Privacy policy
What data is processed, why, for how long, and how to exercise your rights.
This is a courtesy translation. In the event of a discrepancy, the French version prevails.
À COMPLÉTER — raison sociale processes personal data as part of Diavi. This policy describes what data, for what purpose, for how long, and how to exercise your rights — which you can exercise yourself, from your settings, without writing to us.
Who is the controller?
À COMPLÉTER — raison sociale, À COMPLÉTER — adresse du siège social. For any question about your data: rgpd@diavi.fr.
A distinction that matters: for your account data (identity, subscription, history), À COMPLÉTER — raison sociale is the controller. For the contents of your repositories, which the service reads in order to produce code, À COMPLÉTER — raison sociale acts as a processor, on your behalf and on your instructions.
What data is processed?
Account data: your identifier on your code-hosting tool, the address of your instance, your role, and your access token held encrypted.
Usage data: the history of your runs — ticket concerned, status, duration, cost, steps — and the execution logs the service produces. Those logs contain excerpts of the code produced.
Billing data: company name, address, tax identifiers, invoices issued.
No browsing data. The service uses no tracker, no advertising cookie and no third-party analytics. Fonts are self-hosted: no request is made to a third party when a page is displayed. Browser local storage is used only to keep your session and your display preferences — being strictly necessary to operation, it requires no prior consent.
Is my source code kept?
Not durably. Each run works on a copy of your repository of its own, deleted when the run ends. What remains are the execution logs, whose retention period you set yourself in your settings.
On what legal bases?
- Performance of the contract for providing the service, managing the account and processing runs.
- Legal obligation for keeping invoices and accounting records.
- Legitimate interest for the security of the service, prevention of abuse, and access logging.
How long is data kept?
- Execution logs: the period you set in your settings, then automatic deletion.
- Run history: for the lifetime of the account.
- Account data: for the lifetime of the account, then deletion or anonymisation.
- Invoices: ten years, under French accounting obligations.
- Audit log: kept so that access and sensitive actions can be traced, including after an account is closed.
Who has access to your data?
At À COMPLÉTER — raison sociale, nobody permanently. For our teams to access a customer's data, a session must be opened with a written justification, limited to two hours, logged, and viewable by you at any time from your settings, under "My data". The full execution log — the one containing your code — is not accessible to any internal role.
Processors: the hosting provider (Amazon Web Services EMEA SARL) and the payment provider (Stripe Payments Europe), which handles payment data without any card data passing through our servers.
The language-model provider you use is tied to your key and your contract: calls are sent to it from our infrastructure but fall under your contractual relationship with it.
No data is sold, rented or transferred for advertising purposes.
Where is data hosted?
In France. No transfer outside the European Union is carried out by the service itself. A transfer may result from the model provider you chose, or from your own code-hosting instance, neither of which is under our control.
What are your rights?
You have the rights of access, rectification, erasure, restriction, objection and portability.
Two of them are exercised directly, without writing to us or waiting, from your settings, under "My data":
- Portability: download all of your data as a readable file. It contains no secrets — no token, no model key: those are your credentials on other systems, and handing them back in the clear would expose them.
- Erasure: delete your runs, logs, settings, members and tokens, and anonymise your record. Two items remain because the law requires it: your invoices for ten years, and the audit-log entries — erasing the proof of an erasure would not be one.
For the other rights, write to rgpd@diavi.fr. You will receive a reply within one month.
You may lodge a complaint with the French data-protection authority (CNIL), 3 place de Fontenoy, 75007 Paris.
Security
Access tokens and model keys are encrypted at rest. Exchanges with your code-hosting tool take place exclusively over HTTPS with certificate verification; an unencrypted address is refused at registration. Internal access is logged and time-limited. Backups are verified and their restoration exercised periodically.
Changes to this policy
Any substantial change is brought to your attention before it takes effect.
Last updated: 2026-08-18.