Diavi

Legal information

Privacy policy

What data is processed, why, for how long, and how to exercise your rights.

This is a courtesy translation. In the event of a discrepancy, the French version prevails.

À COMPLÉTER — raison sociale processes personal data as part of Diavi. This policy describes what data, for what purpose, for how long, and how to exercise your rights — which you can exercise yourself, from your settings, without writing to us.

Who is the controller?

À COMPLÉTER — raison sociale, À COMPLÉTER — adresse du siège social. For any question about your data: rgpd@diavi.fr.

A distinction that matters: for your account data (identity, subscription, history), À COMPLÉTER — raison sociale is the controller. For the contents of your repositories, which the service reads in order to produce code, À COMPLÉTER — raison sociale acts as a processor, on your behalf and on your instructions.

What data is processed?

Account data: your identifier on your code-hosting tool, the address of your instance, your role, and your access token held encrypted.

Usage data: the history of your runs — ticket concerned, status, duration, cost, steps — and the execution logs the service produces. Those logs contain excerpts of the code produced.

Billing data: company name, address, tax identifiers, invoices issued.

No browsing data. The service uses no tracker, no advertising cookie and no third-party analytics. Fonts are self-hosted: no request is made to a third party when a page is displayed. Browser local storage is used only to keep your session and your display preferences — being strictly necessary to operation, it requires no prior consent.

Is my source code kept?

Not durably. Each run works on a copy of your repository of its own, deleted when the run ends. What remains are the execution logs, whose retention period you set yourself in your settings.

On what legal bases?

How long is data kept?

Who has access to your data?

At À COMPLÉTER — raison sociale, nobody permanently. For our teams to access a customer's data, a session must be opened with a written justification, limited to two hours, logged, and viewable by you at any time from your settings, under "My data". The full execution log — the one containing your code — is not accessible to any internal role.

Processors: the hosting provider (Amazon Web Services EMEA SARL) and the payment provider (Stripe Payments Europe), which handles payment data without any card data passing through our servers.

The language-model provider you use is tied to your key and your contract: calls are sent to it from our infrastructure but fall under your contractual relationship with it.

No data is sold, rented or transferred for advertising purposes.

Where is data hosted?

In France. No transfer outside the European Union is carried out by the service itself. A transfer may result from the model provider you chose, or from your own code-hosting instance, neither of which is under our control.

What are your rights?

You have the rights of access, rectification, erasure, restriction, objection and portability.

Two of them are exercised directly, without writing to us or waiting, from your settings, under "My data":

For the other rights, write to rgpd@diavi.fr. You will receive a reply within one month.

You may lodge a complaint with the French data-protection authority (CNIL), 3 place de Fontenoy, 75007 Paris.

Security

Access tokens and model keys are encrypted at rest. Exchanges with your code-hosting tool take place exclusively over HTTPS with certificate verification; an unencrypted address is refused at registration. Internal access is logged and time-limited. Backups are verified and their restoration exercised periodically.

Changes to this policy

Any substantial change is brought to your attention before it takes effect.

Last updated: 2026-08-18.