Personal data
TickDoc is a tool for collecting supporting documents. Two very different situations meet in it, and they do not follow the same rules: that of the professional using the service, and that of the private individual being asked for documents.
The French version prevails. This text applies the GDPR as it stands in France, and names the French supervisory authority. This translation is provided for information · read the French version.
Are you a private individual who has been sent a TickDoc link? For the documents you upload, the data controller is the professional asking you for them, not us. We act as a processor on their instructions. To find out how long your documents are kept, or to ask for their erasure, contact them: it is their name that appears on the page where you upload.
1. This public site
No cookie is set by this site. No analytics, no advertising, no preference. So there is no consent banner, because there is nothing to consent to.
The technical server logs keep connection IP addresses for a limited period, for security and fault diagnosis. They serve no commercial analysis and are cross-referenced with nothing.
No font, no script and no image is loaded from a third-party service: visiting this site tells nobody but us that you were here.
Contact form
| Data collected | Name, email address, organisation (optional), content of the message, date sent, IP address. |
|---|---|
| Purpose | Answering your enquiry. Nothing else: no prospecting, no resale, no passing on to a third party. |
| Legal basis | Your enquiry itself (legitimate interest in replying to whoever writes to us). |
| Retention period | Twelve months, then automatic erasure. The IP address is kept for thirty days, solely to protect against mass sending. |
| Anti-bot protection | Handled by our own server, without cookie and without third-party service. Nothing is sent to a third party to validate your message. |
2. If you are a TickDoc customer
For your account and your users, we are the data controller.
| Data collected | Company name, contact details, email addresses of users, sign-in log, activity log, billing data. |
|---|---|
| Purpose | Providing the service, securing access, invoicing, and proving what happened on a case. |
| Legal basis | Performance of the contract, and legal obligation for invoicing. |
| Retention period | For the duration of the subscription, then a thirty-day grace period. Invoices are kept for ten years, an accounting obligation. The activity log is kept beyond the purge of cases: it must outlive what it describes, otherwise it would prove nothing. |
| Processors | Hosting in France. A payment provider for subscriptions. No transfer of uploaded documents outside the European Union. |
A data processing agreement is presented to you at sign-up, and its acceptance is timestamped and kept as proof, in a form that cannot be rewritten.
3. The documents uploaded by private individuals
For these documents we are a processor: the data controller is the professional asking for them. We do not access them for our own purposes, we do not analyse them, and we do not use them to train anything.
- Each case is encrypted with its own key. Text fields are encrypted just like files.
- The retention period is set by the professional, within a ceiling. At its end, the key of the case is destroyed: the documents become unreadable instantly, including in backups already taken.
- When a private individual no longer has any live case with a professional, their identity is erased in turn.
- Every access to a document is logged, including our own support accesses, which require a written reason and enter the customer's log.
To exercise your rights over documents you have uploaded, contact the professional concerned. If you do not know whom to contact, write to us: we will point you to them without disclosing any information about their case.
4. Your rights
Access, rectification, erasure, restriction, objection, portability. To exercise them over the data for which we are the controller: contact@tickdoc.app. An answer within one month.
If the answer does not satisfy you, you may refer the matter to the CNIL, the French data protection authority.
5. Data breach
In the event of a personal data breach, the customers concerned are informed without undue delay, with the nature of the incident, the data concerned and the measures taken. The CNIL is notified within the statutory deadlines. We will not play down an incident to protect an image.
Last update of this page: to complete before going live.