Privacy policy
Last updated: 5 October 2026
This is an English translation provided for convenience. In the event of any discrepancy, the French version prevails.
Catpilot takes the protection of your data very seriously. This page explains what data we collect, why, how long we keep it, how we protect it and what your rights are, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).
1. Data controller
The data controller is Timothy Mariaud--Quéré, publisher of Catpilot. Contact: timothy.mariaudquere@catpilot.fr.
2. Data collected and purposes
We only collect the data strictly necessary for the purpose of the processing (data minimisation principle, Article 5 GDPR). No sensitive data within the meaning of Article 9 GDPR is collected.
2.1 “Contact us” form
First name, last name, work email address, phone number (optional) and the free text of your message. This data is used solely to answer your request and, where appropriate, to present Catpilot to you. Legal basis: our legitimate interest in answering the requests we receive, and pre-contractual measures taken at your request.
2.2 Information about your company
When your access is set up: group name, market covered, segments and brands of the group. This information is used solely to configure your dashboards. Legal basis: performance of the contract.
2.3 User accounts
Work email address, company, password (stored in encrypted form by our provider, never readable by us) and, if you enable it, two-factor authentication details. This data provides secure access to the software. Legal basis: performance of the contract.
2.4 Access log
The main actions carried out in the software (login, file upload or deletion, viewing a tool, export) are recorded with their date and the account concerned, for security and traceability purposes. The content of your files is never included. Legal basis: our legitimate interest in securing the service.
2.5 Files uploaded by our clients
The extracts uploaded contain commercial data belonging to the client company. Catpilot processes them solely on behalf of that client, to produce its dashboards: they are never sold, never shared with a third party and never combined with another client's data.
3. Retention periods
In accordance with Article 5(1)(e) GDPR, your data is kept for no longer than is necessary for the purposes for which it is processed. After that, it is deleted or anonymised, unless it must be archived to meet a legal obligation or to defend our rights.
- User account. Your account data (identity, work email, settings) is kept for the duration of the contract with the client company, then deleted within 30 days.
- Inactive accounts. Accounts with no login for 24 months are deleted, after prior notice to the user.
- Contractual data. Evidence of the business relationship is kept for 5 years from the end of the contract, in restricted-access archives, in line with the limitation period set out in Article 2224 of the French Civil Code.
- Invoices and accounting records. They are kept for 10 years from the end of the financial year, in accordance with Article L123-22 of the French Commercial Code.
- Prospects. Data of people contacted by email or LinkedIn, or who requested a demo, is kept for 3 years from its collection or from the last contact initiated by the prospect, in line with the CNIL guidelines on customer management.
- Clients, for marketing purposes. Data is kept for 3 years from the end of the business relationship.
- Marketing opt-out list. The information needed to respect your objection is kept for 3 years from the exercise of this right.
- Requests to exercise rights. Information relating to your request is kept for 5 years from its closure. Any proof of identity is deleted as soon as it has been checked.
- Login and security logs. They are kept for 12 months and then deleted automatically, in line with the CNIL recommendations on logging.
- Technical backups. They are kept on a rolling 30-day basis.
- Data imported by our clients. Data imported into Catpilot by client companies is kept for the duration of the contract. At its end, it is returned on request and then deleted within 60 days, backups included, in accordance with the client's instructions (Article 28(3)(g) GDPR).
4. Recipients and service providers
Your data is only accessible to authorised Catpilot staff and to our technical service providers, within the limits of their role:
- Vercel: application hosting (processing in Paris, France).
- Supabase: database, accounts and file storage (hosted in Paris, France).
- Resend: sending service emails (invitations, password resets, notifications).
- OVHcloud: Catpilot's email service.
Some of these providers are companies established outside the European Union. Any transfers are covered by appropriate safeguards (standard contractual clauses of the European Commission).
5. Data security
Protecting our clients' data is at the heart of how Catpilot is designed. Here are the concrete measures in place:
- Hosted in France: the application runs in the Paris region, and data (accounts, files) is hosted in Paris.
- Strict separation between companies: access rules are enforced directly by the database, not only by the application. Each user only sees their own company's data, and an extract uploaded as personal is only visible to its author.
- Encryption: all exchanges with the website are encrypted (HTTPS), and data is encrypted on our host's servers.
- Protected files: uploaded files are kept in private storage, and uploads go through temporary, secure links.
- Checks on uploaded files: only Excel files are accepted, their size is limited and their content is checked (no hidden macros, protection against malicious files).
- Secure access: accounts are created by invitation only, strong passwords are mandatory (at least 12 characters, with upper and lower case letters, a digit and a special character), and two-factor authentication is available to everyone and mandatory for the Catpilot team.
