This English translation is provided for information. The French version is the only legally binding one.
Privacy policy — Soluax
Version in force from 2 October 2026. It is updated when the service's providers or settings change.
Who processes your data?
AXIIZ, a French single-shareholder simplified joint-stock company with a share capital of €100, registered with the Montpellier Trade and Companies Register under number 881 813 174, whose registered office is at 222 place Ernest Granier, 34000 Montpellier, France (EU VAT number FR50881813174) is the controller of the processing related to running Soluax. Contact for personal data: support@soluax.ai. No data protection officer is appointed, as this is not mandatory for this service; data requests are handled by Jérôme Ferrand, president of AXIIZ, at the address above.
For the reports your organization sends, we act on its instructions as a processor, or possibly as a sub-processor. The processing annex sets out the responsibilities. If you are concerned by a log sent by your employer or provider, address your request to that organization; we will assist it.
Data and purposes
| Processing | Data concerned | Publisher's legal basis |
|---|---|---|
| Account and access | Work email, identifier, organization, authentication data | Performance of the contract; legitimate interest for users employed by a client organization |
| Subscription and billing | Plan, dates, status, Stripe identifiers, billing details | Performance of the contract; legal obligation for accounting |
| Support | Contact details and content of your request | Contract or legitimate interest in responding |
| Security and abuse prevention | Strictly necessary request metadata and technical events | Legitimate interest in protecting the service |
| Relevant business prospecting | Company, role, business contact details, public source and history of exchanges | Legitimate interest, subject to your right to object |
| Native reception of reports by email | Raw message, sender, dedicated recipient, subject, headers, body and any attachments while in transit; reception metadata | Contractual instructions of the client acting as controller |
| Backup reports | Filtered text, status, date, monitor label/alias, summary and metadata | Contractual instructions of the client acting as controller |
The fields required for the account or for payment are indicated when they are collected. Without them, the service or subscription concerned cannot be provided. We do not store full card numbers or their security code: they are processed by the payment provider.
Logs, analysis and optional AI
Native reception uses an email address dedicated to each monitor and Mailgun configured in the EU region. The raw message and its metadata pass through Mailgun and then to the Soluax reception server before redaction. If you attach files, they may therefore pass through these providers even though Soluax does not analyze them. Put the useful report in the body of the message and avoid unnecessary attachments. Forwarding set up in your own mailbox is also subject to that provider's processing.
Soluax does not archive the full raw message or attachments in its application database. It keeps the filtered text, up to 20,000 characters, with the necessary results and metadata. Mailgun's technical retention of messages and events is separate and is described below. Filtering does not guarantee the removal of all identifiable information and happens after reception. Do not send passwords, tokens, private keys, sensitive data or business data whose presence the analysis does not require. Use aliases for your clients and machines. Text/CSV imports and the webhook remain available; an n8n instance used by your organization is an optional choice, with its own processing terms.
Statuses are determined by software rules. If the AI explanation is enabled, the user must tick an authorization and then request an explanation: the user chooses the provider among those offered (Mistral AI, OpenAI or Anthropic), and only the first 2,000 characters of the filtered text and its status are then sent to that provider, through the Publisher's business account. No other provider receives the report. The answer is labelled as AI-generated and must be checked. It is displayed in the browser; the V1 code does not save it in the Soluax history. This feature does not evaluate people and makes no decision producing a legal effect on them. Default models: Mistral Small (Mistral AI), GPT-6 Luna (OpenAI) and Claude Haiku 4.5 (Anthropic). Under their terms for business APIs, these providers do not use this data to train their models and keep it only for a limited period, in particular for abuse prevention. Only the providers actually configured are offered in the interface.
Recipients and location
Internal access is limited to the persons authorized to operate and support the service. Our providers access only the data needed for their function, under their contracts.
| Provider | Role | Location and safeguards |
|---|---|---|
| Supabase | Database and authentication | Project in Ireland, West EU region eu-west-1; provider's data processing agreement |
| Cloudflare | Running the application (Cloudflare Workers) and delivering the website | Global network: the code runs in the data center closest to the request, with no durable storage of application data, which is kept in the Supabase database; company established in the United States; provider's data processing agreement and standard contractual clauses for transfers |
| Stripe | Payments and subscriptions | Stripe Payments Europe, Limited (Ireland), controller for its own payment obligations; payments not yet enabled; policy: https://stripe.com/privacy |
| Mailgun / Sinch | Reception of reports by email before redaction and HTTP forwarding to the Soluax server; sending of alerts and service emails | Reception domain and routing configured in the EU region; some account and billing data is managed globally; provider's data processing agreement and standard contractual clauses for transfers |
| Mistral AI, if chosen by the user | Optional AI explanation of a report | Mistral AI (France); EU hosting by default as stated by the provider; provider's data processing agreement |
| OpenAI, if chosen by the user | Optional AI explanation of a report | OpenAI Ireland Ltd for European customers; processing possible in the United States; provider's data processing agreement and standard contractual clauses |
| Anthropic, if chosen by the user | Optional AI explanation of a report | Anthropic Ireland, Limited for European customers; processing possible in the United States; provider's data processing agreement and standard contractual clauses |
Slack and Microsoft Teams alerts. From the Starter plan, you can send alerts to a Slack or Teams space. These services are not Soluax providers: you choose the destination, you provide its address and you use it under your own contract with Slack or Microsoft, which determines in particular the location and retention of the messages received. Each alert contains only its title, the client name, the task name, its state and a link to your dashboard; report content is never sent. The destination address is encrypted and no longer displayed once saved. Soluax only accepts the official addresses of Slack and Microsoft. You can disable or delete a channel at any time.
