— gdpr · personal data
GDPR Policy
fiine complies with the General Data Protection Regulation. All data you share with us is stored in the EU, with no third-party trackers, and deleted automatically after 12 months.
Data protection policy
When you use the fiine AI chat, you share information about your company and your projects. We use it only to get back to you and arrange a possible diagnostic call. Nothing more.
Data we collect
During a conversation with the fiine AI agent, we collect:
- Your email address — requested by the agent in the first message, so the fiine team can reply to you.
- The conversation transcript — the text exchanges with the AI agent.
- Booking metadata — time slots selected if you book a diagnostic call.
- Your explicit GDPR consent — collected by the agent before any data is stored.
Why we collect this data
- To reply by email (draft written by the agent, reviewed and sent by one of the founders).
- To keep a thread if you come back to the conversation.
- To organise diagnostic calls in the assigned host's calendar (Rémi or Sébastien).
Retention
Your data is kept for a maximum of 12 months from your last interaction, unless you give explicit consent to extend. After 12 months, the conversation, your email and the session file are deleted automatically.
Your rights
You have the following rights over your data:
- Right of access — you can request a full copy of your conversation by emailing remi@fiine.io.
- Right of rectification — you can ask to correct information shared during the chat.
- Right of erasure — you can request complete deletion of your data at remi@fiine.io.
How to exercise your rights
Send an email to remi@fiine.io describing your request. Legal processing time: 30 days. Deletion confirmation within 72 hours. remi@fiine.io
Data collected via the GEO diagnostic
If you use the GEO diagnostic tool (“Is your website ready for AI?”), we also collect:
- Your email address — to send you the analysis report by email.
- Your website URL — analysed automatically to produce the diagnostic.
- An ip_hash (an anonymised fingerprint of your IP address, via HMAC-SHA256) — kept only to prevent abuse, never shared.
- Your explicit consent — collected before any processing.
A report email is sent automatically to the address provided as soon as the analysis is complete.
Based on your consent, you then receive a few follow-up tips by email (two messages, at D+2 and D+5) to help you prepare your website. These marketing emails are optional: each one carries a one-click unsubscribe link, and you can opt out at any time without losing access to your report.
This data is kept for 12 months from the analysis date, then anonymised automatically (email, URL and ip_hash erased).
You can request early deletion at remi@fiine.io. Your data is then physically deleted from the database within 72 hours.
Hosting
The database, file storage and sessions are hosted in the EU (Hetzner Frankfurt or OVH Gravelines by default, via Dokploy). Encryption at rest is enabled at disk level (AES-256).
Cookies
We use only two technical cookies:
- NEXT_LOCALE — a technical cookie to remember the chosen language (FR or EN). No personal data.
- better-auth.session_token — a session cookie for the fiine admin area. Never exposed to public visitors.
No third-party cookies. No analytics tracker. No ad network.