Privacy Policy - Entity Enricher

Privacy Policy

Last updated: March 6, 2026

1. Data Controller

The data controller for personal data processed through Entity Enricher ("Service") is TOT Concept SAS, a company registered in Nantes, France, founded in 2006, within the meaning of the EU General Data Protection Regulation (GDPR).

For any privacy-related inquiries, please contact us at:

2. Personal Data We Collect

We collect only the minimum personal data necessary to provide the Service:

  • Account information: email address, display name, and profile picture — provided by you or your authentication provider (Google, GitHub, or email registration)
  • Authentication data: Firebase user ID and email verification status, managed by Google Firebase Authentication
  • Organization membership: your role and status within your organization

We do not use analytics cookies, tracking pixels, browser fingerprinting, or any third-party analytics services. We do not collect IP addresses beyond what is transiently logged by our infrastructure for security purposes.

3. Entity Data (Non-Personal)

In addition to personal data, the Service processes entity data that you provide for enrichment (e.g., company names, product data, organizational information). This data is typically non-personal and is processed solely to deliver the enrichment results you request.

If you submit personal data about individuals as entity data for enrichment, you are responsible for ensuring you have a valid legal basis to do so under applicable data protection laws.

4. Legal Basis for Processing

We process your personal data on the following legal bases under the GDPR:

  • Contract performance (Art. 6(1)(b)): processing necessary to provide the Service, manage your account, and deliver enrichment results
  • Legitimate interest (Art. 6(1)(f)): security logging, fraud prevention, and service improvement

5. How We Use Your Data

Your personal data is used exclusively to:

  • Create and manage your account and organization membership
  • Authenticate you and secure access to the Service
  • Communicate with you about your account, service updates, and changes to these policies
  • Enforce our Terms of Service and protect against unauthorized or abusive usage

We do not use your personal data for marketing, profiling, automated decision-making, or any purpose unrelated to the Service.

6. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data to third parties.

Data is shared with the following categories of processors:

  • Google Firebase: authentication provider that processes your email, name, and authentication tokens. See Firebase Privacy Policy
  • LLM providers (OpenAI, Anthropic, Google, Mistral, and others): your entity data (not personal account data) is sent to these providers to perform enrichment. No personal information from your account is included in LLM requests

When using Bring Your Own Key (BYOK) mode, your LLM API calls are made directly with the provider under your own account and their respective privacy policies apply.

7. Data Storage & Security

All data is stored on servers located in Germany (EU), hosted by Hetzner Online GmbH, a GDPR-compliant European hosting provider. No personal data is transferred outside the European Economic Area (EEA) by us.

We implement the following security measures:

  • Encryption in transit (TLS/HTTPS) for all communications
  • Encryption at rest for sensitive data (API keys are encrypted using Fernet symmetric encryption)
  • Network isolation for database services (not exposed to the public internet)
  • Role-based access control for user permissions
  • JWT-based authentication with short-lived access tokens

8. Data Retention

Account data is retained for as long as your account is active. You may delete your data through the Service or request deletion by contacting us.

Enrichment records are retained until you choose to delete them. Upon account or organization deletion, enrichment records and schemas are detached from your organization.

Backups may contain your data for up to 90 days after deletion before being permanently removed through our automated backup rotation.

9. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): obtain a copy of your personal data
  • Right to rectification (Art. 16): correct inaccurate personal data
  • Right to erasure (Art. 17): request deletion of your personal data
  • Right to data portability (Art. 20): receive your data in a structured, machine-readable format
  • Right to restriction (Art. 18): restrict the processing of your personal data
  • Right to object (Art. 21): object to processing based on legitimate interest

To exercise any of these rights, contact us at . We will respond within 30 days as required by the GDPR.

10. Supervisory Authority

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL), the French data protection authority.

CNIL — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr

11. Cookies & Local Storage

The Service uses only strictly necessary browser storage for authentication and user preferences:

  • localStorage: authentication tokens (JWT), theme preference, and UI state — required for the Service to function
  • Firebase cookies: session cookies set by Firebase Authentication for login persistence

We do not use advertising cookies, analytics cookies, or any third-party tracking cookies. Because we only use strictly necessary cookies, no cookie consent banner is required under the ePrivacy Directive.

12. Children's Privacy

The Service is not intended for individuals under 16 years of age, in accordance with the GDPR. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16 without parental consent, we will take steps to delete that information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification at least 30 days before taking effect. The "Last updated" date at the top of this page indicates when the policy was last revised.

Continued use of the Service after the effective date of any changes constitutes your acknowledgment of the updated policy.

14. Contact Us

For any questions or concerns about this Privacy Policy or our data practices, please contact us at:

For general inquiries about the Service, see our Terms of Service.