Privacy policy
How InTraTool processes personal data, under Regulation (EU) 2016/679 (GDPR) and French Act no. 78-17 of 6 January 1978 as amended.
Two distinct roles
InTraTool processes two categories of data that are not subject to the same regime, and they must be kept apart to understand what follows.
- Accounts and the public site. E.S.K.V. is the controller: it is the publisher who decides why and how this data is processed.
- The content entered into the application — incidents, impacts, dialogs, attachments, action plans — belongs to the customer who entered it. That customer is the controller; E.S.K.V. acts only as a processor, on instructions, under the terms of the contract between them (GDPR art. 28). The publisher does not exploit this content for any purpose of its own, does not sell it and does not use it to train anything.
Data processed and purposes
| Data | Purpose | Legal basis |
|---|---|---|
| Business email address, display name, language, link to the customer or the supplier, role | Create and manage the account, deliver the service's notifications, apply access rights | Performance of the contract |
| Password (non-reversible hash), two-factor authentication secret, WebAuthn passkeys (public keys), reset tokens | Authenticate the user and secure access | Performance of the contract and legitimate interest in security |
| Audit trail: author, date and content of every change | Preserve the evidential value of the files, trace changes, settle disputes | Legitimate interest: traceability is the very purpose of the tool |
| Log of sent emails: sender, recipients, subject, date, delivery status | Prove that a reminder or a notification was sent, diagnose failures | Legitimate interest |
| Server technical logs: IP address, timestamp, page requested | Security, abuse detection, incident diagnosis | Legitimate interest |
| Contact requests sent from the public site | Answer the request | Pre-contractual measures at the data subject's request |
The service asks for no special category of data within the meaning of article 9 of the GDPR. No automated decision-making and no profiling is carried out. The site performs no audience measurement and displays no advertising.
Recipients
The data is neither sold, nor rented, nor passed to third parties for commercial purposes. Only the following have access:
- the authorised users of the customer concerned, according to their role;
- the contacts of the supplier concerned, for the files that name that supplier and no others;
- the staff of E.S.K.V. in charge of operations and support, strictly as necessary;
- for those customer companies only for which the publisher has enabled it, Mistral AI (Paris, France), as a sub-processor, when a user asks for an action plan to be reviewed (see below);
- the host, acting as a processor, named in the legal notice.
Hosting and transfers
The data is hosted in France. No transfer outside the European Union takes place.
Review of action plans
Where the publisher has enabled it for a customer company, a user of that company or of its supplier may ask for an action plan to be reviewed by an artificial intelligence tool provided by Mistral AI (Paris, France). The plan is then sent to Mistral AI and processed within the European Union for the time needed to produce the review.
Only what is needed to review the plan is sent: the problem description, the causes, the actions and their follow-up. The costing of the incident and the names of individuals are never sent — the team is identified by role and company. Nothing is sent without a user's click, and Mistral AI does not use this data to train its models.
Retention periods
These periods are not declaratory: they are applied by an automatic process that reads exactly the values shown below.
- User accounts: for the whole term of the contract. 1 year after an account is deactivated, it is anonymised: name, email address and means of sign-in are erased for good.
- Audit trail: 5 years, and only once the file concerned is closed. A file still open is never cut back, however old it may be: it is this trail that gives it weight in a dispute.
- Log of sent emails: 5 years.
- Business content (incidents, dialogs, attachments): for the term of the contract. At its end, the customer receives its data back, after which the data is erased under the terms of the contract.
- Server technical logs: 1 year.
- Contact requests: 3 years from the last exchange.
What anonymisation erases, and what it leaves
An account is never deleted. Its identifier is cited by the incidents, the dialogs, the action plans and every line of the audit trail: deleting it would break the chain of evidence the tool exists to keep. It is the identity that is erased, not the trace.
- Erased: name, email address, password, two-factor authentication secret, passkeys, display preferences, and the address everywhere it appeared in the log of emails.
- Kept: the actions recorded in the log of the files, now attributed to an anonymous label, and the messages written in the dialogs — they belong to the file and bind both parties.
The text users type freely into the dialogs is not reprocessed: if it names someone, that name remains. We cannot guess at it without altering the content of a contractual file.
Security
Exchanges are encrypted in transit. Passwords are never stored in clear text but as a non-reversible hash, and are subject to a strict complexity policy. Two-factor authentication and passkeys are available on every account. Access is partitioned by customer and by role; a supplier account sees only the files that name it. Every change is logged with its author.
Your rights
You have a right of access, rectification, erasure and restriction, a right to portability, and a right to object to processing based on legitimate interest. You may also give directives as to what becomes of your data after your death.
Access and portability: on request, the application produces a file containing everything it holds about you, in a machine-readable format. Your administrator obtains it from your account page; you can obtain it yourself from your own.
Erasure: it takes the form of anonymisation, under the terms described above. Article 17(3)(e) of the GDPR reserves the case of data necessary for the establishment and exercise of legal claims: what you have written in a contractual file binds the parties and cannot be withdrawn unilaterally.
These rights are exercised with the publisher, at contact@eskv-intratool.fr. You will receive an answer within one month.
If the data concerning you was entered into the application by a customer — your employer or its principal — contact that customer first: it is the one responsible. We will pass your request on where appropriate.
Finally, you may lodge a complaint with the French data protection authority: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at www.cnil.fr. You may equally address the supervisory authority of your country of residence.
Changes
This policy may be amended to follow changes in the service or in the law. The date it was last updated appears below.
Last updated: 22 septembre 2026
This translation is provided for convenience. In case of divergence, the French version prevails.