Back to Home
Legal Documents

Privacy Policy

Last updated: April 2026

Proxia Studio, SASU with a share capital of €1,000, whose registered office is located at 47 rue Vivienne, 75002 Paris, France, is the Data Controller for the personal data collected via the proxia.studio platform. This Privacy Policy describes how we collect, process, and protect your personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and French Data Protection Act No. 78-17 of 6 January 1978, as amended.

1. Data Collected

1.1 Data Provided Directly by the User

  • Registration data: email address, password (hashed), first and last name, status (individual/professional)
  • Profile data: preferences, custom instructions, profile picture
  • Billing data: company name, address, intra-Community VAT number (professionals)
  • User Content: project files (XML, DRP, PRPROJ), video files, audio, documents
  • Conversations with AVA: prompts, questions, feedback, votes and contributions
  • Knowledge base files: documents uploaded to the personal knowledge base

1.2 Data Collected Automatically

  • Connection data: IP address, browser type, operating system, pages visited, timestamps
  • Performance data: Vercel Analytics and Speed Insights metrics (anonymized, cookie-free, anonymized IP)
  • Error data: technical logs via Sentry (anonymized, no PII, 10% sampling)
  • Usage data: credits consumed, features used, actions performed

2. Legal Bases and Purposes of Processing

  • Performance of the contract (Art. 6(1)(b) GDPR): creating and managing the account, providing the Service, project analysis, AVA conversations, subscription management, billing, storage
  • Consent (Art. 6(1)(a) GDPR): sending newsletters and marketing communications, placing non-essential cookies, using voluntary contributions to improve AI models (separate opt-in)
  • Legitimate interest (Art. 6(1)(f) GDPR): security of the Platform, abuse prevention, technical improvement of the Service, anonymized performance measurement
  • Legal obligation (Art. 6(1)(c) GDPR): retention of billing data, responding to requests from judicial authorities, LCEN compliance

2.1 Note on AI Processing

Data transmitted to the Google Gemini API (prompts, content, embeddings) is processed by Google as a Data Processor within the meaning of the GDPR, under a compliant Data Processing Agreement (DPA). In accordance with the Google Cloud API terms, data submitted via the API is not used by Google to train or improve its general artificial intelligence models.

3. Retention Period

  • Account data: duration of the active subscription + 1 month after termination, unless deleted earlier
  • User Content and files: retained for the defined period; deleted 1 month after subscription termination or account deletion
  • AVA conversations and user memory: retained for the lifetime of the account, deletable on request (see Article 5)
  • Billing data: 10 years (French accounting and tax obligations)
  • Connection logs: 1 year (LCEN)
  • Performance/error data: 90 days maximum
  • Security backups: a complete backup of the database, encrypted in transit, is performed daily for business continuity and disaster recovery purposes. These backups are retained for 7 days on our infrastructure servers, then for a further 30 days with our storage hosting provider (Cloudflare R2), before automatic and permanent deletion. Access to these backups is strictly limited to the technical team when restoration is necessary.

4. Communications and Emails

Proxia Studio sends you email communications in connection with your use of the Platform. These emails are grouped into categories, each with its own legal basis.

4.1 Legal Bases by Category

  • Security & Account, Billing: performance of the contract (Art. 6(1)(b) GDPR); these emails are inherent to the proper performance of the Service and cannot be disabled.
  • Service, Collaboration, Gamification: legitimate interest (Art. 6(1)(f) GDPR); these emails relate to active use of the Platform and can be disabled from your settings.
  • Product Updates, Marketing, Newsletter: consent (Art. 6(1)(a) GDPR); consent is collected at registration and may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.

4.2 Right to Withdraw

You may withdraw your consent or disable non-mandatory communications at any time from your account settings page or via the unsubscribe link included in each relevant email. This withdrawal does not affect the lawfulness of processing carried out before it.

4.3 Retention

Email preferences are retained for the entire duration of your account, then deleted along with it.

Manage your email preferences →

5. Data Processors and Transfers of Data Outside the EU

We rely on the following Data Processors. Each Data Processor has specific contractual safeguards in place (a DPA, Standard Contractual Clauses (SCCs), and/or Data Privacy Framework (DPF) certification, where applicable). Details are available on request at privacy@proxia.studio.

Data ProcessorPurposeLocationSafeguard
Vercel Inc.Frontend hosting, analyticsUSA (Global Edge)DPF + SCC
Railway Corp.Backend hostingEU West (Ireland)No transfer outside the EU
Supabase Inc.Database, authEU West (Ireland)No transfer outside the EU
Cloudflare Inc.CDN, security, storage of user files (Proxia Cloud) and encrypted database backupsUSA (global) and EU for R2 cloud storageDPF + SCC
Google LLCGemini API (AI), embeddingsUSA (global)DPF + Google Cloud DPA
Resend Inc.Transactional emailsUSASCC
SentryMonitoring, error logsUSADPF + SCC
Stripe, Inc.Payment, billingUSADPF + SCC
Hetzner Online GmbHHosting of the infrastructure server (VPS)Finland (EU)No transfer outside the EU

Transfers outside the EU are governed, in accordance with Chapter V of the GDPR, by the EU-U.S. Data Privacy Framework (DPF), the Standard Contractual Clauses (SCCs) approved by the European Commission, and/or specific Data Processing Agreements (DPAs) depending on the Data Processor.

6. User Rights

In accordance with the GDPR, you have the following rights:

  • Right of Access: obtain confirmation that your data is being processed and receive a copy of it
  • Right of Rectification: correct inaccurate or incomplete data
  • Right to Erasure: request the deletion of your data under the conditions set out in the GDPR
  • Right to Restriction of Processing: temporarily restrict the processing of your data
  • Right to Portability: receive your data in a structured, commonly used, machine-readable format
  • Right to Object: object to processing based on legitimate interest
  • Right to Withdraw Consent: at any time, without affecting the lawfulness of prior processing

To exercise these rights, contact us at: privacy@proxia.studio. We commit to responding within 30 days.

6.1 User Memory

The Platform may store persistent memory related to the User's interactions with AVA (detected preferences, conversational context). The User may at any time review or request the deletion of their user memory by simply emailing privacy@proxia.studio. Requests are processed within a maximum of 30 days.

You also have the right to lodge a complaint with the CNIL (French Data Protection Authority): www.cnil.fr (opens in a new tab)

7. Data Security

Proxia Studio implements appropriate technical and organizational measures:

  • Encryption of data in transit (TLS/HTTPS)
  • Secure authentication (JWT RS256 via JWKS, HS256 fallback, encrypted tokens)
  • Password hashing (bcrypt via Supabase Auth)
  • Per-user data isolation (PostgreSQL Row Level Security)
  • Security monitoring and alerts (Sentry, 10% sampling, 401/403/404 filtering, no PII collected)
  • Strict access control on production environments

8. Minors

The Platform is intended for individuals aged 16 and over. Users aged 16 to 18 represent that they have obtained the authorization of their legal guardians. We do not knowingly collect personal data from individuals under 16.

9. Changes

Proxia Studio reserves the right to amend this policy. Material changes will be notified to Users by email or via the Platform.