Privacy Policy
GDPR information on the processing operations carried out by Diffusons.
Last updated: 13 September 2026
1. Controller and contact
IXYS acts as data controller for accounts, billing, security, support and the operations necessary to Diffusons. For the content, subscribers, campaigns and messages processed on behalf of a customer, IXYS acts primarily as processor on the documented instructions of the customer.
GDPR (« RGPD ») contact: contact@ixys.fr.
2. Processing operations and legal bases
- Accounts and access: account creation, authentication, roles, security — contract and legitimate interest.
- Billing and payment: subscriptions, invoices, tokenised payments — contract and legal obligation.
- Content and publishing: media, posts, calendars, metrics — performance of the service and the customer's instructions.
- CRM, campaigns and DMs: subscribers, purchases, segments, opt-outs — the customer's instructions; email/SMS only where a marketing legal basis is documented.
- Partner area (external contributors to a production): identity, age of majority, consents, contracts — contract, legal obligation and legitimate interest for evidential purposes.
- Diffusons Copilot (AI assistant): instructions, media or messages passed on to the artificial-intelligence provider when the feature is enabled — contract, the customer's instructions and legitimate interest. This processing is subject to an impact assessment that is kept up to date.
3. Categories of data
The data processed may include identity, contact details, roles, billing data, media content, technical metadata, handles, messages, preferences, purchases, consents, identity documents, access logs and usage data. Technical secrets and full payment details are not stored by Diffusons.
4. Recipients and processors
The recipients are IXYS, the customer's authorised members, the providers necessary to the service and the platforms configured by the customer. The application register lists in particular Scaleway, Stancer, Twilio, xAI/Grok and the publishing or messaging platforms chosen by the customer. Transfers outside the EU are subject to a dedicated assessment and to contractual safeguards where the provider requires it.
4 bis. YouTube API Services
When the customer links a YouTube channel, Diffusons uses the YouTube API Services to upload their videos, edit or remove one, read the statistics of their channel and videos, and read or reply to the comments received. Use of these services is subject to the YouTube Terms of Service and to the Google Privacy Policy.
The data obtained from YouTube (channel identifier and name, access tokens, video identifiers and statistics, comments) is kept for as long as the channel remains linked, for the sole purposes above, and is neither shared with third parties nor used for advertising. It is deleted when the customer removes the channel or their workspace. The customer may revoke Diffusons' access to their Google account at any time from the Permissions page of their Google account.
5. Retention periods
- Account and operating data: for the term of the contract, then purged or anonymised.
- Inactive accounts: prior notice, deactivation, then purging of the operational data after the recovery window (see §5 bis).
- Invoices, payments and accounting records: minimised legal archive for 10 years.
- Raw files in the partner area: purged at D+30 after delivery, with a certificate.
- Consents and verification traces: 5 years for evidential purposes, unless longer obligations apply.
- Logs of exchanges with the platforms: kept without their detailed content, and purged within a short period.
5 bis. Inactive accounts and communications
In the absence of significant activity over a configurable period (12 months by default), IXYS informs the customer by email, offers to keep or close the account, then deactivates the organisation and purges the operational data after a recovery period. Legally required accounting records are kept in a minimised archive.
Marketing emails and SMS carry a means of unsubscribing (signed link, List-Unsubscribe header, STOP SMS). Transactional messages (billing, security, access) are not covered by the marketing opt-out. Service communication preferences are set in the account; a public GDPR request form is available at /en/demande-rgpd.
Diffusons does not use advertising trackers or third-party audience measurement, neither on the public website nor in the application. Only the cookies strictly necessary for operation (session, authentication, security) are set, and they do not require prior consent: no consent banner is therefore displayed.
6. Rights
Individuals may request access, rectification, erasure, restriction, objection and portability via the GDPR form or contact@ixys.fr. Customers may export their organisation or request its deletion from the account settings. External contributors have a “My data” area. Requests are handled within one month, unless the complexity justifies otherwise. Some data may be retained where a legal obligation so requires.
7. Security
Each organisation and each space is strictly segregated. Internal identifiers never appear in public addresses, files are only accessible to those entitled to them, sensitive documents are served through short-lived links, and several sensitive fields are encrypted in the database. In addition, access is traceable, two-factor authentication is mandatory on the operator side, security headers are set and logs have their sensitive content removed.
8. Complaints
If you are not satisfied with a response, you may lodge a complaint with the CNIL (the French data protection authority). IXYS cooperates with the competent authority and documents data breaches in an internal register.