Personal data

Privacy policy

This policy describes the personal data processing related to the OneChain website, contact forms, early access requests and newsletter subscription.

Last updated: September 28, 2026 DPO: dpo@onechain-tms.com

Data controller

The data controller is Foresea Technologies, a French société par actions simplifiée registered with the Paris Trade and Companies Register under number 832 541 189, operating the OneChain website.

Data collected

When you use the website, OneChain may process the following data:

  • data submitted through contact, demo or early access forms: name, professional email, company, phone number, role, use case and message;
  • email address submitted through the newsletter form;
  • technical data strictly necessary for website operation and security: IP address, timestamp, access logs and browser information;
  • after consent to audience measurement: pseudonymous cookie identifiers, browser and device information, page path, referring hostname and allowed campaign context;
  • data generated by embedded content when you interact with a third-party item, for example a demo video.

Purposes and legal bases

  • Responding to demo, contact or early access requests: OneChain's legitimate interest in processing inbound requests.
  • Sending newsletters or marketing communications: consent from the subscriber.
  • Measuring visits and campaign performance with Google Analytics: consent, where given.
  • Providing hosting, security and website availability: legitimate interest and applicable legal obligations.
  • Keeping evidence required in case of dispute: legitimate interest and legal obligations.

Recipients and processors

Data is accessible only to authorized OneChain teams and service providers involved in hosting, security, form management or commercial follow-up.

The website is hosted by Netlify. OneChain product data is hosted in the European Union and protected by encryption in transit and at rest. OneChain application processing relies in particular on AWS, Auth0/Okta, Datadog and other processors contractually governed when personal data is involved.

When you accept it, Google Analytics is used as the audience measurement provider. It may process pseudonymous cookie identifiers, browser and device information, as well as the page path, referring hostname and a limited set of allowed campaign context. Search queries, URL fragments and values entered into forms are not sent for this purpose.

Optional audience measurement

Audience measurement is disabled by default. It is enabled only after your explicit choice. Measurement cookies placed on this site have a maximum lifetime of 6 months; your consent choice is stored for 6 months.

These periods are separate from the retention settings of the Google Analytics property: event data is retained for 2 months and user data for 14 months.

You can withdraw your choice at any time with the “Cookie preferences” button in the footer. Withdrawal stops new optional collection and removes Google Analytics cookies placed by the site.

Retention periods

  • Contact, demo and early access requests: up to 3 years after the last commercial interaction.
  • Newsletter: until unsubscribe or withdrawal of consent.
  • Technical website logs: limited to security and operational needs.
  • Contractual or regulatory data: according to applicable legal retention obligations.

Transfers outside the European Union

Some providers may be located outside the European Union. In that case, OneChain frames transfers through appropriate safeguards, including standard contractual clauses where required.

Your rights

You have the right to access, rectify, erase, restrict, object to and, where applicable, port your personal data.

You can exercise your rights by writing to dpo@onechain-tms.com. OneChain responds to GDPR requests within a maximum of 30 calendar days, except in cases of particular complexity.

You may also lodge a complaint with the CNIL, the French data protection authority.

Security

OneChain applies appropriate security measures, including encryption in transit, encryption at rest, access controls, security logging and technical monitoring.