Privacy Policy
Version dated 30 September 2026
This English version is provided for convenience. The French version prevails.
Purpose and controller
This policy covers two sets of processing operations:
- the dexlo.fr website and Dexlo’s business prospecting, including demo requests sent through the website form;
- the service: the Dexlo software, which client establishments access by subscription.
The sections on retention, recipients, transfers, security and your rights apply to both.
Controller, except for the operating data processed on behalf of hoteliers (see The Dexlo service: two distinct roles): Adam Ben Hadj Ali, sole proprietor (entrepreneur individuel, EI), trade name Dexlo, 41 rue Ernest Renan, 92310 Sèvres, France, SIREN 109 281 824, RCS Nanterre. Contact: contact@dexlo.fr.
The dexlo.fr website
The website sets no cookies and stores no data in your browser’s local storage. It measures its traffic using its host’s audience measurement tool, Vercel (see Audience measurement below).
It is hosted by Vercel. Like any host, Vercel processes visitors’ IP addresses and the pages requested in order to serve the website; these technical logs are retained for Vercel’s own periods, which are provided on request. Pages may be served from servers located outside the European Union. Legal basis: Dexlo’s legitimate interest in ensuring the security and availability of the website (Art. 6(1)(f) GDPR).
The product screens shown on the website are reproductions: the hotel and the figures shown in them are fictitious.
The website has a single form, the demo request, described below.
Audience measurement
The website measures its traffic with Vercel Web Analytics, its host’s audience measurement tool. The measurement script is served by the website itself, from its own domain; each page viewed results in a measurement being sent to Vercel.
Data recorded. According to Vercel’s documentation, each measurement may include: the date and time of the visit, the address of the page viewed, with some of its parameters (filtered by Vercel), the referring page, an approximate location (country, region, city), the operating system and the browser, with their versions, the device type (desktop, mobile or tablet) and the version of the measurement script. Vercel states that these measurements are linked neither to a person nor to an IP address, and are used only to produce aggregated statistics.
Recognising visitors. To count visitors without cookies, Vercel computes, from the incoming request, a hash that is valid for a single day: it is then automatically reset. A visitor therefore cannot be tracked from one day to the next, or from one website to another.
Why your consent is not requested. The tool sets no cookies, writes no data to your browser’s local storage and reads no identifier from it: it relies on the information your browser transmits to display the page. For these reasons, Dexlo considers that this measurement does not require your consent under Article 82 of the French Data Protection Act (loi Informatique et Libertés); the website therefore does not display a consent banner.
Legal basis. Dexlo’s legitimate interest in measuring traffic to its website (Art. 6(1)(f) GDPR).
Retention. Vercel guarantees that the statistics are retained for a period that depends on the plan subscribed (one month on the Hobby plan, twelve months on the Pro plan, twenty-four months with the Web Analytics Plus add-on or on the Enterprise plan) and states that it may retain them for longer, so that the plan can be upgraded without losing data. The maximum retention period is not documented by Vercel; it is provided on request.
Location and transfer. The measurements are processed by Vercel Inc., a company established in the United States, whose primary processing facilities are located in the United States; the precise storage location of the statistics is not documented by Vercel and is provided on request. For this transfer outside the European Union, Dexlo relies on Vercel Inc.’s certification under the EU-U.S. Data Privacy Framework, which benefits from an adequacy decision of the European Commission; this certification is active as of the date of this version.
Objecting to the measurement. You may object to this measurement at any time by preventing the script from running: by disabling JavaScript for this website, or by using a blocking extension in your browser; the website remains viewable. As the measurements are not linked to any person, Dexlo cannot retrieve those that concern you. For any question, or to exercise your rights, write to contact@dexlo.fr (see Your rights).
Demo requests
This section describes what happens to a request sent through the website’s “Request a demo” form.
Data collected
The information you enter: name, business email address, hotel, city, number of rooms and PMS used. These six fields are required to process your request: without them, it cannot be sent. The form sets no cookies; neither its submission nor the information you enter in it is transmitted to the website’s audience measurement tool.
How your request is handled
Your browser sends the request to Dexlo’s CRM (crm.dexlo.fr), an application hosted by Vercel whose server functions run in the Paris region. The CRM records it in its database, hosted by Supabase in the European Union, in the Frankfurt region (Germany). This database is dedicated: it is separate from that of the Dexlo service. The CRM then, where applicable, sends an email notification to Dexlo by means of Resend, from its Ireland region, in the European Union. This notification is received in Dexlo’s email system.
