KEY EXCHANGE…000
Skip to content

Last updated · September 24, 2026

GDPR & your data.

Your rights, how to use them, and how encryption helps companies meet their own obligations.

01

Your rights

If we hold personal data about you, the General Data Protection Regulation (GDPR) gives you the right to:

  • access it and get a copy (art. 15);
  • have it corrected (art. 16);
  • have it erased (art. 17);
  • restrict its processing (art. 18);
  • receive it in a portable format (art. 20);
  • object to its processing (art. 21);
  • give instructions on what happens to it after your death (French law).

02

How to exercise them

Write to contact@quorvault.com with the subject "GDPR request". We answer within one month. If we have a reasonable doubt about your identity, we may ask for information to confirm it, never more than necessary.

If you think your rights aren't respected, you can complain to your data protection authority. In France: the CNIL, cnil.fr/fr/plaintes.

03

What we hold

  • Contact and report requests (name, email, company, message, calculator values): to answer you and prepare a quote, at your request. Kept up to 3 years after our last exchange.
  • Customer records: to perform our contract. Kept for the contract, then as required by law (e.g. 10 years for invoices).
  • Server logs kept by our host: for security, for a short period.

No cookies, no advertising trackers. Details in our privacy policy.

04

Our processors

  • Cloudflare, Inc.: Website hosting, DNS, security and cookieless visit statistics (Global network (EU and US))
  • Resend, Inc.: Delivery of contact form messages, confirmations and reports (United States)
  • Cal.com, Inc.: Call booking (only if you book a call) (United States)

05

When we work on your data

During a diagnostic or an installation, we may access personal data held by your company. We then act as your processor (art. 28): we sign a data processing agreement, access only what the job requires, and keep nothing once the mission ends.

06

How QuorVault helps your own compliance

Art. 32, security of processing, explicitly lists "the pseudonymisation and encryption of personal data" among the appropriate measures. QuorVault encrypts the sensitive columns of your database with standardized algorithms.

Art. 34, data breaches: you don't have to notify the people affected by a breach if the stolen data was rendered unintelligible, for example by encryption, to anyone not authorised to access it. Encrypted columns can change how a breach has to be handled.

Art. 25, data protection by design: encrypting at the field level, bound to each row, limits exposure by default, including to people with direct database access.

Encryption supports compliance; it doesn't replace the rest of it (legal basis, retention periods, records of processing, etc.).