Source
Privacy policy — Dastra
Checked for Dastra on 17 Sep 2026
- Page
- https://www.dastra.eu/en/legal/privacy-policy
- Checked
- 17 Sep 2026, 03:20 UTC
- How we may use it
- Public page, crawling permitted
Technical details
- type
- page
- http status
- 200
- content hash
- sha256:b966b74f76f81cb6a80fb0194f8b0ce62d47179dc932e3c813c3069e3216339a
- permission
- robots_ok
- screenshot
- Screenshot on file (internal exhibit, not published)
Cited by
Facts read from this source
-
Entity name Report an error
“Name: DASTRA SAS”
-
Address Report an error
“Address: 14 Avenue du Général de Gaulle – 94160 Saint-Mandé”
-
Supervisory authority Report an error
“you may file a complaint with the CNIL (www.cnil.fr) or any other competent supervisory authority.”
-
Storage location Report an error
“Your data are mainly stored on servers located in the European Union (particularly in France).”
-
Provider Report an error
“Hosting Microsoft Azure European Union No Data hosted in Europe”
-
Office collaboration Report an error
“Office collaboration / Messaging Microsoft 365 (Exchange, OneDrive, Teams...) European Union No”
-
Newsletter Report an error
“Newsletter sending Brevo European Union No”
-
Website security Report an error
“Website access security Cloudflare EU / USA Yes DPF + SCC”
-
Statistical analysis Report an error
“Statistical analysis PiwikPro (EU), Google Analytics (USA) EU / USA Yes (Google) DPF + SCC, IP anonymization”
-
CRM Report an error
“CRM management ZohoCRM (EU / India), Hubspot (USA) EU / India / USA Yes SCC (India); DPF + SCC (USA)”
-
B2b prospecting Report an error
“B2B prospecting Lemlist (EU), Lusha (USA / IL), Topo (France), Dropcontact (France) EU / USA / Israel Yes (Lusha) SCC for USA/Israel”
-
Advertising Report an error
“Advertising tools Microsoft Clarity (USA), Google Ads (USA) USA Yes DPF (Microsoft, Google) + SCC”
-
Recruitment Report an error
“Recruitment Welcome to the Jungle France No”
-
Social media Report an error
“Social media & multimedia YouTube (Google, USA) USA Yes DPF (Google) + SCC”
-
Certification ISO 27001 Report an error
“ISO/IEC 27001: Information security management system”
-
Certification iso27701 Report an error
“ISO/IEC 27701: Privacy extension for personal data management”
-
Encryption Report an error
“Encryption: communications in transit (TLS 1.2+), sensitive data at rest (AES-256 or equivalent)”
-
Access controls Report an error
“Access controls: multi-factor authentication, strict permission management, principle of least privilege”
-
Breach notification Report an error
“notify the CNIL and, where applicable, the concerned individuals within the legal deadlines,”
-
Retention contract Report an error
“Data linked to a contract or subscription Contractual relationship duration + 5 years (civil/commercial statute of limitations) Contract + legal obligations”
-
Retention contact form Report an error
“Data from contact form 1 year Legitimate interest to respond”
-
Retention prospecting Report an error
“Data used for prospecting 3 years from last contact by the person or end of contractual relationship Legitimate interest (B2B prospecting)”
-
Retention browsing Report an error
“Browsing data (statistical & marketing cookies/trackers) Maximum 13 months Consent (non-essential cookies)”
-
Retention consent cookies Report an error
“Consent cookies 6 months CNIL recommendation”
-
Retention security logs Report an error
“Security data and technical logs Duration necessary for security purposes (≤ 12 months) Legitimate interest (security)”
-
Retention job applications Report an error
“Job applications 2 years after last contact with candidate CNIL recommendation”
-
Retention expiry action Report an error
“After these periods expire, your data are either deleted or irreversibly anonymized.”
-
Dsr response time Report an error
“We will respond within one month of receipt (extendable by two months in case of complexity or numerous requests, in accordance with Article 12 GDPR).”
-
Dsr no fee Report an error
“You will not have to pay any fee to exercise your rights.”
-
Cross border transfer safeguards Report an error
“Standard Contractual Clauses adopted by the European Commission and/or the UK regulator (SCC/UK Addendum), and”
-
Applicable law Report an error
“Under data protection regulations (GDPR, French Data Protection Act), you have the following rights:”
-
Rights erasure Report an error
“Right to erasure ("right to be forgotten"): obtain deletion of your data in certain circumstances (e.g., consent withdrawal, legitimate objection, unnecessary data).”
-
Rights portability Report an error
“Right to portability: receive the data you provided in a structured, commonly used, machine-readable format, or request direct transfer to another controller.”
-
Governing language Report an error
“In case of discrepancies, the French version shall prevail.”
