Table of Contents
Privacy Policy
Introduction
This policy explains how we collect and process personal data.
Data collection
We collect the minimum data necessary to provide the service.
- Account & identity: name, email address, phone number and authentication identifiers.
- Business details: company name, VAT/SIRET number, billing address and logo.
- Customer & billing data: your clients' names, addresses and contact details used to create invoices and contracts.
- Payment & transaction records: payment status, invoices and receipts (payment card data is handled securely by our payment processor).
- Usage data: IP address, device/browser metadata, logs and diagnostic information to secure and improve the service.
How we use your data
Data is used to provide and improve our services.
- Provide, operate and improve the MyFact platform (generate, send and archive invoices, quotes and contracts).
- Process payments, manage subscriptions and handle billing disputes.
- Authenticate users, prevent fraud and secure accounts.
- Provide customer support and respond to enquiries.
- Analyze anonymized usage data to improve product performance and user experience.
Legal basis
We process data under legitimate interests and contractual necessity.
- Performance of a contract: to deliver services you requested.
- Legal obligation: to satisfy accounting, tax and regulatory requirements.
- Legitimate interests: to operate, secure and improve the service, balanced against your rights.
- Consent: for optional features such as marketing communications or certain AI features when required.
Data retention
We retain data only as long as required for the service and legal obligations.
Your rights
You can access, rectify, and request deletion of your data.
Security
We apply industry-standard protections to your data.
- Encryption: TLS for data in transit and AES-256 for data at rest where applicable.
- Access controls and least-privilege principles for internal systems.
- Regular security testing, monitoring and incident response procedures.
- Automated backups and disaster recovery processes.
Sub-processors
We share data with trusted subprocessors under contract.
- Supabase (EU) — database hosting, auth and file storage.
- Stripe — payment processing (payment data handled directly by Stripe).
- Brevo (Sendinblue) — transactional email delivery.
- Mistral AI (France/EU) — optional AI-assisted generation (DPA in place).
- Botpress Cloud — optional chatbot for Business customers.
- Google / Microsoft — optional OAuth authentication providers.
Sub-processors maintain a DPA when required.
OAuth providers
You can sign in with third-party providers.
- Google LLC — Google's privacy policies apply when using Google sign-in. | DPA
- Microsoft Corporation — Microsoft's privacy policies apply when using Microsoft sign-in. | DPA
Data processing facts
Providing OAuth data is optional.
Virtual Assistant
We may use a virtual assistant for support.
Messages may be transferred to the provider for processing.
A DPA exists with the provider. botpress.com/privacy
Avoid sharing sensitive personal data in chat.
AI-assisted processing
We may use AI to improve document processing; data is handled securely.
What we process
- Client names and contact details used in documents.
- Commercial information: line items, amounts and payment terms.
- Free‑text content and contract clauses you provide.
We do not use your data to train third-party AI models.
Legal basis for processing
Data Processing Addendum mistral.ai/terms
Privacy contact
For privacy questions contact our DPO. molka.zitouni@drag-and-code-tunisia.com (we respond within 30 days)
We aim to reply within 30 days
You may file a complaint with your supervisory authority www.cnil.fr/fr/plaintes