Privacy Policy
Last updated: April 2026
Proxia Studio, SASU with a share capital of €1,000, whose registered office is located at 47 rue Vivienne, 75002 Paris, France, is the Data Controller for the personal data collected via the proxia.studio platform. This Privacy Policy describes how we collect, process, and protect your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and French Data Protection Act No. 78-17 of 6 January 1978, as amended.
1. Data Collected
1.1 Data Provided Directly by the User
- •Registration data: email address, password (hashed), first and last name, status (individual/professional)
- •Profile data: preferences, custom instructions, profile picture
- •Billing data: company name, address, intra-Community VAT number (professionals)
- •User Content: project files (XML, DRP, PRPROJ), video files, audio, documents
- •Conversations with AVA: prompts, questions, feedback, votes and contributions
- •Knowledge base files: documents uploaded to the personal knowledge base
1.2 Data Collected Automatically
- •Connection data: IP address, browser type, operating system, pages visited, timestamps
- •Performance data: Vercel Analytics and Speed Insights metrics (anonymized, cookie-free, anonymized IP)
- •Error data: technical logs via Sentry (anonymized, no PII, 10% sampling)
- •Usage data: credits consumed, features used, actions performed
2. Legal Bases and Purposes of Processing
- •Performance of the contract (Art. 6(1)(b) GDPR): creating and managing the account, providing the Service, project analysis, AVA conversations, subscription management, billing, storage
- •Consent (Art. 6(1)(a) GDPR): sending newsletters and marketing communications, placing non-essential cookies, using voluntary contributions to improve AI models (separate opt-in)
- •Legitimate interest (Art. 6(1)(f) GDPR): security of the Platform, abuse prevention, technical improvement of the Service, anonymized performance measurement
- •Legal obligation (Art. 6(1)(c) GDPR): retention of billing data, responding to requests from judicial authorities, LCEN compliance
2.1 Note on AI Processing
Data transmitted to the Google Gemini API (prompts, content, embeddings) is processed by Google as a Data Processor within the meaning of the GDPR, under a compliant Data Processing Agreement (DPA). In accordance with the Google Cloud API terms, data submitted via the API is not used by Google to train or improve its general artificial intelligence models.
3. Retention Period
- •Account data: duration of the active subscription + 1 month after termination, unless deleted earlier
- •User Content and files: retained for the defined period; deleted 1 month after subscription termination or account deletion
- •AVA conversations and user memory: retained for the lifetime of the account, deletable on request (see Article 5)
- •Billing data: 10 years (French accounting and tax obligations)
- •Connection logs: 1 year (LCEN)
- •Performance/error data: 90 days maximum
- •Security backups: a complete backup of the database, encrypted in transit, is performed daily for business continuity and disaster recovery purposes. These backups are retained for 7 days on our infrastructure servers, then for a further 30 days with our storage hosting provider (Cloudflare R2), before automatic and permanent deletion. Access to these backups is strictly limited to the technical team when restoration is necessary.
4. Communications and Emails
Proxia Studio sends you email communications in connection with your use of the Platform. These emails are grouped into categories, each with its own legal basis.
4.1 Legal Bases by Category
- •Security & Account, Billing: performance of the contract (Art. 6(1)(b) GDPR); these emails are inherent to the proper performance of the Service and cannot be disabled.
- •Service, Collaboration, Gamification: legitimate interest (Art. 6(1)(f) GDPR); these emails relate to active use of the Platform and can be disabled from your settings.
- •Product Updates, Marketing, Newsletter: consent (Art. 6(1)(a) GDPR); consent is collected at registration and may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.
4.2 Right to Withdraw
You may withdraw your consent or disable non-mandatory communications at any time from your account settings page or via the unsubscribe link included in each relevant email. This withdrawal does not affect the lawfulness of processing carried out before it.
4.3 Retention
Email preferences are retained for the entire duration of your account, then deleted along with it.
5. Data Processors and Transfers of Data Outside the EU
We rely on the following Data Processors. Each Data Processor has specific contractual safeguards in place (a DPA, Standard Contractual Clauses (SCCs), and/or Data Privacy Framework (DPF) certification, where applicable). Details are available on request at privacy@proxia.studio.
| Data Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Vercel Inc. | Frontend hosting, analytics | USA (Global Edge) | DPF + SCC |
| Railway Corp. | Backend hosting | EU West (Ireland) | No transfer outside the EU |
| Supabase Inc. | Database, auth | EU West (Ireland) | No transfer outside the EU |
| Cloudflare Inc. | CDN, security, storage of user files (Proxia Cloud) and encrypted database backups | USA (global) and EU for R2 cloud storage | DPF + SCC |
| Google LLC | Gemini API (AI), embeddings | USA (global) | DPF + Google Cloud DPA |
| Resend Inc. | Transactional emails | USA | SCC |
| Sentry | Monitoring, error logs | USA | DPF + SCC |
| Stripe, Inc. | Payment, billing | USA | DPF + SCC |
| Hetzner Online GmbH | Hosting of the infrastructure server (VPS) | Finland (EU) | No transfer outside the EU |
Transfers outside the EU are governed, in accordance with Chapter V of the GDPR, by the EU-U.S. Data Privacy Framework (DPF), the Standard Contractual Clauses (SCCs) approved by the European Commission, and/or specific Data Processing Agreements (DPAs) depending on the Data Processor.
6. User Rights
In accordance with the GDPR, you have the following rights:
- •Right of Access: obtain confirmation that your data is being processed and receive a copy of it
- •Right of Rectification: correct inaccurate or incomplete data
- •Right to Erasure: request the deletion of your data under the conditions set out in the GDPR
- •Right to Restriction of Processing: temporarily restrict the processing of your data
- •Right to Portability: receive your data in a structured, commonly used, machine-readable format
- •Right to Object: object to processing based on legitimate interest
- •Right to Withdraw Consent: at any time, without affecting the lawfulness of prior processing
To exercise these rights, contact us at: privacy@proxia.studio. We commit to responding within 30 days.
6.1 User Memory
The Platform may store persistent memory related to the User's interactions with AVA (detected preferences, conversational context). The User may at any time review or request the deletion of their user memory by simply emailing privacy@proxia.studio. Requests are processed within a maximum of 30 days.
You also have the right to lodge a complaint with the CNIL (French Data Protection Authority): www.cnil.fr (opens in a new tab)
7. Data Security
Proxia Studio implements appropriate technical and organizational measures:
- •Encryption of data in transit (TLS/HTTPS)
- •Secure authentication (JWT RS256 via JWKS, HS256 fallback, encrypted tokens)
- •Password hashing (bcrypt via Supabase Auth)
- •Per-user data isolation (PostgreSQL Row Level Security)
- •Security monitoring and alerts (Sentry, 10% sampling, 401/403/404 filtering, no PII collected)
- •Strict access control on production environments
8. Minors
The Platform is intended for individuals aged 16 and over. Users aged 16 to 18 represent that they have obtained the authorization of their legal guardians. We do not knowingly collect personal data from individuals under 16.
9. Changes
Proxia Studio reserves the right to amend this policy. Material changes will be notified to Users by email or via the Platform.