Privacy Policy

Last updated: February 18, 2026

This Privacy Policy explains how Xerify SAS ("Xerify", "we", "us", or "our") collects, uses, stores, and protects your personal data when you use our XBRL/iXBRL validation platform ("Service"). We are committed to protecting your privacy and complying with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.

1. Introduction and Data Controller

Xerify SAS acts as the data controller for the personal data collected through our Service. We are responsible for determining the purposes and means of processing your personal data. Data Controller: Xerify SAS Address: Paris, France Email: [email protected] This Privacy Policy applies to all users of our website (xerify.io) and our SaaS platform, including free and paid plan subscribers.

2. Personal Data We Collect

We collect the following categories of personal data: Account Information: When you register, we collect your email address, full name, and organization name. You may also provide an avatar image. Authentication Data: We store a hashed version of your password (using bcrypt). We never store passwords in plaintext. Billing Information: If you subscribe to a paid plan, Stripe (our payment processor) collects your payment details. We store your Stripe customer ID and subscription status, but never your credit card number or bank details. Usage Data: We collect information about how you use the Service, including validations performed, files uploaded (metadata only), API calls made, and features used. Technical Data: We automatically collect IP addresses, browser type, operating system, device information, and access timestamps through server logs. Upploaded Files: XBRL/iXBRL files you upload for validation are temporarily stored for processing. File contents are not analyzed for purposes other than providing the Service. Communications: If you contact us via email or the contact form, we retain the correspondence to provide support.

3. How We Use Your Data

We process your personal data for the following purposes: Service Delivery: To provide, maintain, and improve the XBRL validation platform, including user authentication, file processing, validation, viewing, and export features. Billing and Payments: To process subscription payments, manage billing, track usage for metered billing, and generate invoices via Stripe. Communications: To send you transactional emails (welcome emails, password resets, validation notifications, billing alerts) and, with your consent, marketing communications about new features and updates. Security: To protect against unauthorized access, detect fraud, and ensure the security and integrity of our platform. This includes rate limiting, brute-force protection, and audit logging. Analytics: To analyze aggregated, anonymized usage patterns to improve our Service. We do not sell or share personal data for third-party advertising. Legal Compliance: To comply with applicable laws, regulations, and legal obligations, including responding to lawful requests from authorities.

4. Legal Basis for Processing (GDPR Article 6)

We process your personal data based on the following legal grounds: Contract Performance (Art. 6(1)(b)): Processing necessary to provide the Service you subscribed to, including account management, file validation, billing, and support. Legitimate Interest (Art. 6(1)(f)): Processing for security purposes (fraud prevention, rate limiting), platform improvement through anonymized analytics, and enforcement of our Terms of Service. Consent (Art. 6(1)(a)): Processing for optional marketing communications. You may withdraw your consent at any time. Legal Obligation (Art. 6(1)(c)): Processing required to comply with tax, accounting, and other legal requirements.

5. Data Sharing and Third Parties

We share your personal data only with the following categories of recipients, and only to the extent necessary: Service Providers (Subprocessors): - Amazon Web Services (AWS): Cloud hosting and file storage (EU region: eu-west-1) - Stripe: Payment processing and billing (PCI DSS compliant) - Cloudflare: CDN, DDoS protection, and DNS - Resend: Transactional email delivery - Sentry: Error monitoring and crash reporting We do NOT sell, rent, or trade your personal data to third parties for marketing or advertising purposes. We may disclose your data if required by law, court order, or governmental authority, or if necessary to protect our rights, safety, or property.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this policy: Account Data: Retained for the duration of your account. Upon account deletion, personal data is permanently removed within 30 days. Uploaded Files: Retained according to your plan's retention policy (Free: 30 days, Starter: 6 months, Pro: 24 months, Enterprise: unlimited). You may delete files at any time. Validation Results: Follow the same retention policy as uploaded files. Billing Records: Retained for 10 years after the last transaction to comply with French accounting and tax obligations. Server Logs: Automatically rotated and deleted after 90 days. Backups: Database backups are retained for 30 days and then permanently deleted.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data: Encryption: All data in transit is encrypted using TLS 1.3. Files at rest are encrypted using AES-256 on AWS S3. Authentication: Passwords are hashed with bcrypt (cost factor 12). API keys are stored as SHA-256 hashes. JWT tokens have short expiration times (15 minutes for access tokens). Access Control: Role-based access control (RBAC) limits data access to authorized users. Our internal team follows the principle of least privilege. Infrastructure: Our services run in isolated containers with security-hardened configurations. We use Cloudflare for DDoS protection and WAF. Monitoring: We continuously monitor for security incidents using Sentry error tracking, structured logging, and Prometheus metrics. Despite our efforts, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to [email protected].

8. Your Rights (GDPR Data Subject Rights)

Under the GDPR, you have the following rights regarding your personal data: Right of Access (Article 15): You can request a copy of all personal data we hold about you. Use the "Export My Data" feature in your account settings or contact us. Right to Rectification (Article 16): You can update or correct your personal data at any time through your account settings. Right to Erasure (Article 17): You can request the deletion of your account and all associated personal data. Use the "Delete Account" feature in your account settings or contact us. Right to Restriction (Article 18): You can request that we restrict the processing of your data in certain circumstances. Right to Data Portability (Article 20): You can export your personal data in a structured, machine-readable JSON format. Use the "Export My Data" feature in your account settings. Right to Object (Article 21): You can object to processing based on legitimate interest or direct marketing at any time. Right to Withdraw Consent (Article 7): Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

9. Cookies and Tracking

We use the following types of cookies: Essential Cookies: Required for the Service to function (authentication tokens, session management). These cannot be disabled. Analytics Cookies: Used to understand how users interact with our Service. We use privacy-respecting analytics that do not track users across websites. Preference Cookies: Store your preferences such as language selection and theme settings. We do NOT use third-party advertising cookies or trackers. We do not participate in ad networks or sell data to advertisers. You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using the Service.

10. International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA). When data is transferred outside the EEA (e.g., to US-based subprocessors), we ensure appropriate safeguards are in place: - EU-US Data Privacy Framework: For US-based processors that are certified under the DPF. - Standard Contractual Clauses (SCCs): For transfers to countries without an adequacy decision from the European Commission. - Data Processing Agreements (DPAs): In place with all subprocessors, ensuring GDPR-equivalent protections. Our primary infrastructure (AWS eu-west-1) is located within the EU.

11. Children's Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at [email protected].

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make changes: - We will update the "Last updated" date at the top of this page. - For material changes affecting your rights, we will notify you via email at least 30 days before the changes take effect. - A history of changes will be maintained and available upon request. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

13. Contact Us

If you have questions, concerns, or complaints about this Privacy Policy or our data processing practices, you may contact us at: Xerify SAS Data Protection Officer: [email protected] General inquiries: [email protected] Address: Paris, France You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement. In France, the supervisory authority is the Commission Nationale de l'Informatique et des Libertes (CNIL) — www.cnil.fr.

Have questions about your privacy? Contact our DPO