-
Last updated Report an error
“Last updated: September 4, 2025”
Scores citing this record
- Dp Ciso Information security management depth
- Dp Ciso European sovereignty
- The Drafted Generalist European sovereignty
- The Drafted Generalist Audit readiness & evidence
- The Drafted Generalist European sovereignty
- The Drafted Generalist Audit readiness & evidence
- The Drafted Generalist European sovereignty
- The Drafted Generalist European sovereignty
- The Drafted Generalist Data subject rights & incidents
- The Drafted Generalist Privacy regime coverage
- The Drafted Generalist Audit readiness & evidence
- The Drafted Generalist European sovereignty
- The Drafted Generalist European sovereignty
- The Drafted Generalist Data subject rights & incidents
- The Drafted Generalist Privacy regime coverage
- The Drafted Generalist Audit readiness & evidence
- The Drafted Generalist European sovereignty
- The Drafted Generalist European sovereignty
- The External DPO European sovereignty
- The External DPO Data subject rights & incidents
- The External DPO European sovereignty
- The External DPO Data subject rights & incidents
- The External DPO European sovereignty
- The External DPO Data subject rights & incidents
- The External DPO Privacy regime coverage
- The External DPO European sovereignty
- The External DPO Data subject rights & incidents
- The External DPO European sovereignty
- The External DPO Privacy regime coverage
- The External DPO European sovereignty
- The External DPO Data subject rights & incidents
- The External DPO Privacy regime coverage
- The External DPO European sovereignty
- The External DPO European sovereignty
- The In-House Counsel Data subject rights & incidents
- The In-House Counsel European sovereignty
- The In-House Counsel Data subject rights & incidents
- The In-House Counsel Privacy regime coverage
- The In-House Counsel Audit readiness & evidence
- The In-House Counsel European sovereignty
- The In-House Counsel Data subject rights & incidents
- The In-House Counsel Privacy regime coverage
- The In-House Counsel European sovereignty
- The In-House Counsel European sovereignty
- The In-House Counsel Privacy regime coverage
- The In-House Counsel European sovereignty
- The In-House Counsel Data subject rights & incidents
- The In-House Counsel Privacy regime coverage
- The In-House Counsel European sovereignty
- The In-House Counsel European sovereignty
- The IT Integrator European sovereignty
- The IT Integrator Audit readiness & evidence
- The IT Integrator European sovereignty
- The IT Integrator Data subject rights & incidents
- The IT Integrator Privacy regime coverage
- The IT Integrator European sovereignty
- The IT Integrator Privacy regime coverage
- The IT Integrator Audit readiness & evidence
- The IT Integrator European sovereignty
- The IT Integrator Privacy regime coverage
- The IT Integrator Audit readiness & evidence
- The IT Integrator European sovereignty
- The IT Integrator European sovereignty
- The IT Integrator Audit readiness & evidence
- The IT Integrator European sovereignty
- The IT Integrator European sovereignty
- The Lead Auditor Data protection management depth
- The Lead Auditor Information security management depth
- The Lead Auditor European sovereignty
- The Lead Auditor Data subject rights & incidents
- The Lead Auditor European sovereignty
- The Lead Auditor Data subject rights & incidents
- The Lead Auditor Privacy regime coverage
- The Lead Auditor European sovereignty
- The Lead Auditor Data subject rights & incidents
- The Lead Auditor Privacy regime coverage
- The Lead Auditor Audit readiness & evidence
- The Lead Auditor European sovereignty
- The Lead Auditor Data subject rights & incidents
- The Lead Auditor Privacy regime coverage
- The Lead Auditor Audit readiness & evidence
- The Lead Auditor European sovereignty
- The Lead Auditor Data subject rights & incidents
- The Lead Auditor Privacy regime coverage
- The Lead Auditor European sovereignty
- The Lead Auditor European sovereignty
- The Lead Auditor Privacy regime coverage
- The Lead Auditor European sovereignty
- The Skeptic Data protection management depth
- The Skeptic Information security management depth
- The Skeptic European sovereignty
- The Skeptic Data subject rights & incidents
- The Skeptic European sovereignty
- The Skeptic Data subject rights & incidents
- The Skeptic Audit readiness & evidence
- The Skeptic European sovereignty
- The Skeptic Data subject rights & incidents
- The Skeptic Privacy regime coverage
- The Skeptic Audit readiness & evidence
- The Skeptic Integrations & automation
- The Skeptic European sovereignty
- The Skeptic Data subject rights & incidents
- The Skeptic Privacy regime coverage
- The Skeptic Audit readiness & evidence
- The Skeptic European sovereignty
- The Skeptic European sovereignty
- The Skeptic Data subject rights & incidents
- The Skeptic Privacy regime coverage
- The Skeptic Audit readiness & evidence
- The Skeptic European sovereignty
- The Skeptic European sovereignty