Privacy Policy

GDPR-compliant — In force as of 15/06/2026

FrançaisEnglishEspañolDeutsch
← Back to site
🔒 Our commitment: Ecopilot protects your personal data in accordance with the GDPR and the amended French Data Protection Act.

1. Data controller

For any request about your data, email contact@ecopilot-ai.com (subject "GDPR").

2. Data collected

2.1 Account data

DataPurposeLegal basis
First and last nameCustomer identificationPerformance of contract
Email addressLogin, communication, billingPerformance of contract
Password (encrypted)Securing accessPerformance of contract
Company, sectorService personalisationPerformance of contract
Phone, address (optional)Billing, contactConsent

2.2 Usage data

DataPurposeLegal basis
Assessment answersProvide the assessmentPerformance of contract
Action plans, indicatorsTracking and improvementPerformance of contract
Assessment historyComparison over timePerformance of contract
Logs, IP addressSecurity, fraud preventionLegitimate interest

2.3 Payment data

Bank details are processed exclusively by Stripe Payments Europe Ltd. (PCI-DSS level 1). They never pass through our servers.

3. Purposes of processing

4. Legal bases

5. Data recipients

RecipientPurposeLocation
Stripe Payments Europe Ltd.PaymentsIreland (EU)
SupabaseDatabase hostingEU (Paris region)
Vercel Inc.Website hostingUnited States*
Anthropic PBCAI (action plans) — pseudonymised dataUnited States*
Brevo (if newsletter)Transactional and marketing emailsFrance (EU)

* Transfers outside the EU are governed by Standard Contractual Clauses (Art. 45 and 46 of the GDPR).

🛡️ We never sell your data. No data is shared for advertising purposes.

6. Retention period

Type of dataPeriod
Account (active)Duration of the subscription
Account (after cancellation)30 days then deletion
Billing10 years (accounting obligation)
Connection logs12 months maximum
Marketing (consent)3 years after last contact
Cookies13 months maximum

7. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the rights of access, rectification, erasure, restriction, portability, objection, rights regarding automated decisions, and the right to set post-mortem directives.

How to exercise them

Response within 1 month maximum. Proof of identity may be requested.

8. Data security

9. Cookies

Strictly necessary cookies (no consent required): session, security (CSRF), language preference. The site uses no third-party analytics cookies and no advertising cookies.

10. Transfers outside the EU

Some processors (Anthropic, Vercel) are located outside the EU (United States). These transfers are governed by Standard Contractual Clauses, confidentiality commitments and technical measures (encryption, pseudonymisation).

11. Complaint to the CNIL

12. Changes

This policy may be amended. Any substantial change is notified by email 30 days before it takes effect.

13. Contact