- Traceability: the main actions are recorded in an access log, kept for 12 months and then deleted automatically. The content of your files is never included.
- Identified exports: every PDF or PowerPoint export carries a watermark showing the company, the user and the date.
- Website protection: content security policy, security headers and rate limiting on sensitive forms (forgotten password, contact).
- Never sold: your data is never sold, never shared with a third party and never combined with another client's data.
6. Cookies
Catpilot only uses cookies that are strictly necessary for it to work (keeping you logged in, display preferences). No analytics or advertising cookies are set, so your consent is not required.
7. Your rights at a glance
In accordance with Articles 15 to 22 GDPR, you remain in control of your personal data. At any time, you can:
- access it: find out what data we hold about you and obtain a copy;
- correct it: have inaccurate information corrected or incomplete information completed;
- have it erased (“right to be forgotten”): request its deletion when it is no longer needed;
- restrict its use: temporarily suspend its processing, for example while a dispute is being examined;
- take it with you (portability): receive it in a structured, machine-readable format to reuse it elsewhere;
- object to its processing: on grounds relating to your particular situation;
- decide what happens to it after your death: set instructions for its retention, deletion or disclosure (Article 85 of the French Data Protection Act).
To exercise any of these rights, simply write to timothy.mariaudquere@catpilot.fr, specifying your request. We will reply within one month. Each of these rights is detailed in section 8 below.
8. Your rights over your personal data
In accordance with Regulation (EU) 2016/679 (GDPR) and French Law No. 78-17 of 6 January 1978 (loi Informatique et Libertés), any individual whose data is processed by the publisher of Catpilot has the following rights.
8.1 Right to information (Articles 12, 13 and 14 GDPR)
You have the right to be informed clearly and accessibly about the identity of the data controller, the purposes and legal bases of the processing, the recipients of your data, how long it is kept and how to exercise your rights. This information is set out on this page.
8.2 Right of access (Article 15 GDPR)
You can obtain confirmation of whether data about you is being processed, together with a copy of that data and information about its processing.
8.3 Right to object (Article 21 GDPR)
You can object, on grounds relating to your particular situation, to processing based on our legitimate interest. You can object at any time, without giving a reason, to the use of your data for marketing purposes, simply by writing to the address below.
8.4 Right to erasure (Article 17 GDPR)
You can request the deletion of your data when it is no longer needed, when you withdraw your consent or object to the processing, or when the processing is unlawful. This right does not apply to data we must keep to comply with a legal obligation or to establish, exercise or defend legal claims.
8.5 Right to rectification (Article 16 GDPR)
You can have inaccurate or incomplete data about you corrected or completed. Some information can be changed directly from your account.
8.6 Right to restriction of processing (Article 18 GDPR)
You can request that the use of your data be temporarily frozen, in particular while we examine a dispute about its accuracy or an objection, or if you prefer restriction to erasure.
8.7 Right to data portability (Article 20 GDPR)
Where the processing is automated and based on your consent or on a contract with you, you can receive the data you provided to us in a structured, commonly used and machine-readable format, or ask for it to be transmitted to another data controller.
8.8 Right to withdraw consent (Article 7(3) GDPR)
Where processing is based on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
8.9 Right to lodge a complaint (Article 77 GDPR)
If you believe your rights are not being respected, you can contact the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or via www.cnil.fr.
8.10 Post-mortem instructions (Article 85 of the French Data Protection Act)
You can set instructions regarding the retention, deletion and disclosure of your data after your death.
8.11 Automated decisions (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. Catpilot makes no such decisions: the analyses and recommendations it produces concern products and markets, not people.
How to exercise your rights
How to contact us. You can exercise your rights by writing to timothy.mariaudquere@catpilot.fr. If we have reasonable doubts about your identity, we may ask you for additional information.
Response time (Article 12(3) GDPR). We reply within one month of receiving your request. This period may be extended by two months given the complexity or number of requests; you will then be informed within one month of your request.
Free of charge (Article 12(5) GDPR). Exercising your rights is free. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or refuse to act on it.
Notification to recipients (Article 19 GDPR). Any rectification, erasure or restriction is notified to the recipients to whom your data has been disclosed, unless this proves impossible or involves disproportionate effort.
Data imported by our clients
Data imported into Catpilot by client companies (sales, panel and leaflet data) is processed on their behalf and according to their instructions. If you wish to exercise your rights over personal data it may contain, please contact the company concerned directly; we will assist it in handling your request (Article 28 GDPR).
9. Changes
This policy may change. The date of the last update is shown at the top of this page.