Privacy Policy
Last updated: [DATE DE MISE A JOUR]
This policy describes how [RAISON SOCIALE] (hereinafter the "Publisher") processes personal data in connection with the provision of its B2B prospecting service (hereinafter the "Service"), in compliance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertes).
1. Two categories of processing
Two situations with different roles must be distinguished:
- Data of the Service's users (accounts, billing, support): the Publisher acts as data controller.
- Prospecting data imported and processed by the Client (prospects, contacts, exchanges): the Client is the data controller and the Publisher acts as data processor on behalf of the Client. This processing is governed by the data processing agreement (DPA).
2. Data processed by the Publisher as controller
- Account data: name, email address, password (in hashed form), organization, role.
- Subscription and billing data: plan, payment history (processed by Stripe).
- Usage data and technical logs: logins, actions, IP addresses, security events.
- Support data: content of requests sent to the team.
3. Purposes and legal bases
- Provision and administration of the Service: performance of the contract.
- Billing and subscription management: performance of the contract and legal obligations.
- Security, abuse prevention, and logging: legitimate interest.
- Improvement of the Service and aggregated statistics: legitimate interest.
- Communications relating to the Service: performance of the contract or legitimate interest.
4. Artificial intelligence processing (BYOK model)
The Service operates on a "BYOK" (Bring Your Own Key) model. Artificial intelligence processing is performed using the Client's own API key (Anthropic, OpenAI, or another provider configured by the Client). As a result, the data submitted to the AI (for example, the content of a message to be drafted or analyzed) passes through the Client's account with its AI provider and is subject to that provider's terms and privacy policy. The Client chooses its provider, accepts its terms, and remains responsible for the data it decides to submit to the AI. The Publisher does not retain a separate copy of the exchanges for the purpose of training its own models.
5. Recipients and processors
The data is accessible to the Publisher's authorized personnel and to technical service providers acting as processors (hosting, transactional emails, payment, AI). The detailed list, purposes, locations, and associated safeguards are set out in the register of subprocessors.
6. Transfers outside the European Union
Some providers may process data outside the European Union. In that case, transfers are governed by appropriate safeguards, in particular the standard contractual clauses of the European Commission (SCCs) and, where applicable, supplementary measures. Details are set out in the register of subprocessors.
7. Retention periods
- Account and workspace data: for the duration of the contractual relationship.
- After deletion of the workspace: erasure or anonymization within a reasonable period, subject to technical backups with limited rotation.
- Billing data: retained for as long as required by statutory accounting and tax obligations.
- Security logs: retained for a limited period proportionate to the security purpose.
For prospecting data processed on behalf of the Client, retention periods are defined by the Client, who is the controller of that data; the Publisher erases or returns it in accordance with the DPA.
8. Your rights
In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection, and portability, as well as the right to set directives regarding the fate of your data after your death. You may exercise these rights by contacting [EMAIL DPO]. Some actions are directly available in the application, in particular the deletion of the workspace, which triggers the erasure of the associated data. Where the data concerned relates to prospecting managed by a Client (data controller), the request is forwarded or directed to that Client. You may lodge a complaint with the CNIL (www.cnil.fr).
9. Security
The Publisher implements appropriate technical and organizational measures, including:
- encryption of sensitive secrets at rest (API keys, access tokens, credentials);
- encryption of communications in transit (TLS);
- password hashing;
- workspace isolation (multi-tenant architecture, access segregation);
- access control, logging, and backups.
10. Cookies
The Service uses cookies and similar technologies that are strictly necessary for its operation (authentication, security). Where applicable, audience-measurement or third-party cookies are subject to notice and, where required, to the collection of consent.
11. Contact
For any question regarding this policy or the exercise of your rights, contact the data protection officer at [EMAIL DPO], or by mail at [ADRESSE].