The detail
What is in place, and on what basis.
Three statuses, used without exception: In place
means a measure that is effective today; Configurable
an option scoped and priced per engagement; Not provided
something that does not exist and will not be implied.
Hosting and processing
In place
Shared OVHcloud server (Apache / PHP) with a MySQL database on the same infrastructure,
in France. Documents uploaded to the client portal reside there too. The website's
processing happens on that same server.
For an engagement that requires it, dedicated hosting — isolated instance, chosen
region, encrypted volumes — can be configured and is priced at scoping.
Who has access, and how
In place
- Engagement data is accessible only to authorised contributors, according to their
role and need to know.
- Confidentiality obligations and access scope are defined contractually before
participation.
- Client access to the portal via username and bcrypt-hashed password, with email
verification.
- Rate-limited login attempts, CSRF protection on forms.
- Least privilege: each client sees only their own projects, documents and messages.
Logging
In place
- Timestamp of each account's last login.
- Failed login attempts recorded, then deleted after a successful login or when
entries older than 24 hours are purged.
- HTTP access logs kept at host level under the host's own retention policy.
A detailed application audit trail — who opened which document and when, exportable —
can be configured as part of an engagement.
Retention periods
In place
- Contact form: 3 years from the last exchange.
- Client portal: length of the commercial relationship + 3 years.
- Invoices and accounting records: 10 years (Art. L123-22, French Commercial Code).
- Failed login attempts: no more than 24 hours; last-login timestamp retained with
the account.
- Data entrusted for an engagement: duration of the engagement + 30 days.
Beyond those periods, data is deleted or anonymised. These are the periods stated in the
privacy policy: both documents say the same thing.
Return and deletion
Contractual
Every engagement contract includes an explicit exit clause:
- Return of deliverables and source data in an open, reusable format.
- Deletion of working copies, indexes and exports within 30 days of your written
sign-off on the handover.
- Written deletion statement provided on request.
- Single exception: records the law requires us to keep (invoicing).
Code produced is transferred to you after full payment — that rule is set out in the
terms and conditions.
Encryption
Partial — see detail
- In transit: HTTPS enforced site-wide, HSTS enabled, encrypted SMTP
for email. In place
- Passwords: hashed with bcrypt, never stored or transmitted in
clear. In place
- At rest: shared hosting provides no guaranteed volume encryption.
Configurable on dedicated infrastructure.
- End-to-end: impossible on a web application where the server must
read the data to process it. Not provided
Security headers are applied (protection against content-type sniffing, framing and
referrer leakage); a stricter content policy is currently in
observation mode before enforcement — we would rather say so than let
you assume otherwise.
Backups and recovery
Host-level — no LinkTec commitment
OVHcloud makes website and database restore points available, but describes them as
non-contractual. LinkTec currently has no documented independent backup
and publishes no recovery point or recovery time objective: none is contracted or
tested in a documented way.
A dedicated backup plan — frequency, retention, restore testing, recovery time —
can be defined and contracted for an engagement that warrants it.
Incident handling
Contractual
- Single point of contact: contact@bn-linktec.fr,
subject line "security incident".
- The affected client is informed without undue delay after a breach is confirmed:
nature, scope and immediate measures. A 24-hour target can be added to the
engagement DPA.
- Notification to the CNIL within 72 hours where the GDPR requires it (Art. 33), and
to data subjects where the risk is high (Art. 34).
- Written report once the incident is closed.
If you find a vulnerability in our services, write to us: any good-faith report gets an
answer and will never be met with legal action.
AI models and indexes
None on the website
The public website and the client portal call no AI model and contain
no vector index. Nothing you type here is sent to an AI provider.
For an engagement, the components — model provider, vector database, processing region —
are chosen with you at scoping. Non-use of your data for model training
is a contractual selection criterion: the chosen provider's commitment
is verified and annexed to the contract. LinkTec does not stand surety for the vendor,
and does not pretend to.
NDA, DPA and contractual framework
Available immediately
- NDA signed before the first exchange of data, including at
pre-sales stage. Your own template is accepted without argument in principle.
- DPA (data processing agreement, GDPR Art. 28) signed as soon as an
engagement involves personal data: purposes, durations, further subprocessors,
fate of the data at the end of the contract.
- Record of processing activities maintained internally where the
processing requires it; no certification is claimed.
- No further subprocessor is added to an engagement without prior notice.
These commitments apply to every contributor engaged by BN-LinkTec. Responsibilities,
confidentiality obligations and access conditions are formalised according to the
actual scope of the engagement.