Data protection and GDPR compliance
FAB-DIS Connect ensures transparent, responsible and secure management of all data collected through our platform.
Our commitment to data protection
FAB-DIS Connect was designed to secure and simplify the exchange of product data between manufacturers and distributors in the FAB-DIS format. The platform meets the highest standards of the General Data Protection Regulation (GDPR) and the requirements of our industrial partners.
We guarantee transparent, responsible and secure management of all data collected through our platform.
Roles and responsibilities
Depending on the use case:
Data controller
for the data they transmit or enter.
Data processor
within the meaning of the GDPR, to carry out the processing related to the operation of the platform (hosting, account management, security, support, billing).
Joint data controller
(e.g. anonymized statistics, user accounts).
Data collected and purposes
The data collected is used exclusively to:
- Manage user accounts and access rights
- Provide support and handle complaints
- Manage subscriptions and billing
- Maintain the security and traceability of operations
- Communicate about technical and commercial developments
- Produce anonymized statistics on the use of the FAB-DIS format
Main categories of data processed:
| Data type | Example fields | Main purpose |
|---|---|---|
| Identity | Last name, first name, title | Account creation and management |
| Contact | Professional email, phone | Communication and support |
| Company | Company name, brands, registration number, role | Rights assignment, eligibility, statistics |
| Security | IP, logs, credentials, roles | Access security, audit, abuse detection |
| Accounting | Email and phone of the accounting department | Billing and payment management |
| Free-text content | Messages, attachments | Assistance and technical diagnosis |
No sensitive data (health, opinions, religion, biometrics, payment) is collected.
Hosting and security
Host
Security measures
- TLS 1.2+ encryption (in transit) and AES-256 (at rest)
- Access management via Azure Active Directory (OAuth)
- Encrypted and redundant backups
Data encryption (Encryption at Rest)
All data stored on Azure Blob Storage and PostgreSQL is protected by Azure’s native Service-Side Encryption (SSE) mechanism, based on 256-bit AES.
Website and exchange security
SSL certificate rated A
The connect.fabdis.fr portal is protected by a verified SSL certificate rated A by Qualys SSL Labs (TLS 1.2 / 256-bit ECDSA).
Two-factor authentication
The platform includes a two-factor authentication system that sends a verification code to secure access to the platform.
Access rights mapping
A complete mapping of roles and permissions is defined for each user profile:
FAB-DIS administrators / Manufacturers / Distributors
Creation, management of accounts and subscriptions, supervision of exchanges.
Standard users
Consultation, file upload, monitoring of Easy-Check analyses.
IT service providers / integration partners
Restricted access to specific API functions.
Each role is associated with precise rights (creation, reading, sharing, analysis, deactivation). Administrators must complete security & compliance training.
Your rights and the GDPR process
Every user has the following rights:
Submission
via the dedicated form.
Acknowledgement
within 7 days.
Identity verification
securing the process.
Processing
within 30 days maximum.
Documented response
export, deletion, justification.
Archiving
for GDPR traceability.
Retention periods
| Data type | Maximum duration | Subsequent action |
|---|---|---|
| Account data | Active account + 3 years | Deletion or anonymization |
| Support / complaints | Up to 10 years | Secure archiving |
| Security logs | According to internal policy | Anonymization |
| Accounting data | Legal prescription (6-10 years) | Legal retention |
| Marketing data | 3 years after last contact | Automatic deletion |
Contact and support
- Provide contractual documents (Register, DPA, Azure certifications, etc.)
- Explain the processing procedures
- Assist with compliance or auditing of solutions connected to FAB-DIS Connect
