Privacy Policy
Last updated: August 28, 2026
1. Data controller
For the site, accounts, demonstration requests, invoicing and commercial relations, the data controller is Damien FLANDRIN EI, 535 rue du 11 Novembre, 59162 Ostricourt, France, reachable at [email protected].
When a client publishes a catalog, measures its reading, creates a nominative link or collects a contact, this client determines the purposes and acts as data controller. Foliade then acts as a subcontractor according to the DPA. Readers must exercise their rights first with the organization that transmitted or presented the catalog to them.
2. Data, purposes, bases and durations
| Data | Purpose and legal basis | Maximum duration |
|---|---|---|
| Account, identity, possible organization, team and settings | Create and administer the space, authenticate users and provide the service — execution of the contract | Duration of the account, then time required for restitution, deletion and defense of rights |
| Catalogs, PDFs, links and metadata | Convert, host and distribute according to client instructions — contract performance or outsourcing | Duration of the account and rules for archiving the formula, then deletion upon instruction or upon closure |
| Stripe IDs, plan, status and billing data | Manage order, payment, taxes and accounting obligations — contract and legal obligation | Duration of the relationship; accounting documents kept for ten years |
| API keys, key fingerprints, and API or MCP call logs | Authenticate automations, execute instructions and secure access — contract performance and legitimate interest | Fingerprint retained until account is revoked or closed; call logs for 13 months |
| Demonstration requests and commercial exchanges | Respond to the request and follow up — pre-contractual measures and legitimate interest | Three years after request or last contact |
| PDF and publishing without an account | Convert, host and provide the expressly requested sharing link — pre-contractual measures | 30 days, then automatic deletion |
| Reads, page views, device, origin and pseudonymous identifier | Produce the statistics requested by the client — basis determined by this client | 13 months |
| Contacts entered in a catalog | Transmit the request to the client — basis and purpose announced by this client | 36 months maximum, or earlier upon instruction or exercise of a right |
| Truncated or hashed IP address, pseudonymous device identifier, attempts and security logs | Prevent abuse, detect repeated account creations and document incidents — legitimate interest | 30 days for security reconciliations, except retention necessary for an incident or dispute |
| Expired login links and invitations | Securing and diagnosing authentication — legitimate interest | Seven days after expiration for links; thirty days for invitations |
3. Origin and obligatory nature
The data comes from the data subject, their organization, the use of the service and from Stripe for billing events. Fields marked as required are required for account creation, security, or contract. Their absence may prevent the provision of the requested function. No decision producing legal effect is made exclusively by an algorithm.
4. Recipients and service providers
The data is accessible to authorized people from the publisher and, for a catalog, to authorized members of the customer area. The host and email provider indicated in the DPA receive only the data necessary for their mission.
Stripe processes payment, taxes, invoices and the billing portal according to the distribution of roles provided for by its own terms and data protection agreement. Foliade does not transmit the content of the catalogs to it and never receives card data.
The Foliade plugin for Codex or Claude Code runs on the user's environment and calls the API with its key. It transmits to Foliade only the PDF and the parameters necessary for the requested action; it does not transmit chat history, assistant memory, or unselected files. The assistant provider can process requests on its own terms when the user chooses to use it.
5. Cookies and local storage
Foliade only uses cookies or storage necessary for the session, security, prevention of repeated account creation, claiming publication without an account or access to a protected catalog. The reader also uses a pseudonymous first-party identifier, valid for a maximum of twelve months, to distinguish readings without tracking navigation on other sites. No advertising cookies or cross-site trackers are placed by Foliade.
6. Your rights
Depending on the basis of the processing, you can request access, rectification, erasure, limitation or portability of your data, and object to processing based on legitimate interest. You can also define directives relating to the fate of your data after your death.
Write to [email protected] en précisant votre demande et le compte ou catalogue concerné. Une pièce d'identité n'est demandée qu'en cas de doute raisonnable. Une réponse est apportée dans le délai légal.
Under the GDPR, data subjects have the right to lodge a complaint with the competent supervisory authority.
7. Transfers and security
Any transfers outside the European Economic Area are governed by an adequacy decision, standard contractual clauses supplemented if necessary, or another recognized mechanism. Security measures include transport encryption, logical separation of spaces, temporary links, hashing of secrets, rights by role, limitation of attempts and logging of support access.
8. Update
This policy may evolve to reflect service or regulation. A material change to an account is notified by an appropriate means before it comes into effect when required.