Privacy Policy

Introduction

This policy explains how we collect and process personal data.

Data collection

We collect the minimum data necessary to provide the service.

  • Account & identity: name, email address, phone number and authentication identifiers.
  • Business details: company name, VAT/SIRET number, billing address and logo.
  • Customer & billing data: your clients' names, addresses and contact details used to create invoices and contracts.
  • Payment & transaction records: payment status, invoices and receipts (payment card data is handled securely by our payment processor).
  • Usage data: IP address, device/browser metadata, logs and diagnostic information to secure and improve the service.

How we use your data

Data is used to provide and improve our services.

  • Provide, operate and improve the MyFact platform (generate, send and archive invoices, quotes and contracts).
  • Process payments, manage subscriptions and handle billing disputes.
  • Authenticate users, prevent fraud and secure accounts.
  • Provide customer support and respond to enquiries.
  • Analyze anonymized usage data to improve product performance and user experience.

Legal basis

We process data under legitimate interests and contractual necessity.

  • Performance of a contract: to deliver services you requested.
  • Legal obligation: to satisfy accounting, tax and regulatory requirements.
  • Legitimate interests: to operate, secure and improve the service, balanced against your rights.
  • Consent: for optional features such as marketing communications or certain AI features when required.

Data retention

We retain data only as long as required for the service and legal obligations.

Your rights

You can access, rectify, and request deletion of your data.

Cookies

We use cookies to improve functionality and analytics.

We may track email opens for transactional messages.

Security

We apply industry-standard protections to your data.

  • Encryption: TLS for data in transit and AES-256 for data at rest where applicable.
  • Access controls and least-privilege principles for internal systems.
  • Regular security testing, monitoring and incident response procedures.
  • Automated backups and disaster recovery processes.

Sub-processors

We share data with trusted subprocessors under contract.

  • Supabase (EU) — database hosting, auth and file storage.
  • Stripe — payment processing (payment data handled directly by Stripe).
  • Brevo (Sendinblue) — transactional email delivery.
  • Mistral AI (France/EU) — optional AI-assisted generation (DPA in place).
  • Botpress Cloud — optional chatbot for Business customers.
  • Google / Microsoft — optional OAuth authentication providers.

Sub-processors maintain a DPA when required.

OAuth providers

You can sign in with third-party providers.

Data processing facts

Providing OAuth data is optional.

Virtual Assistant

We may use a virtual assistant for support.

Messages may be transferred to the provider for processing.

A DPA exists with the provider. botpress.com/privacy

Avoid sharing sensitive personal data in chat.

AI-assisted processing

We may use AI to improve document processing; data is handled securely.

What we process

  • Client names and contact details used in documents.
  • Commercial information: line items, amounts and payment terms.
  • Free‑text content and contract clauses you provide.

We do not use your data to train third-party AI models.

Legal basis for processing

Data Processing Addendum mistral.ai/terms

Privacy contact

For privacy questions contact our DPO. privacy@myfact.fr (we respond within 30 days)

We aim to reply within 30 days

You may file a complaint with your supervisory authority www.cnil.fr/fr/plaintes

Last updated: 9/23/2026© 2026 MyFact. All rights reserved