Privacy Policy
Last updated: August 5, 2026
Catalog SAS (“Catalog”, “we”) operates a B2B SaaS platform for automated order processing (Smart Order), intelligent email triage (Smart Inbox), and AI agents. This policy describes the personal data we collect, why we collect it, who we share it with, how long we keep it, and how you can exercise your rights.
1. Catalog’s roles under the GDPR
Depending on the context, Catalog acts either as a data controller or as a processor within the meaning of the GDPR.
Catalog acts as a data controller for the management of its website, prospects, user accounts, support, and legal obligations.
Catalog acts as a processor when it processes personal data contained in emails, orders, quotes, attachments, customer data, product data, or ERP systems on behalf of its B2B customers.
Catalog SAS, a simplified joint-stock company with share capital of €2,001,000, registered with the Bordeaux Trade and Companies Register under number 950 871 848.
Registered office: 51 Quai Lawton, 33300 Bordeaux, France.
Privacy contact: dpo@startcatalog.com.
2. Data we collect
We collect and process the following categories of data:
- User account data: first and last name, business email, hashed password, role, organization (seller).
- Connected mailbox content (Gmail, Microsoft 365 / Outlook, IMAP): inbound and outbound messages, attachments, senders, recipients, subjects, headers, labels / categories, threads, technical identifiers.
- B2B business data: orders, quotes, products, customers, prices, ERP integrations.
- Application and technical logs: IP addresses, user-agent, session identifiers, execution traces, errors, performance metrics.
- Cookies and browsing data on startcatalog.com, where applicable, managed through the cookie banner or cookie settings module.
- Phone data (when provided by your customers): normalized numbers used for matching purposes.
3. Purposes and legal bases
We process your data for the following purposes:
- Provide the Catalog service (contract performance): email ingestion, order extraction, classification, follow-ups, reply sending, ERP integration.
- Improve service quality and the performance of AI features configured for the service (legitimate interest or contract performance depending on the context): evaluation, quality control, and error detection. Customer data is not used to train public or general-purpose models.
- Security, fraud prevention, and continuity (legitimate interest and legal obligation).
- Transactional and support communications (contract performance).
- Marketing communications (consent only, opt-out available at any time).
4. AI processing
Catalog relies on AI models, including third-party models, to analyze email content, extract orders, classify messages, and generate suggested replies.
When third-party AI model providers are used, Catalog configures the services and contractually governs its providers so that customer data is not used to train public or general-purpose models.
No purely automated decisions producing legal effects or similarly significant effects are made without human intervention. You retain the final say over what is sent to your ERP or to your customers.
5. Compliance with the Google API Services User Data Policy (Limited Use)
Catalog’s use of information received from Google APIs, including Gmail, adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: we use Gmail data only to provide the user-facing features the user has requested (Smart Inbox, Smart Order, Smart Agents); we never sell this data; we do not use it for advertising; we transfer it to third parties only as strictly necessary to operate the service (subprocessors listed below); humans at Catalog do not read your emails except with your explicit consent, to comply with a legal obligation, for security purposes, or for user support.
Gmail data is retained only for as long as necessary to provide the service, in accordance with the retention periods described below, and is then deleted or anonymized according to applicable settings and contractual obligations.
6. Microsoft Graph and IMAP compliance
When you connect a Microsoft 365 / Outlook or IMAP mailbox, the principles above — minimization, no resale, no advertising, and no reuse for public training — apply in the same way.
Access and refresh tokens are encrypted at rest. You can revoke access at any time from your Microsoft admin console, your email provider, or the Catalog console depending on the connection method used.
7. Subprocessors and partners
To operate the service we rely on the subprocessors listed below. Each is bound by a GDPR-compliant data processing agreement.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage, databases, cache, messaging, and managed AI services. | European Union |
| MongoDB Atlas | Document database (seller settings, email metadata, logs). | European Union |
| Google Cloud / Google Workspace APIs | Gmail / Workspace connection, push notifications, cloud services, and managed AI services. | European Union |
| Microsoft Corporation | Outlook / Microsoft 365 connection, Microsoft Graph, Entra ID, and configured Azure services. | European Union |
| Microsoft Azure OpenAI | GPT models powering the service's AI features. | European Union |
| Datadog Inc. | Application monitoring and observability. | European Union |
| Vercel Inc. | Front-end hosting (seller-front, public-website). | European Union |
| Auth0 (Okta) | Identity management and SSO. | European Union |
| Amazon Cognito | User authentication and identity management. | European Union |
| SendGrid (Twilio Inc.) | Transactional email delivery (notifications, account emails). | European Union |
8. Data location
Catalog prioritizes hosting and processing data within the European Union or the European Economic Area.
Where contractual commitments with a customer provide for hosting or processing exclusively within the European Economic Area, those specific commitments prevail for the relevant customer.
If a transfer outside the European Economic Area were to become necessary, Catalog would ensure that it relies on a GDPR-compliant transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or any other appropriate safeguard.
9. Retention periods
- Account data: throughout the contractual relationship, then 3 years for evidentiary purposes.
- Connected mailbox content and attachments: retained for as long as necessary to provide the service, then deleted within a reasonable period after termination, mailbox disconnection, or applicable request, unless a legal or contractual obligation requires otherwise.
- Attachments archived on S3 for Smart Order extraction: retained for as long as necessary to provide the service, according to the settings applicable to the customer.
- Technical logs: retained for a limited period necessary for monitoring, security, diagnostics, and service continuity, according to the settings applicable to the relevant systems.
- BigQuery analytics data: 13 months by default, configurable.
- Accounting data and invoices: 10 years (legal obligation).
10. Security
We implement appropriate technical and organizational measures, including TLS encryption in transit, encryption at rest for OAuth tokens and secrets, strict isolation of environments and customer data, role-based access control, logging and alerting, code reviews, automated tests, and continuous monitoring.
Catalog prepares or performs the security assessments required by Google for the use of restricted Gmail scopes, where such scopes are necessary for the service.
11. Your rights
Under the GDPR, you have the following rights:
- Access, rectify, and erase your personal data.
- Restrict and object to processing.
- Data portability.
- Withdraw consent at any time, without retroactive effect.
- Define post-mortem directives.
- Lodge a complaint with the CNIL (cnil.fr).
12. Cookies
On first load, a consent module asks you to accept or decline three categories of cookies: strictly necessary (locked, stores only your choice), audience measurement (Google Analytics), and advertising (Google Ads, LinkedIn). Declining is as easy as accepting, and you can change your mind at any time from the “Cookie settings” page, available in the footer.
The detailed list of cookies and storage technologies we set, their origin, and how long they are kept is published on that “Cookie settings” page.
13. Changes
We may update this policy to reflect legal, technical, or commercial changes. The last-updated date appears at the top of the page. For material changes, we will notify you by email or in-app.
To exercise your rights or for any question, contact us at: dpo@startcatalog.com