Skip to main content

Privacy Policy

Last updated: August 5, 2026

Catalog SAS (“Catalog”, “we”) operates a B2B SaaS platform for automated order processing (Smart Order), intelligent email triage (Smart Inbox), and AI agents. This policy describes the personal data we collect, why we collect it, who we share it with, how long we keep it, and how you can exercise your rights.

1. Catalog’s roles under the GDPR

Depending on the context, Catalog acts either as a data controller or as a processor within the meaning of the GDPR.

Catalog acts as a data controller for the management of its website, prospects, user accounts, support, and legal obligations.

Catalog acts as a processor when it processes personal data contained in emails, orders, quotes, attachments, customer data, product data, or ERP systems on behalf of its B2B customers.

Catalog SAS, a simplified joint-stock company with share capital of €2,001,000, registered with the Bordeaux Trade and Companies Register under number 950 871 848.

Registered office: 51 Quai Lawton, 33300 Bordeaux, France.

Privacy contact: dpo@startcatalog.com.

2. Data we collect

We collect and process the following categories of data:

  • User account data: first and last name, business email, hashed password, role, organization (seller).
  • Connected mailbox content (Gmail, Microsoft 365 / Outlook, IMAP): inbound and outbound messages, attachments, senders, recipients, subjects, headers, labels / categories, threads, technical identifiers.
  • B2B business data: orders, quotes, products, customers, prices, ERP integrations.
  • Application and technical logs: IP addresses, user-agent, session identifiers, execution traces, errors, performance metrics.
  • Cookies and browsing data on startcatalog.com, where applicable, managed through the cookie banner or cookie settings module.
  • Phone data (when provided by your customers): normalized numbers used for matching purposes.

3. Purposes and legal bases

We process your data for the following purposes:

  • Provide the Catalog service (contract performance): email ingestion, order extraction, classification, follow-ups, reply sending, ERP integration.
  • Improve service quality and the performance of AI features configured for the service (legitimate interest or contract performance depending on the context): evaluation, quality control, and error detection. Customer data is not used to train public or general-purpose models.
  • Security, fraud prevention, and continuity (legitimate interest and legal obligation).
  • Transactional and support communications (contract performance).
  • Marketing communications (consent only, opt-out available at any time).

4. AI processing

Catalog relies on AI models, including third-party models, to analyze email content, extract orders, classify messages, and generate suggested replies.

When third-party AI model providers are used, Catalog configures the services and contractually governs its providers so that customer data is not used to train public or general-purpose models.

No purely automated decisions producing legal effects or similarly significant effects are made without human intervention. You retain the final say over what is sent to your ERP or to your customers.

5. Compliance with the Google API Services User Data Policy (Limited Use)

Catalog’s use of information received from Google APIs, including Gmail, adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In practice: we use Gmail data only to provide the user-facing features the user has requested (Smart Inbox, Smart Order, Smart Agents); we never sell this data; we do not use it for advertising; we transfer it to third parties only as strictly necessary to operate the service (subprocessors listed below); humans at Catalog do not read your emails except with your explicit consent, to comply with a legal obligation, for security purposes, or for user support.

Gmail data is retained only for as long as necessary to provide the service, in accordance with the retention periods described below, and is then deleted or anonymized according to applicable settings and contractual obligations.

6. Microsoft Graph and IMAP compliance

When you connect a Microsoft 365 / Outlook or IMAP mailbox, the principles above — minimization, no resale, no advertising, and no reuse for public training — apply in the same way.

Access and refresh tokens are encrypted at rest. You can revoke access at any time from your Microsoft admin console, your email provider, or the Catalog console depending on the connection method used.

7. Subprocessors and partners

To operate the service we rely on the subprocessors listed below. Each is bound by a GDPR-compliant data processing agreement.

SubprocessorPurposeLocation
Amazon Web Services (AWS)Hosting, storage, databases, cache, messaging, and managed AI services.European Union
MongoDB AtlasDocument database (seller settings, email metadata, logs).European Union
Google Cloud / Google Workspace APIsGmail / Workspace connection, push notifications, cloud services, and managed AI services.European Union
Microsoft CorporationOutlook / Microsoft 365 connection, Microsoft Graph, Entra ID, and configured Azure services.European Union
Microsoft Azure OpenAIGPT models powering the service's AI features.European Union
Datadog Inc.Application monitoring and observability.European Union
Vercel Inc.Front-end hosting (seller-front, public-website).European Union
Auth0 (Okta)Identity management and SSO.European Union
Amazon CognitoUser authentication and identity management.European Union
SendGrid (Twilio Inc.)Transactional email delivery (notifications, account emails).European Union

8. Data location

Catalog prioritizes hosting and processing data within the European Union or the European Economic Area.

Where contractual commitments with a customer provide for hosting or processing exclusively within the European Economic Area, those specific commitments prevail for the relevant customer.

If a transfer outside the European Economic Area were to become necessary, Catalog would ensure that it relies on a GDPR-compliant transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or any other appropriate safeguard.

9. Retention periods

  • Account data: throughout the contractual relationship, then 3 years for evidentiary purposes.
  • Connected mailbox content and attachments: retained for as long as necessary to provide the service, then deleted within a reasonable period after termination, mailbox disconnection, or applicable request, unless a legal or contractual obligation requires otherwise.
  • Attachments archived on S3 for Smart Order extraction: retained for as long as necessary to provide the service, according to the settings applicable to the customer.
  • Technical logs: retained for a limited period necessary for monitoring, security, diagnostics, and service continuity, according to the settings applicable to the relevant systems.
  • BigQuery analytics data: 13 months by default, configurable.
  • Accounting data and invoices: 10 years (legal obligation).

10. Security

We implement appropriate technical and organizational measures, including TLS encryption in transit, encryption at rest for OAuth tokens and secrets, strict isolation of environments and customer data, role-based access control, logging and alerting, code reviews, automated tests, and continuous monitoring.

Catalog prepares or performs the security assessments required by Google for the use of restricted Gmail scopes, where such scopes are necessary for the service.

11. Your rights

Under the GDPR, you have the following rights:

  • Access, rectify, and erase your personal data.
  • Restrict and object to processing.
  • Data portability.
  • Withdraw consent at any time, without retroactive effect.
  • Define post-mortem directives.
  • Lodge a complaint with the CNIL (cnil.fr).

12. Cookies

On first load, a consent module asks you to accept or decline three categories of cookies: strictly necessary (locked, stores only your choice), audience measurement (Google Analytics), and advertising (Google Ads, LinkedIn). Declining is as easy as accepting, and you can change your mind at any time from the “Cookie settings” page, available in the footer.

The detailed list of cookies and storage technologies we set, their origin, and how long they are kept is published on that “Cookie settings” page.

13. Changes

We may update this policy to reflect legal, technical, or commercial changes. The last-updated date appears at the top of the page. For material changes, we will notify you by email or in-app.

To exercise your rights or for any question, contact us at: dpo@startcatalog.com