Quick access
1 — Data processing principles
NOVALYNX applies the six fundamental principles of the GDPR: lawfulness, fairness, and transparency. Purpose limitation. Data minimization. Accuracy. Storage limitation. Integrity and confidentiality.
2 — Legal basis of the processing
Our processing is based on one of the legal bases provided for by the GDPR: consent (contact form, newsletter), performance of a contract (business relationship), legal obligation (accounting, taxation), and legitimate interest (website security, anonymous audience measurement).
3 — Rights of data subjects
You have the right to access your data. Right to rectification. Right to erasure ("right to be forgotten"). Right to restriction of processing. Right to data portability. Right to object. These rights can be exercised free of charge by email at contact@novalynx.fr.
4 — Technical measures
TLS encryption of all communications · Pseudonymization and anonymization of data as soon as possible. Logging of access to sensitive data. Encrypted backups. Regular security updates. Periodic resilience testing.
5 — Organizational measures
Internal personal data protection officer appointed. Regular employee awareness training on GDPR. Access control and authorization policy. Annual compliance audits. Up-to-date processing activities register. Documented incident management procedure.
6 — International transfers
Our data is hosted and processed within the European Union. In the event of using a subcontractor established outside the EU, we apply the standard contractual clauses adopted by the European Commission and conduct a transfer impact assessment (TIA) to guarantee an equivalent level of protection.
7 — Record of processing activities
In accordance with Article 30 of the GDPR, NOVALYNX maintains an internal record of personal data processing activities specifying the purpose, categories of data, recipients, retention periods, and security measures. This record is made available to the CNIL upon request.
8 — Breach notification
In the event of a personal data breach, NOVALYNX will notify the CNIL within 72 hours (Article 33 GDPR) and directly inform the individuals concerned when the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR). Each incident is documented in the internal register.



