Legal information

Privacy policy

What we record, why, for how long, and what you can demand.

To be reviewed by a lawyer

This text is a skeleton written during the development of the platform. The clauses on Vena Tokens, the right of withdrawal and account deletion were reviewed by a lawyer on 3 August 2026; the rest of the document was not, and several legal facts are still missing. As it stands, it constitutes neither a contractual commitment nor an enforceable document.

Every “[TO BE COMPLETED]” marker flags a legal fact that does not exist yet (company name, registration, host, providers). They will be filled in before any real launch.

01

Data controller

The data controller is the publisher of the site: VENALABS, SAS, 105 avenue André Malraux, 57000 Metz, France.

No data protection officer has been appointed at this stage. Any question about your data goes to hello@venalabs.com.

02

What we do not do

It is more useful to start here, because this is what actually distinguishes two privacy policies.

  • We neither sell, rent nor trade any personal data.
  • We display no advertising and set no third-party advertising tracker.
  • The content of your conversations with the models never leaves the service that processes them: no usage ledger, audit trail or error message copies it.
  • No banking data enters our systems: payment happens at a specialised provider, of which we keep only an opaque reference.
  • No password is stored in clear text, and no personal data appears in our technical logs.

03

Where the data comes from

It comes from you, almost always directly: what you enter at sign-up, in your settings, in a contact form, in the diagnostic questionnaire or when booking a meeting.

Added to that is data produced by your use of the service — track progress, Vena Token usage, security events — and, if you belong to a company account, the information provided by that account's manager when inviting you.

04

On which legal bases

Four bases are used, and the table below states which applies to each family of data.

  • Performance of the contract: everything without which the requested service cannot work (account, progress, subscription, token wallet).
  • Consent: publishing your public profile, subscribing to the newsletter, publishing a testimonial. It is requested by an explicit act, and can be withdrawn at any time with immediate effect.
  • Legitimate interest: service security, fraud prevention, follow-up of a professional business enquiry and product audience measurement.
  • Legal obligation: retention of accounting records and contractual documents.

05

For how long

Each family of data has its own period, stated in the table below. Two principles govern them: data whose purpose has disappeared is erased, and data the law requires us to keep is kept in a form reduced to the strict minimum.

Deleting an account immediately disables access and makes the associated public pages unreachable; permanent erasure happens thirty days later. That delay is a purge schedule, not a grace period: deletion is not reversible, no reactivation procedure exists, and coming back means creating a new account. Some data is kept beyond that point in anonymised form, meaning it can no longer be linked to you: what accounting law requires, and statistical aggregates.

Several periods are still being settled at the time of writing. They are flagged as such in the table, rather than replaced by a reassuring figure that would commit no one.

06

Security

Passwords are stored as hashes computed with a modern derivation algorithm, never in clear text. Sessions rely on short-lived, revocable tokens, and abnormal reuse of a token revokes the whole session family concerned.

Access to prospect data and administration functions is restricted to administrator accounts, protected by mandatory two-factor authentication, and every sensitive action is logged. Exports of commercial data are traced and capped.

Access links sent by email — diagnostic report, quote, download, meeting cancellation — rely on opaque, time-limited tokens stored as hashes: intercepting one grants temporary access, never account access.

07

Transfers outside the European Union

At the time of writing, no transfer outside the European Union is in place, for the simple reason that no external provider is contracted yet: the platform runs locally while it is being built.

The providers selected, their location and, where applicable, the safeguards framing a transfer outside the European Union will be published here before the service opens: [TO BE COMPLETED].

08

Minors

The service is not intended for children. Registering a minor under fifteen requires the authorisation of the holder of parental authority.

An account reported as belonging to a minor without authorisation is deleted, and the associated data erased.

09

Changes to this policy

This page evolves with the product. The version date appears at the bottom of the page, and any substantial change — a new purpose, a new recipient — is announced to existing accounts before it takes effect.

A change in the purpose of audience measurement asks for your decision again: agreement given for one thing does not hold for another.

Processing register

The detail, family of data by family of data

This table is the publication of our internal register, not a generic text: every row corresponds to data actually recorded by the platform.

  • Account and authentication

    Purpose
    Create your account, sign you in, secure your sessions and detect session theft.
    Legal basis
    Performance of the contract, and legitimate interest for the security part.
    Retention
    Life of the account, then erasure thirty days after deletion. Revoked session families are kept ninety days for investigation.
    Recipients
    No external recipient.
  • Progress, XP, badges and certificates

    Purpose
    Track your progress, award rewards, issue a certificate and make it verifiable.
    Legal basis
    Performance of the contract.
    Retention
    Life of the account. Public certificate pages disappear as soon as it is deleted.
    Recipients
    None, unless you choose to publish a certificate yourself.
  • Public profile

    Purpose
    Publish a page carrying your handle, level, badges and certificates.
    Legal basis
    Consent, off by default and withdrawable at any time with immediate effect.
    Retention
    As long as consent is active.
    Recipients
    Public by nature — that is the point of publishing.
  • Conversations and assisted exercises

    Purpose
    Produce the answers requested and let you find your exchanges again.
    Legal basis
    Performance of the contract.
    Retention
    Twelve months from the last message in a conversation, after which the thread and its content are erased; a conversation you come back to starts another twelve months. Erased with the account.
    Recipients
    Artificial intelligence model providers, from the opening of the service.
  • Wallet and usage ledger

