TblFlowTblFlow

Privacy policy

Version 1.1 — published 23 September 2026, effective 7 October 2026. Previous version: 1.0 of 15 September 2026.

1. Controller

SPACE UNITY, a French SASU with variable capital, RCS Sedan 994 377 208, 34 route Nationale, 08140 Douzy, France ("we").

To contact us about data protection:

  • by e-mail at [email protected];
  • by post to SPACE UNITY, Data protection, at the address above.

We have not appointed a data protection officer, as this is not mandatory for our activity. Management handles requests directly.

2. Scope of this policy

This policy covers the data we process on our own behalf: data about users of app.tblflow.com, our customers and prospects, and people who contact support.

Space content is different. This means data that a customer organisation stores about its own customers, employees or contacts, or collects through the forms and interfaces it publishes. For that data, the customer organisation is the controller and we act as its processor under the Data processing agreement. If your data appears in such content, please contact that organisation. We forward any request we receive to it.

3. Data, purposes and legal bases

PurposeDataLegal basisRetention
Create and manage your account, authenticate youe-mail, name; if you provide them, first name, last name, phone and avatar; language; passkeys (public key); recovery codes (hashed); date terms were accepted; sign-in datesperformance of the contractlife of the account; erased on deletion (§ 7)
Collaboration: invitations, comments, mentions, notificationsinvitee e-mails, comments, notifications, notification preferences, recently visited resourcesperformance of the contractlife of the account; e-mail invitations expire after one month
Invitations to a shared appemail of the invited person, inviter and date; on sign-up, the account (§ 3, first row), without a personal spaceperformance of the contract (of the inviting organisation); pre-contractual steps for the invited personas long as the invitation exists; the account follows § 7
Security: logging sign-ins and sensitive actions, abuse detectionIP address, account ID, e-mail address used, event, timestamplegitimate interest (security of the Service, Art. 32 GDPR)log: 6 months; session: 7 days
Customer support by chat and e-mailID, e-mail, name, plan and subscription status, space name and ID, number of spaces, messages exchangedperformance of the contractlife of the account, then deleted within 30 days of closure
Automated AI replies in the support chatmessage sent to the chatlegitimate interest (responsive support)life of the conversation
Support access to your accountdata displayed during the access, reason, timestampsconsent, given and withdrawn in your settingsaccess: 30 minutes at most; record kept 6 months
Billing and subscription managementbilling e-mail, Stripe customer and subscription IDs, plan, status, renewal date; Stripe collects name, address and payment methodperformance of the contract; legal obligation (accounting)life of the subscription; accounting records: 10 years
AI features you triggercontent submitted for processingperformance of the contractfor the duration of processing by the provider (§ 4)
AI indexing of your documents (chunking, embeddings, memory extraction)content of the documents you importlegitimate interest (relevant search and assistant), with a right to objectas long as the document exists
Browser skillssite address, username, encrypted secret, certificationperformance of the contract90 days without use (§ 4a)
Voice narration of a browser skill, if you turn it ontimestamped text of your explanations; no audioconsent, given by turning on the microphoneuntil the skill is validated, then deleted (§ 4b)
Audience measurement of tblflow.com (Google Analytics)pseudonymous ID, pages viewed and events, technical device informationconsenttrackers: 13 months at most; data: 14 months at most
Information about Service updatese-mail, namelegitimate interest (business-to-business marketing); you can object at any timeuntil you object, or 3 years after last contact
Waiting liste-mailpre-contractual steps taken at your requestuntil your access opens or you ask to be removed
Establishing and defending our rights, responding to authoritiesstrictly necessary datalegitimate interest; legal obligationapplicable limitation period

We do not ask for any sensitive data. We make no decision based solely on automated processing that produces legal effects concerning you. We do not sell your data and do not run targeted advertising.

4. Artificial intelligence features

When you use an AI feature, the content it needs is sent to the chosen model for the duration of the processing, either directly or through the Vercel AI Gateway. The providers used on our instance are listed in § 5.

If your space is configured with its own provider key or a local model, that provider was chosen by the customer organisation and is not one of our processors.

We do not use your content to train models. We use providers' business (API) offerings, whose terms exclude training on submitted data by default. Some providers keep that data for a few weeks to detect abuse, under their own terms.

Secrets are never sent to a model. This includes passwords, tokens and browser skill credentials.

Your choices. In your account settings, under "Data processing", you can:

  • object to AI indexing of your documents, which covers chunking, embeddings and memory extraction;
  • restrict processing. This suspends automated processing that is not essential to the Service (currently, that indexing) without deleting your data.

Other AI features run only when a user asks, or as configured for the space by the customer.

4a. Browser skills and saved credentials

A "browser skill" replays a journey you recorded on a third-party site. If that journey requires signing in, you may save the corresponding credential.

What we do with it.

  • The secret is encrypted before storage, with a key dedicated to this purpose.
  • It is never displayed again, never returned by our interface and never written to our logs.
  • It is never sent to an AI model. Screenshots submitted to a model are masked first.
  • During a replay, our server types the value into the page. It never passes through your browser.

Who can use it. The credential belongs to the base, not to you: anyone with write access to that base will be able to use it to sign in, without ever seeing its value. Bear this in mind before saving an access.

What you must certify. You certify that the saved account belongs to you or to your organisation. Third-party accounts are out of scope.

For how long. The credential is deleted automatically after 90 days without use. You can delete it at any time and save it again. It is also deleted with the skill, with the base or with your account.

What we do not store. Physical security keys (WebAuthn) cannot be saved: the key stays with you.

4b. Voice narration while recording a skill

While recording a browser skill, you can turn on the microphone to explain aloud what you are doing and why. These explanations become the skill's rules.

