Privacy Policy — Alpik Pro
Last updated: June 2026
1. Data Controller and Account Model
Alpik Pro uses a three-level account model:
| Level | Created by | Alpik's role |
|---|---|---|
| Organisation account | Alpik support (on request) | Data controller |
| Administrator account | Alpik support (on request) | Data controller |
| User accounts | Organisation administrator | Data processor |
For organisation and administrator accounts, Alpik determines the purposes and means of processing and acts as the data controller.
For user accounts created by an organisation administrator, the client organisation is the data controller. Alpik processes this data solely on behalf of the organisation, acting as a data processor under the terms of a Data Processing Agreement (DPA). The organisation is responsible for informing its own users about data processing and for ensuring it has a valid legal basis for creating and managing their accounts.
Data controller contact: privacy@alpik.fr
2. Data Processing Agreement (DPA)
If your organisation creates and manages user accounts through the Alpik Pro console, a Data Processing Agreement is required between your organisation (as data controller) and Alpik (as data processor), in accordance with GDPR Article 28.
To request the DPA, contact privacy@alpik.fr.
3. Data We Process
Organisation account data (Alpik as controller)
| Data | Purpose |
|---|---|
| Organisation name | Identifying the client organisation |
| Billing and administrative contact | Contract management |
Administrator account data (Alpik as controller)
| Data | Purpose |
|---|---|
| First name, last name | Identifying the account holder |
| Email address | Authentication, account notifications |
User account data (Alpik as processor — on behalf of the organisation)
| Data | Purpose |
|---|---|
| First name, last name | Identifying the user within the organisation |
| Email address | Authentication, notifications |
| Role / permissions | Access control within the console |
Platform usage data
When users interact with the console, we process:
- Login timestamps and session identifiers
- Actions performed in the console (audit trail)
- IP address and browser type
Device and IoT data
When devices are managed through the console:
- Device identifiers and configuration parameters
- Uplink data (sensor payloads, RSSI, timestamps) forwarded by Alpik devices
- Event rules configured by users and their trigger history
Technical and security data
- Server access logs (IP address, request method, response code, timestamp)
- Error and diagnostic logs
4. Purpose and Legal Basis
For organisation and administrator accounts (Alpik as controller)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide access to the Alpik Pro platform | Contract performance — Art. 6(1)(b) |
| Send account and security notifications | Contract performance — Art. 6(1)(b) |
| Detect and prevent unauthorised access | Legitimate interest — Art. 6(1)(f) |
| Comply with legal obligations | Legal obligation — Art. 6(1)(c) |
For user accounts (Alpik as processor)
Alpik processes user account data solely on documented instructions from the organisation, as specified in the DPA. The organisation is responsible for establishing and documenting the legal basis for processing its users' data.
5. Data Retention
| Category | Retention period |
|---|---|
| Organisation and administrator account data | Duration of the contract + 1 year after termination |
| User account data | Until deleted by the organisation administrator, or contract end + 1 year |
| Device and event data | 90 days after deletion or contract end |
| Audit and access logs | 12 months |
| Security and error logs | 12 months |
After the applicable period, data is permanently deleted or anonymised.
6. Third-Party Processors
We use the following sub-processors, all operating under GDPR-compliant data processing agreements:
| Processor | Role | Location |
|---|---|---|
| Scaleway SAS | Cloud hosting and infrastructure | EU (France) |
We do not sell or share your data with third parties for marketing purposes.
7. Data Transfers
All data is hosted and processed within the European Union. No transfers to third countries take place.
8. Security
We implement appropriate technical and organisational measures to protect data against unauthorised access, alteration, disclosure, or destruction, including:
- Encrypted connections (TLS) for all communications
- Access control restricted to authorised personnel
- Regular security reviews
9. Your Rights
Administrator and organisation contacts (Alpik as controller)
As a data subject under the GDPR, you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data (GDPR Art. 15–21). Contact privacy@alpik.fr to exercise these rights.
Users managed by an organisation (Alpik as processor)
For user accounts created by an organisation administrator, data subjects should exercise their rights directly with their organisation (the data controller). The organisation may contact privacy@alpik.fr to fulfil requests under the terms of the DPA.
You also have the right to lodge a complaint with the French data protection authority (CNIL): https://www.cnil.fr.
10. Contact
Data Protection contact: privacy@alpik.fr
For general support: contact@alpik.fr