Data Protection and GDPR Compliance
FAB-DIS Connect ensures transparent, responsible and secure management of all data collected through our platform.
Our commitment to data protection
FAB-DIS Connect was designed to secure and simplify the exchange of product data between manufacturers and distributors in the FAB-DIS format. The platform meets the highest standards of the General Data Protection Regulation (GDPR) and the requirements of our industrial partners.
Roles and responsibilities
Depending on the use case:
The client is the Data Controller
for the data they transmit or enter.
FAB-DIS Connect acts as a Data Processor
within the meaning of the GDPR, to carry out the processing operations related to the platform’s operation (hosting, account management, security, support, billing).
In certain specific cases, FAB-DIS Connect acts as a Joint Controller
(e.g. anonymised statistics, user accounts).
Collected data and purposes
The data collected is used exclusively to:
- Manage user accounts and access rights
- Provide support and handle complaints
- Manage subscriptions and billing
- Maintain the security and traceability of operations
- Communicate about technical and commercial updates
- Produce anonymised usage statistics for the FAB-DIS format
Main categories of processed data:
| Data type | Example fields | Main purpose |
|---|---|---|
| Identity | Last name, first name, title | Account creation and management |
| Contact | Professional email, phone number | Communication and support |
| Company | Company name, brands, SIREN number, role | Rights assignment, eligibility, statistics |
| Security | IP, logs, identifiers, roles | Access security, auditing, abuse detection |
| Accounting | Email and phone of the accounting department | Billing and payment management |
| Free-form content | Messages, attachments | Support and technical diagnostics |
Hosting and security
Hosting provider
Security measures
- TLS 1.2+ encryption (in transit) and AES-256 (at rest)
- Access management via Azure Active Directory (OAuth)
- Encrypted and redundant backups
Azure certifications
Data encryption (Encryption at Rest)
All data stored on Azure Blob Storage and PostgreSQL is protected by Azure’s native Service-Side Encryption (SSE) mechanism, based on AES 256-bit.
Website and exchange security
The portal connect.fabdis.fr is protected by a verified SSL certificate rated A by Qualys SSL Labs (TLS 1.2 / ECDSA 256-bit).
The platform includes a two-factor authentication system with a verification code sent to secure access to the platform.
Access rights mapping
A comprehensive mapping of roles and permissions is defined for each user profile:
FAB-DIS Administrators / Manufacturers / Distributors
Account and subscription creation and management, exchange supervision
Standard users
Viewing, file uploading, Easy-Check analysis tracking
IT service companies / Integration partners
Restricted access to specific API functions
Each role is associated with specific rights (creation, reading, sharing, analysis, deactivation). Administrators must complete security & compliance training.
Your rights and the GDPR process
Each user has the following rights:
🔁 Request process:
Submission
via the dedicated form
Acknowledgement of receipt
within 7 days
Identity verification
securing the process
Processing
within 30 days maximum
Documented response
export, deletion, justification
Archiving
for GDPR traceability
Retention periods
| Data type | Maximum duration | Subsequent action |
|---|---|---|
| Account data | Active account + 3 years | Deletion or anonymisation |
| Support / complaints | Up to 10 years | Secure archiving |
| Security logs | Per internal policy | Anonymisation |
| Accounting data | Legal limitation period (6–10 years) | Legal retention |
| Marketing data | 3 years after last contact | Automatic deletion |
Contact and support
For any request related to data protection:
FAB-DIS is available to its clients and partners to:
- Provide contractual documents (Register, PII, Azure certifications, etc.)
- Explain data processing procedures
- Assist with compliance or auditing of solutions connected to FAB-DIS Connect
