Legal information
Privacy policy
What we record, why, for how long, and what you can demand.
This text is a skeleton written during the development of the platform. The clauses on Vena Tokens, the right of withdrawal and account deletion were reviewed by a lawyer on 3 August 2026; the rest of the document was not, and several legal facts are still missing. As it stands, it constitutes neither a contractual commitment nor an enforceable document.
Every “[TO BE COMPLETED]” marker flags a legal fact that does not exist yet (company name, registration, host, providers). They will be filled in before any real launch.
01
Data controller
The data controller is the publisher of the site: VENALABS, SAS, 105 avenue André Malraux, 57000 Metz, France.
No data protection officer has been appointed at this stage. Any question about your data goes to hello@venalabs.com.
02
What we do not do
It is more useful to start here, because this is what actually distinguishes two privacy policies.
- We neither sell, rent nor trade any personal data.
- We display no advertising and set no third-party advertising tracker.
- The content of your conversations with the models never leaves the service that processes them: no usage ledger, audit trail or error message copies it.
- No banking data enters our systems: payment happens at a specialised provider, of which we keep only an opaque reference.
- No password is stored in clear text, and no personal data appears in our technical logs.
03
Where the data comes from
It comes from you, almost always directly: what you enter at sign-up, in your settings, in a contact form, in the diagnostic questionnaire or when booking a meeting.
Added to that is data produced by your use of the service — track progress, Vena Token usage, security events — and, if you belong to a company account, the information provided by that account's manager when inviting you.
04
On which legal bases
Four bases are used, and the table below states which applies to each family of data.
- Performance of the contract: everything without which the requested service cannot work (account, progress, subscription, token wallet).
- Consent: publishing your public profile, subscribing to the newsletter, publishing a testimonial. It is requested by an explicit act, and can be withdrawn at any time with immediate effect.
- Legitimate interest: service security, fraud prevention, follow-up of a professional business enquiry and product audience measurement.
- Legal obligation: retention of accounting records and contractual documents.
05
For how long
Each family of data has its own period, stated in the table below. Two principles govern them: data whose purpose has disappeared is erased, and data the law requires us to keep is kept in a form reduced to the strict minimum.
Deleting an account immediately disables access and makes the associated public pages unreachable; permanent erasure happens thirty days later. That delay is a purge schedule, not a grace period: deletion is not reversible, no reactivation procedure exists, and coming back means creating a new account. Some data is kept beyond that point in anonymised form, meaning it can no longer be linked to you: what accounting law requires, and statistical aggregates.
Several periods are still being settled at the time of writing. They are flagged as such in the table, rather than replaced by a reassuring figure that would commit no one.
06
Security
Passwords are stored as hashes computed with a modern derivation algorithm, never in clear text. Sessions rely on short-lived, revocable tokens, and abnormal reuse of a token revokes the whole session family concerned.
Access to prospect data and administration functions is restricted to administrator accounts, protected by mandatory two-factor authentication, and every sensitive action is logged. Exports of commercial data are traced and capped.
Access links sent by email — diagnostic report, quote, download, meeting cancellation — rely on opaque, time-limited tokens stored as hashes: intercepting one grants temporary access, never account access.
07
Transfers outside the European Union
At the time of writing, no transfer outside the European Union is in place, for the simple reason that no external provider is contracted yet: the platform runs locally while it is being built.
The providers selected, their location and, where applicable, the safeguards framing a transfer outside the European Union will be published here before the service opens: [TO BE COMPLETED].
08
Minors
The service is not intended for children. Registering a minor under fifteen requires the authorisation of the holder of parental authority.
An account reported as belonging to a minor without authorisation is deleted, and the associated data erased.
09
Changes to this policy
This page evolves with the product. The version date appears at the bottom of the page, and any substantial change — a new purpose, a new recipient — is announced to existing accounts before it takes effect.
A change in the purpose of audience measurement asks for your decision again: agreement given for one thing does not hold for another.
Processing register
The detail, family of data by family of data
This table is the publication of our internal register, not a generic text: every row corresponds to data actually recorded by the platform.
Account and authentication
- Purpose
- Create your account, sign you in, secure your sessions and detect session theft.
- Legal basis
- Performance of the contract, and legitimate interest for the security part.
- Retention
- Life of the account, then erasure thirty days after deletion. Revoked session families are kept ninety days for investigation.
- Recipients
- No external recipient.
Progress, XP, badges and certificates
- Purpose
- Track your progress, award rewards, issue a certificate and make it verifiable.
- Legal basis
- Performance of the contract.
- Retention
- Life of the account. Public certificate pages disappear as soon as it is deleted.
- Recipients
- None, unless you choose to publish a certificate yourself.
Public profile
- Purpose
- Publish a page carrying your handle, level, badges and certificates.
- Legal basis
- Consent, off by default and withdrawable at any time with immediate effect.
- Retention
- As long as consent is active.
- Recipients
- Public by nature — that is the point of publishing.
Conversations and assisted exercises
- Purpose
- Produce the answers requested and let you find your exchanges again.
- Legal basis
- Performance of the contract.
- Retention
- Twelve months from the last message in a conversation, after which the thread and its content are erased; a conversation you come back to starts another twelve months. Erased with the account.
- Recipients
- Artificial intelligence model providers, from the opening of the service.
Wallet and usage ledger
- Purpose
- Hold your Vena Token balance, keep it recomputable and handle any claim.
- Legal basis
- Performance of the contract and accounting obligation.
