Data Retention Policy for Euphile Platform
Introduction
This Data Retention Policy describes how long revzper SAS retains different categories of data across the Euphile platform.
1. Purpose
This policy establishes retention periods for data processed by revzper SAS on the Euphile platform, ensuring compliance with applicable legal and regulatory requirements while respecting user rights.
Data Categories and Retention Periods
1. Subscription and Billing Records
Subscription and billing records are retained for 10 years in compliance with French commercial law (Code de commerce L123-22).
Ref: French commercial law (Code de commerce L123-22)
2. Usage Telemetry Metadata
Usage telemetry metadata is retained for 24 months. During this period, the data is considered personal data under GDPR. After 24 months, the metadata is irreversibly de-identified using technical and organizational measures that ensure the data cannot be linked to any individual. Once de-identified, the data is no longer considered personal data and is exempt from GDPR's retention and user rights provisions.
Ref: GDPR
3. AI Prompt Bodies and Response Content
AI prompt bodies and response content are not stored beyond the duration of the request.
4. Secure Authentication Tokens
Secure authentication tokens are ephemeral and never persisted.
5. Session Management Data
Session management data is retained for a maximum of 30 days from the last activity. In exceptional circumstances, such as ongoing fraud investigations, litigation holds, or regulatory requests, session data may be retained for up to 90 days beyond the standard period. Any extension beyond 30 days will be documented and justified in revzper SAS's records of processing activities.
6. Audit Logs
Audit logs are retained for 24 months, unless a longer retention period is required for specific legal or security purposes. Any extension beyond 24 months will be documented and justified in revzper SAS's records of processing activities.
User Rights and Early Deletion
1. Early Deletion Requests
Users may request early deletion of personal data or exercise their GDPR rights by contacting privacy@revzper.com. All data subject requests will be handled by the designated Data Protection Officer (DPO) to ensure consistent and compliant processing.
Ref: GDPR
2. Your Rights Under GDPR
Ref: GDPR
GDPR Rights
- You can ask us to confirm whether we are processing your personal data and, if so, to provide you with a copy of that data along with details about how it is being used.
- If any of your personal data is incorrect or outdated, you can request that we update or correct it without delay.
- In certain situations, you can ask us to temporarily stop processing your personal data. For example, if you believe the data is incorrect, we will pause processing until the issue is resolved.
- If you have concerns about how we are using your data, you can object to such processing, particularly if it is based on our legitimate interests or for marketing purposes.
- You can ask us to delete your personal data in specific cases, such as when the data is no longer needed for the purpose it was collected or if you withdraw your consent.
- You can request a copy of your personal data in a format that is easy to read and share with others, and we will help transfer it to another service if technically possible.
3. How to Exercise Your Rights
To exercise any of the above rights, please contact our Data Protection Officer at privacy@revzper.com. We will respond to your request without undue delay and in any event within one month of receipt. If we need more time, we will inform you of the reasons for the delay and provide an updated response timeline.
Ref: GDPR
International Data Transfers
1. Data Transfer Policy
revzper SAS processes and stores all personal data within the European Union (EU) or the European Economic Area (EEA). We do not transfer personal data outside the EU/EEA. All data processing activities are performed using cloud infrastructure located within the EU, ensuring compliance with GDPR's requirements for international data transfers.
Ref: GDPR
2. Exceptions
Some rights may not apply if we are legally required to retain your data (e.g., for 10 years under French commercial law for subscription and billing records). We will inform you if this is the case when responding to your request.
Ref: GDPR, French commercial law (Code de commerce L123-22)