Skip to content
Last updated: May 10, 2026

Privacy policy

Winch SAS places a high priority on the protection of personal data. This policy describes the data processing activities carried out in connection with the use of bywinch.com, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.

Scope of this policy. This policy applies exclusively to the bywinch.com website. Processing operations performed on the ByWinch platform (Fynko, Ledger, Connect) cover subscriptions, registers, KYC, AML/CFT and investor data on behalf of asset-management firm clients. They are governed by the data-processing agreements (Article 28 GDPR) signed individually with each client.

01Controller

Data controller

The data controller is Winch SAS, SIREN 989 672 209, with registered address at 60 rue François Ier, 75008 Paris, France. For any question related to the processing of your data, you may contact privacy@bywinch.com.

02Purposes

Data collected and purposes

We only collect the data strictly necessary for the following purposes:

  • Demo request by email. The “Request a demo” button opens your email client pre-filled to contact@bywinch.com. The data you choose to send us in that email (professional identity, organization, content of your request) is processed to respond to your request and qualify a potential commercial project. Legal basis: pre-contractual measures at your request (Art. 6.1.b GDPR).
  • Spontaneous applications. Information sent voluntarily to careers@bywinch.com: to process your application (legal basis: pre-contractual measures).
  • Server logs and security. Strictly necessary technical browsing data (IP address, user agent, request timestamps): to ensure the correct operation, security and abuse prevention of the site (legal bases: legitimate interest under Article 6.1.f GDPR, and legal obligation to ensure security under Article 6.1.c GDPR).

ByWinch uses no third-party audience measurement tool, no advertising cookie, and makes no automated decision or profiling on the basis of your data (within the meaning of Article 22 GDPR).

03Retention

Retention periods

  • Commercial form data: 3 years from last contact, unless converted into a contractual relationship.
  • Applications: 2 years from last exchange, unless the candidate explicitly consents to a longer retention.
  • Technical logs: 12 months maximum.
04Recipients

Recipients and processors

Your data is processed by authorized teams at Winch SAS. It may be transmitted to technical providers acting as processors (within the meaning of Article 28 GDPR) under a compliant contract:

  • Vercel Inc. (US company, global edge network). Hosts the static corporate site bywinch.com. The site is served from points of presence located in several jurisdictions, including the United States. Transfers outside the EU are framed by the European Commission’s Standard Contractual Clauses (SCCs) and remain limited to technical service data. No investor data, no KYC documents and no subscription data are processed through this infrastructure.
  • Scaleway SAS (France and the European Union). DNS, certificates, internal infrastructure, and hosting of the operational ByWinch platform (governed by separate processor contracts with each asset-management firm client).
05Rights

Your rights

Under the GDPR, you have the following rights:

  • right of access, rectification, erasure;
  • right to restriction and objection to processing;
  • right to object to the processing of your data for direct marketing purposes, at any time and without justification (Art. 21.2 GDPR);
  • right to data portability;
  • right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before that withdrawal (Art. 7-3 GDPR);
  • right (under French law, Art. 85 LIL) to issue post-mortem directives regarding your data.

To exercise these rights, write to privacy@bywinch.com stating your request. We reply within one month of receipt, in accordance with Article 12.3 GDPR. This deadline may be extended by an additional two months for complex or numerous requests, after notification.

You also have the right to lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

06Cookies

Cookies and trackers

bywinch.com uses no advertising cookies, no third-party marketing tracking cookies and no audience measurement tool. A single strictly necessary cookie may be set to remember your language preference (FR/EN) when you switch. This cookie is exempt from prior consent under Article 82 of the French Data Protection Act.

Should non-exempt audience measurement tools be added in the future, a consent banner will be implemented before any deposit.

07Security

Data security

Winch SAS implements appropriate technical and organizational measures within the meaning of Article 32 GDPR to protect your data against loss, alteration or unauthorized access: encryption in transit, access controls limited to what is strictly necessary, security event logging. Detailed elements (security policy, business continuity plan, controls aligned with the targeted ISO 27001 and SOC 2 frameworks) are available under NDA in the institutional client pack.

08Changes

Changes to this policy

This policy may be updated to reflect legal, technical or organizational changes. The last update date is shown at the top of this document.