Privacy Policy
Effective date: 26 July 2026 · Last updated: 26 July 2026
This Privacy Policy explains how FluxeHRa (Foil Envie SAS) processes personal data for website visitors and users of the FluxeHRa application. It covers contact forms, authentication, cookies, analytics, and HR data we process on behalf of customer organizations.
1. Who we are
FluxeHRa is a registered brand of Foil Envie SAS (France). Contact: contact@fluxehra.ai.
2. Scope
This Policy applies to our public website (including the Trust Center and contact form) and to the FluxeHRa SaaS application used by employees, managers, HR, and administrators—including users who sign in with SSO.
3. Controller vs processor
We act as controller for website contact data, account authentication, security, and certain operational analytics. For HR employee data stored in a customer’s FluxeHRa tenant, the customer organization is the controller and FluxeHRa acts as processor under a Data Processing Agreement (DPA). Employees should usually contact their employer first for HR data rights requests.
4. Data we process
Visitors: contact-form details, technical logs, language preference in localStorage, optional Turnstile challenges, and aggregated performance analytics. Users: account email and role, Supabase session cookies, sessionStorage aids (browser-session lock, proxy state), audit events, voluntary bug reports, uploaded documents, and HR domain data processed for the customer.
5. Purposes and legal bases
We process data to operate and secure the site and Service, respond to contact messages, authenticate users, deliver the HRIS to customers under the DPA, prevent abuse, improve reliability with aggregated analytics, and meet legal obligations. Bases include contract, legitimate interests, and legal obligation as applicable.
7. Sub-processors and hosting
Core production hosting uses Supabase (eu-west-1, Ireland) and Vercel (dub1, Dublin). Optional tools and customer-configured integrations are listed in our sub-processors note: sub-processors list.
8. Retention
Contact messages are kept as needed to handle your request. Auth sessions last until logout, expiry, or browser-session controls. Customer HR data retention follows the customer’s instructions and configuration. Audit and bug-report data are kept as needed for security, accountability, and improvement.
9. International transfers
Core platform processing is designed in the European Union. Optional or customer-configured tools may involve other regions; safeguards are addressed in the DPA and sub-processors documentation.
10. Your rights
Where applicable (including GDPR), you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to a supervisory authority (in France: CNIL). For HR tenant data, contact your employer first. For our controller processing, email contact@fluxehra.ai.
11. Security
We apply technical and organizational measures appropriate to the risk (access control, encryption in transit, tenant isolation, audit capabilities, EU hosting for core services). More detail is available in the Trust Center.
12. Children
FluxeHRa is a business HR platform and is not directed at children. We do not knowingly collect children’s personal data through the website or Service.
13. Changes
We may update this Policy from time to time. The “Last updated” date will change when we do. Material changes may also be noted on the Trust Center or communicated to customers.
14. Contact
This page is a transparency notice. It does not replace the DPA between FluxeHRa and a customer, nor an employer’s own employee privacy notice. Download the full Markdown text for the complete version.