Privacy policy
Draft document — to be reviewed by a lawyer.
This policy explains which personal data WYRLO processes, why, for how long, and what your rights are. It covers the public website and the WYRLO service.
Who is responsible
For account and website data, the controller is [company name TO BE CONFIRMED], [address TO BE CONFIRMED], reachable at [email address TO BE CONFIRMED].
For traces sent by the WYRLO library, your organisation remains the controller. WYRLO acts as a processor within the meaning of article 28 of the GDPR, under the data processing agreement.
Data protection officer
[Appointment and contact details of the data protection officer: TO BE CONFIRMED]
Data we process
- Account data: name, work email address, organisation, role, sign-in information.
- Traces: the question asked, excerpts of the passages retrieved by your RAG, the answer produced, the confidence level and the decision. Traces are masked before storage [masked data and method TO BE CONFIRMED].
- Activity log: sensitive actions performed in your organisation, with who did them and when.
- Billing data: [TO BE CONFIRMED, depending on the payment provider chosen].
- Technical logs needed to run and secure the service: [content TO BE CONFIRMED].
Your documents are never stored: WYRLO only receives the excerpts sent with each question.
Purposes
- Providing the service: checking answers against their sources, computing the confidence level, and deciding whether to answer or say “I don’t know”.
- Adjusting your organisation’s settings every night from its own traces, and producing the weekly report.
- Managing your account, your organisation and, where relevant, your subscription.
- Keeping the service secure and preventing abuse.
- Responding to your requests.
[No other use of traces, in particular for training models: TO BE CONFIRMED]
Legal bases
- Performance of the contract: providing the service, managing the account and the subscription.
- Legitimate interest: service security, abuse prevention, activity log.
- Legal obligation: keeping accounting records.
- [Processing based on consent, if any: TO BE CONFIRMED]
Retention periods
- Traces: 30 days by default, then deleted. Your organisation can choose 30, 90 or 180 days.
- Account data: for as long as the account exists, then [period TO BE CONFIRMED] after it is closed.
- Activity log: [period TO BE CONFIRMED].
- Accounting records: [legal period TO BE CONFIRMED].
- Technical logs: [period TO BE CONFIRMED].
Recipients
Data is only accessible to authorised people at WYRLO and in your organisation. It is hosted in the European Union by our technical processors:
- Supabase: database and functions, eu-west-3 region (Paris).
- Vercel: web application hosting, functions in the cdg1 region (Paris).
[Other processors, if any (payments, email delivery, language models), and transfers outside the European Union: TO BE CONFIRMED]
Your rights
The GDPR gives you the following rights over your data:
- access;
- rectification;
- erasure;
- restriction of processing;
- objection;
- portability;
- instructions on what happens to your data after your death.
To exercise these rights, write to [email address TO BE CONFIRMED]. We reply within one month.
For data contained in traces, contact the organisation that uses WYRLO first: it is the controller, and we help it respond to you.
If you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr) or with your local data protection authority.
Security
The technical and organisational measures that protect your data are described on the Security page.
Changes
This policy may change. The last updated date is shown at the top of the page. If we make a significant change, we notify account holders [method TO BE CONFIRMED].