Protection against abusive submissions
Your IP address is not retained: only a hash of it, computed with a secret key (HMAC), is retained, for 30 days, to limit abusive submissions. This anti-abuse log also retains, for 30 days, a hash of the email address entered, computed with the same key, as well as the date and outcome of the submission.
Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to your request: contacting you, organising the demonstration, making you an offer | Pre-contractual measures taken at your request (Art. 6(1)(b) GDPR) |
| Subsequent business follow-up, between professionals | Dexlo’s legitimate interest in developing its business with hoteliers (Art. 6(1)(f) GDPR) |
| Anti-abuse log | Dexlo’s legitimate interest in protecting the form against automated or abusive submissions (Art. 6(1)(f) GDPR) |
Retention periods
The data in your request is retained for three years from the last contact, then deleted, including the copy received by email. If your establishment becomes a customer, the data is subject to the periods applicable to customers (see Retention periods). The anti-abuse log is retained for 30 days. The notification sent by Resend and its sending log are retained for 30 days by Resend. The CRM database is subject to no backup: deleted data is erased without any backup copy.
If you had objected to prospecting by Dexlo, your request is recorded in order to respond to it, without any subsequent sales follow-up: your objection remains in force.
Recipients
Your data is neither sold, rented out nor assigned. It is processed by Dexlo and by its technical service providers: Vercel, Supabase, Resend and Dexlo’s email service provider (see Recipients and processors).
Your rights
You have the rights of access, rectification, erasure, objection (including objection to prospecting, at any time and without giving reasons), restriction and, where applicable, portability. To exercise them, write to contact@dexlo.fr; you will receive a response within one month. You may also lodge a complaint with the CNIL (see Your rights).
Business prospecting
Purpose. Dexlo prospects hotel establishments: identifying hotels, reaching their decision-makers, and following exchanges and opportunities through to subscription. For this, it uses its CRM (crm.dexlo.fr), which is separate from the Dexlo service: the CRM has access to none of the service’s data.
Data. Identity and business contact details (surname, first name, email address, telephone number, job title, professional social network profile address), notes and follow-up of exchanges, and establishment data (name, city, number of rooms, PMS, website).
Source. Publicly accessible professional sources (establishments’ websites, professional directories, professional social networks, trade fairs), direct exchanges, and demo requests.
Legal basis. Dexlo’s legitimate interest (Art. 6(1)(f) GDPR): prospecting professionals at their business contact details, in connection with their job. For emails sent to business addresses, on a subject related to the recipient’s job, prospecting does not require prior consent: the persons concerned are informed of it at the first contact and may object to it at any time.
Retention. Three years from the last contact, then deletion; if the establishment becomes a customer, the data is subject to the periods applicable to customers. If you object, your email address is kept on an objection list, for the sole purpose of no longer contacting you, for as long as necessary to respect your objection.
Access. The CRM is accessible only to accounts authorised by Dexlo; there is no public sign-up.
The Dexlo service: two distinct roles
For the service, Dexlo acts in two different capacities, on two different sets of data.
| Set | Data concerned | Dexlo’s role | Applicable framework |
|---|---|---|---|
| A | User account, invoicing, support | Controller | This policy (see Service processing for which Dexlo is the controller) |
| B | Establishment operating data (bookings, rates, booking pace) | Processor for the hotelier | Data processing agreement, Article 28 GDPR |
For set B, the hotelier is the controller: it determines the purposes and means, and Dexlo acts only on its documented instructions.
Service processing for which Dexlo is the controller
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Creating and managing accounts, authentication | Business email address, password hash (bcrypt), role, linked establishment, active status, creation date | Performance of the contract (Art. 6(1)(b) GDPR) | Term of the contract, then see Retention periods |
| Service security, technical logging | Request identifier, method, path, status code, duration, timestamp | Legitimate interest (Art. 6(1)(f) GDPR): security and continuity of the service | See Retention periods |
| Invoicing and accounting obligations | Billing details, invoices | Legal obligation (Art. 6(1)(c) GDPR) | 10 years (Article L. 123-22 of the French Commercial Code) |
| Support and customer relations | Exchanges by email or telephone | Performance of the contract or legitimate interest | See Retention periods |
There is no public sign-up: accounts are created by the publisher at the customer’s request.
Data read from the customer’s systems
For set B, the software reads three families of data.
Bookings
When the customer connects its PMS, the connector reads only nine fields per booking. The list is closed: a technical booking identifier, its status, the source channel, the creation, cancellation and last-modification timestamps, the arrival and departure dates, and the requested room category.
