- Last updated
- 5 August 2026
Catalog SAS (“Catalog”, “we”) publishes a B2B SaaS platform for automated order processing (Smart Order), intelligent email sorting (Smart Inbox) and AI agents. This policy describes which personal data we collect, why, with whom we share it, how long we keep it, and how you can exercise your rights.
1. Catalog’s roles under the GDPR
- Two roles
- Depending on the context, Catalog acts either as a data controller or as a data processor within the meaning of the GDPR.
- Controller
- Catalog acts as a data controller for the management of its website, its prospects, its user accounts, its support and its legal obligations.
- Processor
- Catalog acts as a data processor when it processes personal data contained in emails, orders, quotes, attachments, customer data, product data or ERP systems on behalf of its B2B customers.
- Company
- Catalog SAS, a French simplified joint-stock company (SAS) with a share capital of €2,001,000, registered with the Bordeaux Trade and Companies Register (RCS) under number 950 871 848.
- Registered office
- 51 Quai Lawton, 33300 Bordeaux, France.
- Personal data contact
- dpo@startcatalog.com.
2. Data collected
We collect and process the following categories of data:
- User account data
- Surname, first name, business email address, hashed password, role, organisation (seller).
- Connected mailboxes
- Content of the connected mailboxes (Gmail, Microsoft 365 / Outlook, IMAP): incoming and outgoing messages, attachments, senders, recipients, subjects, headers, labels / categories, threads, technical identifiers.
- B2B business data
- Orders, quotes, products, customers, prices, ERP integrations.
- Application and technical logs
- IP addresses, user agent, session identifiers, execution traces, errors, performance metrics.
- Cookies and browsing data
- On startcatalog.com, where applicable, managed through the cookie banner or cookie management module.
- Telephone data
- Where entered by your customers: normalised numbers for matching purposes.
3. Purposes and legal bases
We process your data for the following purposes:
- Providing the service
- Providing the Catalog service (performance of the contract): email ingestion, order extraction, classification, follow-up, sending replies, ERP integration.
- Improving the service
- Improving the quality of the service and the performance of the AI features configured for the service (legitimate interest or performance of the contract, depending on the context): evaluation, quality control, error detection. No customer data is used to train public or general-purpose models.
- Security
- Security, fraud prevention and continuity (legitimate interest and legal obligation).
- Transactional communications
- Transactional communications and support (performance of the contract).
- Marketing communications
- Marketing communications (consent only; you may unsubscribe at any time).
4. Processing by artificial intelligence
- Models
- Catalog relies on AI models, including third-party models, to analyse the content of emails, extract orders, classify messages and generate suggested replies.
- Third-party providers
- Where third-party AI model providers are used, Catalog configures the services and binds its providers contractually so that customer data is not used to train public or general-purpose models.
- Human oversight
- No purely automated decision producing legal effects or significantly affecting a person is taken without human intervention. You keep the final say on what is sent to your ERP or to your customers.
5. Compliance with the Google API Services User Data Policy (Limited Use)
- Principle
- Catalog’s use of information received from Google APIs, including Gmail, complies with the Google API Services User Data Policy, and in particular with its Limited Use requirements.
- In practice
- We use Gmail data only to provide the features requested by the user (Smart Inbox, Smart Order, Smart Agents); we never sell this data; we do not use it for advertising; we transfer it to third parties only where strictly required to perform the service (the processors listed below); people at Catalog do not read your emails except with your explicit consent, under a legal obligation, or for security or user-support purposes.
- Retention
- Gmail data is kept only for as long as necessary to provide the service, in line with the retention periods set out below, and is then deleted or anonymised according to the applicable settings and contractual obligations.
6. Compliance for Microsoft Graph and IMAP
- Same principles
- When you connect a Microsoft 365 / Outlook or IMAP mailbox, the principles above (minimisation, no resale, no advertising, no reuse for public training) apply identically.
