PERSONAL DATA

Privacy policy

This page explains, without badges or vague claims, which data is used, why it is used, how long it is kept, and how to exercise your rights.

Last updated: August 5, 2026

1. Who does what?

For the public website, contact requests and SqareX account administration, the SqareX legal operator acts as data controller. For business or patient data processed in a clinic workspace, the clinic determines the purposes and generally remains the controller; the SqareX legal operator acts as processor under its agreement with that clinic.

2. Contact form

We use your name, email address, topic and message, plus your phone number and clinic name when provided, to answer your request and arrange a demo or account connection. Required fields are necessary to process the request.

The legal basis is taking pre-contractual steps at your request or, depending on the request, the SqareX legal operator's legitimate interest in answering professional contacts. The form does not subscribe you to a newsletter.

3. Accounts and platform

The platform processes account information, sessions, roles and site access to provide and secure the service. Clinic workspaces may contain operational data and, depending on enabled modules, health data. Access is restricted by role and site; requests about patient data should first be sent to the relevant clinic.

Depending on the operating configuration, technical logs from the proxy, application or hosting provider may contain the IP address, user agent, timestamp and requested route for security and diagnostic purposes. Their scope, access and retention must be minimised and formalised in the operating record.

4. Recipients and service providers

Data is available to authorised staff of the SqareX legal operator and, where relevant, the clinic concerned. The primary infrastructure runs on AWS in the Europe (Paris) region. Resend handles email delivery and Cloudflare Turnstile protects the contact form from abuse. AI providers may be enabled in selected modules under the clinic's contractual configuration.

Cloudflare, Resend or an AI provider may involve processing outside the European Economic Area. The applicable contractual safeguards, regions, retention periods and settings must be documented in the contract and processing record before the relevant service is enabled.

5. Retention periods

  • Turnstile tokens: used for verification and not retained by SqareX.
  • Contact requests in the technical outbox: 90 days after a terminal state, up to 180 days for errors requiring investigation.
  • Business correspondence: as long as needed to follow up the request, then according to contractual policy and applicable legal requirements.
  • Account sessions: 7 days with controlled renewal; accounts follow the contract term and security obligations.
  • Clinic data: according to the agreement, the clinic's instructions and the legal requirements applying to the data.

6. Cookies and local storage

The public website currently loads neither targeted advertising nor audience analytics. It only uses necessary or expected items: language preference, session and security cookies, and Turnstile on the contact form. These purposes are exempt from prior consent, so no choice banner is displayed unless optional tracking is later introduced.

7. Your rights

You may request access, correction, deletion, restriction or portability, and object to processing based on legitimate interests. Use the dedicated form below; the request is forwarded to the internal channel configured for SqareX. Proportionate identity verification may be requested. You may also lodge a complaint with the CNIL.

Exercise my rightsSubmit a complaint to the CNIL

8. Security and claims

SqareX uses controls including TLS in transit, role- and site-based access, audit logs and a PostgreSQL database that is not publicly exposed. GDPR is not a certification. SqareX only displays a third-party certification when a valid certificate or report actually covers the service being presented.