Mirage Analytics

Legal information

Privacy policy

Last updated·2026-06-18

Contents

  • Data controller
  • Definitions
  • Customer account data
  • Payment data
  • Data collected by the measurement script
  • Purposes and legal bases
  • Recipients and processors
  • Third-party integrations (SEO audit)
  • Hosting and data location
  • Retention periods
  • Your rights
  • Security
  • Minors
  • Changes to this policy
  • Governing language

Data controller

The data controller is DPLIANCE SAS, 24 Boulevard du Grand Cerf — HTAG Bureau 11, 86000 Poitiers, France (Poitiers Trade Register 853 089 142).

Contact: contact@dpliance.com.

Data protection officer (DPO): dpo@dpliance.com.

This policy describes how DPLIANCE SAS collects, uses and protects personal data within the Mirage Analytics dashboard and its audience measurement script, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.

Definitions

  • Customer: the legal entity or professional who subscribes to the Mirage Analytics dashboard.
  • Visitor: the internet user whose activity is measured on the website operated by the Customer.
  • Service: the Mirage Analytics audience analytics dashboard, accessible online.
  • Measurement script: the software component, supplied by DPLIANCE and installed by the Customer on their site, which collects Visitors' usage data.

Customer account data

Creating and managing the dashboard account relies on a minimal set of data:

  • an email address, used as the login identifier;
  • a password (stored hashed, never in clear text);
  • where applicable, the URL of the analysed site.

No other identity data (surname, first name, job title) is required. The purpose of this processing is account creation, Customer authentication and delivery of the Service; its legal basis is performance of the contract.

Payment data

Payment of the subscription is the subject of separate processing, carried out by our payment provider Mollie. The information needed for payment (in particular bank card and billing details) is collected and processed directly by Mollie, acting as a provider, in accordance with its own privacy policy. DPLIANCE has no access to bank card numbers.

Data collected by the measurement script

The measurement script installed on the Customer's site collects data about how Visitors use that site:

  • page views and navigation paths;
  • interaction events (clicks, scrolling, form submissions);
  • session recording (session replay);
  • heatmaps;
  • device, operating system and browser type;
  • traffic source (referrer);
  • approximate location (country, region) derived from the IP address.

Mirage uses no cookie and does not store the IP address in clear text: it is used transiently to derive an approximate location, then not retained in any identifying form. No directly identifying Visitor data (name, email) is required or collected by the measurement script.

Purposes and legal bases

  • Account and subscription management — legal basis: performance of the contract entered into with the Customer.
  • Audience measurement — legal basis: the Customer's legitimate interest in knowing the audience of their site. Because measurement is carried out without cookies and on data that does not directly identify anyone, it falls within the conditions of the consent exemption set out by the CNIL for audience measurement.
  • Service-related communications — legal basis: performance of the contract and legitimate interest, for transactional emails and information about the Service.
  • Security and fraud prevention — legal basis: legitimate interest.

Recipients and processors

The data is intended for the authorised internal departments of DPLIANCE. Mirage Analytics uses the following processors, which act on instructions and provide sufficient guarantees:

  • Scaleway (data hosting and storage, Paris, France);
  • Brevo (sending transactional emails);
  • Mollie (payment processing).

All of these providers are located in the European Union. No data is transferred or sold to third parties.

Third-party integrations (SEO audit)

When the Customer enables the SEO audit feature, Mirage Analytics queries third-party services in order to retrieve search data. Only non-personal data is involved (public technical and search data: domain name, URL, keywords, ranking and performance indicators). No personal data, and no Visitor data, is sent to these services: the data comes from these services and is displayed in the dashboard.

  • Google Search Console — with the Customer's authorisation via OAuth, read-only access to the search statistics of their own property (queries, pages, impressions, clicks). Access tokens are stored encrypted and can be revoked by the Customer at any time.
  • Google PageSpeed Insights — returns performance indicators for an analysed page.
  • DataForSEO — returns ranking and market data.

Since these exchanges concern only non-personal data, they do not constitute a transfer of personal data outside the European Union.

Hosting and data location

Account and measurement data is hosted in France, at Scaleway, and is subject to no transfer outside the European Union. The optional SEO audit feature exchanges only non-personal data with third-party services (see “Third-party integrations”).

Retention periods

  • Account data: retained for the whole duration of the subscription, then archived for as long as necessary to meet our legal and accounting obligations (up to 10 years for accounting records).
  • Measurement data (sessions): retained for 36 months, then deleted or aggregated anonymously.
  • Session replay recordings: retained for 3 months.

Your rights

In accordance with the GDPR, you have the following rights over your personal data:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to data portability;
  • right to object.

You can exercise these rights by writing to contact@dpliance.com or to our DPO at dpo@dpliance.com. You also have the right to lodge a complaint with the French data protection authority (CNIL).

Security

DPLIANCE implements appropriate technical and organisational measures to protect data against destruction, loss, alteration or unauthorised access: encryption of communications in transit (HTTPS/TLS), password hashing, access restricted to authorised people only, logging and regular backups.

Minors

The Service is intended for professionals and is not designed for minors. We do not knowingly collect data concerning minors. If you believe a minor's data has been sent to us, please contact us so that we can delete it.

Changes to this policy

This privacy policy may change to reflect changes in our practices or in the applicable regulations. The date it was last updated appears at the top of the document. We invite you to consult it regularly.

Governing language

This document is an English translation provided for information. In the event of any discrepancy, the French version prevails.

© DPLIANCE — Mirage Analytics
CGUCGV Privacy policy Cookie policy