Privacy Policy
What personal data FI-DATA (“we”, “causalIT”) processes when you visit causalit.fr, create an account, use the service or browse a website measured with causalIT — and what your rights are.
Who is responsible
The data controller for the causalit.fr website and for customer accounts is FI-DATA, a simplified joint-stock company (SAS) under French law with a share capital of €1,500, registered with the Auch Trade and Companies Register under number 900 033 622, whose registered office is at 80 rue Jean Jaurès, 32500 Fleurance, France. We have not appointed a data protection officer; the contact point for every privacy matter is contact@causalit.fr.
For the audience measurement our customers run on their own websites, the customer is the controller and we act as processor on their instructions (see “Visitors of sites measured with causalIT” below, and the Data Processing Agreement).
Two situations, two roles
- You are a customer or a visitor of causalit.fr: we decide why and how your data is processed — we are the controller.
- You visit a website that uses causalIT: the owner of that site decides to measure its audience — they are the controller, and we only process the measurement data on their behalf.
Data we process as a controller
| Data | Source | Purpose |
|---|---|---|
| Account: e-mail address, name, password (stored only as a salted scrypt hash), language, notification preferences, e-mail verification status | You, at signup and in your settings | Create and operate your account; send the e-mails the service requires (verification, password reset, invitations, e-mail change) |
| Organisation and sites: organisation name, memberships and roles, site configuration (hostname, time zone, retention period, goals, funnels, alerts, reports, custom domain, API keys stored as SHA-256 hashes, white-label branding) | You and your team | Provide the service |
| Login sessions: session token, creation and expiry dates, IP address and browser (user agent) of the device | Your browser, at login | Keep you signed in for up to 30 days, show you your active sessions, detect account misuse |
| Security counters: login attempts keyed on the IP address and e-mail | Your browser | Protect accounts against brute force and abuse |
| Activity log: dated entries about significant account actions (login, invitation, plan change, export, deletion, administrator impersonation), with a frozen label of the author and target | Your use of the service | Security, traceability and evidence |
| Billing: plan, subscription status, Stripe customer and subscription identifiers, invoices | You and Stripe | Bill paid plans, keep accounting records |
| Report recipients and alert addresses: e-mail addresses you enter to receive scheduled reports or alerts | You | Send those reports and alerts on your instruction |
| Support exchanges: e-mails you send to contact@causalit.fr | You | Answer you |
| Use of causalit.fr and of the application: pages viewed, tied to your account when signed in, otherwise to a daily anonymous fingerprint (see below) | Your browser | Measure and improve the product — with our own cookieless method |
We never see card numbers: payment happens on Stripe's hosted pages and Stripe only sends us the status of the subscription.
Why we process it and on what legal basis
- Performance of the contract (GDPR art. 6.1.b): creating your account, providing the service, sending the e-mails the service needs, billing.
- Legal obligations (art. 6.1.c): keeping invoices and accounting records, answering lawful requests from authorities.
- Our legitimate interests (art. 6.1.f): securing accounts and the platform, preventing abuse, keeping a trace of significant actions, measuring the use of our own product with a method that identifies nobody.
- Your consent (art. 6.1.a): only for the optional third-party services listed in the Cookie Policy, should we activate one — none is active today.
Visitors of sites measured with causalIT
When you browse a website that uses causalIT, the tag (or the site's server) sends us the page viewed, the referrer, the browser family, the screen size and the time of the visit. Personal data is kept to the minimum:
- No cookie and no storage is read or written on your device, so the site does not need your consent to measure its audience in this default mode.
- Your IP address is used only in memory, for two things: deriving a non-reversible daily identifier — a hash of a global secret, a per-site secret, the day, the IP address and the browser — and looking up an approximate location (country, region, city) in a database hosted on our own servers. The IP address itself is never stored and never leaves our infrastructure.
- The identifier changes every day and differs from one site to another: we cannot follow you across days or across sites, and we cannot identify you.
- Query strings are stripped from page addresses before storage, and customers are contractually forbidden from putting personal data in the paths or custom properties they send.
- A customer using our backend SDK may enable an “identified mode” and send an already-hashed identifier of their own users. That pseudonymised data belongs to the customer, who must have a legal basis and inform their users; we re-hash it per site and never receive the original value.
For these measurements the site owner is the controller: exercise your rights with them. We help them answer you, as our Data Processing Agreement requires.
