Privacy · Art. 13 GDPR

Privacy policy

How Lampion processes the personal data of its site and console users.

This document covers the data Lampion processes on its own behalf (account, billing, support). The data you store in your databases is governed by the DPA, where Lampion acts as a processor and never accesses its content.

Last updated: September 24, 2026

01Data controller

Lampion SAS, [TO BE COMPLETED]. Contact: [email protected].

Lampion has not appointed a Data Protection Officer (DPO), as this is not mandatory given its processing activities. Requests are handled at the address above.

02Data collected

CategoryDataSource
AccountName, email address, password (bcrypt-hashed), preferred languageYou, at sign-up
Third-party sign-inIdentifier, email and name provided by Google, GitHub or your SSO providerThe identity provider
OrganizationOrganization name, role, membershipsYou
UsageCompute, storage and transfer volumes per projectAutomatic metering
BillingBilling details, invoice historyYou and Stripe
Audit logActions performed in the console, timestamp, user identifierAutomatic
TechnicalIP address, error and access logsAutomatic

Lampion never accesses the content of your databases. Metering measures volumes, not data.

03Purposes and legal bases

PurposeLegal basis
Create and manage your account, deliver the servicePerformance of a contract (art. 6.1.b)
Confirm your email address and secure sign-upLegitimate interest — abuse prevention (art. 6.1.f)
Meter consumption and billPerformance of a contract (art. 6.1.b)
Issue and retain invoicesLegal obligation (art. 6.1.c)
Log actions (audit, security)Legitimate interest — security (art. 6.1.f)
Answer support requestsPerformance of a contract (art. 6.1.b)
Send product newsConsent (art. 6.1.a), withdrawable at any time

04Recipients and sub-processors

Sub-processorRoleLocation
Scaleway SASHosting of the service and databasesFrance
OVH SASData plane hostingFrance
Cloudflare, Inc.Marketing site hosting, network protectionOutside the EU — standard contractual clauses
Stripe Payments Europe, Ltd.Payment and invoicingIreland (EU)
ResendTransactional email deliveryOutside the EU — standard contractual clauses
Grafana LabsTechnical monitoring (metrics and logs)Outside the EU — standard contractual clauses

No data is sold or transferred to third parties for commercial purposes.

05Retention periods

DataPeriod
Account and organizationUntil the account is deleted
Databases and backupsDeleted within 30 days of account deletion
Audit log12 months
Technical logs14 days
Invoices and accounting records10 years (legal obligation, art. L.123-22 French Commercial Code)

06Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability set out in articles 15 to 22 of the GDPR.

Account deletion is available directly in the console and triggers effective erasure of the associated data. For any other request: [email protected]. Lampion responds within one month.

You may lodge a complaint with the CNIL (French data protection authority), 3 place de Fontenoy, 75007 Paris — cnil.fr.

07Security

Encryption in transit (TLS), bcrypt-hashed passwords, organization isolation, role-based access control, logging of sensitive actions, and hardened authentication for administrative access.

Technical and organizational measures are detailed in the DPA.

08Cookies

See the cookie policy. Lampion sets no advertising cookies and no third-party analytics.