under their own policies, for which they are responsible.
Our LinkedIn page: LinkedIn and AWACLOUD are joint controllers for the page's visitor statistics; LinkedIn has primary responsibility, and you can exercise your rights with it.
6. Your rights
You have the right of access, rectification, erasure, restriction and, for processing based on contract or consent, portability of your data. You may object at any time, without giving a reason, to business prospecting, and, on grounds relating to your particular situation, to other processing based on our legitimate interest. You may withdraw your consent at any time, in particular for the "Notify me" list.
Write to privacy@awacloud.com. We respond within one month. We may ask you to prove your identity where we have reasonable doubts.
You may lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr), or, if you live in another Member State of the European Union, with the supervisory authority of that State.
7. Security
Access to data is limited to the people who need it, through named accounts. All our online accounts are protected by two-factor authentication, and our credentials are kept in an encrypted vault. Our email is hosted by Proton, which encrypts the messages it stores. The data of our customers, prospects and correspondents is never placed in our public code repositories. Security reports can be sent to us encrypted, using the OpenPGP key published in the websites' security.txt file. If a personal data breach is likely to result in a risk to your rights, we notify the CNIL within 72 hours and, if that risk is high, we inform you.
8. Changes
This policy may change, in particular if we open a customer area, a forum or any service collecting data on our websites. The date of the last update is shown at the top; the version in force is the one published on the websites.