- Tokens and revocation
- Access and refresh tokens are encrypted at rest. You can revoke access at any time from your Microsoft admin console, your email provider, or the Catalog console, depending on the connection method used.
7. Processors and partners
To operate the service, we rely on the following processors. Each is bound by a GDPR-compliant data processing agreement.
- Amazon Web Services (AWS)
- Hosting, storage, databases, cache, messaging and managed AI services. Location: European Union.
- MongoDB Atlas
- Document database (seller settings, email metadata, logs). Location: European Union.
- Google Cloud / Google Workspace APIs
- Gmail / Workspace connection, push notifications, managed cloud and AI services. Location: European Union.
- Microsoft Corporation
- Outlook / Microsoft 365 connection, Microsoft Graph, Entra ID and configured Azure services. Location: European Union.
- Microsoft Azure OpenAI
- GPT models for the service’s AI features. Location: European Union.
- Datadog Inc.
- Application monitoring and observability. Location: European Union.
- Vercel Inc.
- Hosting of the front-end interfaces (seller-front, public-website). Location: European Union.
- Auth0 (Okta)
- Identity management and SSO. Location: European Union.
- Amazon Cognito
- User authentication and identity management. Location: European Union.
- SendGrid (Twilio Inc.)
- Sending transactional emails (notifications, accounts). Location: European Union.
8. Data location
- Preference
- Catalog favours hosting and processing data within the European Union or the European Economic Area.
- Contractual commitments
- Where the contractual commitments made to a customer provide for hosting or processing exclusively within the European Economic Area, those specific commitments prevail for the customer concerned.
- Transfers outside the EEA
- Should a transfer outside the European Economic Area become necessary, Catalog would ensure that it relies on a GDPR-compliant transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or any other appropriate safeguard.
9. Retention periods
- Account data
- For the whole duration of the contractual relationship, then 3 years for evidentiary purposes.
- Connected emails and attachments
- For as long as necessary to provide the service, then deletion within a reasonable time after termination, disconnection of the mailbox or an applicable request, unless a legal or contractual obligation provides otherwise.
- Archived attachments
- Attachments archived on S3 for the purposes of Smart Order extraction: for as long as necessary to provide the service, according to the settings applicable to the customer.
- Technical logs
- Limited to the needs of monitoring, security, diagnostics and service continuity, according to the settings applicable to the systems concerned.
- BigQuery analytics data
- 13 months by default, configurable.
- Accounting data and invoices
- 10 years (legal obligation).
10. Security
- Measures
- We implement appropriate technical and organisational measures: TLS encryption in transit, encryption at rest for OAuth tokens and secrets, strict isolation of environments and data per customer, role-based access control, logging and alerting, code reviews, automated tests and continuous monitoring.
- Google security assessments
- Catalog prepares or undergoes the security assessments required by Google for the use of restricted Gmail scopes, where those scopes are necessary to the service.
11. Your rights
Under the GDPR, you have the following rights:
- Access, rectification, erasure
- Access to, rectification and erasure of your personal data.
- Restriction and objection
- Restriction of and objection to processing.
- Portability
- Portability of your data.
- Withdrawal of consent
- Withdrawal of consent at any time, without retroactive effect.
- Post-mortem directives
- Setting directives on the fate of your data after your death.
- Complaint
- Lodging a complaint with the CNIL (cnil.fr).
12. Cookies
- Consent module
- When the site first loads, a consent module asks you to accept or refuse three categories of cookies: strictly necessary (locked; it only stores your choice), audience measurement (Google Analytics), and advertising (Google Ads, LinkedIn). Refusing is as simple as accepting, and you can change your mind at any time from the “Cookies” page, accessible from the footer.
- Detailed list
- The detailed list of the cookies and storage technologies set, their origin and their retention period is published on that “Cookies” page.
13. Changes
- Updates
- We may update this policy to reflect legal, technical or business developments. The date of the last update appears at the top of the page. For substantial changes, we will notify you by email or through the application.
To exercise your rights or for any question, contact us: dpo@startcatalog.com
