Data we collect
- Account information: email, name, organization.
- Usage data: messages exchanged with the assistant, connected integrations, executed actions.
- Technical data: IP address, browser type, error logs.
We DO NOT collect: your business data in Salesforce, HubSpot, Gmail, etc. — we query them in real time via OAuth and do not store them.
Processing purpose
- Provide the Meir AI service: route your requests, maintain conversation context.
- Billing and account management.
- Product improvement (aggregated, anonymized data only).
- Transactional communication (notifications, security).
Legal basis (GDPR)
- Contract performance: to deliver the subscribed service.
- Legitimate interest: security, fraud prevention, product improvement.
- Consent: marketing, non-essential cookies.
- Legal obligation: billing, accounting retention.
Hosting & transfers
All your personal data is hosted in the European Union. No transfers outside the EU.
Technical subprocessors (OpenAI, Anthropic) operate under Data Processing Agreements (DPA) and use Standard Contractual Clauses for international transfers.
Retention
- Account data: as long as the account is active, then 3 years after deactivation (accounting obligations).
- Conversation history: 12 months by default, configurable.
- Technical logs: 90 days.
- Billing data: 10 years (legal requirement).
Your GDPR rights
Per GDPR articles 15-22, you have the following rights: - Access your data. - Rectification. - Erasure ("right to be forgotten"). - Restriction of processing. - Portability. - Objection.
To exercise these rights: ilan@meir-ai.com. Response within 30 days.
Contact & DPO
Data Protection Officer: ilan@meir-ai.com Data Controller: Meir AI, Paris, France. Supervisory authority: CNIL (cnil.fr) — you have the right to lodge a complaint.