Behavior measurement (heatmaps)
Some site owners also enable behavior measurement — heatmaps of clicks, hovers, scroll depth and attention — to understand how their pages are used. It is off by default, opt-in per site, and adds nothing an ordinary page view does not already disclose:
- The site owner turns it on in their settings and chooses a sample rate; the tag stays silent — no listener, no observer — on sites that did not opt in.
- What is measured: which elements of a page a visitor saw, for how long, clicked or hovered, plus scroll depth and attention by 5% band of the page.
- What is never collected: no mouse trail, no session replay, no screenshot, no form value, no paragraph text (only its position under the nearest heading) — and no visitor or session identifier of any kind.
- The recorded time is rounded to the hour and the rows cannot be tied to one person even by us: there is no query that replays an individual visit.
- Whether a page view is included is decided from the same daily fingerprint described above, then the fingerprint is discarded — it is never stored alongside behavior data.
Retention and roles are the same as for audience events (see “How long we keep it” below): the site owner is the controller for this data too, and we act as processor on their instructions.
Who receives the data
Our team accesses data only when operations or support require it. The following providers process data on our behalf, under a contract:
| Provider | Role | Location |
|---|---|---|
| OVH SAS (OVHcloud), 2 rue Kellermann, 59100 Roubaix, France | Hosting of servers, databases and backups | France |
| Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland | Payment processing and invoicing for paid plans (customers only) | European Union; transfers to Stripe, Inc. (United States) under the EU–US Data Privacy Framework and standard contractual clauses |
Transactional e-mails are sent from our own mail server: no third-party e-mail provider sees them. Geolocation uses a MaxMind GeoLite2 database copied onto our servers: no request is sent to MaxMind. We do not sell personal data and do not share it with advertisers.
We may disclose data when the law requires it, or to a successor in the event of a merger or sale of the business, under the same commitments.
Where the data is hosted
Our servers, databases and backups are hosted in France. The only transfer outside the European Union concerns the payment data handled by Stripe, described above.
How long we keep it
| Data | Retention |
|---|---|
| Account, organisation and site configuration | For as long as the account exists; deleted when you delete your account |
| Login sessions | 30 days after creation, or as soon as you log out or revoke them |
| E-mail verification, password reset and invitation tokens | Until used or expired |
| Security counters | Minutes to hours |
| Activity log | For the life of the account; once the account is deleted, entries keep only a frozen label (name or e-mail) so that the trail of past actions stays intelligible |
| Invoices and accounting records | 10 years (French Commercial Code, art. L123-22) |
| Audience events of a site (as processor) | The retention period set by the site owner — at most 180, 365, 730 days depending on the plan. A daily job purges older events, and a 24-month ceiling applies in any case. Deleting a site deletes all its events. |
| Behavior data of a site (heatmaps — as processor) | Same retention as audience events, above, set by the site owner; deleting a site deletes it immediately. |
| Use of causalit.fr and of the application | 180 days; the daily fingerprint cannot be linked back to a person after the day |
| Support e-mails | For as long as needed to handle your request, then archived for no longer than 3 years |
| Backups | Daily backups of the account database, kept 14 days; deleted data disappears from backups at the end of that cycle |
Your rights
Under the GDPR and the French Data Protection Act you may access your data, rectify it, have it erased, restrict or object to its processing, receive it in a portable format, and give instructions about what happens to it after your death.
- Most rights are self-service: in Account settings you can edit your profile, change your e-mail address, download a JSON export of your personal data, revoke sessions and delete your account — which immediately deletes the organisations and sites you were the sole owner of, together with their audience data.
- For anything else, write to contact@causalit.fr. We answer within one month; we may ask you to prove your identity when there is a reasonable doubt.
- You may lodge a complaint with the supervisory authority — in France, the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
If your request concerns a website measured with causalIT, it must be addressed to the owner of that site, who is the controller; we will assist them.
Security
Passwords are hashed with scrypt; API keys and tokens are stored as SHA-256 hashes; every connection is encrypted (TLS); the administration area is restricted and every administrator action on an account — including impersonation for support — is logged; servers are hardened and patched automatically; the account database is backed up daily. No system is infallible: if a breach affects your data, we will notify you and the CNIL as the law requires.
Children
The service is intended for professionals and is not directed at children under 15. We do not knowingly collect their data.
Changes
We update this policy when the service or the law changes. Significant changes are announced by e-mail to account holders or by a notice in the application; the version in force is the one published on this page, with its date.
Last updated: August 21, 2026
← Back to home