Privacy Policy

Last updated: 21 August 2026

1. Who is responsible for your data

The controller is Maxence-Olivier Parlant, sole trader, whose contact details appear in the Legal notice.

Contact for any question relating to personal data: [email protected].

No data protection officer has been appointed, as such an appointment is not mandatory given the nature and volume of the processing carried out.

2. Two distinct roles

This distinction governs the entire document.

The Publisher acts as controller for data relating to the creation and management of accounts, subscriptions and billing, as well as for the technical and security records it keeps on its own behalf. That is the subject of this policy.

The Publisher acts as processor for the personal data that the Customer transmits to it in the course of using the tools, notably the documents submitted to the Factur-X tool. In that case, the Customer remains the controller and determines the purposes. The applicable conditions are set out in the data processing agreement annexed to the Terms of Sale.

3. What we do not do

These commitments are verifiable and constitute design choices:

4. Data processed and legal bases

4.1 Account and authentication

DataPurposeLegal basis
Email addressIdentification, sign-in, transactional notificationsPerformance of the contract
Password, in hashed and salted formSecuring accessPerformance of the contract
API keys, in hashed form, with their prefix, label and date of last useAuthentication of calls, access managementPerformance of the contract
Access tokens issued to automated agents, in hashed formAuthentication of automated accessPerformance of the contract

Passwords and secrets are never stored in cleartext. As key labels are entered freely, it is recommended not to include any personal data in them.

4.2 Subscriptions and billing

DataPurposeLegal basis
Customer identifier assigned by the payment providerLinking payments to the accountPerformance of the contract
Subscriptions, plans, statuses, periodsContractual managementPerformance of the contract
Balance and movements of the prepaid walletConsumption accountingPerformance of the contract
Card brand and last four digits, payment method identifierIdentification of the payment methodPerformance of the contract
Accounting recordsCompliance with accounting and tax obligationsLegal obligation

The full bank card number is never transmitted to the Publisher's servers. It is entered directly with the payment provider.

4.3 Factur-X tool audit records

DataPurposeLegal basis
Account and key identifier, timestamp, fingerprint of the submitted document, result, ruleset version, profile, durationEstablishing proof of the response provided, security of the serviceLegitimate interest, and legal obligation for the retention of records
Issued response, kept encryptedProof of the content of the responseLegitimate interest

Neither the submitted documents nor their structured content are retained. The details of this mechanism, its encryption and its limits are set out in Annex 1 to the Terms of Sale.

4.4 Technical records

DataPurposeLegal basis
Request log: method, path, response code, durationMonitoring and diagnosticsLegitimate interest
IP address, only in the event of a server errorIncident diagnosticsLegitimate interest
Recipient's email address, only in the event of a delivery failureDelivery diagnosticsLegitimate interest

The request log contains no IP address, no request content, and no browser identifier. The records above are not stored in the database.

The hosting and routing providers also keep their own technical logs, which include IP addresses, as part of the operation of their infrastructure.

4.5 Usage metrics

The tools' usage counters are aggregated and contain no personal data.

5. Retention periods

CategoryPeriod
Account and associated dataDuration of the contractual relationship. In the absence of deletion on request, a free Account left inactive for twenty-four (24) months may be closed, after two email reminders (at 60 then 30 days), under the conditions of §17.4 of the Terms of Use
Revoked API keys and tokensDeleted upon revocation
Accounting and billing recordsLegal retention period applicable to accounting documents
Factur-X audit recordsTen (10) years from the date of entry (accounting and litigation evidence)
Technical recordsShort period, limited to diagnostic needs

Important information: no automatic purge is currently in place upon expiry of these periods, nor for the closure of inactive accounts. Deletions are carried out manually. This limitation is being corrected.

6. Recipients

The data is accessible only to the Publisher and to the following providers, acting as processors, on instruction and solely for the purposes indicated.

ProviderRoleData concerned
StripePayment processingEmail address, customer and subscription identifiers, payment method data
ResendDelivery of transactional emailsRecipient's email address and message content
Neon, LLCDatabase hosting (London region, United Kingdom)All recorded data
Render Services, Inc.Application hosting (Ireland region, European Union)All data processed during execution
Cloudflare, Inc.Domain-name management (DNS) and routing of inbound emailDNS routing data; email address and content of inbound messages routed

Cloudflare does not intercept the service's web traffic (no proxy, no content-delivery network): accordingly, it does not process the content of application requests and sets no cookie on the site.

No other communication is made, subject to requests from a legally authorised judicial or administrative authority.

7. Transfers outside the European Union

The data is hosted in data centres located in the European Union (application hosting in Ireland) and in the United Kingdom (database in London). The United Kingdom is the subject of an adequacy decision by the European Commission, which recognises a level of protection equivalent to that of the Union.

As the providers concerned are companies established in the United States, access from that country cannot be excluded for operational and technical support purposes. Such access is governed by the standard contractual clauses adopted by the European Commission, supplemented where applicable by the provider's certification under the data protection framework applicable between the European Union and the United States, and by each provider's own safeguards.

You can obtain a copy of the applicable safeguards by writing to [email protected].

8. Your rights

You have, under the conditions provided by the GDPR, the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to define directives on the fate of your data after your death.

How to exercise them

By email to [email protected], from the address linked to your account. An identity check may be requested in the event of reasonable doubt.

Important information: these requests are not handled self-service in the management area. They are subject to manual handling. The Publisher undertakes to respond within one month, which may be extended by two months in the event of complexity, in accordance with the GDPR.

Limits on erasure

Certain data cannot be erased at your request:

Complaint

You may lodge a complaint with the French Data Protection Authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.

9. Security

The following measures are implemented:

Known limitation: the session token has a validity period of seven days and is not revocable server-side. In the event of suspected compromise, write immediately to [email protected].

As no security measure can guarantee zero risk, the Publisher undertakes to notify any data breach under the conditions provided by the GDPR.

10. Cookies

See the Cookie Policy.

11. Amendment

This policy may be amended to reflect changes in the Service or in regulations. Any substantial change is notified by email to account holders. The last update date appears at the top of the document.