Effective date: March 1, 2024
1. Introduction
VW-CODING ("we", "our", "us"), SASU with a capital of 4000€, registered with the RCS of Paris under number 914 650 387, headquartered at 121 quai de Valmy, 75010 Paris, VAT number FR41914650387, considers the protection of your personal data a top priority in operating the magif.ai platform. This privacy policy details our practices regarding the collection, use, and protection of your information in compliance with the General Data Protection Regulation (GDPR).
2. Data Collection
2.1. We collect the following data:
- Account data: name, email, password (hashed), profile information - Usage data: agent interactions, message history, platform usage statistics - Technical data: IP addresses, cookies, session identifiers, browser information (see our Cookie Policy at https://www.magif.ai/cookies for the specific cookies we use, their purpose, duration, and how to manage your choice) - Payment data: transaction history, subscription information - Agent configuration data: settings, customizations, instructions, and uploaded knowledge - Communication data: support tickets, feedback, correspondence - Integration data: connected platform identifiers (Telegram, etc.)
2.2. Data sources: - Directly from you during registration and platform use - Through your interactions with AI agents - Via integrated third-party services - Through automated technical collection
3. Processing Purposes
3.1. Contract execution (GDPR Art. 6.1.b): - Platform access and feature provision - AI agent operation and customization - Subscription management - Technical support - Service improvement
3.2. Legitimate interests (GDPR Art. 6.1.f): - Platform security and fraud prevention - Service optimization - Usage analytics - Feature development - Technical maintenance
3.3. Conversation Access and Sharing: - Each agent runs in one of two privacy modes, set by its creator. In standard mode, the creator who operates an agent can review the conversations held with that agent to supervise quality and follow up with their clients, and Magif.ai personnel may access conversation content only for support, security, or incident handling, on a need-to-know basis - In fully private mode, conversation content is not readable through the Platform by anyone, including the creator and Magif.ai personnel; dashboards show aggregate counts only. The privacy level a client starts a conversation under is never lowered for that client afterwards - Magif.ai does not use customer or end-user conversation content to train AI models - We will not share your private conversations with unaffiliated third parties except as described in this Privacy Policy. Full details of who can access each category of data, and the retention that applies, are published in the Magif Trust Center (see the Privacy & Data Handling page at /trust/privacy)
4. Legal Basis
Our processing is based on: - Contract execution for service provision - Legitimate interests for platform operation - Your consent for specific features - Legal obligations compliance
5. Data Retention
5.1. Retention periods: - Account data: Duration of account + 5 years - Message history: 24 months - Technical logs: 13 months - Payment records: 10 years (legal requirement) - Agent configurations: Account duration
5.2. After retention period: - Secure deletion - Irreversible anonymization - Archived if legally required
6. Data Security
6.1. Technical measures: - Encryption in transit and at rest where supported by our infrastructure - Secure cloud infrastructure - Regular security audits - Intrusion detection - Regular backups - Access control
6.2. Organizational measures: - Access limited to authorized personnel - Regular security training - Documented security procedures - Incident response plan - Data protection impact assessments
7. Data Processors and Transfers
7.1. Main processors: - Cloud providers (EU region) - AI model hosting providers (EU region, open-source models) - Payment processors - Communication platforms - Analytics services
7.2. International transfers: - Limited to necessary cases - Protected by Standard Contractual Clauses - Regular compliance assessment - Appropriate safeguards
8. Your Rights
8.1. GDPR rights: - Access - Rectification - Erasure - Processing limitation - Data portability - Objection - Consent withdrawal - Post-mortem directives
8.2. Exercise your rights: - Email: [email protected] - Mail: DPO, VW-CODING, 121 quai de Valmy, 75010 Paris - Response within 1 month - ID verification required
9. AI and Automated Processing
9.1. AI processing: - Automated message processing - Agent configuration and knowledge retrieval - Performance optimization - Content generation
9.2. Safeguards: - Human oversight - Regular accuracy checks - Bias prevention measures - Clear processing documentation
10. Platform-Specific Protections
10.1. Agent data: - Isolated processing environments - Secure message handling - Regular data cleanup - Access controls
10.2. User control: - Agent configuration options - Data export capability - Deletion requests - Usage transparency
11. Updates to This Policy
11.1. We may update this policy: - For legal compliance - To reflect service changes - To enhance protection - To add new features
11.2. Notification: - Email for significant changes - Website announcements - 30 days notice - Version history maintained
12. Contact Information
12.1. General contact: VW-CODING 121 quai de Valmy 75010 Paris [email protected]
12.2. Data Protection Officer: Vincent Wargnier DPO, VW-CODING 121 quai de Valmy 75010 Paris [email protected]
12.3. Supervisory Authority: Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy TSA 80715 75334 PARIS CEDEX 07 www.cnil.fr
Last updated: March 1, 2024