Privacy policy
Version 1.1 — published 23 September 2026, effective 7 October 2026. Previous version: 1.0 of 15 September 2026.
1. Controller
SPACE UNITY, a French SASU with variable capital, RCS Sedan 994 377 208, 34 route Nationale, 08140 Douzy, France ("we").
To contact us about data protection:
- by e-mail at [email protected];
- by post to SPACE UNITY, Data protection, at the address above.
We have not appointed a data protection officer, as this is not mandatory for our activity. Management handles requests directly.
2. Scope of this policy
This policy covers the data we process on our own behalf: data about users of app.tblflow.com, our customers and prospects, and people who contact support.
Space content is different. This means data that a customer organisation stores about its own customers, employees or contacts, or collects through the forms and interfaces it publishes. For that data, the customer organisation is the controller and we act as its processor under the Data processing agreement. If your data appears in such content, please contact that organisation. We forward any request we receive to it.
3. Data, purposes and legal bases
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Create and manage your account, authenticate you | e-mail, name; if you provide them, first name, last name, phone and avatar; language; passkeys (public key); recovery codes (hashed); date terms were accepted; sign-in dates | performance of the contract | life of the account; erased on deletion (§ 7) |
| Collaboration: invitations, comments, mentions, notifications | invitee e-mails, comments, notifications, notification preferences, recently visited resources | performance of the contract | life of the account; e-mail invitations expire after one month |
| Invitations to a shared app | email of the invited person, inviter and date; on sign-up, the account (§ 3, first row), without a personal space | performance of the contract (of the inviting organisation); pre-contractual steps for the invited person | as long as the invitation exists; the account follows § 7 |
| Security: logging sign-ins and sensitive actions, abuse detection | IP address, account ID, e-mail address used, event, timestamp | legitimate interest (security of the Service, Art. 32 GDPR) | log: 6 months; session: 7 days |
| Customer support by chat and e-mail | ID, e-mail, name, plan and subscription status, space name and ID, number of spaces, messages exchanged | performance of the contract | life of the account, then deleted within 30 days of closure |
| Automated AI replies in the support chat | message sent to the chat | legitimate interest (responsive support) | life of the conversation |
| Support access to your account | data displayed during the access, reason, timestamps | consent, given and withdrawn in your settings | access: 30 minutes at most; record kept 6 months |
| Billing and subscription management | billing e-mail, Stripe customer and subscription IDs, plan, status, renewal date; Stripe collects name, address and payment method | performance of the contract; legal obligation (accounting) | life of the subscription; accounting records: 10 years |
| AI features you trigger | content submitted for processing | performance of the contract | for the duration of processing by the provider (§ 4) |
| AI indexing of your documents (chunking, embeddings, memory extraction) | content of the documents you import | legitimate interest (relevant search and assistant), with a right to object | as long as the document exists |
| Browser skills | site address, username, encrypted secret, certification | performance of the contract | 90 days without use (§ 4a) |
| Voice narration of a browser skill, if you turn it on | timestamped text of your explanations; no audio | consent, given by turning on the microphone | until the skill is validated, then deleted (§ 4b) |
| Audience measurement of tblflow.com (Google Analytics) | pseudonymous ID, pages viewed and events, technical device information | consent | trackers: 13 months at most; data: 14 months at most |
| Information about Service updates | e-mail, name | legitimate interest (business-to-business marketing); you can object at any time | until you object, or 3 years after last contact |
| Waiting list | pre-contractual steps taken at your request | until your access opens or you ask to be removed | |
| Establishing and defending our rights, responding to authorities | strictly necessary data | legitimate interest; legal obligation | applicable limitation period |
We do not ask for any sensitive data. We make no decision based solely on automated processing that produces legal effects concerning you. We do not sell your data and do not run targeted advertising.
4. Artificial intelligence features
When you use an AI feature, the content it needs is sent to the chosen model for the duration of the processing, either directly or through the Vercel AI Gateway. The providers used on our instance are listed in § 5.
If your space is configured with its own provider key or a local model, that provider was chosen by the customer organisation and is not one of our processors.
We do not use your content to train models. We use providers' business (API) offerings, whose terms exclude training on submitted data by default. Some providers keep that data for a few weeks to detect abuse, under their own terms.
Secrets are never sent to a model. This includes passwords, tokens and browser skill credentials.
Your choices. In your account settings, under "Data processing", you can:
- object to AI indexing of your documents, which covers chunking, embeddings and memory extraction;
- restrict processing. This suspends automated processing that is not essential to the Service (currently, that indexing) without deleting your data.
Other AI features run only when a user asks, or as configured for the space by the customer.
4a. Browser skills and saved credentials
A "browser skill" replays a journey you recorded on a third-party site. If that journey requires signing in, you may save the corresponding credential.
What we do with it.
- The secret is encrypted before storage, with a key dedicated to this purpose.
- It is never displayed again, never returned by our interface and never written to our logs.
- It is never sent to an AI model. Screenshots submitted to a model are masked first.
- During a replay, our server types the value into the page. It never passes through your browser.
Who can use it. The credential belongs to the base, not to you: anyone with write access to that base will be able to use it to sign in, without ever seeing its value. Bear this in mind before saving an access.
What you must certify. You certify that the saved account belongs to you or to your organisation. Third-party accounts are out of scope.
For how long. The credential is deleted automatically after 90 days without use. You can delete it at any time and save it again. It is also deleted with the skill, with the base or with your account.
What we do not store. Physical security keys (WebAuthn) cannot be saved: the key stays with you.
4b. Voice narration while recording a skill
While recording a browser skill, you can turn on the microphone to explain aloud what you are doing and why. These explanations become the skill's rules.
What we receive. Text only, timestamped. Speech recognition happens in your browser: no audio reaches our servers, and we keep none.
