Privacy and Data Protection Policy
Introduction
At GlassPredict, the trading name of Seironis Engineering, a French société par actions simplifiée unipersonnelle (SASU) registered under SIREN 108859042 ("the Data Controller"), we are committed to safeguarding the personal data we collect and process. This Privacy and Data Protection Policy outlines how we collect, use, share, and protect the personal information of our customers, employees, suppliers, and other stakeholders, in compliance with the General Data Protection Regulation (GDPR) and French Law No. 78-17 of 6 January 1978, relating to data processing, files, and freedoms (Loi Informatique et Libertés).
Data Controller
GlassPredict, the trading name of Seironis Engineering, a French société par actions simplifiée unipersonnelle (SASU) registered under SIREN 108859042, is the Data Controller responsible for ensuring that personal data is processed in compliance with applicable laws and regulations. As the Data Controller, we determine the purposes and means of the processing of personal data.
For any inquiries related to data protection or to exercise your data subject rights, you may contact us using the following channels:
- Email:
- Postal Address: 63 rue André Bollier, 69007 Lyon, France
Purposes of Data Processing
| Processing purpose | Legal basis |
|---|---|
| Responding to inquiries and pre-contractual exchanges | Legitimate interest / pre-contractual measures, Art. 6(1)(b) and (f) GDPR |
| Providing requested services to our clients | Performance of a contract, Art. 6(1)(b) GDPR |
| Managing user accounts and authentication on the Portal | Performance of a contract, Art. 6(1)(b) GDPR |
| Operating and securing the Portal, including access control, job monitoring, and prevention of unauthorized access | Legitimate interest (service operation and security), Art. 6(1)(f) GDPR |
| Processing technical files uploaded through the Portal | Performance of a contract, Art. 6(1)(b) GDPR |
| Logging technical/security events (login attempts, errors, security events) | Legitimate interest (system security and fraud prevention), Art. 6(1)(f) GDPR |
| Complying with legal and contractual obligations, including accounting and invoicing | Legal obligation, Art. 6(1)(c) GDPR |
| reCAPTCHA (spam and abuse protection) | Consent, Art. 6(1)(a) GDPR |
Providing the data required for the above purposes is generally necessary to respond to your request or to perform the applicable contract; where data is optional, this is indicated at the point of collection. Where a purpose relies on legitimate interest, you may object to that processing as described under "Data Subject Rights" below.
Data Subject Rights
- Right of access: Individuals can request access to their personal data.
- Right to rectification: Individuals can request the correction of inaccurate or incomplete data.
- Right to erasure (right to be forgotten): Individuals can request the deletion of their data in certain circumstances.
- Right to restriction of processing: Individuals can request that the processing of their data be restricted under certain conditions.
- Right to data portability: Individuals can request to receive their data in a structured format and transfer it to another data controller.
- Right to object: Individuals can object to the processing of their data based on legitimate interests or for direct marketing purposes.
- Right to lodge a complaint: Individuals have the right to lodge a complaint with the French data protection authority (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with the supervisory authority of their own EU member state.
To exercise these rights, data subjects may contact us via contact@glasspredict.com or by post at 63 rue André Bollier, 69007 Lyon, France.
Transfer of Data to Third Parties
We will not share personal data with third parties unless:
- It is necessary for providing our services (e.g., with service providers).
- It is required by law.
- We have obtained the consent of the data subject.
When transferring data to third parties, we ensure that appropriate safeguards are in place to protect the data.
Online Client Portal - Specific Processing
When using the online client Portal, additional categories of data may be processed in connection with account management and service execution.
- Account data: email address, username, encrypted password, login timestamps, access history.
- Technical log data: IP address, browser information, timestamps, session identifiers, security-related logs.
- Execution metadata: job identifiers, module type, execution status, timestamps, and system-generated logs.
Technical files uploaded to the Portal (such as CAD files or input parameters) are processed exclusively for the purpose of generating requested calculation or simulation results. These files are not used for profiling, marketing, resale, or training of external systems.
Simulation results made available through the Portal are generated by automated processes. Unless expressly agreed in writing, no systematic human validation or interpretation is performed.
Data Processors
OVH SAS
- Role: Web-app hosting, database storage, calculation/simulation processing, mail hosting, SMTP relay, webmail access
- Location: France (EEA) - OVHcloud data centres
- Data processed:
- Web server logs (IP addresses, timestamps, user agent)
- Contact form submissions (name, e-mail, message)
- E-mail metadata (timestamps, IP addresses)
- Authentication-related data (username, hashed password, login timestamps, session tokens)
- Storage and processing of uploaded technical files and generated results on calculation servers operated within the European Economic Area (EEA), for operational purposes and for a duration consistent with the contractual relationship and applicable retention policies.
- Purpose:
- Hosting and operation of our website, back-end, and the online client Portal
- Execution of automated calculation and simulation workflows
- Delivery, storage and transmission of transactional e-mails
- Legal basis:
- Performance of contract (Art. 6(1)(b) GDPR)
- Legitimate interest (Art. 6(1)(f) GDPR)
- Retention: Contact-form emails are retained by GlassPredict for up to 24 months. OVHcloud retains deleted items (from the Trash/Deleted Items folder) for 14 days, after which they are permanently purged. Portal account data is retained until account deletion or as required by law.
- DPA: A Data Processing Agreement in accordance with Article 28 GDPR forms part of OVHcloud's contractual framework and applies to the services used by GlassPredict.
- Security: TLS encryption in transit; technical and organizational measures implemented in accordance with Article 32 GDPR; data centres located within the EEA.
International Transfers
OVH (France) operates within the European Economic Area (EEA), so no additional safeguards are required under Chapter V of the GDPR.
Sub-processor Transparency
OVH may engage additional subprocessors (e.g. CDN providers, network carriers). Their current list can be found here:
- OVH sub-processors (via Data Processing Agreement appendix): Data Processing Agreement (DPA)
We rely on their published lists to ensure compliance and transparency regarding the subprocessors they use.
Data Retention
- Contact-form submissions (names, email addresses, messages) are retained for up to 24 months to allow us to handle your request and provide follow-up service.
- Email exchanges with customers (support or commercial correspondence) are archived for 5 years in order to meet legal prescription requirements and to have records in the event of a dispute.
- Accounting and invoicing records are kept for 10 years in accordance with commercial law.
- Portal account data is retained for the duration of the contractual relationship and deleted upon account closure, except where legal retention obligations apply.
- Uploaded technical files and generated results are stored only for operational purposes and for a limited duration. Long-term storage is not guaranteed. Users are responsible for downloading and archiving any results they wish to retain.
- Security and access logs may be retained for a limited period necessary to ensure system integrity, prevent abuse, and investigate incidents.
Cookies and Tracking Technologies
Our website uses cookies and similar technologies to ensure its proper functioning and enhance the user experience.
- Strictly necessary cookies: These are essential for the website to function (e.g., session management, CSRF protection) and cannot be switched off.
- Analytical cookies: Not used at this time.
- Marketing/third-party cookies: We use Google reCAPTCHA to protect our forms against spam and abuse. This may place cookies from Google on your device. Google reCAPTCHA is only loaded after you have accepted third-party cookies.
When you first visit our site, you are asked whether you accept or reject third-party cookies. You may change your preferences at any time using the "Manage Cookies" link in the footer.
For more information about Google reCAPTCHA, see Google's privacy policy: policies.google.com/privacy
Modifications to the Privacy and Data Protection Policy
We reserve the right to modify this Policy at any time. Any changes will be published on our website and communicated to data subjects by appropriate means.