Data protection
Privacy policy
A security practice that collected more than it needed would be poorly placed to lecture anyone. Here is what is collected, why, and for how long — one processing operation at a time.
Last updated
01
Data controller
Tom Gernez, trading as Ruvalin, SIRET 947 978 433 00037. For any question or request about your data: contact@ruvalin.com, or by telephone on +33 6 44 64 17 13. The controller's postal address is given in the legal notice.
The practice meets none of the criteria that make appointing a data protection officer mandatory under article 37 GDPR. Requests are therefore handled by the publisher himself, which at least makes them quick.
02
What is not done
- No advertising cookies and no third-party behavioural tracking.
- No sale, exchange or rental of data to anyone.
- No profiling, and no automated decisions producing legal effects.
- No record kept of the domain you submit to the checker.
- No account to create: the site offers no sign-up.
03
Simply visiting the site
The host keeps the technical logs needed to serve pages and keep the service secure: IP address, timestamp, page requested, browser type. Those logs are the host's, are kept briefly, and are not mined for analysis.
Traffic is measured with Vercel Web Analytics, which sets no cookie and creates no lasting identifier: each visit is tied to a hash computed from the request and discarded after twenty-four hours. What is kept is the timestamp, the URL, the referrer, a city-level location, the operating system and the browser.
Lawful basis: the legitimate interest in knowing which pages are read (article 6(1)(f) GDPR). No cross-site correlation is possible and no profile is built. The detail is in the cookie policy
04
The domain checker
The domain you type is sent in the request body rather than in the address: an address ends up in access logs and in every proxy along the way, and a company checking its own domain is disclosing an exposure by doing so. It is used to query DNS, then forgotten. It is written to no log, tied to no visitor, and passed to no analytics tool.
DNS queries leave our servers, never your browser, and go to two public resolvers: Cloudflare and Google Public DNS. They see the domain asked about and our server's address, not yours. The domain itself is never contacted: the checker sends it no HTTP request, no mail, and opens no port to it.
Your IP address is used only as a counting key, to stop the tool becoming a free reconnaissance service: 5 checks a minute and 30 an hour. Those counters live in memory, are tied to no domain, and vanish after an hour or when the service restarts. A result is cached for fifteen minutes, with no link to whoever asked for it.
Lawful basis: the legitimate interest in providing the tool and protecting it from abuse (article 6(1)(f) GDPR).
05
The phishing test
The test runs entirely in your browser. The ten scenarios ship with the page, your answers never leave your device, the score is worked out on the spot, and nothing is stored — not on our servers, not in your browser's storage. Reload the page and the test is blank again.
There is therefore no processing of personal data to declare for this test. It is also why it asks for no email address and no sign-up before showing your result.
06
Booking a call
The booking calendar is provided by Google. It is not loaded with the page: until you click the button that displays it, no request is sent to Google and no data reaches it. That is a choice, not a side effect.
If you do display it and book a slot, what you enter — name, email address, chosen time, any message — is processed by Google as a processor and reaches the practice's calendar. It is used to hold the appointment and to get back to you, and is kept for three years after the last exchange.
Lawful basis: your request, as a pre-contractual step (article 6(1)(b) GDPR).
07
If you write or call
An email, a call or a voicemail produces whatever data you put in it: your identity, contact details, company, and what you are asking about. Business calls are logged by the telephony tool (number, date, duration) so that we know who to call back.
Lawful basis: the legitimate interest in answering an enquiry, or pre-contractual steps where your message concerns an engagement. Retention: three years from the last contact.
08
Business prospecting
Ruvalin approaches companies. The contact details used are business ones and come from public sources: professional directories, company registries, published websites and public DNS records. They are kept in a prospect file with the firm's name, address, a business contact and, where relevant, the technical finding that prompts the call.
Lawful basis: the legitimate interest in offering a professional service to professionals whose activity is directly concerned by it (article 6(1)(f) GDPR). Prospecting never targets private individuals on their personal contact details.
You can object at any time, without giving a reason, by writing to contact@ruvalin.com or simply saying so on a call. The objection takes effect immediately and permanently: the details are then kept on a suppression list whose only purpose is to make sure you are not contacted again. Prospect data is deleted three years after the last contact that led nowhere.
09
If you become a client
Running an engagement produces the usual records of a commercial relationship: contacts, correspondence, quotes, invoices. Invoices are kept for ten years, as accounting law requires; the rest for three years after the relationship ends.
DMARC monitoring adds one particular category: the aggregate reports sent back by mail servers around the world contain sender IP addresses, which are personal data. For those reports you are the controller and Ruvalin is the processor. The terms are in the data processing annex
10
Who else sees this data
No data is sold or passed to third parties for commercial purposes. The only parties involved are the technical providers the practice runs on, each bound by contract and acting only on instructions:
- Vercel Inc.
- site hosting and cookieless audience measurement — United States
- Google Ireland Ltd.
- business email and receipt of DMARC reports; appointment scheduling, loaded only if you ask for it — Ireland, with transfers to the United States
- Cloudflare, Inc. · Google LLC
- DNS resolvers queried by the domain checker — United States
- Notion Labs, Inc.
- prospect file and client relationship records — United States
- Allo
- business telephony and call history — European Union
To which are added, where applicable, the accountant, and administrative or judicial authorities where the law requires it.
11
Transfers outside the European Union
Some of the providers above are established in the United States. Those transfers rest either on the provider's certification under the EU–US Data Privacy Framework, or on the standard contractual clauses adopted by the European Commission, supplemented where appropriate by technical measures such as encryption in transit.
It is also why the checker keeps no record of the domains submitted to it: what is not stored is not transferred.
12
Retention, in summary
- Domain submitted to the checker
- not retained
- Phishing test answers
- not retained, never transmitted
- Abuse counters (IP address)
- one hour at most, in memory
- Cached analysis result
- fifteen minutes
- Audience measurement
- visit hash discarded after twenty-four hours
- Correspondence and prospecting
- three years from the last contact
- Appointments booked online
- three years from the last exchange
- Invoices and accounting records
- ten years
- A client's DMARC reports
- per the contract, thirteen months by default
13
Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, together with the right to give directions on what becomes of your data after your death.
To exercise them, write to contact@ruvalin.com. You will have an answer within one month. Proof of identity will be asked for only where there is reasonable doubt about who is asking, and it will be destroyed as soon as the request is dealt with.
If the answer does not satisfy you, you may lodge a complaint with the French supervisory authority, the Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07. https://www.cnil.fr
14
Security
The site is served over HTTPS only, with HSTS, and the headers that limit framing and content-type sniffing. Access to the practice's tools requires two-factor authentication. The principle applied throughout is the data not collected: it is the only kind that cannot leak.
In the event of a breach likely to result in a risk to your rights, the CNIL would be notified within seventy-two hours, and you would be told without delay where the risk is high.
15
Changes
This policy may change as the processing does. The date it was last updated is at the top of the page, and the version in force is always the one published at https://ruvalin.com/en/legal/privacy.