Privacy Policy
Version: 2.0 — Last updated: 2026-02-13
1. Introduction
Welcome to Posty. We take the protection of your personal data and respect for your privacy very seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the General Data Protection Regulation (GDPR) and applicable French data protection laws.
By using our application, you agree to the practices described in this policy.
2. Data Controller
Posty
Emilien Nepveu, sole proprietor
Address: 42170 Chambles, France
Email: postygroup@gmail.com
GDPR / DPO Contact: postygroup@gmail.com
3. Data Collected
We collect the following categories of data:
3.1 Identification Data
- First and last name
- Email address
- Profile photo (if provided via Google)
3.2 Professional Profile Data
- Industry
- Role / Job title
- Preferred LinkedIn style
- Professional objectives
3.3 Usage Data
- Post generation history
- Prompts entered
- Content preferences
3.4 Technical Data
- IP address
- Browser type
- Connection data
3.5 Payment Data
- Credit card information (processed by Stripe, not stored by Posty)
- Transaction history
- Billing address (if applicable)
4. Purposes of Processing
Your data is used for:
- Service delivery: Generation of personalized LinkedIn posts
- Personalization: Adapting content to your profile and preferences
- Service improvement: Analyzing usage to improve the experience
- Communication: Informing you of important updates
- Security: Protecting your account and preventing fraud
5. Legal Basis for Processing
We process your data on the following legal bases:
- Consent: For collecting profile data and sending marketing communications
- Performance of contract: For providing content generation services
- Legitimate interest: For improving our services and ensuring security
- Legal obligation: For meeting our regulatory obligations
6. Data Sharing
Your data may be shared with:
- Firebase (Google): Hosting and authentication
- OpenAI / Anthropic: AI content generation (anonymized data)
- Stripe: Secure payment processing and billing
- Vercel: Application hosting and deployment
We never sell your personal data to third parties. All sharing is governed by contracts that ensure the protection of your data.
7. Data Retention
We retain your data for the following periods:
- Account data: Until account deletion + 30 days
- Post history: 2 years after last activity
- Technical data: 12 months
- Billing data: 10 years (legal requirement)
8. Your GDPR Rights
Under the GDPR, you have the following rights:
Right of access
Obtain a copy of your personal data
Right to rectification
Correct inaccurate or incomplete data
Right to erasure
Request the deletion of your data
Right to data portability
Receive your data in a structured format
Right to object
Object to certain processing activities
Right to restriction
Restrict the processing of your data
Right to withdraw consent
Withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal
To exercise these rights or withdraw your consent, go to the Privacy Settings in the application or contact us at: postygroup@gmail.com
9. Data Security
We implement appropriate security measures to protect your data:
- Data encryption in transit (HTTPS/TLS)
- Data encryption at rest
- Secure authentication
- Restricted access to personal data
- Intrusion monitoring and detection
10. Cookies and Trackers
Our application uses essential cookies for the operation of the service. For non-essential cookies (analytics), we request your explicit consent. For more details, please refer to our Cookie Policy. Politique de cookies
11. International Transfers
Your data may be transferred to servers located outside the EU (notably in the USA via Firebase/Google). These transfers are governed by Standard Contractual Clauses or adequacy decisions of the European Commission.
12. Changes to This Policy
We may update this Privacy Policy. In the event of a substantial change, we will inform you by email or through the application. The Last updated date is indicated at the top of this page.
13. Complaints
If you believe your rights are not being respected, you may file a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): www.cnil.fr
14. Automated Decisions and Profiling
Posty uses artificial intelligence (via OpenAI and Anthropic) to generate personalized content based on your profile data (industry, role, style, objectives). This processing constitutes profiling within the meaning of Article 22 of the GDPR.
However, no decision with legal or significant effect on you is made in an automated manner. Content generation is an assistive tool: you remain in full control of the final decision to publish or not.
Your profile data is anonymized before being sent to AI services. No directly identifiable data (name, email) is transmitted to the language models.
You may modify your profile or withdraw your consent for personalized processing at any time from the application Settings.
15. Sub-processors and Data Processing Agreements (DPA)
We use the following sub-processors for the operation of the service. Each is bound by a GDPR-compliant Data Processing Agreement (DPA):
| Sous-traitant | Finalité | Localisation | DPA |
|---|---|---|---|
| Google / Firebase | Hosting, database, authentication | USA (Standard Contractual Clauses) | Voir le DPA |
| OpenAI | AI content generation (anonymized data) | USA (Standard Contractual Clauses) | Voir le DPA |
| Anthropic | AI content generation (anonymized data) | USA (Standard Contractual Clauses) | Voir le DPA |
| Stripe | Payment processing and billing | USA (Standard Contractual Clauses) | Voir le DPA |
| Vercel | Application hosting and deployment | USA (Standard Contractual Clauses) | Voir le DPA |
| LinkedIn (Microsoft) | OAuth connection and post publishing | USA (Standard Contractual Clauses) | Voir le DPA |
| X Corp. (Twitter) | OAuth connection and post publishing | USA (Standard Contractual Clauses) | Voir le DPA |
| Meta Platforms | OAuth connection and publishing on Facebook/Threads | USA (Standard Contractual Clauses) | Voir le DPA |
This list is updated regularly. Any addition of a sub-processor is subject to prior GDPR compliance verification.
16. Data Breach Notification
In the event of a personal data breach likely to pose a risk to your rights and freedoms, we commit to:
- Notifying the CNIL within 72 hours of becoming aware of it, in accordance with Article 33 of the GDPR
- Informing you as soon as possible if the breach poses a high risk to your rights and freedoms (Article 34 of the GDPR)
- Documenting any breach in an internal incident register
- Implementing necessary corrective measures to limit the impact of the breach
If you suspect a breach of your data, contact us immediately: postygroup@gmail.com
17. Data Protection Impact Assessment (DPIA)
In accordance with Article 35 of the GDPR, we conduct Data Protection Impact Assessments (DPIA) for processing activities likely to pose a high risk to the rights and freedoms of data subjects. The processing of data by AI models for content personalization is subject to a documented internal DPIA.
18. Contact
For any questions regarding this policy or your personal data:
General email: postygroup@gmail.com
GDPR / DPO email: postygroup@gmail.com
