Legal
Privacy Policy
Last updated: 30 September 2026
1. Controller
The controller of the processing described below is [À COMPLÉTER], [À COMPLÉTER], registered with the [À COMPLÉTER] under number [À COMPLÉTER], with its registered office at [À COMPLÉTER], operating the OpenTremor service (the "Publisher"). For any question or request: [email protected].
The Publisher has not appointed a data protection officer, as its activity does not require one.
2. Scope of this policy
This policy covers the data whose purposes the Publisher alone decides: user accounts, the security of the service, the business relationship and the website.
Personal data that clients submit to the service in their organizations (code, configuration, infrastructure plans, and any names or addresses they contain) is processed by the Publisher on the client's behalf, as a processor, under the data processing agreement in annex 2 of the Terms of Sale, which applies to every plan, including the free demo (article 17 of the Terms of Use). For that data, the client is the controller: data subjects exercise their rights with the client.
3. Data processed, purposes, legal bases and retention
User account. Email address, name (optional), password (stored hashed), two-factor authentication secret (encrypted) and recovery codes (hashed), the identifier assigned by the identity provider when signing in with Google, Microsoft or the organization's single sign-on, organizations and roles, and the record of acceptance of the terms (version and date).
- Purpose: create and manage the account, provide the service.
- Legal basis: performance of the contract (article 6.1.b GDPR).
- Retention: as long as the account is active. An account inactive for three (3) years is deleted; its holder is informed by email one (1) month before deletion, unless this is impossible. A demo organization inactive for thirty (30) days may be deleted, after its owners are informed; they then have fifteen (15) days to request an export of their data.
Security and logs. IP address, date and time, the action performed (audit log of administrative operations), sign-in attempts (to limit the number of tries), technical operating traces.
- Purpose: secure the service, detect and prevent abuse, keep evidence of operations.
- Legal basis: the legitimate interest of the Publisher and its clients in the security of the service (article 6.1.f GDPR).
- Retention: audit log, two (2) years by default; technical traces, thirty (30) days; sign-in attempt counters, for the rate-limit window (fifteen minutes by default, twenty-four hours at most). The audit log is kept after an organization is deleted, for the same period.
Business relationship and invoicing. Name, job title and business contact details of contacts, correspondence, quotes, contracts, invoices, and the usage data used for invoicing.
- Purpose: answer requests, issue quotes, perform contracts, invoice, collect payment.
- Legal basis: pre-contractual steps and performance of the contract (article 6.1.b); legal accounting and tax obligations (article 6.1.c).
- Retention: accounting records, ten (10) years (article L123-22 of the French Commercial Code); contracts and relationship data, five (5) years after the relationship ends; requests that led nowhere, three (3) years after the last contact.
Support. The content of exchanges with support.
- Purpose: handle and answer requests.
- Legal basis: performance of the contract for clients (article 6.1.b); pre-contractual steps and the legitimate interest in answering requests for prospects (articles 6.1.b and 6.1.f).
- Retention: three (3) years after the relationship ends or the last exchange.
Data remaining in backups is erased as the backups rotate, within thirty (30) days at most.
4. Recipients
The data is processed by the Publisher alone. It is hosted by Scaleway SAS, in Paris (fr-par), France, as a processor.
When a user signs in with Google or Microsoft, or when an organization turns on an integration (GitHub, Slack, webhooks) or a language model provider, the exchanges with those services happen at the user's or the client's initiative, under their own terms. The language model provider is chosen and paid for by the client, who contracts with it directly.
The data is not sold, rented or used for advertising. It may be disclosed to an authority that requests it as provided by law.
5. Transfers outside the European Union
The Publisher does not transfer the data it controls to a third country: the service is hosted in France. A transfer may result from a client's choice of a hosting provider, language model provider or integration located outside the European Union; it is then the client's responsibility.
6. Cookies and trackers
The service uses only trackers that are strictly necessary for it to work, which are exempt from consent (article 82 of French law no. 78-17 of 6 January 1978):
mcp_session: keeps the signed-in user's session (the session's duration, eight hours by default);oauth_stateandsso_state: secure a sign-in through an identity provider (ten minutes);cookie_consent: keeps the user's cookie choices (six months);sidebar_state: keeps whether the sidebar is open or collapsed (seven days).
The display preference (light or dark theme) is stored in the user's browser (local storage); it is never sent to the Publisher and allows no audience measurement.
No analytics, advertising or social media cookie is set.
7. Security
The Publisher implements measures appropriate to the risk: encrypted communications, hashed passwords, encrypted stored secrets, isolation between organizations, role-based access control, two-factor authentication, sign-in attempt limits and logging of administrative operations.
8. Your rights
You have the right to access, rectify and erase your data, to restrict and object to its processing, and to data portability, as well as the right to set instructions for what happens to your data after your death (article 85 of French law no. 78-17). Where processing relies on your consent, you may withdraw it at any time.
To exercise them, write to [email protected]. The Publisher replies within one (1) month, which may be extended by two months for a complex request, in which case you are informed of the extension; it may ask you to prove your identity if it has reasonable doubts.
You may lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
9. Changes
This policy may change. The date of its last update is shown at the top of the page. Material changes are brought to users' attention by email or by a notice in the service, at least fifteen (15) days before they take effect.
10. Language
This policy is written in French. This English translation is provided for information only; in case of discrepancy, the French version prevails.