- 100 %
- inside your org
- 0
- outbound data by default
- 71/255
- controls self-assessed
- 10 min
- to install
The French text governs. This page is the English translation of Politique de confidentialité FR. The French version is the one that governs; this translation is provided for understanding. Where the two diverge, the French text prevails.
This page describes the processing of data by the orgguardian.com website. The processing of data by the OrgGuardian product, installed in your Salesforce org, falls under the data processing agreement (DPA) supplied before subscription; the essentials are summarised further down.
This site sets no cookies
No cookie is placed on your device, neither technical nor advertising. There is no audience measurement, no analytics tool, no tracking pixel and no social network button.
One single thing is written to your device, and only if you ask for it
A cookie is not the only way to write to a device, and the CNIL places the others —
localStorage included — under the same regime. We use one, and
here it is in full:
og-lang-refus-
Value
"1", with no expiry date, written to your browser'slocalStorageonly if you click “Stay in French” / “Rester en anglais” in the band that offers the other language. Its purpose is to stop offering you that band again. It contains no identifier, enables no tracking, is read only by this site and is never transmitted to a server — including ours.
Why there is no consent banner. This write results from an explicit action on your part and serves solely to carry out what you have just asked for. It falls under the exemption provided for trackers strictly necessary to a service expressly requested by the user. Nothing else is written: if you do not click that button, your device leaves this site exactly as it entered it.
How to erase it. Clearing the site data for orgguardian.com in
your browser settings deletes it. The suggestion band will reappear, which is the proof that
the key had indeed gone.
No third-party resource is loaded
Fonts are served from this domain and not from a third-party service. When you browse this site, your IP address is transmitted to no ad network, no third-party CDN and no font provider. The only network requests the page triggers go to orgguardian.com.
What is necessarily recorded
Our host keeps technical connection logs (IP address, date, resource requested, response code, user agent), necessary for the operation and security of the service, and kept by the host for a period we do not set ourselves and cap at twelve months, the legal maximum for connection data in France (decree 2021-1363); we keep no copy of our own. These logs are not used for profiling purposes and are not cross-referenced with other sources.
- Legal basis: legitimate interest in ensuring the availability and security of the site (GDPR Art. 6(1)(f)).
- Host: Infomaniak Network SA, Switzerland — a country benefiting from an adequacy decision of the European Commission.
If you write to us
The addresses published on this site reach a business mailbox. The content of your message and your contact details are used to reply to you and, where applicable, to handle your commercial enquiry. They are neither sold, nor rented, nor used for any other purpose.
- Legal basis: pre-contractual measures taken at your request (GDPR Art. 6(1)(b)).
- Retention: three years from the last contact, unless a contractual relationship is ongoing.
The product: what stays with you
OrgGuardian is a managed package installed in your own Salesforce org. By default, the analysis, the findings and the history are computed and stored in your org, under your own access rules. No business data is transmitted to the publisher. What does reach us, through Salesforce's standard licensing mechanism and not through the package: your org identifier, edition, installed version and licence count — subscription metadata, never a record from your org.
The external viewer is an optional feature, disabled by default. As long as an administrator does nothing, your org makes no call at all to that service. Once they open it, four exchanges — and only four — may leave for it. Here they are, in the order in which they occur, with what each one carries.
-
The activation request, when the administrator clicks "Request
activation": the body sent contains your org identifier (
00D…) and nothing else. It is the one exchange that does not yet ask for your consent, and for a reason: it precedes the issuing of the key that all the others require. It hands over no secret and carries no data. - The connection test, when the administrator checks the address they typed: a plain health request, with no body at all — no data, no signature, no token. It only fires once consent has been granted.
- The posture summary, the flow the viewer exists for. What leaves: a health score, the counts of open findings by severity, a metric count, a region code and a timestamp. This is not an intention but a filter written into the package: before transmission, a sieve drops by name the user identifiers and usernames, IP addresses, session and login keys, URLs and request identifiers, then lets through only what it can prove harmless — numbers, booleans and short strings of a known shape (region code, timestamp). Any free text and any nested structure is dropped by default, for want of being able to show it carries nothing. On this flow, only your org identifier travels with the payload: it designates an organisation, never a person.
- The TLS certificate expiry probe, and only if you additionally enable certificate monitoring for your external endpoints — also disabled by default. Apex cannot read a remote server's certificate: the external service performs the TLS handshake on your org's behalf. To do so, your org sends it the hostnames of your external endpoints, the ones it reads from your Named Credentials (one hundred at most), along with your org identifier and a timestamp. Nothing else: no credentials, no secrets, no content of your calls. This flow does not go through the sieve described above, and that is deliberate: those hostnames are precisely what must arrive intact to be probed. They are not personal data — they are server names — but they are information about your integrations, and we would rather write it than leave it out. If you do not want them to leave, keep that monitoring disabled: the probe then makes no call at all.
In all four cases: no business data, no record, no finding text leaves your org, and no personal data: neither your customers' nor your own staff's. The two data-bearing flows are cryptographically signed (HMAC-SHA256), consent is re-checked immediately before every transmission and remains revocable at any time from the org: revoking it stops the egress at once, without waiting for a cycle to end. That service is hosted in the European Union, and here is who operates it — the publisher's only two sub-processors, within the meaning of Article 13(1)(e) GDPR:
- Salesforce, Inc. (Heroku platform) — hosting of the ingestion service and of the viewer, Heroku EU region. Salesforce standard contractual clauses, Heroku DPA.
- Amazon Web Services, Inc. (Heroku Postgres add-on) — database of the multi-tenant viewer, AWS eu-west-1 (Ireland). Through Heroku; TLS connections, encryption at rest.
Neither is involved unless you switch the Heroku tier on: while it is off — which is its state at install — no data reaches them. The same list, with the same guarantees, is published on the publisher security page. Finally, the viewer link that the administration screen composes carries your org identifier and your token: it is opened by your browser, never by your org.
Your rights
You have a right of access, rectification, erasure, restriction, objection and portability over the data concerning you. To exercise it, write to privacy@orgguardian.com. You may also lodge a complaint with the CNIL, the French data protection authority.
Data controller
DOPAMINE SAS, 5388 Chemin des Châteaux, 84300 Cavaillon, France — SIREN 922 481 403, R.C.S. Avignon. Full details on the legal notice page.
Back to home