Terms of use

01

Read this first

This document is not legal advice. It was written by the team that writes the product, from what the code actually does, and it must be reviewed by a lawyer before any payment is taken.

It is published anyway because a verified, provisional text is worth more than a contract template describing some other product.

Last updated: 25 September 2026.

02

Purpose

Jalon is a browser-based roadmap tool: milestone timeline by swimlane, issue board, tree, Gantt chart, activity log, delivery metrics and an optional forge connector — GitLab or GitHub, the organisation’s choice.

These terms govern use of the service at roadmap.ofnir.fr. Creating an account constitutes acceptance.

03

Your account

Creating an account asks for three things and nothing else: an email address, a password of at least twelve characters, and the name you want to appear under. No phone number or postal address is requested.

The password is never stored in clear: only an Argon2 hash is, and it cannot be turned back into the password. Keeping it confidential is your responsibility; a reset link can be requested at any time and is sent by email.

Language

Your account language is the one you pick on the sign-up screen: if you made a choice there, that choice is what the account records; otherwise it is derived from the Accept-Language header sent by your browser. It is then kept with the account, because it decides the language of your emails — including those sent at night, when nobody is in front of a screen.

It can be changed at any time from the Account page, and that choice overrides the browser for good.

04

Organisations and roles

Every account belongs to at least one organisation: you create one when signing up, or you join the one that invited you. Working data — swimlanes, milestones, tasks, people records, tags — belongs to the organisation, never to the account.

Four roles, from widest to narrowest: owner, administrator, member, viewer. A viewer reads without changing anything; only the owner can transfer, export or delete the organisation.

One person may belong to several organisations and move between them without signing in again. What they see is always bounded by the organisation currently open.

05

The data your organisation puts in

An organisation that puts personal data into Jalon remains the controller of it under the GDPR: the work of its members, and people records carrying the name and email address of people who have no account here. The organisation decides what it writes there; the publisher only hosts and runs the tool on its behalf, and is then merely a processor.

Article 28 of the GDPR requires a written contract between the two. That contract is published at /en/data-processing: it forms an integral part of these terms, and accepting these accepts it. Creating an account is therefore acceptance of both texts together.

That is why they carry the same version number, and it is that number which is recorded with your account: there is no accepting one without the other. Changing the data processing agreement changes these terms.

06

What you agree not to do

Do not attempt to reach the data of an organisation you do not belong to, nor to bypass role checks.

Do not subject the service to automated load beyond the normal use of a project tracking tool. Public authentication and invitation routes are rate-limited per address; exceeding them results in a temporary refusal.

Do not put data into the product that you have no right to put there — in particular data classified as sensitive under the GDPR, which Jalon is not designed for.

07

Availability

No service level is committed to at this stage. Jalon runs as a single instance on a server administered by the publisher, and every release restarts the application: short interruptions are normal and give no right to compensation.

A database backup is taken every night, verified by an actual restore into a throwaway database, and kept for thirty days. That backup protects against failure, not against deliberate deletion: what you delete from the application is deleted.

08

Leaving

Account deletion happens from the Account page. It is immediate and final: there is no bin and no grace period. The safeguards therefore sit before the act — password re-entered and email address retyped.

It runs in three steps. If you own an organisation where other people work, deletion is refused: ownership must first be transferred, or the organisation deleted. Organisations you own alone go with the account, in the same transaction. Only then is the account itself erased, and your address becomes available again.

What survives, and is better known than assumed: your person record stays in the organisations where it exists, detached from any account — it may have been created by someone else, and erasing it would unassign tasks that are not yours. Activity and audit traces also survive, with the actor anonymised but their name kept as it was at the time of the event. The matching retention periods are described on the privacy page.

Before leaving, the owner of an organisation can export its working data as JSON from the Organisation page: the organisation, its members and their roles, swimlanes, milestones, tasks, people records, the label catalogue and the board columns. Not included, and better known before deleting anything: snapshots and the organisation’s time zone.

09

Liability

The service is provided as is, with no service-level commitment. To the extent permitted by law, the publisher is liable only for proven direct damage, and its total liability is capped at the amounts actually paid by the organisation during the twelve months preceding the event giving rise to the claim.

That cap does not apply to liabilities that the law does not allow to be limited, including bodily injury, fraud or gross negligence, nor to the parties’ liability under the data processing agreement, which stipulates none. Indirect loss, lost revenue, or loss of data that the organisation should have backed up or exported is excluded to the extent permitted by law.

10

Intellectual property

The publisher retains all rights in Jalon, its software, interface, names, logos and content. During the contract, the organisation receives a non-exclusive, non-transferable right to use it for its internal needs. It may not copy, resell, decompile or attempt to extract the code, except where mandatory law permits it.

The organisation retains its data and warrants that it has the rights needed to upload it. It authorises the publisher to host, process and display it only to provide the service. Content imported from a forge remains subject to its rightsholders’ rights.

11

Suspension and closure

The publisher may restrict or suspend access, then close an account or organisation, for a serious breach of these terms, unlawful or dangerous use, a security risk, or an unpaid Pro invoice after an unanswered formal notice. A temporary restriction may take effect without notice when needed to protect the service or comply with the law.

Where the applicable offer or contract provides for it, a plan or payment limit may put an organisation into read-only mode. The publisher will not destroy data solely because of a suspension without following applicable retention and export obligations; the account and organisation deletion rules remain those in “Leaving”.

12

Changes to these terms

These terms live in the product’s repository and change with it. Any substantial change will be announced inside the application before it takes effect.

13

Governing law

French law applies. Subject to mandatory jurisdiction rules, including those protecting consumers, the competent courts are those of Reims. The publisher’s full identity — legal form, registration, head office address, publication director and host — appears in the legal notice.

Create an account