Who receives your voice. To transcribe it, your browser sends the audio to its vendor's speech recognition service: Google for Chrome, Microsoft for Edge, Apple for Safari. This transfer is made by your browser, under its vendor's policy, and the vendor may process the audio outside the European Union. These vendors are not our processors: we neither receive nor transmit this audio.
How long. The text is kept with the skill until it is validated. On validation, its useful parts are carried into the skill's rules, with their timestamps, and the raw text is deleted; it leaves our backups according to the rotation in § 7. It is also deleted with the skill, the base or your account.
Who can read it. Until the skill is validated, the people who have access to its base.
Your choices. The microphone is off by default. You turn it on yourself, for one recording, and can stop it at any time.
5. Recipients and processors
Your data is accessible only to authorised SPACE UNITY staff who need it. It is also visible to members of the spaces you join, according to their roles. We disclose it to authorities only when legally required to do so. Our processors are:
| Provider | Role | Data location | Transfer safeguard |
|---|---|---|---|
| netcup GmbH | application and database hosting | Germany | — (EU) |
| Cloudflare, Inc. | network, protection, access tunnel; file and backup storage (R2) | files and backups: EU; transit: global network | Data Privacy Framework; standard clauses |
| Plus Five Five, Inc. (Resend) | e-mail delivery: sign-in links, invitations, notifications | United States | Data Privacy Framework; standard clauses |
| Stripe Payments Europe, Limited | payments and subscriptions | Ireland; transfers to Stripe, Inc. (United States) | Data Privacy Framework; standard clauses |
| Chatwoot, Inc. | support chat | United States | standard clauses |
| Google Ireland Limited | audience measurement of tblflow.com, with your consent | Ireland; United States (Google LLC) | Data Privacy Framework; standard clauses |
| Vercel, Inc. | gateway to AI models | United States | Data Privacy Framework; standard clauses |
| Anthropic, PBC | language models | United States | standard clauses |
| OpenAI | language models, document embeddings | United States | standard clauses |
| Mistral AI | language models | France | — (EU) |
| Replicate, Inc. | image and video generation | United States | standard clauses |
| Eleven Labs, Inc. (ElevenLabs) | speech synthesis and transcription | United States | standard clauses |
We add any new processor to this list before using it.
Stripe also acts as a separate controller for its own obligations, such as fraud prevention and regulatory compliance.
Third-party services that you connect yourself receive and send data on your initiative, under their own policies. These include mail, calendar, storage, team chat, code hosting and APIs.
6. Transfers outside the European Union
Some providers are based in the United States. Transfers to them rely on one of the following:
- the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, where the provider is certified;
- otherwise, the standard contractual clauses adopted by the Commission on 4 June 2021.
These safeguards are supplemented by additional measures: encryption in transit, minimisation of the data sent, and exclusion of secrets.
You can request a copy of the safeguards at [email protected].
7. Account deletion and retention
Account deletion takes effect immediately:
- your e-mail address and name are replaced with anonymous values;
- your phone number, first and last names and avatar are erased;
- your passkeys, recovery codes, tokens, connected accounts, browser skill credentials and notifications are deleted;
- your comments are anonymised.
Records you created in other organisations' spaces remain there, attributed to a "deleted user".
Trash: a deleted space, base or table stays in the trash for 30 days and is then permanently erased.
Backups are taken hourly and encrypted. They are kept on a rotation that thins out over time: 48 hours, 14 days, 8 weeks, 12 months, then 3 years. Deleted data leaves the backups when the last backup containing it expires. Backups are used only to restore the Service.
Other retention periods are listed in the table in § 3.
8. Your rights
You have the right to access, rectify, erase, restrict, port and object to the processing of your data. You can withdraw your consent at any time. You can also leave instructions on what happens to your data after your death (Article 85 of the French Data Protection Act).
From your account, you can:
- edit your profile;
- export your data ("Export my data");
- delete your account;
- restrict processing;
- object to AI indexing;
- grant or withdraw support access;
- manage notifications.
For anything else, write to [email protected]. We reply within one month, which may be extended by two months for complex requests. If we have reasonable doubts about your identity, we may ask you to prove it.
You can lodge a complaint with the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (www.cnil.fr), or with the authority of your country of residence.
9. Security
Our measures include:
- hosting in the European Union;
- encryption in transit (TLS);
- application-level encryption of secrets and tokens;
- passwordless sign-in, with passkeys required for administrative roles;
- isolation between spaces;
- rate limiting;
- logging of sign-ins, support access and agent actions;
- encrypted backups, with a sample read back weekly.
See Annex 2 of the DPA for details.
10. Cookies and trackers
| Name | Purpose | Type | Duration |
|---|---|---|---|
auth_session | keep you signed in | strictly necessary | 1 year; the server-side session expires after 7 days |
tblflow_consent | remember your cookie choices | strictly necessary | 1 year |
NEXT_LOCALE | remember your language | strictly necessary | 1 year |
tblflow_impersonation | support access session, if you allowed it | strictly necessary | 30 minutes at most |
| cookie named after a share ID | access to a password-protected share | strictly necessary | for the visit |
oauth_state_* and similar | secure the connection of a third-party account | strictly necessary | for the connection |
| Chatwoot cookies | support chat, set only if you open it | needed for support | set by Chatwoot |
Google Analytics cookies (_ga*) | audience measurement of tblflow.com | consent required | 13 months at most |
Consent-based trackers are set only after you agree. To change your choice, clear the site's cookies and the banner will be shown again.
11. Data breaches
If a breach presents a risk to individuals, we notify the CNIL within 72 hours. If the risk is high, we also inform you.
12. Changes
This policy is dated and versioned. We announce any substantial change by e-mail or in the product before it takes effect.
This is a translation. The French version prevails.