Legal

Privacy Policy

Last updated: August 25, 2026

Esta página está disponível apenas em inglês. O texto em inglês é a versão vinculante.

Written in plain language on purpose. It names every service that touches your data, says why, and says for how long — because the people we work with deserve to know exactly that.

1. Who we are (the data controller)

Engadi Digital ("Engadi AI", "we") is the company operating www.engadi.com and the Engadi AI platform. It is established in France, so the GDPR and the French Data Protection Act apply, and the CNIL is our supervisory authority. For anything about your personal data, write to privacy@engadi.com — that address always works, whatever else this policy describes.

2. What we collect, and where it comes from

Directly from you: your name, email address, phone number, organisation and its type, the message you send us, and what you tell an AI agent — in the web chat, on the phone, or over WhatsApp/SMS. From the services you use: which pages you visit and which features you use (only if you accept analytics — see §6), the technical details every web server sees (IP address, browser), and the usage of your AI agent (message counts and token usage, so we can bill and rate-limit it). From third parties: if you give us a company email address we may look up public firmographic data about the company (Apollo); if you run our free Cyber Health Check and tick the box, we check whether the one address you typed appears in known data breaches (Have I Been Pwned). Payments: Stripe collects your card details directly — we never see or store a card number.

3. Phone calls, chat and messaging — what an AI agent keeps

When you call one of our phone lines, an AI assistant answers and says so at the start of the call. The call is not recorded. To understand you, the audio is processed live by our speech model provider (Google) and a transient transcript exists only for the duration of the call; when the call ends we keep a short written note of what you needed, your number, and an email address if you gave one, and the transcript is discarded. If you gave us an email address on the call we send you one recap of what was agreed. Web-chat conversations with the public demo and with your own agent are stored so the agent can remember the conversation; WhatsApp and SMS messages are stored so replies make sense and so we can honour a STOP. All of these are subject to the retention periods in §8. We never use what you say to train AI models; our AI providers process it under their API terms, which exclude training.

4. Why we process your data, and on what legal basis

Each purpose rests on one basis under GDPR Article 6:

  • To answer a request you make (a contact form, a scoping call, an audit, a cyber check, a phone call, a support ticket) — steps at your request before a contract, or performance of the contract once you are a customer.
  • To run your AI agent, your account and your billing — performance of the contract.
  • To send you marketing by email, SMS or WhatsApp — your consent, given separately for each channel. Ticking one never signs you up for another, and every message carries a way to stop.
  • To keep the platform secure (rate limits, bot checks, the security log of blocked requests) and to look up a company's public details so we prepare properly for a call — our legitimate interest, which you can object to at any time.
  • To measure how the website is used — your consent (the cookie banner).
  • To keep invoices and accounting records — our legal obligation.

5. The services that process data for us

We do not sell personal data, and we share it only with providers who process it on our instructions, under a data-processing agreement. Where a provider is outside the EU/EEA, see §7.

  • Hosting and delivery — Vercel (website and API; United States, with EU edge locations), Fly.io (the voice agent and the AI backend, Paris region), Cloudflare (DNS, R2 file storage, and the Turnstile check that keeps bots off our forms).
  • Database — Neon (PostgreSQL on AWS, us-east-1, United States). This is where the information above lives.
  • Sign-in — Clerk (authentication for the customer portal; United States).
  • Email — Resend (transactional email: confirmations, reports, recaps) and, as a fallback, MailerSend. Brevo (EU) for marketing email and SMS.
  • Messaging and voice — Meta (WhatsApp Business Platform), Twilio (the telephone network side of our phone lines; the numbers themselves are French), LiveKit (real-time audio during a call).
  • AI — Google (Gemini models: chat, voice, translation, the one-paragraph summary in a cyber-check report, the note kept after a call) and, if you are a customer who chose to use your own key, Anthropic. Model inputs are processed under API terms that exclude training.
  • Sales and support — HubSpot (our CRM mirror; United States), Cal.com (booking a call), Apollo (company lookups on business addresses; United States).
  • Payments — Stripe.
  • Analytics, only if you accept — PostHog (product analytics, keyed on an internal identifier rather than your email; United States), Vercel Web Analytics and Cloudflare Web Analytics (page-view counts).
  • Cyber Health Check only — Have I Been Pwned (Australia), and only for the one address you tick the box for.

6. Cookies and analytics

Strictly necessary: a session cookie that keeps you signed in to the portal, a token that protects our forms from cross-site requests, a short-lived counter that rate-limits the AI demo, and the record of your cookie choice itself. These need no consent. Everything else — PostHog product analytics and the Vercel and Cloudflare page-view counters — runs only after you accept the banner, and stops (with PostHog's storage cleared) if you decline or change your mind under "Cookie settings" in the footer. None of it is used for advertising or tracking across other sites.

7. Transfers outside the EU/EEA

Several providers in §5 are in the United States (Vercel, Neon, Clerk, Resend, HubSpot, Apollo, PostHog, Google, Anthropic, Twilio, Meta, Cal.com, Stripe) and one in Australia (Have I Been Pwned). For each of them we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses, together with the provider's data-processing agreement. Copies of the relevant clauses are available on request at privacy@engadi.com.

8. How long we keep it

Your contact record (name, email, phone, organisation, the notes of what you asked for) is kept for as long as we have a relationship with you or a reasonable prospect of one, and deleted on request (§9). Invoices and payment records are kept for the period French accounting law requires. The following are deleted automatically:

  • WhatsApp, SMS and email message bodies — 1 year.
  • Web-chat conversations with the demo agent — 1 year after the last message.
  • Sermon-to-content transcripts and uploads — 3 months.
  • Prayer requests — 6 months after we have responded, or 1 year if no response was ever needed.
  • Impact Edition applications — 1 year after the decision.
  • Cyber Health Check reports — 90 days; the ownership confirmations they may need — 30 days.
  • The security log of blocked requests (IP address, browser) — 90 days. Rate-limit counters — 48 hours.

9. Your rights

You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive the data you gave us in a portable format. You can withdraw any consent at any time: the unsubscribe link in any marketing email, replying STOP to an SMS or WhatsApp message, "Cookie settings" in the footer for analytics — or simply emailing privacy@engadi.com, which works for everything and always. We answer within one month. If you think we have handled your data unlawfully you can complain to the CNIL (www.cnil.fr) or to the supervisory authority of the EU country where you live. Deleting your data removes it from our systems and from the providers in §5 that hold a copy of your contact record; where we must keep an invoice by law, it is kept without the rest.

10. Children

Our services are for organisations and the adults who run them. We do not knowingly collect personal data from anyone under 15 (the age of digital consent in France) and we delete it if we learn we have.

11. Security

Data is encrypted in transit (TLS) and at rest. Files you or we upload are held in a private bucket and served only through short-lived signed links. Keys that customers give us for their own AI provider are encrypted before they are stored. Access to production systems is limited to the people who run them, every request that is refused for security reasons is logged, and an independent monitor checks the platform from outside every few minutes.

12. Changes and contact

When this policy changes we update the date at the top, and we email account holders about material changes. Questions, requests, or a copy of a data-processing agreement: privacy@engadi.com.