Last updated: 6 June 2026 · Version 1.5
In brief: Nael processes accounting ledger data imported by your Consultant solely to produce your financial indicators and compare them to industry benchmarks for your NAF code. Your data is hosted in France, isolated per client, never sold. Deletion on request.
Nael SASU β 103 883 377 R.C.S. Paris
Registered office: 122 rue Amelot, 75011 Paris, France
Contact: hello@nael.so
As Nael is not legally required to appoint a DPO (fewer than 250 employees, no large-scale processing of sensitive data within the meaning of Article 9 GDPR), equivalent responsibilities are handled directly by Geoffrey Gotfryd, President of Nael SASU.
DPO contact: hello@nael.so β Geoffrey responds personally within 24 business hours (the formal GDPR response deadline remains one month maximum).
Accounting ledger data β the Fichier des Γcritures Comptables (FEC) or an equivalent general ledger export (CSV) imported by the appointed Consultant β is processed solely to extract the financial indicators needed to:
data.benchmarks_sectoriels table, associated with the NAF code provided at registration.Legal basis: contract performance (Article 6(1)(b) GDPR). Accounting ledger data is never used for other purposes (advertising, resale, third-party model training) without separate explicit consent.
During the waiting period for ledger data processing (between import by the Consultant and dashboard availability), the application may call the GET /api/benchmarks/:naf_code route to temporarily display the sector average margins corresponding to the User's NAF code.
This call transmits no personal accounting data: only the NAF code is used. Returned values come exclusively from the aggregated data.benchmarks_sectoriels table. No identifying User data is retained beyond what is strictly necessary for the Service to function.
Fundamental principle: Nael never receives raw documents directly from the Client. Accounting ledger data, exported and imported by the appointed Consultant, is processed exclusively to produce indicators, the score, and the diagnostic report.
Accounting ledger data enables generation, at the User's exclusive request, of an exportable diagnostic report in PDF format (4 pages). This document includes the Nael Score, a summary of sector variances, historical trajectory, and a simplified income statement.
The report is generated only upon explicit action by the User. Data it contains remains strictly confidential and is not transmitted to any third party without prior consent.
Nael uses the following subprocessors to provide the Service:
| Subprocessor | Role | Location | Legal basis |
|---|---|---|---|
| OVH SAS | API hosting, PostgreSQL database | Strasbourg, France | Art. 6(1)(b) GDPR |
| Vercel Inc. | nael.so frontend hosting | USA (Paris CDG1 edge) | SCC + DPF |
| Mistral AI SAS | AI analysis β inferences (indicator calculation, alerts, monthly summary) | Paris, France (EU) | Art. 6(1)(b) GDPR |
| Conversational memory | Local PostgreSQL, OVH France VPS β self-hosted storage; no third-party subprocessor (Letta or otherwise); no memory data leaves the VPS | Strasbourg, France | Art. 6(1)(b) GDPR |
| Brevo SAS | Transactional email | France (EU) | Art. 6(1)(b) GDPR |
| Cloudflare Inc. | DNS, DDoS protection | USA (transit) | SCC + DPF |
| Stripe Inc. | Card payment β activated only if a paid subscription is taken out; no Stripe data is exchanged during the free trial | USA | SCC + DPF |
| Namecheap Inc. | Domain name registration | USA | SCC + DPF |
Subprocessors located in the United States (Vercel, Cloudflare, Stripe, Namecheap) are governed by:
The Client does not upload any documents to Nael themselves. Accounting ledger data imported by the appointed Consultant is processed. Mistral AI receives only the minimised accounting data necessary for analysis; Stripe receives data only if an active paid subscription is in place.
Conversations with the Nael advisor are stored exclusively in the PostgreSQL database hosted on the OVH VPS (France). Nael does not use Letta or any other third-party service to store client exchange history.
AI financial analyses are processed by Mistral AI SAS (Paris, France). Only the content of your message and the financial indicators necessary to the response are transmitted. Mistral does not store API call data for model training (see Mistral Privacy Policy). Legal basis: contract performance (Art. 6(1)(b) GDPR). Mistral DPA available on request at hello@nael.so.
When data is processed by our AI provider, Nael never transmits a full bank identifier (truncated IBAN), account number, or third-party name where this can be avoided. Only data strictly necessary for extraction and analysis is transmitted.
The guarantees below are identical to those displayed on the free diagnostic page:
With your consent, Nael may use your financial data in strictly anonymised and aggregated form for the following purposes:
Technical guarantees: Anonymisation is irreversible β no identifying data (name, SIRET, email, address) is included in aggregated datasets. Published results (benchmarks) are calculated from a minimum of 5 distinct establishments, in accordance with CNIL recommendations on statistical anonymisation (Deliberation No. 2014-298). This anonymised data does not constitute personal data within the meaning of Article 4(1) of Regulation (EU) 2016/679.
Legal basis: consent (Article 6(1)(a) GDPR), freely revocable at any time from account settings or by email to hello@nael.so.
→ Read the full information page on anonymised data
Under Articles 15 to 22 of the GDPR, you have the following rights:
To exercise these rights, contact us at hello@nael.so. A response is guaranteed within 30 days (extendable by 2 months in complex cases).
The nael.so website and Nael application use no advertising cookies or third-party trackers. No marketing analytics tools (Google Analytics, Meta Pixel, etc.) are installed.
Only cookies and local storage strictly necessary for the Service to function are used. Authentication relies on an HttpOnly cookie (nael_auth) set by the server: the session token is never accessible to JavaScript or stored in localStorage. The browser retains only non-sensitive metadata (first name, plan, display preferences). These items are exempt from prior consent (Article 82 of the French Data Protection Act).
If you believe, after contacting us, that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des LibertΓ©s (CNIL):
Invite your accountant or share your figures β bank statements, till records, invoices. Score out of 100, quantified variances, action plan. One diagnostic on us, no credit card required.