- Retention
- Detailed entries are reduced after twenty-four months, the balance remaining recomputable. Once an account is closed, the evidential archive is kept five years, and ten years for the entries alone that justify a payment or an invoice — not the whole journal. Settled token reservations and daily quota counters are erased after thirty days.
- Recipients
- None: the ledger never leaves our systems.
Subscriptions, payments and receipts
- Purpose
- Manage your plan, open the corresponding rights and justify the amounts charged.
- Legal basis
- Performance of the contract, then legal accounting retention obligation.
- Retention
- Duration of the subscription, then ten years for accounting records.
- Recipients
- The payment provider, from the opening of the service. No banking data is stored on our side.
AI diagnostic and report
- Purpose
- Compute your score, produce the report and send it to you.
- Legal basis
- Pre-contractual measure and legitimate interest for product measurement.
- Retention
- Thirty days if no address was given. Otherwise aligned with the related business enquiry. Anonymised answers feed the sector reference with no time limit.
- Recipients
- No external recipient.
Business enquiries and follow-up
- Purpose
- Answer an incoming enquiry and follow the commercial relationship.
- Legal basis
- Legitimate interest, for strictly professional outreach. Campaign marketing requires separate consent.
- Retention
- Twenty-four months after the last activity for an enquiry without follow-up; duration of the contract plus three years for a client.
- Recipients
- No external recipient.
Meetings
- Purpose
- Arrange and honour a business meeting.
- Legal basis
- Pre-contractual measure.
- Retention
- Twenty-four months after the meeting, then anonymisation.
- Recipients
- The calendar service used to create the event, from the opening of the service: your name, address and the subject of the meeting are then sent to it.
Quotes and acceptances
- Purpose
- Issue a quote and prove its acceptance.
- Legal basis
- Pre-contractual measure, then accounting obligation once the quote is accepted.
- Retention
- Ten years for an accepted quote, a contractual record. Twenty-four months for a quote left unanswered. The signatory's name and the fingerprint of their IP address belong to the evidential archive: they are kept five years, then removed — they do not follow the accounting period of the document carrying them.
- Recipients
- No external recipient.
Automation template downloads
- Purpose
- Verify your address and deliver the file you asked for.
- Legal basis
- Consent. The marketing opt-in is a separate box, unticked by default, and refusing it never blocks the download.
- Retention
- Twenty-four hours for verification, seven days for the download right, then twenty-four months after the last delivery, like the related business enquiry.
- Recipients
- No external recipient.
Company accounts
- Purpose
- Manage seats, track assignments and produce progress reports for a funding body.
- Legal basis
- Performance of the contract.
- Retention
- Duration of the contract, then five years of archive: a funded training file can be audited years after it closes. Ten years for the records alone that justify the funding. An invitation left unanswered or closed is erased ninety days after it closes.
- Recipients
- The appointed managers of your organisation, for progress only — never for the content of your conversations.
Newsletter
- Purpose
- Send you the watch digest you subscribed to.
- Legal basis
- Consent, confirmed by a second email.
- Retention
- Until you unsubscribe, possible from every issue.
- Recipients
- The sending service selected, from the opening of the service.
Product audience measurement
- Purpose
- Understand which pages are useful and where journeys fail, using a random identifier not linked to your identity.
- Legal basis
- Legitimate interest. The exact legal qualification of this measurement is being validated; in the meantime nothing is measured without your agreement, and your browser's “do not track” signal is respected.
- Retention
- Thirteen months, enforced by the database itself rather than by a scheduled job that an incident could interrupt without a sound.
- Recipients
- None: measurement is performed by our own servers, with no third-party tool.
Security and administration log
- Purpose
- Trace sign-ins, account lockouts and administration actions.
- Legal basis
- Legitimate interest, service security.
- Retention
- Twelve months for the security and administration log. The IP address fingerprint of an administration login follows the same period, without exception.
- Recipients
- No external recipient.
Processors
No external provider is contracted at the time of writing: the platform runs on local infrastructure while it is being built. The categories below describe what will be put in place, and each will be replaced by a name, a country and a contract reference before the service opens.
- Collecting subscriptions and top-ups: [TO BE COMPLETED]. It processes payment data; we keep only an opaque reference.
- Synchronising meetings with a professional calendar: [TO BE COMPLETED]. It receives the name, email address and subject of the meeting.
- Providing the artificial intelligence models: [TO BE COMPLETED]. The settings preventing reuse of content for training will be stated here.
- Delivering transactional emails and the newsletter: [TO BE COMPLETED].
- Hosting the application, the database and the files: [TO BE COMPLETED], with the corresponding processing region.
Your rights
They are exercised by a simple request to hello@venalabs.com, free of charge, with an answer within one month. Proof of identity is requested only in case of serious doubt about the requester's identity, and is never kept.
- Access: obtain confirmation that data about you is processed, and receive a copy of it.
- Rectification: correct inaccurate or incomplete data, most of the time directly from your settings.
- Erasure: delete your account and the associated data, subject to what the law requires us to keep.
- Portability: receive, in a machine-readable format, the data you provided and the data produced by your use of the service.
- Objection: refuse processing based on legitimate interest, in particular business outreach and audience measurement.
- Restriction: ask for a processing to be frozen while a dispute is examined.
- Complaint: refer the matter to the French data protection authority if an answer does not satisfy you.
Working draft of 4 August 2026 · token, withdrawal and account deletion clauses reviewed by a lawyer · company details pending