Your Data

Where it is, who can read it, and how you leave

Your Data

Before installing software in a lodge, you don’t ask what features it offers. You ask who can read us, and what happens if the publisher disappears.

This page answers those questions in order, without detours. It is written to be read in committee, with us out of the room.

1. Where does our data physically live?

On OVH servers, in Roubaix, France. European jurisdiction, GDPR applies as a matter of course.

No data transits through or resides outside the European Union. That’s not an intention: it’s article 10 of your contract, which forbids any transfer outside the EU without your prior written consent.

Databases are encrypted at rest. Backups run daily, are encrypted too, and are replicated to a second site.

2. Who can read our data?

The members you grant access to. And, in one specific case, us — that needs to be said plainly.

Janus includes a support access that lets the publisher open a session on a user’s behalf, to diagnose an incident no description could reproduce. It’s a useful function — and the most intrusive one in the software.

Here is exactly what constrains it:

  • It is disabled by default. It doesn’t exist until you turn it on.
  • Every time a session opens and closes, it is timestamped and logged in your lodge’s own audit trail — not ours.
  • That log can be checked by your administrator, whenever they want, without asking us.
  • The reason the session ended is recorded too: manual stop, disconnection, or timeout.

We’d rather tell you than let you find out. And above all, don’t take our word for it: check for yourselves — the log is in your application.

3. Are we pooled with other lodges?

No. Each lodge has its own installation: its own application server, its own database, its own file storage. These aren’t partitions inside a shared database — they are separate installations.

A malformed request in one lodge cannot reach another lodge’s data: they don’t exist in the same space.

When you choose to share a document or an event with another lodge in your obedience, the exchange travels through an end-to-end encrypted relay. The relay holds no key and cannot open what it carries.

4. How do we leave?

In one click, whenever you want, without telling us.

Your administrator triggers the export from the application and receives an archive containing:

  • accounting — income and expenses together, with their supporting documents
  • bank statements
  • archives — all your documents, with an index describing each file
  • members, and visitors
  • the library
  • events, in standard calendar format

Everything is in CSV and open formats: readable in a spreadsheet, importable elsewhere, with no proprietary tool and no involvement from us.

5. And if you stop operating?

Two answers, and the second matters more than the first.

A continuity contract is in place. If anything were to happen to the publisher, another software company takes over the hosting. Your instances don’t shut down overnight, and you’re not left without anyone to call.

But you don’t have to rely on that. Your data comes out whenever you decide, in open formats, without our permission or our help. A lodge that can leave in one click isn’t betting on its supplier’s survival — it stays in control, whatever happens.

A dependency that can be broken unilaterally is not a dependency.

What we don’t claim

We don’t claim round-the-clock surveillance, or the infrastructure of a large corporation, or an uptime guarantee we couldn’t keep.

What we do guarantee is more modest, and verifiable: your data is in Europe, encrypted, isolated from other lodges, backed up, and yours to take back at any time.

The privacy policy details the processing involved, and the contract binding us to you sets its terms.