Privacy Policy

πŸ‡«πŸ‡· Data hosted in France β€” OVH Strasbourg
Infrastructure outside US CLOUD Act scope Β· GDPR-native

Last updated: 6 June 2026 · Version 1.5

In brief: Nael processes accounting ledger data imported by your Consultant solely to produce your financial indicators and compare them to industry benchmarks for your NAF code. Your data is hosted in France, isolated per client, never sold. Deletion on request.

1. Data controller

2. Data Protection Officer (DPO)

As Nael is not legally required to appoint a DPO (fewer than 250 employees, no large-scale processing of sensitive data within the meaning of Article 9 GDPR), equivalent responsibilities are handled directly by Geoffrey Gotfryd, President of Nael SASU.

DPO contact: hello@nael.so β€” Geoffrey responds personally within 24 business hours (the formal GDPR response deadline remains one month maximum).

3. Data collected and purposes

3.1 At registration

3.2 Processing of accounting ledger data and purpose

Accounting ledger data β€” the Fichier des Γ‰critures Comptables (FEC) or an equivalent general ledger export (CSV) imported by the appointed Consultant β€” is processed solely to extract the financial indicators needed to:

Legal basis: contract performance (Article 6(1)(b) GDPR). Accounting ledger data is never used for other purposes (advertising, resale, third-party model training) without separate explicit consent.

3.3 Sector preview during processing

During the waiting period for ledger data processing (between import by the Consultant and dashboard availability), the application may call the GET /api/benchmarks/:naf_code route to temporarily display the sector average margins corresponding to the User's NAF code.

This call transmits no personal accounting data: only the NAF code is used. Returned values come exclusively from the aggregated data.benchmarks_sectoriels table. No identifying User data is retained beyond what is strictly necessary for the Service to function.

3.4 During use of the Service

Fundamental principle: Nael never receives raw documents directly from the Client. Accounting ledger data, exported and imported by the appointed Consultant, is processed exclusively to produce indicators, the score, and the diagnostic report.

3.5 PDF report generation and export

Accounting ledger data enables generation, at the User's exclusive request, of an exportable diagnostic report in PDF format (4 pages). This document includes the Nael Score, a summary of sector variances, historical trajectory, and a simplified income statement.

The report is generated only upon explicit action by the User. Data it contains remains strictly confidential and is not transmitted to any third party without prior consent.

4. Subprocessors and international transfers

Nael uses the following subprocessors to provide the Service:

SubprocessorRoleLocationLegal basis
OVH SASAPI hosting, PostgreSQL databaseStrasbourg, FranceArt. 6(1)(b) GDPR
Vercel Inc.nael.so frontend hostingUSA (Paris CDG1 edge)SCC + DPF
Mistral AI SASAI analysis β€” inferences (indicator calculation, alerts, monthly summary)Paris, France (EU)Art. 6(1)(b) GDPR
Conversational memoryLocal PostgreSQL, OVH France VPS β€” self-hosted storage; no third-party subprocessor (Letta or otherwise); no memory data leaves the VPSStrasbourg, FranceArt. 6(1)(b) GDPR
Brevo SASTransactional emailFrance (EU)Art. 6(1)(b) GDPR
Cloudflare Inc.DNS, DDoS protectionUSA (transit)SCC + DPF
Stripe Inc.Card payment β€” activated only if a paid subscription is taken out; no Stripe data is exchanged during the free trialUSASCC + DPF
Namecheap Inc.Domain name registrationUSASCC + DPF

4.1 Transfers outside the European Union β€” Art. 44 GDPR

Subprocessors located in the United States (Vercel, Cloudflare, Stripe, Namecheap) are governed by:

The Client does not upload any documents to Nael themselves. Accounting ledger data imported by the appointed Consultant is processed. Mistral AI receives only the minimised accounting data necessary for analysis; Stripe receives data only if an active paid subscription is in place.

4.2 Note on conversational memory

Conversations with the Nael advisor are stored exclusively in the PostgreSQL database hosted on the OVH VPS (France). Nael does not use Letta or any other third-party service to store client exchange history.

4.3 Note on Mistral AI

AI financial analyses are processed by Mistral AI SAS (Paris, France). Only the content of your message and the financial indicators necessary to the response are transmitted. Mistral does not store API call data for model training (see Mistral Privacy Policy). Legal basis: contract performance (Art. 6(1)(b) GDPR). Mistral DPA available on request at hello@nael.so.

4.4 Minimisation during AI processing

When data is processed by our AI provider, Nael never transmits a full bank identifier (truncated IBAN), account number, or third-party name where this can be avoided. Only data strictly necessary for extraction and analysis is transmitted.

5. Hosting and security

The guarantees below are identical to those displayed on the free diagnostic page:

6. Retention periods

6.3 Anonymised data and performance reference

With your consent, Nael may use your financial data in strictly anonymised and aggregated form for the following purposes:

Technical guarantees: Anonymisation is irreversible β€” no identifying data (name, SIRET, email, address) is included in aggregated datasets. Published results (benchmarks) are calculated from a minimum of 5 distinct establishments, in accordance with CNIL recommendations on statistical anonymisation (Deliberation No. 2014-298). This anonymised data does not constitute personal data within the meaning of Article 4(1) of Regulation (EU) 2016/679.

Legal basis: consent (Article 6(1)(a) GDPR), freely revocable at any time from account settings or by email to hello@nael.so.

→ Read the full information page on anonymised data

7. Your GDPR rights

Under Articles 15 to 22 of the GDPR, you have the following rights:

To exercise these rights, contact us at hello@nael.so. A response is guaranteed within 30 days (extendable by 2 months in complex cases).

8. Cookies and trackers

The nael.so website and Nael application use no advertising cookies or third-party trackers. No marketing analytics tools (Google Analytics, Meta Pixel, etc.) are installed.

Only cookies and local storage strictly necessary for the Service to function are used. Authentication relies on an HttpOnly cookie (nael_auth) set by the server: the session token is never accessible to JavaScript or stored in localStorage. The browser retains only non-sensitive metadata (first name, plan, display preferences). These items are exempt from prior consent (Article 82 of the French Data Protection Act).

9. Complaints to the supervisory authority

If you believe, after contacting us, that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des LibertΓ©s (CNIL):

Free diagnostic

Nael benchmarks on your real numbers.

Invite your accountant or share your figures β€” bank statements, till records, invoices. Score out of 100, quantified variances, action plan. One diagnostic on us, no credit card required.