Privacy Policy
Last updated: 04/09/2026
This policy describes how SHRIVATSA (MDDev) collects and processes personal data through the www.assilya.fr website (the "Website") and the Assilya platform available at https://app.assilya.fr (the "Platform"), in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act of 6 January 1978, as amended. It sets out the data processed, how it is used and the rights you have.
1. Data controller and roles
The data controller is:
- SHRIVATSA, SASU with a share capital of €78,000, trading as MDDev
- RCS Toulouse 881 836 845, SIRET 88183684500027
- Registered office: 156 route de la Salvetat, 31470 Fontenilles, France
- Email: contact@assilya.fr, phone: +33 (0)5 82 95 06 78
No data protection officer (DPO) has been appointed; any question may be sent to the contact address above.
Depending on the processing, we act in two distinct capacities:
- Data controller for the Website's visitors and prospects, the management of our Clients' accounts, billing, security and the improvement of our services.
- Data processor (Article 28 GDPR) when we process, on behalf of our Clients, the data of their own customers (the "End Customers"): messages, orders, deliveries. This processing is governed by a Data Processing Agreement (DPA) available upon request.
2. Data collected
We process the following categories of data:
- Prospects (Website demo form): name, business email, phone number (optional), store name, e-commerce platform, message volume and optional message.
- Account data: first and last name, business email address, login credentials, preferences.
- Billing data: company name, contact details, payment information.
- Usage data: IP address, technical and connection logs, browsing data on the Website, actions performed on the Platform.
- End Customer data (processed on behalf of our Clients): content of messages received through the connected channels (marketplaces, emails, chatbot, connectors), contact details of correspondents, order and delivery data, and the knowledge base the Client provides to its AI agents.
3. Purposes and legal bases
Your data is processed for the following purposes:
- Handling your demo or contact request and contacting you back. Legal basis: pre-contractual measures and consent.
- Providing and administering the service, including message processing by AI agents. Legal basis: performance of the contract.
- Managing the client relationship, support and billing. Legal basis: performance of the contract and legal obligation.
- Ensuring the security of the Website and the Platform, preventing fraud and abuse. Legal basis: legitimate interest.
- Improving our services. Legal basis: legitimate interest.
- Measuring the audience of the Website and the Platform and the effectiveness of our advertising campaigns. Legal basis: consent (non-essential cookies).
- Sending marketing communications. Legal basis: consent, withdrawable at any time.
4. Recipients and subprocessors
Your data is accessible to the publisher's authorised staff and to the following subprocessors, acting on instructions, bound by confidentiality and strictly to the extent necessary for their mission:
- OVHcloud (OVH SAS): hosting of the Website and the Platform, data storage and email delivery. European Union (France).
- Stripe: subscription payment and billing. United States.
- Anthropic: AI processing of messages (Claude models). United States.
- OpenAI: content vectorisation (embeddings). United States.
- Resend: delivery of the emails related to the Website demo form. United States.
- Google: reCAPTCHA (anti-spam protection of the demo form) and, subject to your consent, Google Tag Manager, Google Analytics 4 (audience measurement) and Google Ads (advertising and conversion measurement). United States.
Administrative or judicial authorities may also be recipients where a legal obligation so requires. We never sell or rent your data to third parties. The list of subprocessors may change; Clients are informed under the conditions set out in the DPA.
5. Third-party services connected by the Client
The Platform lets the Client connect their own accounts with third-party services. These services are not subprocessors of the publisher: the Client holds their own accounts there and remains subject to their terms and privacy policies. We access their official APIs solely to provide the features requested by the Client, within the permissions they grant and acting as the Client's processor. The connectable services and the data categories involved are:
- Marketplaces: Amazon, eBay, ManoMano, Mirakl, Octopia (Cdiscount). Data involved: buyer messages, order and delivery data.
- Online stores: Magento (Adobe Commerce), PrestaShop, Shopify, WooCommerce. Data involved: orders, customer records, products and returns.
- Mailboxes: Gmail (Google), IMAP. Data involved: email content and attachments.
- Carriers and parcel tracking: Baback, Colissimo (La Poste), Correos, YunExpress. Data involved: shipment tracking statuses.
Data obtained from these services is processed exclusively to centralise conversations, suggest or send replies and track the Client's orders. It is never sold, rented, used for advertising purposes or used to train an artificial-intelligence model.
6. Artificial intelligence
The Platform's AI agents rely on models provided by Anthropic (Claude models: message analysis, drafting of suggestions or replies, translation, conversation summaries) and by OpenAI (embeddings model: vectorisation of content for knowledge-base search and agent memory) to analyse messages, suggest replies and, depending on the configuration chosen by the Client, answer them automatically. These providers are used through their commercial API offerings, called directly, without any intermediary, aggregator or third-party gateway.
- No training: under these providers' commercial terms, the content transmitted is not used to train or improve their models. The publisher itself does not train, fine-tune or build any artificial-intelligence model from the data of Clients, End Customers or connected services, including data received from Google APIs.
- Limited retention: the providers retain requests for at most 30 days, solely for security and abuse-detection purposes, then delete them.
- Minimisation: only the elements required for the requested feature (conversation content, order context, the Client's knowledge base) are transmitted, at the time of processing.
- Human oversight: the Client chooses how each agent operates, suggestion subject to human validation before sending or autonomous reply.
- Article 22 GDPR: no decision producing legal effects concerning a person is based solely on automated processing.
- Transparency: End Customers are informed when they interact with an AI system, in accordance with applicable regulations.
7. Data from Google APIs (Gmail)
When a Client connects a Gmail mailbox, they grant access via OAuth 2.0 (gmail.modify scope) to message content (subject, body, sender, recipients, attachments), associated metadata and mailbox labels.
