Quick access
1 — Legal framework
NOVALYNX processes your personal data in compliance with the General Data Protection Regulation (GDPR - EU 2016/679) and the amended French Data Protection Act (Loi Informatique et Libertés). NOVALYNX SAS acts as the data controller for the data collected through this website.
2 — Technical measures
TLS encryption across all site-to-server communications. Hosted in ISO 27001 certified datacenters (European Union) · Web application firewall and intrusion detection system. Encrypted daily backups. Regular security updates.
3 — Organizational measures
Data access is strictly limited to authorized personnel. Confidentiality agreement signed by all employees. Regular cybersecurity awareness training. Formalized procedure in the event of a data breach. Up-to-date data processing register.
4 — Subcontractors
Our technical subcontractors (Framer hosting, anonymous analytics tools, professional email platform) are selected based on their GDPR guarantees and are bound by a subcontracting agreement. No data transfer is made to a third country without standard contractual clauses validated by the European Commission.
6 — Incident Management
In the event of a personal data breach likely to result in a risk to your rights and freedoms, NOVALYNX undertakes to notify the CNIL within 72 hours and to inform you directly if the incident justifies it, in accordance with Articles 33 and 34 of the GDPR.
7 — Backups
Data is backed up daily on encrypted media, kept in environments separate from the production system. The restoration procedure is tested regularly to guarantee the integrity and availability of data in the event of an incident.
8 — Standards
Our approach is based on the recommendations of the CNIL and ANSSI (French National Agency for the Security of Information Systems). For sensitive projects (nuclear, defense), we comply with the applicable sectorial standards, including, where appropriate, industrial cybersecurity requirements (IEC 62443).



