Privacy Policy

Last updated: January 2026

1. Data Controller

Stiamond Agents SAS is the data controller for personal data processed through the Service. Data is hosted in the European Union (France). Contact: privacy@stiamond.com.

2. Data We Collect

  • Account data: name, email, company name, password (hashed with bcrypt).
  • Usage data: conversations, leads, funnel stages, analytics, API calls.
  • Payment data: processed by Stripe. We do not store credit card numbers.
  • Technical data: IP address, browser type, device info (for security and analytics).
  • End-user data: messages sent to your AI agents, contact information shared during conversations.

3. How We Use Your Data

  • To provide and improve the Service.
  • To process payments and manage subscriptions.
  • To send service notifications (billing, security, product updates).
  • To generate analytics and reports for your dashboard.
  • To prevent fraud, abuse, and security threats.

4. Legal Basis (GDPR Article 6)

  • Contract: processing necessary to deliver the Service you subscribed to.
  • Legal obligation: compliance with tax, accounting, and EU regulations.
  • Legitimate interest: security, fraud prevention, and service improvement.
  • Consent: for optional analytics and marketing communications.

5. Data Retention

  • Account data: retained while your account is active. Deleted within 30 days of account closure.
  • Conversation data: retained while your subscription is active. Exportable at any time.
  • Payment records: retained for 10 years per French tax law requirements.
  • Server logs: retained for 90 days for security purposes.

6. Data Sharing

We do not sell your data. We share data only with:

  • Stripe: payment processing (PCI-DSS compliant).
  • SendGrid: transactional email delivery.
  • Twilio: SMS delivery (optional, only if you enable SMS channel).
  • Cloud infrastructure provider: EU-based hosting (AWS Frankfurt or equivalent).

7. Your Rights (GDPR)

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data ("right to be forgotten").
  • Portability: export your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • Restriction: request temporary restriction of processing.

To exercise these rights, email privacy@stiamond.com. We respond within 30 days.

8. Security

  • Data is tenant-isolated (each customer's data is logically separated).
  • Authentication via JWT with expiration.
  • API keys hashed with bcrypt.
  • Helmet security headers (CSP, COOP, Referrer-Policy).
  • Rate limiting (100 requests/minute per IP).
  • HTTPS/TLS encryption in transit.
  • Database encryption at rest.

9. International Transfers

Data is hosted in the European Union. Third-party processors (Stripe, SendGrid) may transfer data outside the EU under Standard Contractual Clauses (SCCs) or adequacy decisions. No data is transferred to countries without adequate data protection.

10. Cookies

We use only essential cookies for authentication and session management. We do not use tracking cookies, advertising pixels, or third-party analytics trackers. No cookie banner is required under ePrivacy Directive Article 5(3) exception.

11. Contact

Stiamond Agents SAS — Email: privacy@stiamond.com — Data Protection Officer available upon request.