Last updated: 30 July 2026.
1. Controller
DEXTA CONSEIL, 200 rue de la Croix Nivert, 75015 Paris, France, SIRET 101 388 254 00019, publisher of the Tenovia service, is the controller for the processing described below. Contact: hello@tenovia.eu.
No data protection officer has been appointed, the company not falling within the mandatory cases set out in article 37 GDPR.
2. Two distinct roles
DEXTA CONSEIL acts as controller for prospect and client data: forms, orders, accounts, invoicing.
DEXTA CONSEIL acts as processor under article 28 GDPR for data collected from the client environment during an audit. That data belongs to the client, who remains its controller. It is used solely to perform the ordered audit and never for any other purpose.
3. Data collected and purposes
3.1 Partner form
Company, name, role, business email, phone, website, type of organisation, number of environments managed, free text. Purpose: handling the partnership request. Legal basis: pre-contractual steps at the request of the individual, article 6(1)(b).
3.2 Audit order
First name, last name, business email, organisation, package and tier selected, amount, timestamp of acceptance of the terms. Purpose: forming and performing the contract, issuing the invoice. Legal basis: performance of a contract, article 6(1)(b), and legal accounting obligations, article 6(1)(c).
An optional checkbox allows you to receive Tenovia publications. Legal basis: consent, article 6(1)(a), withdrawable at any time.
3.3 Client console account
Account identifier, business email, the immutable technical identifier returned by Microsoft or Google at sign-in, the second-factor secret in encrypted form, hashes of the recovery codes, last sign-in date, chosen language. Purpose: opening and securing access to the console. Legal basis: performance of the contract, and legitimate interest in protecting the service, article 6(1)(f).
No client password is ever received or stored: authentication is delegated to Microsoft or Google. The second-factor secret is encrypted at rest using a key that does not reside in the database. Recovery codes are stored only as irreversible hashes and are therefore unreadable, including by DEXTA CONSEIL.
3.4 Audit collection data
Collection is read-only and covers configuration elements: tenant settings, privileged accounts and roles, authentication methods, access policies, authorised applications, shares, devices, administration logs. It may contain account identifiers and business email addresses.
Collection does not cover message content, file content, or passwords. The technical credentials needed to reach the interfaces travel with the request and are not stored on the server.
Purpose: producing the audit report and the remediation plan. Legal basis: performance of the contract with the client, DEXTA CONSEIL acting as processor.
3.5 Technical and security logs
IP address, timestamp, user agent, sign-in attempts. Purpose: service security, fraud and abuse prevention. Legal basis: legitimate interest, article 6(1)(f).
4. Recipients and processors
- Infomaniak Network SA, Switzerland: hosting of the site, the database and the mail service. Switzerland benefits from an adequacy decision.
- Stripe: payment processing and invoicing. Card data never passes through Tenovia servers, it is entered directly with Stripe. Transfers framed by the European Commission standard contractual clauses.
- Microsoft and Google: authentication of client accounts to the console, where the client selects that provider, and audit collection interfaces.
- Intuition Machines, Inc. (hCaptcha): protecting forms against automated submissions. Transfers framed by the standard contractual clauses.
No data is sold, rented, or passed on for advertising purposes.
5. Retention periods
- Partnership requests and unconverted prospects: three years from the last contact.
- Raw collection records: automatic purge at the retention deadline set for the engagement, thirty days by default from collection.
- Audit reports and findings: for the duration of the contractual relationship, then one year, to allow comparison between two runs.
- Console accounts: for the duration of the contractual relationship, then deletion within three months.
- Accounting records and invoices: ten years, under article L.123-22 of the French commercial code.
- Technical logs: twelve months.
6. Cookies
The site sets no advertising cookie and performs no behavioural tracking. Only strictly necessary cookies are used, which are exempt from consent:
- session cookies opened after sign-in to the console, and a fifteen-minute temporary token binding the authentication request to the browser that initiated it;
- a display preference cookie, light or dark, stored locally by the browser;
- hCaptcha technical cookies, required for the anti-robot check to work.
7. Security
Access to the console requires authentication by the client identity provider, then a Tenovia second factor, mandatory without exception and re-requested at most every fourteen days. Traffic is encrypted in transit. Authentication secrets are encrypted at rest. Report access is partitioned by organisation: a client can only see their own engagements.
8. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions on the fate of your data after your death. These rights are exercised at hello@tenovia.eu. A reply is provided within one month.
Where the request concerns audit collection data, DEXTA CONSEIL acts as processor: the request is forwarded to the client controller, who decides on the outcome.
You may lodge a complaint with the French data protection authority, CNIL, 3 place de Fontenoy, 75007 Paris, cnil.fr, or with the supervisory authority of your own country.