This information is used exclusively to centralise emails in the unified inbox, generate suggestions or replies through the Client's AI agents and organise conversations. It is only transmitted to the strictly necessary subprocessors (OVHcloud for hosting, Anthropic and OpenAI for AI processing, under the conditions described in the "Artificial intelligence" section) and is never sold, rented or used for advertising purposes.
Gmail data is retained while the integration is active, then deleted within 30 days of its deactivation, unless a legal obligation requires longer retention. The Client may revoke access at any time from the Platform or from the security settings of their Google account.
8. Google data Limited Use commitment
The publisher's use of raw or derived data received from Google Workspace APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. In particular:
- this data is only used to provide or improve user-facing features within the Platform;
- it is not transferred to third parties, except to provide those features, to comply with the law or as part of a merger or acquisition, and never for advertising purposes;
- the publisher's staff do not access the content of this data, except with the Client's explicit agreement (for example for a support request), for security purposes, to comply with a legal obligation or for internal operations on aggregated and anonymised data;
- it is not used, transferred or sold to create, train or improve a generalised artificial-intelligence or machine-learning model.
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
9. Data from the Amazon marketplace
When a Client connects their Amazon store to our service, we access the Amazon Selling Partner API (SP-API) and receive marketplace information that may include buyers' personal data: name, shipping address, email address, message content and order details.
This data is processed exclusively to provide the features requested by the seller (order management and replies to buyer messages) and to satisfy our legal obligations. It is never used for advertising, prospecting, profiling or resale, nor shared with third parties outside the use cases authorised by Amazon.
- Retention: buyers' personal data is deleted no later than 30 days after order delivery, unless a legal obligation requires longer retention, in which case it is archived in encrypted form.
- Security: encryption in transit (TLS 1.2 minimum) and at rest (AES-128 minimum), access limited to authorised staff under the least-privilege principle with multi-factor authentication, logs free of personal data.
- Deletion: upon termination of the service or revocation of the authorisation, all information obtained from Amazon is permanently and irreversibly deleted within 30 days.
- Incidents: any security incident affecting this data is reported to Amazon within 24 hours, in addition to the notifications required by the GDPR.
This processing complies with Amazon's Data Protection Policy and Acceptable Use Policy.
10. Transfers outside the European Union
Data is hosted within the European Union (OVHcloud, France). Some subprocessors are however established in the United States or may process data there: Anthropic, OpenAI, Stripe, Resend and Google. These transfers are governed by appropriate safeguards within the meaning of Articles 44 et seq. GDPR: the European Commission's standard contractual clauses and, where applicable, the subprocessor's certification under the EU-US Data Privacy Framework.
11. Retention periods
- Prospects: 3 years from the last contact.
- Account data: duration of the contractual relationship, then deletion or anonymisation.
- Billing data: 10 years (accounting obligation).
- End Customer data processed on behalf of the Client: duration of the contract, then deletion or return in accordance with the DPA.
- Connected-service data: deletion within 30 days of the service's disconnection.
- Technical logs: for the duration strictly necessary for security purposes.
- Cookies: as per the durations shown in the "Cookies and trackers" section.
Specific retention periods imposed by certain connected services (notably Amazon and Google) are detailed in their dedicated sections.
12. Cookies and trackers
On your first visit to the Website or to the public pages of the Platform (login, registration, billing), a banner lets you accept or refuse non-essential cookies. Your choice is remembered for both the Website and the Platform. The working pages of the Platform, available after login, only set strictly necessary cookies.
| Cookie / tracker | Purpose | Duration |
|---|---|---|
| assilya_session | Maintains the browsing session (strictly necessary) | Session |
| XSRF-TOKEN | Protection against cross-site request forgery, CSRF (strictly necessary) | 2 hours |
| remember_web_* | "Remember me" persistent login on the Platform (strictly necessary) | 400 days |
| cc_cookie | Stores your cookie preferences (strictly necessary) | 6 months |
| _ga, _ga_* | Audience measurement, Google Analytics 4 via Google Tag Manager (subject to consent) | 13 months |
| _gcl_*, _gac_* | Advertising and conversion measurement, Google Ads (subject to consent) | 90 days |
| _GRECAPTCHA | Anti-spam protection of the Website demo form, Google reCAPTCHA (subject to consent) | 6 months |
The Website demo form is protected by reCAPTCHA: Google's privacy policy and terms of service apply.
The Platform also uses your browser's local storage to remember your interface preferences (theme, sidebar); this information never leaves your device.
You can review or withdraw your consent at any time:
13. Data security
We implement appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, disclosure, alteration or destruction: encryption in transit (TLS), role-based access control, multi-factor authentication, operation logging, regular backups and hosting within the European Union.
14. Your rights
In accordance with the GDPR, you have the following rights over your data:
- Right of access: obtain confirmation that your data is processed and receive a copy.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure: request the deletion of your data.
- Right to restriction of processing.
- Right to object, in particular to commercial prospecting.
- Right to portability of your data.
- Right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
- Right to set directives regarding the fate of your data after your death.
To exercise these rights, contact us at contact@assilya.fr. A response will be provided within one month at most.
If you are the end customer of a company using Assilya, that company is the controller of your data: address your requests to it directly; we assist it in responding.
15. Complaint to the CNIL
If you believe, after contacting us, that your rights are not respected, you may lodge a complaint with the French data protection authority (CNIL): www.cnil.fr.
16. Modifications
This policy may be modified at any time to reflect legal developments or changes to our services. The date of the last update appears at the top of the page.
17. Contact
For any question regarding this policy or the processing of your data, you can write to us at contact@assilya.fr or by post at 156 route de la Salvetat, 31470 Fontenilles, France.