Privacy Policy

Last updated: October 3, 2026

1. Data controller

Monsieur Pipeline — publisher of the Recovizy platform (recovizy.com)
DPO contact: privacy@recovizy.com

2. Data collected

We collect the following data:

  • Account data: email, name, hashed password (bcrypt)
  • Billing data: handled by Qonto and its payment provider — we never store your bank details
  • Connector API keys: encrypted with AES-256 at rest, never exposed in plain text, revocable at any time
  • Imported CRM data: contacts (name, email, phone, company, job title) provided by the user through their REST connectors
  • Usage and scoring data: activity logs, ICP scores, detected signals, AI agent actions
  • Technical data: IP address, browser, session cookies
  • Website telemetry: page viewed, Web Vitals, conversion events and technical error messages, with no advertising cookie or fingerprinting

3. Purposes of processing

  • Providing the service and managing the user account
  • Synchronizing and analyzing CRM data through REST connectors
  • Producing ICP scores, detecting signals and making sales recommendations
  • Processing payments and managing monthly access (Recovizy Scale)
  • Improving the service and anonymized statistics
  • Sending transactional communications (confirmations, invoices, alerts)

4. Legal basis (GDPR)

  • Performance of a contract (Art. 6(1)(b)) for providing the service and analyzing CRM data
  • Legitimate interest (Art. 6(1)(f)) for improving the service and security
  • Consent (Art. 6(1)(a)) for marketing communications

5. Processors

  • Supabase — database hosting (EU region)
  • Qonto / Mollie — secure payment processing
  • Vercel — frontend hosting
  • Anthropic — artificial intelligence models used for scoring and signal detection (data sent anonymized or pseudonymized)

All our processors are bound by GDPR-compliant DPAs. No directly identifying personal data is sent to AI models without prior pseudonymization.

6. Retention periods

  • Account data: length of the contract + 3 years
  • CRM data and scores: deleted when the account is closed
  • Connector API keys: deleted immediately on revocation or account closure
  • Activity logs: rolling 12 months
  • Billing data: 10 years (legal obligation)

7. Security

Recovizy implements the following technical measures to protect your data:

  • TLS encryption in transit for all communications
  • AES-256 encryption at rest for connector API keys
  • Secure authentication with bcrypt password hashing
  • Per-user data isolation (Row Level Security)
  • Restricted and logged access to production data

8. Your rights

Under the GDPR, you have the following rights:

  • Right of access, rectification and erasure
  • Right to data portability
  • Right to object and to restrict processing
  • Right to withdraw your consent at any time

To exercise these rights: privacy@recovizy.com
You may also lodge a complaint with the CNIL, the French data protection authority (cnil.fr).

9. Cookies

Recovizy only uses cookies that are strictly necessary for the service to work (authentication session). No advertising or third-party tracking cookie is used. First-party audience measurement uses a session identifier stored in the browser, performs no fingerprinting and is disabled when the "Do Not Track" signal is on.

This English version is provided for convenience. In case of discrepancy, the French version prevails.