Outgoing notification emails must contain no backup log or infrastructure details: they invite you to check the authenticated account. This does not apply to incoming emails, which contain precisely the reports to analyze. The Soluax database is in Ireland (EU); choosing Mailgun EU concerns the regional processing of messages and is not a promise that all data, metadata, support or operations in the provider chain stay exclusively in the EU. A copy of the relevant transfer safeguards can be requested from our data contact, subject to confidential information.
How long?
- Reports, filtered texts and deterministic results: a rolling 90-day history window from the report date. Older items are hidden and then deleted during the daily retention pass run by the scheduled task, normally within 24 hours of their expiry. This purge must be supervised by the Publisher.
- Messages received on a client address without a single match (“Messages to assign”): filtered text, redacted subject and sender, deleted 30 days after their reception, or 30 days after their manual assignment to a task.
- Aggregated monthly calendar (statuses per expected run, without report text) and monthly PDF reports: 13 months by default, a period the Client can set from 1 to 36 months.
- Tickets: kept while they are open or acknowledged; a resolved ticket, with its notes and history, is deleted 36 months after its resolution.
- Alert delivery log (channel, date, title, client, task, delivery result): 90 days after the alert was created. An alert still waiting to be sent is not deleted before it has succeeded or failed for good.
- Raw incoming messages, delivery queues and events at Mailgun: kept by Mailgun for the period provided by the plan subscribed; the Publisher enables no storage option for received messages. The 90-day period of Soluax reports does not describe that of these technical copies. The Publisher favors direct forwarding, without enabling additional archiving of raw messages.
- Account and settings: for the duration of the contractual relationship; deleting the account triggers the deletion of the associated application data, except for legally justified and separate retention.
- Technical backups: expiry according to the backup cycle of the Supabase plan subscribed, provided on request; a restore reapplies the deletions made since the backup.
- Invoices and accounting records: ten years from the end of the financial year concerned, where this obligation applies.
- Support requests: twelve months after they are closed, except in a dispute.
- Technical security logs: for the period provided by the Cloudflare and Supabase plans subscribed; they never contain report bodies.
- Prospecting: at most three years after collection or your last active contact, stopping immediately if you object. Unanswered follow-ups do not extend this period.
- Proof of objection: only the information needed to prevent a new contact is kept, for three years from the objection.
In the event of a dispute or a legal obligation, some data may be placed in restricted-access intermediate archiving. Deleting application data does not delete invoices that must be kept.
Your rights
Under the conditions set by the GDPR, you can request access to, rectification, erasure, restriction and portability of your data, and object to certain processing. For prospecting, you can object at any time, without giving a reason and free of charge: reply “stop” to a message or write to support@soluax.ai. Where processing is based on your consent, you can withdraw it as easily as you gave it.
The interface lets you export your account data as JSON. Deletion from the interface is available after cancellation and the end of the active subscription, so as not to leave an active payment without an associated account. For an earlier erasure request or any other right, write to the contact above: GDPR rights are examined regardless of this limit of the automatic flow. Proportionate proof of identity may be requested in case of reasonable doubt; do not send a copy of an identity document unprompted. We normally reply within one month, subject to the extensions provided by the GDPR, of which you will be informed. You can lodge a complaint with the CNIL, the French data protection authority: https://www.cnil.fr/fr/plaintes.
Cookies
In the launch configuration, no audience analytics tool or advertising tracker is enabled. The following cookies are necessary for authentication and are not used for advertising tracking:
| Soluax cookie | Environment | Purpose | Maximum duration set when issued |
|---|---|---|---|
solaux_session | Local demonstration | Session of a local test account | 7 days |
solaux_access | Supabase production | Access token of the authenticated session | 1 hour |
solaux_refresh | Supabase production | Session renewal | 30 days, reissued on renewal |
These cookies are HttpOnly, SameSite=Lax and Secure when the site is served over HTTPS. They are deleted on sign-out. Locally, the password is hashed with scrypt and a salt; in production, authentication is handled by Supabase. Local mode is reserved for trials and is not where clients are hosted.
The payment provider may set its own cookies on its separate flow; the applicable information is presented there. If an optional tool is added to Soluax, this policy and the consent collection will be adapted before it is enabled.
Changes
Substantial changes are announced in the service or by a service message. The applicable version and its date remain available from the website. Contact: support@soluax.ai.