Privacy policy

This policy describes how DINAO collects, uses and protects your personal data, in accordance with the General Data Protection Regulation (GDPR — EU 2016/679) and the French Data Protection Act.

It supplements the legal notices and our general terms of sale.

Last updated: August 3, 2026

Data controller: DINAO — SARL with a capital of €50,000
TOULON Trade Register — SIREN: 448091181 — VAT: FR25448091181
Registered office: 307, chemin de la Marine — 83110 Sanary-sur-Mer — France
Phone: +33 (0)4 84 250 220

1. Who is responsible for processing your data?

DINAO SARL is the data controller for the personal data collected on https://dinao.com and in the context of the hosting, domain name and e-mail services it provides to its customers.

For any question about the protection of your personal data, you can contact us:

  • via the website contact form;
  • by post: DINAO — Data Protection, 307 chemin de la Marine, 83110 Sanary-sur-Mer, France.

2. What data do we collect?

Depending on how you use our services, we collect:

  • Identification and contact data: name, company, postal address, e-mail address, phone number (client account creation, orders, contact requests);
  • Billing and payment data: order and invoice history, payment method used. Credit card numbers are never stored by DINAO: they are entered and processed directly by our payment service providers (currently Monetico — Crédit Mutuel/CIC, PayPal and Stripe);
  • Technical and connection data: IP addresses, server logs, website browsing data;
  • Support data: content of support tickets, e-mails exchanged and attachments;
  • Data related to subscribed services: domain names, e-mail accounts, technical identifiers of the services (passwords are stored securely).

3. Why do we use your data, and on which legal basis?

We process your data only for the following purposes:

  • Performance of the contract: client account management, provisioning of ordered services, billing, technical assistance and support;
  • Legal obligations: retention of invoices and accounting records, retention of identification data and connection logs as required by law;
  • Legitimate interest: security of the infrastructure and services (detection of abuse, intrusion and fraud), improvement of our offers;
  • Consent: audience measurement, advertising personalisation and interface preferences, via the cookie banner (see section 4). You may withdraw your consent at any time.

4. Cookies and audience measurement

On your first visit, a consent banner lets you accept, refuse or customise cookies by category:

  • Audience measurement: traffic statistics (Google Analytics 4);
  • Marketing and advertising: cookies and data used to measure and personalise advertising;
  • Preferences: interface personalisation and storage of your choices;
  • Security (always active): cookies strictly necessary for the operation and security of the website — they do not require consent.

No audience-measurement or marketing cookie is set without your consent. Your choices are kept for 1 year and can be changed at any time via the "Cookies settings" link at the bottom of every page.

5. Who has access to your data?

Your data is accessible to authorised DINAO staff, within the limits of their duties. It may also be transmitted to the following recipients, each for its own purposes:

  • Payment service providers: the providers offered at checkout — currently Monetico (Crédit Mutuel/CIC), PayPal and Stripe — for secure payment processing. This list may change; the provider used is always indicated at the time of payment;
  • Domain name registries and registrars (AFNIC for .fr, and the relevant registries depending on the extension), for the registration and management of your domains;
  • Google, for audience measurement and advertising, only if you have consented;
  • Administrative or judicial authorities, where required by law.

DINAO hosts its services on its own infrastructure located in France, and never sells or rents your personal data.

6. Does your data leave the European Union?

DINAO services (website, client area, hosting services, e-mail) are hosted in France. Some third-party tools used with your consent (in particular Google Analytics and Google advertising services), as well as some payment service providers (for example Stripe or PayPal), may involve transfers of data to countries outside the European Union; such transfers are governed by appropriate safeguards (adequacy decision, standard contractual clauses).

7. How long do we keep your data?

  • Client account and service data: for the duration of the contract, then archived for 5 years from the end of the service (statutory limitation period for contractual evidence);
  • Invoices and accounting records: 10 years (accounting obligations);
  • Connection logs: 12 months;
  • Cookie consent choices: 1 year;
  • Support tickets: duration of the contract, then archived with the client file.

At the end of these periods, data is deleted or anonymised; our management system performs automatic purging.

8. What are your rights?

In accordance with the GDPR and the French Data Protection Act, you have the following rights over your personal data:

  • right of access, rectification and erasure;
  • right to restriction of processing and right to object;
  • right to data portability;
  • right to withdraw your consent at any time (without affecting the lawfulness of prior processing);
  • right to define directives regarding your data after your death.

To exercise these rights: contact form or post to DINAO — Data Protection, 307 chemin de la Marine, 83110 Sanary-sur-Mer, France. We reply within one month. If you consider that your rights are not respected, you may lodge a complaint with the CNIL (www.cnil.fr), the French supervisory authority.

9. How do we protect your data?

DINAO implements appropriate technical and organisational measures, in particular:

  • encryption of exchanges (TLS/HTTPS) on the website and services;
  • access control and segregation, restricted to authorised staff;
  • infrastructure monitoring and protection against intrusion and abuse;
  • regular encrypted backups;
  • hosting on infrastructure located in France.

10. Data you host with DINAO (processing on your behalf)

The data you store or process through the subscribed services (websites, databases, mailboxes, servers, application containers) remains under your responsibility: for this data, you are the data controller and DINAO acts as a processor within the meaning of Article 28 GDPR.

As such, DINAO accesses this data only to the extent necessary for the operation, maintenance and support of the services, does not use it for any other purpose, and applies the security measures described in section 9. The terms of this processing are governed by our general terms of sale; a data processing agreement can be provided on request.

11. Updates to this policy

This policy may change, in particular in the event of regulatory changes or changes to our services. The date of the last update is shown at the top of this page. In the event of a substantial change, we will inform you by any appropriate means.

New · Managed apps catalog

987 open-source applications, hosted in France and managed by DINAO

Nextcloud, n8n, Plex, Jellyfin, Mattermost, Open WebUI, Immich, Seafile, WordPress, Grafana, Gitea… Ready-to-use Docker containers, GDPR-compliant, 24/7 support.

Explore the catalog →

Popular categories: AI / LLM· Cloud & files· No-code automation· Media· Collaboration