None of these fields directly identifies a person.
Rates
The rates published by the establishment, as well as the public rates of its competitors collected from sources accessible to all. The latter are establishments’ prices, not personal data.
Booking pace
The pace (the number of bookings on the books by booking date and by night of stay) is derived from the timestamps above. It is not collected separately.
What else feeds the service
The establishment itself (name, type, city, geographical coordinates), its competitor panel, and public context data: weather, local events. These data do not relate to identified natural persons.
Sending a price to the PMS
When the sending feature is activated for the establishment during onboarding (it depends on the compatibility of the PMS), the customer can send to its PMS in one click, from a night’s file, the price it has chosen. No price is ever changed without the customer’s explicit action; by default, the decision is only recorded in the Dexlo software.
No directly identifying data of hotel guests
The service neither reads nor collects any directly identifying data of the hotel’s guests: no surname, first name, email address, telephone number, postal address, payment card number, identity document, stay preference or guest profile identifier.
This exclusion is structural:
- The connector cannot read what it does not request. The list of nine fields described above is an exhaustive allowlist. The fields that directly identify a person, or can be linked to one, which the PMS otherwise exposes (account, booker, profile or customer identifiers, payment method, number of guests, booking number, assigned room, travel agency) are never accessed, not even transiently.
- The destination table has no column in which to write them. The data model that receives bookings contains no column that could receive directly identifying data.
Retention periods
There is currently no automatic erasure mechanism on expiry in the service, and the CRM purge is triggered manually: the periods below are commitments that Dexlo carries out itself.
| Data | Retention period |
|---|---|
| Demo requests and prospecting data | Three years from the last contact, then deletion, including the copy received by email. If the establishment becomes a customer: for the duration of the contractual relationship, then according to the periods applicable to customers set out below. |
| Form anti-abuse log | 30 days |
| Email address on the objection list | As long as necessary to respect the objection |
| Technical logs of the website and the CRM | Periods specific to the providers concerned, provided on request |
| Demo request notifications sent by Resend (emails and sending logs) | 30 days at Resend (Resend free plan) |
| Website traffic statistics (audience measurement) | Period guaranteed by Vercel depending on the plan subscribed: one month (Hobby plan), twelve months (Pro plan), twenty-four months (Web Analytics Plus add-on or Enterprise plan). Vercel may retain them for longer; the maximum period is provided on request. The hash used to recognise a visitor is valid for a single day only. |
| User account and authentication | Term of the contract, then erasure within three months of its end |
| Establishment operating data (set B) | Term of the contract, then return and erasure in accordance with the data processing agreement |
| Service application logs | Seven days; the host’s own logs are retained for its own periods, provided on request |
| Invoices and accounting records | Ten years (legal obligation) |
| Support exchanges | Three years from the last exchange |
| Backups of the service database | Deleted data may remain in the host’s backups until they expire; the backup retention period is provided on request. |
| Backups of the CRM database | None: the database is not backed up (Supabase free plan). Deleted data is erased without any backup copy. |
Recipients and processors
Data is neither sold, rented out nor assigned. It is processed, solely for the purposes described in this policy, by the following providers.
Website, demo requests and prospecting
| Provider | Role | What it receives | Place of processing |
|---|---|---|---|
| Vercel | Hosting of the dexlo.fr website and of Dexlo’s CRM (crm.dexlo.fr); audience measurement for the website | IP address and pages requested; for audience measurement, the data described in the Audience measurement section; for the CRM, the demo requests and prospecting data processed by its server functions | Website: pages may be served from servers located outside the European Union. Audience measurement: United States. CRM: server functions run in the Paris region. Company governed by U.S. law. |
| Supabase | CRM database and authentication | Demo requests, prospecting data, anti-abuse log, CRM access accounts | European Union, Frankfurt region (Germany). Company governed by U.S. law. |
| Resend | Sending of demo request notifications | The fields entered in the form | European Union, Ireland. Company governed by U.S. law. |
| Dexlo’s email service provider | Receipt of emails sent to contact@dexlo.fr and support@dexlo.fr, including demo request notifications | Content of the emails received | Provided on request |
Service
| Provider | Role | What it receives | Place of processing |
|---|---|---|---|
| Render | Hosting of the application, the database and the cache | All service data | European Union, Frankfurt region (Germany). Company governed by U.S. law. |
| Vercel | Hosting of the service’s authenticated interface (app.dexlo.fr) | Users’ requests (IP address, pages requested) and, on protected pages, the session token (user identifier and role, signed), read by the access control. Service data (bookings, rates, recommendations) is exchanged directly between the browser and the application hosted by Render, without passing through Vercel. | Execution region not fixed: the interface may run outside the European Union. Company governed by U.S. law. |
| Sentry | Monitoring of technical errors | Technical error reports, which may include technical elements of the request concerned | European Union |
| DataForSEO | Collection of competitors’ public rates | Search subjects: establishments, locations, dates. No customer data. | Not applicable: no personal data is transmitted to it. |
The customer’s PMS
The customer’s PMS is not a processor of Dexlo: it is the customer’s tool, under its own contract. Dexlo connects to it with the access credentials the customer grants it: it receives data from it and, when the sending feature is activated, transmits to it the prices the customer decides to send. Dexlo is not its principal. The customer remains in control of this connection and may revoke it at any time.