    Purpose
    Hold your Vena Token balance, keep it recomputable and handle any claim.
    Legal basis
    Performance of the contract and accounting obligation.
    Retention
    Detailed entries are reduced after twenty-four months, the balance remaining recomputable. Once an account is closed, the evidential archive is kept five years, and ten years for the entries alone that justify a payment or an invoice — not the whole journal. Settled token reservations and daily quota counters are erased after thirty days.
    Recipients
    None: the ledger never leaves our systems.
  • Subscriptions, payments and receipts

    Purpose
    Manage your plan, open the corresponding rights and justify the amounts charged.
    Legal basis
    Performance of the contract, then legal accounting retention obligation.
    Retention
    Duration of the subscription, then ten years for accounting records.
    Recipients
    The payment provider, from the opening of the service. No banking data is stored on our side.
  • AI diagnostic and report

    Purpose
    Compute your score, produce the report and send it to you.
    Legal basis
    Pre-contractual measure and legitimate interest for product measurement.
    Retention
    Thirty days if no address was given. Otherwise aligned with the related business enquiry. Anonymised answers feed the sector reference with no time limit.
    Recipients
    No external recipient.
  • Business enquiries and follow-up

    Purpose
    Answer an incoming enquiry and follow the commercial relationship.
    Legal basis
    Legitimate interest, for strictly professional outreach. Campaign marketing requires separate consent.
    Retention
    Twenty-four months after the last activity for an enquiry without follow-up; duration of the contract plus three years for a client.
    Recipients
    No external recipient.
  • Meetings

    Purpose
    Arrange and honour a business meeting.
    Legal basis
    Pre-contractual measure.
    Retention
    Twenty-four months after the meeting, then anonymisation.
    Recipients
    The calendar service used to create the event, from the opening of the service: your name, address and the subject of the meeting are then sent to it.
  • Quotes and acceptances

    Purpose
    Issue a quote and prove its acceptance.
    Legal basis
    Pre-contractual measure, then accounting obligation once the quote is accepted.
    Retention
    Ten years for an accepted quote, a contractual record. Twenty-four months for a quote left unanswered. The signatory's name and the fingerprint of their IP address belong to the evidential archive: they are kept five years, then removed — they do not follow the accounting period of the document carrying them.
    Recipients
    No external recipient.
  • Automation template downloads

    Purpose
    Verify your address and deliver the file you asked for.
    Legal basis
    Consent. The marketing opt-in is a separate box, unticked by default, and refusing it never blocks the download.
    Retention
    Twenty-four hours for verification, seven days for the download right, then twenty-four months after the last delivery, like the related business enquiry.
    Recipients
    No external recipient.
  • Company accounts

    Purpose
    Manage seats, track assignments and produce progress reports for a funding body.
    Legal basis
    Performance of the contract.
    Retention
    Duration of the contract, then five years of archive: a funded training file can be audited years after it closes. Ten years for the records alone that justify the funding. An invitation left unanswered or closed is erased ninety days after it closes.
    Recipients
    The appointed managers of your organisation, for progress only — never for the content of your conversations.
  • Newsletter

    Purpose
    Send you the watch digest you subscribed to.
    Legal basis
    Consent, confirmed by a second email.
    Retention
    Until you unsubscribe, possible from every issue.
    Recipients
    The sending service selected, from the opening of the service.
  • Product audience measurement

    Purpose
    Understand which pages are useful and where journeys fail, using a random identifier not linked to your identity.
    Legal basis
    Legitimate interest. The exact legal qualification of this measurement is being validated; in the meantime nothing is measured without your agreement, and your browser's “do not track” signal is respected.
    Retention
    Thirteen months, enforced by the database itself rather than by a scheduled job that an incident could interrupt without a sound.
    Recipients
    None: measurement is performed by our own servers, with no third-party tool.
  • Security and administration log

    Purpose
    Trace sign-ins, account lockouts and administration actions.
    Legal basis
    Legitimate interest, service security.
    Retention
    Twelve months for the security and administration log. The IP address fingerprint of an administration login follows the same period, without exception.
    Recipients
    No external recipient.

Processors

No external provider is contracted at the time of writing: the platform runs on local infrastructure while it is being built. The categories below describe what will be put in place, and each will be replaced by a name, a country and a contract reference before the service opens.

  • Collecting subscriptions and top-ups: [TO BE COMPLETED]. It processes payment data; we keep only an opaque reference.
  • Synchronising meetings with a professional calendar: [TO BE COMPLETED]. It receives the name, email address and subject of the meeting.
  • Providing the artificial intelligence models: [TO BE COMPLETED]. The settings preventing reuse of content for training will be stated here.
  • Delivering transactional emails and the newsletter: [TO BE COMPLETED].
  • Hosting the application, the database and the files: [TO BE COMPLETED], with the corresponding processing region.

Your rights

They are exercised by a simple request to hello@venalabs.com, free of charge, with an answer within one month. Proof of identity is requested only in case of serious doubt about the requester's identity, and is never kept.

  • Access: obtain confirmation that data about you is processed, and receive a copy of it.
  • Rectification: correct inaccurate or incomplete data, most of the time directly from your settings.
  • Erasure: delete your account and the associated data, subject to what the law requires us to keep.
  • Portability: receive, in a machine-readable format, the data you provided and the data produced by your use of the service.
  • Objection: refuse processing based on legitimate interest, in particular business outreach and audience measurement.
  • Restriction: ask for a processing to be frozen while a dispute is examined.
  • Complaint: refer the matter to the French data protection authority if an answer does not satisfy you.

Working draft of 4 August 2026 · token, withdrawal and account deletion clauses reviewed by a lawyer · company details pending