What we receive. Text only, timestamped. Speech recognition happens in your browser: no audio reaches our servers, and we keep none.

Who receives your voice. To transcribe it, your browser sends the audio to its vendor's speech recognition service: Google for Chrome, Microsoft for Edge, Apple for Safari. This transfer is made by your browser, under its vendor's policy, and the vendor may process the audio outside the European Union. These vendors are not our processors: we neither receive nor transmit this audio.

How long. The text is kept with the skill until it is validated. On validation, its useful parts are carried into the skill's rules, with their timestamps, and the raw text is deleted; it leaves our backups according to the rotation in § 7. It is also deleted with the skill, the base or your account.

Who can read it. Until the skill is validated, the people who have access to its base.

Your choices. The microphone is off by default. You turn it on yourself, for one recording, and can stop it at any time.

5. Recipients and processors

Your data is accessible only to authorised SPACE UNITY staff who need it. It is also visible to members of the spaces you join, according to their roles. We disclose it to authorities only when legally required to do so. Our processors are:

ProviderRoleData locationTransfer safeguard
netcup GmbHapplication and database hostingGermany— (EU)
Cloudflare, Inc.network, protection, access tunnel; file and backup storage (R2)files and backups: EU; transit: global networkData Privacy Framework; standard clauses
Plus Five Five, Inc. (Resend)e-mail delivery: sign-in links, invitations, notificationsUnited StatesData Privacy Framework; standard clauses
Stripe Payments Europe, Limitedpayments and subscriptionsIreland; transfers to Stripe, Inc. (United States)Data Privacy Framework; standard clauses
Chatwoot, Inc.support chatUnited Statesstandard clauses
Google Ireland Limitedaudience measurement of tblflow.com, with your consentIreland; United States (Google LLC)Data Privacy Framework; standard clauses
Vercel, Inc.gateway to AI modelsUnited StatesData Privacy Framework; standard clauses
Anthropic, PBClanguage modelsUnited Statesstandard clauses
OpenAIlanguage models, document embeddingsUnited Statesstandard clauses
Mistral AIlanguage modelsFrance— (EU)
Replicate, Inc.image and video generationUnited Statesstandard clauses
Eleven Labs, Inc. (ElevenLabs)speech synthesis and transcriptionUnited Statesstandard clauses

We add any new processor to this list before using it.

Stripe also acts as a separate controller for its own obligations, such as fraud prevention and regulatory compliance.

Third-party services that you connect yourself receive and send data on your initiative, under their own policies. These include mail, calendar, storage, team chat, code hosting and APIs.

6. Transfers outside the European Union

Some providers are based in the United States. Transfers to them rely on one of the following:

  • the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, where the provider is certified;
  • otherwise, the standard contractual clauses adopted by the Commission on 4 June 2021.

These safeguards are supplemented by additional measures: encryption in transit, minimisation of the data sent, and exclusion of secrets.

You can request a copy of the safeguards at [email protected].

7. Account deletion and retention

Account deletion takes effect immediately:

  • your e-mail address and name are replaced with anonymous values;
  • your phone number, first and last names and avatar are erased;
  • your passkeys, recovery codes, tokens, connected accounts, browser skill credentials and notifications are deleted;
  • your comments are anonymised.

Records you created in other organisations' spaces remain there, attributed to a "deleted user".

Trash: a deleted space, base or table stays in the trash for 30 days and is then permanently erased.

Backups are taken hourly and encrypted. They are kept on a rotation that thins out over time: 48 hours, 14 days, 8 weeks, 12 months, then 3 years. Deleted data leaves the backups when the last backup containing it expires. Backups are used only to restore the Service.

Other retention periods are listed in the table in § 3.

8. Your rights

You have the right to access, rectify, erase, restrict, port and object to the processing of your data. You can withdraw your consent at any time. You can also leave instructions on what happens to your data after your death (Article 85 of the French Data Protection Act).

From your account, you can:

  • edit your profile;
  • export your data ("Export my data");
  • delete your account;
  • restrict processing;
  • object to AI indexing;
  • grant or withdraw support access;
  • manage notifications.

For anything else, write to [email protected]. We reply within one month, which may be extended by two months for complex requests. If we have reasonable doubts about your identity, we may ask you to prove it.

You can lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (www.cnil.fr), or with the authority of your country of residence.

9. Security

Our measures include:

  • hosting in the European Union;
  • encryption in transit (TLS);
  • application-level encryption of secrets and tokens;
  • passwordless sign-in, with passkeys required for administrative roles;
  • isolation between spaces;
  • rate limiting;
  • logging of sign-ins, support access and agent actions;
  • encrypted backups, with a sample read back weekly.

See Annex 2 of the DPA for details.

10. Cookies and trackers

NamePurposeTypeDuration
auth_sessionkeep you signed instrictly necessary1 year; the server-side session expires after 7 days
tblflow_consentremember your cookie choicesstrictly necessary1 year
NEXT_LOCALEremember your languagestrictly necessary1 year
tblflow_impersonationsupport access session, if you allowed itstrictly necessary30 minutes at most
cookie named after a share IDaccess to a password-protected sharestrictly necessaryfor the visit
oauth_state_* and similarsecure the connection of a third-party accountstrictly necessaryfor the connection
Chatwoot cookiessupport chat, set only if you open itneeded for supportset by Chatwoot
Google Analytics cookies (_ga*)audience measurement of tblflow.comconsent required13 months at most

Consent-based trackers are set only after you agree. To change your choice, clear the site's cookies and the banner will be shown again.

11. Data breaches

If a breach presents a risk to individuals, we notify the CNIL within 72 hours. If the risk is high, we also inform you.

12. Changes

This policy is dated and versioned. We announce any substantial change by e-mail or in the product before it takes effect.

This is a translation. The French version prevails.