Privacy policy
01In short
Dooplik processes two categories of data: your account data and your exchanges with us (contact form, support), for which the publisher is controller; and, on your behalf, the API credentials of your Odoo instances, the data they give access to and execution logs, for which it acts as processor. Everything is hosted in the European Union. We sell no data and we do not keep the content of the records the tool passes through.
02Data controller
Alexandre PETIT, sole trader (entrepreneur individuel) operating under the trade name SERENITE, 2 rue des Peupliers, 17170 La Ronde, France (SIREN 895 174 910). For any question about your data: bonjour@dooplik.com.
03Account data
Name, work email address, company, password (stored as a hash, never in clear text), role in the workspace, billing history and support exchanges. Purposes: opening and administering your account, billing the subscription, answering your requests. Legal basis: performance of the contract. Contact data: name, email address, company and message sent through the contact form. Purpose: answering your request. Legal basis: pre-contractual steps taken at your request or the publisher's legitimate interest in answering enquiries.
04Credentials for your Odoo instances
URL, database name, user and API key for the instances you connect. They are encrypted at rest with AES-256-GCM under a per-account derived key, and are decrypted in memory only, for the time it takes to run an operation you triggered. They are never copied to a target instance and are accessible to no other account.
05Data processed on your behalf inside your instances
When you start a propagation, Dooplik reads from your source instance and writes to your target instance — including, if you enable the data step, records that may contain personal data (contacts, users). That content passes through memory and is not retained. On this scope Dooplik acts solely on your documented instructions, as a processor within the meaning of Article 28 GDPR. The publisher's commitments as processor are set out in the “Personal data and processing on behalf of the Customer” article of the terms of sale; a signed data processing agreement can be concluded on request.
06Execution logs
For each run we keep the technical name of the objects processed, their XML ID, their status and the error message returned by Odoo where applicable. These logs are what produce your audit reports and let us diagnose failures. How long they are kept depends on your plan and is stated on the pricing page.
07Cookies
The site and service only set trackers that are strictly necessary for them to work: a session cookie that keeps you signed in; a cookie remembering your chosen language; local storage of your display preference (light or dark theme). These trackers are exempt from consent under Article 82 of French Law No. 78-17 of 6 January 1978. No audience measurement, advertising or social media tracker is set. Payment takes place on a page hosted by Stripe, which applies its own tracker policy there.
08Recipients and sub-processors
Your data is neither sold nor transferred. It is accessible to the publisher and, where applicable, the persons it authorises, strictly as far as running the service requires, and to our technical providers: [TO BE COMPLETED: hosting provider], [TO BE COMPLETED: payment provider], [TO BE COMPLETED: email delivery provider, if any]. All process the data in the European Union or under a transfer framework compliant with the GDPR.
09Retention periods
Account data: for as long as you use the Service, including on the free plan; an account inactive for [TO BE COMPLETED: period, e.g. three years] is deleted after prior notice. After the account is closed, data needed to prove the contract is kept in intermediate archive for five years. Contact form data: three years from the last exchange. Execution logs: for the period set by your plan, and at the latest until the workspace is closed. Accounting records and invoices: ten years, as required by law. Instance credentials: until you delete them, and at the latest thirty days after the account is closed.
10Your rights
You have the right to access, rectify, erase, restrict, object to and port your data. You can exercise those rights at bonjour@dooplik.com, and lodge a complaint with your national supervisory authority. If your request concerns data held inside your own Odoo instances, it falls under your own responsibility as controller: we assist you, but we do not answer it on your behalf.
11Security
Credentials encrypted at rest, data partitioned between accounts at the database level, traffic encrypted in transit, two-factor authentication available from the Studio plan and SSO/SAML sign-in on the Agence+ plan. We claim no security certification: we describe the measures actually in place.
12Changes to this policy
This policy changes as the service does. Any substantial change is notified to account holders by email before it takes effect. Version of [TO BE COMPLETED: publication date of this version].