Privacy Policy

Version 2.2Effective date: August 11, 2026

Privacy Policy

Effective: August 9, 2026

The most important thing first

Dataskera never sees the data you work with.

Our viz extensions run entirely on your machine, inside Tableau's sandbox. Your dashboards, datasets, fields, queries, and values stay in your Tableau environment. Nothing about that data is sent to us. Ever.

We only collect what we strictly need to give you access to the product and to support you when you ask for help. That's it.


1. Who we are

Dataskera is a French limited liability company (EURL).

  • Registered office: 1 rue Marguerin, 75014 Paris, France
  • SIREN: 991 710 070
  • Share capital: EUR 1,000
  • Legal representative: Salah Eddine El Ghachi (Manager)
  • Contact: contact@dataskera.com
  • Support: support@dataskera.com

We act as Data Controller for the limited personal data described below. For any privacy matter, our designated privacy contact is contact@dataskera.com.

2. What we collect

We collect only what we need to operate the service:

DataWhy we have it
Email addressAccount login, license activation, account-related communication
Password (hashed)Authentication
Company nameLicense management (per-organization licensing)
License plan and statusGranting access to the right product tier
Server logs (IP, timestamps)Security, abuse prevention, billing accuracy
Support messages you send usAnswering your tickets

That is the full list. We do not ask for your phone number, postal address, or any other personal detail.

We will never intentionally collect (and we ask you never to send us) any sensitive personal data: health or medical information, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, or data concerning your sex life or orientation.

3. What we never collect

The following data never leaves your environment and never reaches us:

  • Any data displayed in your Tableau dashboards (cells, measures, dimensions, field names)
  • Queries, calculations, or workbook content
  • Configuration or input you provide inside the extension dialog
  • Screenshots or visual content of your visualizations
  • Behavioral analytics inside the extension

This is a technical guarantee, not just a policy: our extensions are built so that the only network call leaving your machine is the periodic license check. There is no telemetry, no usage tracking, no data exfiltration path, by design.

We also make no automated decisions and no profiling of any kind based on your data.

PurposeLegal basis (GDPR Art. 6)
Providing the service and managing your licenseContract performance, Art. 6(1)(b)
Security, fraud prevention, abuse loggingLegitimate interest, Art. 6(1)(f)
Operational emails (account, license, critical updates)Contract performance, Art. 6(1)(b)
Newsletter (if you opt in)Consent, Art. 6(1)(a), withdrawable anytime
Keeping records of consent and Terms acceptanceLegitimate interest / legal claims defense, Art. 6(1)(f), Art. 17(3)(e)

5. Where your data is stored

All personal data is stored in the European Union: our application and database are hosted in France.

Our viz extension static files (JavaScript, CSS; no personal data) are delivered from a separate content server. Its access logs are anonymized at the source (IP addresses are truncated before being written), so no personal data is processed on that server.

We use a small number of carefully selected sub-processors:

Sub-processorPurposeLocation
Google Cloud Platform (Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland)Hosting and databaseEuropean Union (France); static-file delivery only from a separate location, with anonymized logs (no personal data)
OVH SAS (2 rue Kellermann, 59100 Roubaix, France)Transactional email (account and license notifications)France

Where a transfer outside the EU could occur (for example Google support access), it is covered by the European Commission's Standard Contractual Clauses and the EU-US Data Privacy Framework, under which Google is certified.

6. How long we keep it

These are maximum retention periods:

  • Active accounts: for as long as your account is active.
  • Deleted accounts: 30-day grace period (during which you can restore your account), then permanent deletion.
  • Inactive accounts: we may delete accounts after 12 months of inactivity, with prior email notice.
  • Server logs: 12 months maximum.
  • Records of consent and terms acceptance: up to 5 years after the end of the relationship, kept only as far as necessary for the establishment or defense of legal claims (GDPR Art. 17(3)(e)).

You can ask us to delete your data sooner; see Section 8.

7. Security

  • TLS 1.2+ for all communications
  • Passwords hashed with bcrypt; session tokens hashed at rest
  • Environment segregation (dev / production)
  • Encrypted, tested backups
  • Restricted administrator access with audit logging

8. Your rights

Under the GDPR you have the right to:

  • access your data
  • correct it if it's wrong
  • ask us to delete it
  • restrict or object to processing
  • get a copy of your data in a portable format (available directly from your account dashboard)
  • withdraw consent (for anything based on consent)
  • define directives on what happens to your data after your death (French Data Protection Act, Art. 84–86)
  • lodge a complaint with the CNIL (French Data Protection Authority, www.cnil.fr) or the data protection authority in your country

To exercise any of these rights, write to contact@dataskera.com. We respond within 30 days.

9. Cookies

Our website uses only session and authentication cookies (strictly necessary, no consent required).

We currently use no analytics at all (not even anonymized ones) and no advertising or profiling cookies. We do not sell or share data with ad networks. If we ever introduce analytics, they will be configured to be exempt from consent under CNIL guidelines, and this policy will be updated first.

10. Changes to this policy

If we change this policy materially, we'll email registered users at least 30 days before the change takes effect.

Version history:

  • v2.2 (August 11, 2026): simplified the company description and generalized hosting-location wording (removed internal infrastructure identifiers), while keeping the EU personal-data storage disclosure.
  • v2.1 (August 9, 2026): corrected hosting locations and the sub-processor list (OVH for email); documented log anonymization on the static-file delivery server; clarified retention as maximum periods and extended consent-record retention for legal-claims defense; added sensitive-data, post-mortem directives, and no-profiling statements; stated that no analytics are currently in use.
  • v2.0 (April 25, 2026): initial public version.

Questions? Email contact@dataskera.com. We answer.

Last updated: August 11, 2026