Public sources queried
The service queries public sources to which it transmits an establishment location or a search subject, and no personal data: weather services, local event services, a public geocoding service.
Transfers outside the European Union
The service’s application, its database and its cache are hosted in the European Union (Frankfurt region, Germany). The CRM database is hosted in the European Union (Frankfurt region, Germany) and its server functions run in Paris; demo request notifications are sent from Resend’s Ireland region, in the European Union.
The following may, however, take place outside the European Union: the running of the service’s authenticated interface by Vercel, whose execution region is not fixed (operating data does not pass through it, but the session token is read there), as well as the delivery of the website’s pages by Vercel’s network.
Audience measurement for the website is processed by Vercel Inc. in the United States, where its primary processing facilities are located; for this transfer, Dexlo relies on Vercel Inc.’s certification under the EU-U.S. Data Privacy Framework, described in the Audience measurement section.
In addition, several providers, including Render, Vercel, Supabase and Resend, are companies governed by U.S. law: even where data is hosted in the European Union, access from the United States, in particular for administration or support purposes, cannot be ruled out and constitutes a transfer. The processing entrusted to Sentry is located in the European Union.
These transfers are subject to the conditions of Chapter V GDPR. The information Dexlo has on the safeguards governing them, provider by provider, is provided on request at contact@dexlo.fr.
Security
For the service, the following measures are in place; they are detailed in Annex 2 to the data processing agreement.
- Encryption in transit: access to the service over HTTPS only.
- Passwords: never stored in plain text (bcrypt hash, 12 rounds).
- Sessions: signed authentication token, set in an httpOnly cookie, marked secure (transmitted over HTTPS only) and SameSite=Strict in production; CSRF protection by double submission, mandatory in production.
- PMS access secrets: each establishment’s access token is encrypted at rest (Fernet, dedicated key) and is decrypted only when it is used. It never appears in a log.
- Start-up guard: the application refuses to start in production if the configuration is dangerous (authentication bypass enabled, a secret left at its default value, missing encryption key, development database, or SQL query echo enabled).
- Access partitioning: access restricted to the establishment linked to the account; allowed origins limited to the official interface; public sign-up closed.
- Logs: application logging excludes the query string, request bodies and authentication headers.
- Sending prices to the PMS: only when the feature is activated for the establishment, and only on explicit action by a user of the customer.
- Hosting of the application and its database in the European Union (see Transfers outside the European Union).
For the CRM: access restricted to accounts authorised by Dexlo, with no public sign-up; the IP address of the persons who submit the form is not retained.
What is not promised: no multi-factor authentication at this stage; no quantified availability commitment; no measures other than those described above.
Your rights
Every data subject has the rights of access, rectification, erasure, restriction, objection and portability provided for in Articles 15 to 22 GDPR, under the conditions laid down therein. Objection to prospecting may be exercised at any time, without giving reasons.
- Website, demo requests, prospecting, accounts, invoicing and support: requests are made to Dexlo, at contact@dexlo.fr. A response is given within one month.
- Establishments’ operating data (set B): requests are addressed to the hotelier, as controller. Dexlo assists the hotelier under the conditions of the data processing agreement and does not respond directly to the data subject.
Anyone may lodge a complaint with the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 (www.cnil.fr).
No decision based solely on automated processing is taken with regard to the persons whose data is processed.
Data protection officer: Dexlo has not appointed a data protection officer, as the appointment is not mandatory given its activity and the volume of its processing; none of the three cases in Article 37(1) GDPR applies.
Changes to this policy
Any substantial change is brought to the attention of customers in writing. The version in force is dated at the top of this page.