At Asfaly, the protection of your personal data is our absolute priority. We are fully compliant with the General Data Protection Regulation (GDPR) and we commit to respecting your rights at every step.
This page explains how we process your data, what your rights are, and how to exercise them.
Who is responsible for your data?
The data controller is:
Asfaly
[Full company or founder address]
Email: contact@asfaly.com
Website: https://www.asfaly.com
What data do we collect?
To provide our post-mortem digital vault service, we collect the following data:
Data you provide directly:
- Email address: to create your account and send you important notifications.
- Master password: to secure access to your vault (it is encrypted and never stored in plain text).
- Stored passwords and credentials: for websites and services you save in your vault (they are end-to-end encrypted).
- Beneficiary information: first name, last name, email, relationship (spouse, child, friend, etc.).
- Post-mortem directives: your choices regarding the transmission, retention, or deletion of your data after your death.
Data collected automatically:
- Connection data: IP address, date and time of login, browser used.
- Activity data: actions performed in your account (adding a password, modifying a beneficiary, etc.).
- Technical data: device type, operating system, security logs.
Sensitive data:
We do not collect sensitive data (racial origin, political opinions, health, etc.) unless you choose to store them yourself in your vault (for example, a password for a medical file). In this case, such data are end-to-end encrypted and we cannot access them.
Why do we collect this data?
We use your data only for the following purposes:
- Provide the Asfaly service: allow you to store your passwords, designate beneficiaries, and organize the transmission of your data after your death.
- Secure your account: detect fraudulent access, prevent intrusions, ensure action traceability.
- Comply with the law: retain certain data to meet legal obligations (e.g., billing, fraud prevention).
- Improve the service: analyze usage to fix bugs, add features, optimize performance.
We never sell your data to third parties and we never use them for advertising purposes.
How do we protect your data?
We have implemented maximum security measures to protect your data:
AES-256-GCM Encryption
All your passwords and sensitive data are encrypted with the AES-256-GCM algorithm, the standard used by banks and government services. Even in the event of server theft, your data would remain unreadable.
End-to-end encryption
Your data is encrypted on your device before being sent to our servers. It remains encrypted during transfer and on our servers. Only your device, with your master password and your 2FA, can decrypt it.
Mandatory Two-Factor Authentication (2FA)
Access to your account requires:
- Your master password.
- A temporary code generated by your phone (Google Authenticator, Microsoft Authenticator, etc.).
No one can access your account without these two elements, not even our teams.
Hosting in Switzerland
All your data is stored on servers located in Switzerland, which benefits from strict data protection legislation (Federal Act on Data Protection – FADP). Switzerland is recognized for its political stability and strong privacy protection.
Logging and traceability
All accesses and actions in your account are logged (date, time, IP address, action performed). This allows us to detect fraudulent access and prove who did what, when.
Who has access to your data?
During your lifetime:
- Only you have access to your data, via your master password and your 2FA.
- Asfaly cannot read your passwords (end-to-end encryption).
- Our technical providers (hosting, maintenance) only have access to encrypted data, without decryption keys.
After your death:
- Your designated beneficiary can request access to your data by providing an official death certificate.
- Access is validated by an Asfaly administrator.
- The beneficiary has temporary access (maximum 30 days) to your data.
- You may have defined directives (notes) to delete certain data after your death.
Legal authorities:
In the event of a judicial requisition, we can only provide encrypted data. Without your decryption key (master password), this data is unusable.
How long do we retain your data?
During your lifetime:
We retain your data as long as your account is active. If you do not log in for an extended period (e.g., 12 months), we may send you an email asking if you wish to keep your account.
After your death:
Data is retained according to your directives (transmission, retention, deletion).
If you have not defined directives, data is retained for 12 months after death, then automatically deleted.
Deletion:
You can request deletion of your account and all your data at any time (see “Your rights” section). After deletion, your data is permanently erased from our servers within a maximum of 30 days.
What are your rights?
In accordance with GDPR, you have the following rights:
Right of access
You can request at any time a copy of all data we hold about you.
How to do it?
Go to Settings → My Personal Data (GDPR) → Request export. You will receive an email with a download link (valid for 6 months).
Right to rectification
You can modify or correct your data at any time from your account (email, beneficiaries, directives, etc.).
How to do it?
Go to Settings → Edit my profile or in the relevant sections (beneficiaries, transmission, etc.).
Right to erasure (right to be forgotten)
You can request deletion of your account and all your data.
How to do it?
Go to Settings → My Personal Data (GDPR) → Delete my account. Enter your password, confirm, and an administrator will validate your request. You will receive a confirmation email.
⚠️ Warning: deletion of your account is irreversible. All your data (passwords, beneficiaries, directives) will be permanently erased.
Right to restriction of processing
You can request restriction of processing of your data in certain cases (e.g., contesting data accuracy, illegal processing).
How to do it?
Contact us at contact@asfaly.com explaining your request.
Right to data portability
You can retrieve your data in a structured, readable format (JSON, CSV) to transfer to another service.
How to do it?
Use the Request export function in Settings → My Personal Data (GDPR).
Right to object
You can object to processing of your data in certain cases (e.g., processing for direct marketing purposes, which is not our case).
How to do it?
Contact us at contact@asfaly.com.
Cookies and trackers
Our website uses technical cookies strictly necessary for the functioning of the service (authentication, security, language preferences).
We do not use advertising cookies or third-party trackers for marketing purposes.
How to manage cookies?
You can configure your browser to accept or refuse cookies. However, if you refuse technical cookies, you will not be able to log in to your Asfaly account.
Data transfer outside the EU
All your data is hosted in France and Switzerland, which benefits from an adequacy decision by the European Commission. This means Switzerland is recognized as offering a level of data protection equivalent to that of the EU. We do not transfer your data outside the EU or Switzerland, except if you use third-party services (e.g., Google Authenticator for 2FA), which have their own privacy policies.
Modifications to this policy
We may modify this privacy policy to reflect legal, technical, or functional changes to our service. In the event of significant changes, we will inform you by email and update this page with the last modification date.
Last update: August 12, 2026
Contact and complaints
Contact us
For any question about the protection of your data, contact us at:
Email: contact@asfaly.com
Address: 65 rue des lieutenants Chauveau 71100 Chalon sur Saone France
Supervisory authority
If you believe your rights are not respected, you can file a complaint with the CNIL (Commission Nationale de l’Informatique et des Libertés) in France:
CNIL
3 Place de Fontenoy
75007 Paris
Website: https://www.cnil.fr
