Privacy Policy
In force as of 6 August 2026.
Data controller
VERIDISQUO STUDIO, a French société par actions simplifiée (SAS) with share capital of 1 000 €, 45 Boulevard Georges Estrangin, 13007 Marseille, France — Marseille Trade and Companies Register 108 141 656.
Contact: contact@veridisquo.studio
VeridisQuo Studio acts as data controller for service user data (accounts, sign-in, billing). It acts as a processor within the meaning of Article 28 GDPR for the data the customer uploads or enters into the platform, including its own directory of business contacts: that data is processed only on the customer's instructions and for the purposes described below.
Data collected
- Account data: name, business email address, company, role, and profile picture when signing in with a Google account.
- Access request data: name, email, company and free-text message entered in the contact form or the waiting list.
- Connection data and technical logs: IP address, timestamp and requested URL, collected by the hosting infrastructure; error traces and session metadata needed to secure the service.
- Billing data: billing details and subscription history. Card data is collected and stored by Stripe alone.
- Business data uploaded by the customer: catalogues, supplier price lists, tenders, product lists. These documents may contain names and contact details of business contacts.
- The customer's recipient directory: where the customer uses the price-list feature, the names, email addresses and phone numbers of its own customers, entered by it.
- Email delivery events: sending, delivery, failure, as well as opens and clicks of the emails the customer sends to its recipients, in order to report deliverability and to disable repeatedly failing addresses.
Purposes and legal bases
- Providing and operating the subscribed service — performance of the contract.
- Billing the subscription and meeting accounting obligations — performance of the contract and legal obligation.
- Securing the platform, preventing abuse and verifying applicants' professional status — legitimate interest.
- Providing support and answering requests — performance of the contract or legitimate interest.
- Measuring the deliverability of emails sent on the customer's behalf — performance of the contract, on the customer's instructions.
- Producing aggregated, anonymised internal statistics to improve the product — legitimate interest.
Ownership of the data
Data uploaded by the customer remains its full and exclusive property. No resale, no assignment and no commercial sharing with third parties. One customer's data is never made accessible to another customer.
Recipients and sub-processors
Data is disclosed only to the providers strictly necessary to operate the service, all bound by a data processing agreement:
| Provider | Establishment / location | Purpose |
|---|---|---|
| Google Cloud EMEA Limited (Google Cloud Platform) | Ireland — processing in the EU (europe-west1) and in the United States (BigQuery) | Application hosting, storage of uploaded files, price data warehouse, secret management, technical logs. |
| Google Ireland Limited (Google Workspace / OAuth) | Ireland | User sign-in with a Google account (name, email address, profile picture). |
| Supabase, Inc. | United States — data hosted on AWS, Tokyo region (Japan) | Application database: accounts and roles, workspaces, invitations, waiting lists, price-list recipient directory, sending history. |
| Resend, Inc. | United States | Sending transactional emails (invitations, sign-in links, notifications, price lists and their attachments) and tracking their deliverability. |
| Stripe Payments Europe, Limited | Ireland | Payment and subscription billing. No card data passes through or is stored on our servers. |
| OpenAI, L.L.C. | United States | AI-assisted analysis of tender documents uploaded by the customer, and processing of questions asked to the search assistant. |
| Anthropic PBC | United States | French-to-English translation of product and attribute labels in the reference data. No personal data is sent to it. |
| GitHub, Inc. (Microsoft) | United States | Source code hosting and deployment pipeline. No end-user service data is stored there. |
Automated ingestion of supplier price lists and the scheduling of recurring jobs are handled by services operated by the Publisher itself and hosted in the European Union.
Data may also be disclosed to administrative or judicial authorities where required by law.
Transfers outside the European Union
The application is hosted in the European Union (europe-west1 region, Belgium). Some components nonetheless rely on infrastructure located outside the European Union:
- United States — the BigQuery price data warehouse (
USregion), as well as the Resend, OpenAI and Anthropic services. These transfers are governed by the European Commission's Standard Contractual Clauses and, for providers that have certified to it, by the EU-U.S. Data Privacy Framework. - Japan — the Supabase application database (
ap-northeast-1region, Tokyo). Japan benefits from an adequacy decision of the European Commission dated 23 January 2019 and renewed in 2023; the relationship with the provider, established in the United States, is additionally governed by the Standard Contractual Clauses.
A copy of the applicable safeguards can be obtained on request at contact@veridisquo.studio.
Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted, logged and limited to authorised team members for the needs of the service. Application secrets are held in a managed vault, never in the code.
Retention periods
- Account data and business data: for the term of the contract, then deleted within a maximum of 30 days after termination.
- Accounting records and invoices: 10 years from the end of the financial year, in accordance with Article L.123-22 of the French Commercial Code.
- Technical and access logs: 30 days.
- Unsuccessful access requests: 12 months from the last exchange.
- Email delivery events: for the term of the contract.
Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict, object to and port your data. You may exercise these rights at any time by writing to contact@veridisquo.studio. You will receive a reply within one month at the latest.
If you are the recipient of a price list sent by a LiveCriée customer, address your request to that customer, who determines the purposes of that processing; we will forward it if you write to us directly.
Cookies
The service sets only cookies that are strictly necessary for it to work. As such they do not require your consent and no banner is displayed.
authjs.session-tokenand the cookies associated with the sign-in flow — authentication session and CSRF protection.lc_active_tenant— the user's active workspace (30 days).NEXT_LOCALE— the chosen display language.
No advertising cookies, no audience-measurement trackers and no third-party analytics tools are used. Fonts are served from our own servers. The service also uses browser local storage to remember your cart and display preferences; that information never leaves your device.
Complaints
If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr.
Last updated: 6 August 2026.