1. Roles
The customer is the controller of the personal data contained in the answers it collects. Citegram SAS is the processor and processes that data only to provide the service, on the customer's documented instructions.
2. Scope of processing
| Subject matter | Hosting and analysis of AI answers collected by the customer |
|---|---|
| Duration | The term of the customer's subscription, plus deletion periods below |
| Data | Answer text, cited URLs, search queries, conversation URLs; workspace user names and emails |
| Data subjects | Customer users; individuals who may be named in AI answers |
3. Processor obligations
- Process personal data only on the customer's instructions.
- Ensure staff with access are bound by confidentiality.
- Apply appropriate technical and organisational security measures, including encryption in transit and at rest.
- Assist the customer with data subject requests and impact assessments.
- Notify the customer without undue delay, and within 72 hours, of a personal data breach.
4. Subprocessors
The customer authorises the use of the subprocessors below. We impose equivalent data protection obligations on them and will give notice of new subprocessors, with the right to object.
| Service | Purpose | Entity and location |
|---|---|---|
| Vercel | Hosting of the website and web app | Vercel Inc., United States |
| Fly.io | Hosting of the API and database | Fly.io, Inc., United States |
| Stripe | Payments and billing | Stripe Payments Europe, Ltd., Ireland (EU) |
| Brevo | Transactional email | Sendinblue SAS (Brevo), France (EU) |
| PostHog | Website analytics; session replay with your consent | PostHog Inc. (EU Cloud), EU hosting (Germany) |
| Sentry | Error monitoring | Functional Software, Inc., United States |
| Sign in with Google | Google Ireland Limited, Ireland (EU) |
5. International transfers
Transfers outside the European Economic Area rely on adequacy decisions or the Standard Contractual Clauses adopted by the European Commission.
6. Return and deletion
On termination, the customer can export its data. We delete it within 30 days, unless the law requires us to keep it.
7. Audits
We make available the information needed to demonstrate compliance and allow reasonable audits, on 30 days' notice and no more than once a year.
8. Contact
Data protection questions: privacy@citegram.com. To sign a countersigned copy of this agreement, write to the same address.