This page explains transparently how Adalense SAS handles the personal data you entrust to us when using our sites and software — and the controls you have at any time.
We collect only the data needed to provide and bill the service. Four categories:
Account data. First name, last name, email, company, phone (optional), password (bcrypt-hashed — we never see your password in clear text).
Billing data. Postal address, Stripe customer ID. Your payment card details never pass through our servers — they are entered directly with Stripe (PCI-DSS level 1).
License and usage data. License keys, named-seat assignments, anonymised machine IDs, and how the software is used: plugin connections (activation and periodic ping) plus a count of executions per module, per day and per workstation. This tells us when, from how many workstations and which SmartRouting modules are used. Never what you produce with it: no Revit modelling data, no file, project or network names, and not even which individual commands were run.
Technical data. Server logs (IP, user agent, page, HTTP status) kept locally for diagnostics. No advertising pixel, no third-party analytics tool.
Section 2
How we use your data
The data we collect is used only for the following purposes:
• Provide and operate the SmartRouting service (authentication, license validation, downloads).
• Handle billing, renewals and refunds through Stripe.
• Provide technical support when you reach out.
• Improve the product and size our support using usage statistics. These are tied to your account: they let us flag, for instance, when the number of workstations in use no longer matches the seats you subscribed to.
• Verify compliance with the licence terms (workstations actually in use versus seats subscribed). Legal basis: legitimate interest. No automated decision is made from this data; you may object by writing to us.
Legal basis
We process your data on the basis of: (i) performance of the contract — to provide the service and handle billing; (ii) our legitimate interest — support and product improvement; (iii) our legal obligations — notably accounting and tax; (iv) your consent, where required.
Sharing with subprocessors
We rely on three technical subprocessors, each bound to Adalense by a GDPR-compliant data processing agreement:
Stripe — payment processing and storage of payment methods. Data limited to email, billing address and customer ID.
Microsoft (Entra ID, SharePoint, Graph) — federated authentication for our team (Entra ID), MSI installer storage (SharePoint). Data limited to professional email and tenant ID.
IONOS / hébergeur SMTP — website hosting, transactional email delivery. Data limited to the recipient email and message content.
Adalense never sells, rents or transfers your data to third parties for commercial or advertising purposes.
For professional customers acting as data controllers, a Data Processing Agreement (DPA) compliant with Article 28 of the GDPR is available on request at privacy@adalense.com.
Section 3
Your rights (GDPR)
At any time you can exercise the following rights over your personal data:
Right of access. Obtain a copy of the data we hold about you.
Right to rectification. Correct any inaccurate or outdated data from your account area or by contacting us.
Right to erasure. Request deletion of your account and associated data, subject to legal retention obligations (e.g. invoices).
Right to portability. Retrieve your data in a structured, machine-readable format.
Right to object. Object to the processing of your data on legitimate grounds, or withdraw consent.
Right to restriction. Request restriction of the processing of your data in the cases provided for by the GDPR (e.g. when you contest the accuracy of the data).
To exercise any of these rights, write to us at privacy@adalense.com. You also have the right to lodge a complaint with your local data protection authority (CNIL in France — cnil.fr).
Section 4
How we protect your data
Your data security is enforced by dedicated technical and organisational measures:
• TLS 1.2+ encryption required for every exchange between your browser and our servers.
• Passwords stored exclusively as bcrypt hashes (adaptive cost, unique salt per password).
• Short-lived authentication tokens (15 min access, 30-day refresh), rotated on each use, revoked on sign-out.
• Database access restricted to the strict minimum, auditable logging of administrative actions.
Section 5
Cookies
Adalense only uses strictly necessary cookies. No advertising or third-party analytics cookies.
Name
Purpose
Lifetime
authjs.session-token
Keep your session signed in.
30 j
NEXT_LOCALE
Remember your language preference (EN/FR).
1 an
We use neither Google Analytics, Meta Pixel, nor any third-party cookie for audience measurement or advertising.
Section 6
Retention periods
We keep your data only as long as needed for the stated purposes, or to comply with legal obligations:
• Account data: as long as your account is active, plus 30 days after deletion to allow restoration in case of error.
• Billing data: 10 years (French legal obligation).
• Technical logs: 12 months maximum.
• Plugin connection history: 180 days, then automatically deleted.
Section 7
International transfers
Your data is hosted in the European Union. Some subprocessors (Stripe, Microsoft) may operate in the United States; in that case, the transfer is governed by the Standard Contractual Clauses adopted by the European Commission.
Primary hosting: France (IONOS) and EU (Microsoft / Stripe).
Section 8
Contact us
For any question about your personal data or this policy:
For sales or product questions, please use the contact page.
Section 9
Changes to this policy
We may update this policy to reflect changes to the product, to our infrastructure or to the law. Not all changes carry the same weight: we distinguish two cases.
Substantial changes. Collecting data of a different nature from those described above (your project content, location, sensitive data), pursuing a purpose unrelated to the service you subscribed to, adding a new processor receiving your data, or transferring it outside the European Union. These are notified by email to holders of an active account at least 30 days before they take effect.
Scope clarifications. Clarifying processing already described, extending the technical usage measurement of the software, adjusting a retention period, or an editorial correction. These updates take effect as soon as they are published on this page.
In every case, the last-updated date is shown at the top of this page, and your right to object (section 3) remains open at any time by writing to privacy@adalense.com.