Privacy Policy
Last updated: October 1, 2026
1. Data Controller
cetome, registered in France with SIRET 849 836 101 00014, is the Data Controller responsible for your personal data. We are committed to protecting your privacy in compliance with the GDPR and the French Data Protection Act (Loi Informatique et Libertés).
2. Data We Collect
- Identity Data: Name, email address, and company details.
- Technical Data: IP address, browser type, and device information.
- Usage Data: How you interact with our SaaS, including assessment inputs, product data and the documents and pictures you upload. Uploaded files are served only to signed-in people who have access to the product.
- Collaboration Data: In an organisation, your name and e-mail address are visible to your colleagues and to the people working on the same product. The product history records who changed an answer, gave a verdict or changed an access, and when.
- Financial Data: Processed solely by our partner, Stripe. We do not store full credit card numbers on our servers.
3. Purpose of Processing
We process your data to:
- Provide, maintain, and improve our SaaS services.
- Process payments and manage your subscription.
- Respond to support requests submitted via our contact form.
- AI-assisted assessment of the content you enter and, when you ask for it, of the documents you upload.
- Comply with legal obligations (e.g., tax records and invoicing).
4. Data Sharing and International Transfers
We do not sell your personal data. We share data only with third-party processors necessary for our operations, such as Stripe (billing), Ionos SE (hosting provider) and Google (Gemini API, AI-assisted assessment of the content you enter and of the documents you ask it to read). Documents are sent to this processor only when you run the AI on them, and the copies uploaded for a run are deleted when it ends.
Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs), to maintain GDPR-level protection.
5. Your Data Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your personal data ("right to be forgotten").
- Restrict or Object to the processing of your data.
- Portability: Receive your data in a structured, machine-readable format.
To exercise these rights, please contact us via our official contact form.
6. Cookies and Tracking
We use essential cookies to manage your session and security. By using our service, you agree to our use of these necessary technologies. We do not use intrusive tracking cookies for advertising purposes.
7. Contact
If you have questions regarding this Privacy Policy, please contact our Data Protection Officer (DPO) or the designated point of contact via our contact form on the website.