Skip to content

Privacy policy

Last updated: [date TO BE CONFIRMED]

Draft document — to be reviewed by a lawyer.

This policy explains which personal data WYRLO processes, why, for how long, and what your rights are. It covers the public website and the WYRLO service.

Who is responsible

For account and website data, the controller is [company name TO BE CONFIRMED], [address TO BE CONFIRMED], reachable at [email address TO BE CONFIRMED].

For traces sent by the WYRLO library, your organisation remains the controller. WYRLO acts as a processor within the meaning of article 28 of the GDPR, under the data processing agreement.

Data protection officer

[Appointment and contact details of the data protection officer: TO BE CONFIRMED]

Data we process

  • Account data: name, work email address, organisation, role, sign-in information.
  • Traces: the question asked, excerpts of the passages retrieved by your RAG, the answer produced, the confidence level and the decision. Traces are masked before storage [masked data and method TO BE CONFIRMED].
  • Activity log: sensitive actions performed in your organisation, with who did them and when.
  • Billing data: [TO BE CONFIRMED, depending on the payment provider chosen].
  • Technical logs needed to run and secure the service: [content TO BE CONFIRMED].

Your documents are never stored: WYRLO only receives the excerpts sent with each question.

Purposes

  • Providing the service: checking answers against their sources, computing the confidence level, and deciding whether to answer or say “I don’t know”.
  • Adjusting your organisation’s settings every night from its own traces, and producing the weekly report.
  • Managing your account, your organisation and, where relevant, your subscription.
  • Keeping the service secure and preventing abuse.
  • Responding to your requests.

[No other use of traces, in particular for training models: TO BE CONFIRMED]

Legal bases

  • Performance of the contract: providing the service, managing the account and the subscription.
  • Legitimate interest: service security, abuse prevention, activity log.
  • Legal obligation: keeping accounting records.
  • [Processing based on consent, if any: TO BE CONFIRMED]

Retention periods

  • Traces: 30 days by default, then deleted. Your organisation can choose 30, 90 or 180 days.
  • Account data: for as long as the account exists, then [period TO BE CONFIRMED] after it is closed.
  • Activity log: [period TO BE CONFIRMED].
  • Accounting records: [legal period TO BE CONFIRMED].
  • Technical logs: [period TO BE CONFIRMED].

Recipients

Data is only accessible to authorised people at WYRLO and in your organisation. It is hosted in the European Union by our technical processors:

  • Supabase: database and functions, eu-west-3 region (Paris).
  • Vercel: web application hosting, functions in the cdg1 region (Paris).

[Other processors, if any (payments, email delivery, language models), and transfers outside the European Union: TO BE CONFIRMED]

Your rights

The GDPR gives you the following rights over your data:

  • access;
  • rectification;
  • erasure;
  • restriction of processing;
  • objection;
  • portability;
  • instructions on what happens to your data after your death.

To exercise these rights, write to [email address TO BE CONFIRMED]. We reply within one month.

For data contained in traces, contact the organisation that uses WYRLO first: it is the controller, and we help it respond to you.

If you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr) or with your local data protection authority.

Cookies and browser storage

The website uses no analytics, advertising or tracking cookies, and no tracking tools.

Only your theme choice (light, dark or system) is kept in your browser, in localStorage. It is never sent to our servers.

[Strictly necessary cookies, such as sign-in session or language: list TO BE CONFIRMED]

Security

The technical and organisational measures that protect your data are described on the Security page.

Changes

This policy may change. The last updated date is shown at the top of the page. If we make a significant change, we notify account holders [method TO BE CONFIRMED].