Privacy policy

Last updated : July 19, 2026

Data controller

The data controller is NeMMi Group (SASU), whose registered office and contact details appear in the Legal notice. For any question about your data: contact@nemmi.group.

Data we collect

We only collect data necessary to operate the service:

  • Email address and account identifier (via Supabase Auth), when you create an account or sign in.
  • Feedback / contact messages: message content, email address, session id, user id and the page of origin.
  • Simulation inputs you type: society description, question and segments. These free-text fields may contain personal or confidential data; include only what is necessary.
  • IP address: used for a country lookup (geolocation) and stored only as a non-reversible hash for abuse prevention (anti-spam / quotas).
  • Usage analytics events: page views, sign-ins, simulation launches, report views and downloads, country, referrer host.

Purposes and legal bases

In line with GDPR articles 6, 13 and 14, each processing activity relies on a legal basis:

  • Providing the service (account, running simulations, reports), basis: performance of the contract.
  • Security, abuse prevention and rate limiting (IP hash, quotas), basis: legitimate interest.
  • Responding to contact / feedback requests, basis: legitimate interest / pre-contractual steps.
  • Audience measurement and service improvement, basis: legitimate interest or consent, depending on cookie/tracker settings.
  • Billing and fraud prevention for credit purchases, basis: performance of the contract and legal obligations (accounting).

Hosting and data location (EU)

Account and application data are stored with Supabase in the eu-north-1 region (European Union). Some sub-processors (see below) are located outside the EU; these transfers are covered by appropriate safeguards: the EU-US Data Privacy Framework adequacy decision for certified processors, and Standard Contractual Clauses (SCCs) for the others.

Sub-processors / recipients

We use the following sub-processors to provide the service. This list must be kept up to date, and every non-EU transfer must be covered by a data processing agreement (DPA) and, where applicable, standard contractual clauses (SCC).

Sub-processorRoleLocation / transfer
SupabaseDatabase and authenticationEU (eu-north-1)
LLM gateway (OmniRoute) and Anthropic models (Claude)Generates the debates and reports: your simulation inputs, the prompts and the reports pass through these modelsInternational (outside EU); signed DPA; Standard Contractual Clauses (SCCs)
TavilyWeb search from queries derived from your inputsUnited States (outside EU); DPA + SCCs
ResendEmail delivery (including contact messages)United States (outside EU); DPA + SCCs
StripePayment and applicable tax calculation (credit purchases)International (outside EU); Stripe DPA; EU-US Data Privacy Framework adequacy decision
Sentry (EU region)Technical error monitoring (browser and server error logs, no simulation data)EU (European Union region)
Google (Sign-in)Authentication via 'Sign in with Google' (OAuth), when you choose that sign-in methodInternational (outside EU); DPA; EU-US DPF adequacy decision
Google Analytics / Google Tag ManagerAudience measurement, set only after your consent (Consent Mode v2)International (outside EU), consent only; EU-US DPF adequacy decision
IP-based country lookupDisabled by default, no transfer. If enabled, the IP is anonymized (last octet dropped) and sent over HTTPS only; target: EU/local solution (MaxMind GeoLite2)No transfer by default

Retention periods

  • Account data: for the lifetime of the account, then 30 days after deletion.
  • Simulation data and reports: 24 months unless deleted at your request.
  • Contact / feedback messages: 24 months.
  • Analytics events: 13 months.
  • Billing data: the legal accounting retention period (generally 10 years in France).

Your rights

Under the GDPR, you have the following rights, exercisable at contact@nemmi.group:

  • Right of access to your data.
  • Right to rectification of inaccurate data.
  • Right to erasure (the 'right to be forgotten') and right to portability / export of your data.
  • Right to object and right to restriction of processing.
  • Right to withdraw consent at any time, where processing relies on it.
  • Right to lodge a complaint with the CNIL (www.cnil.fr) or your local supervisory authority.

Cookies and trackers

The site uses strictly necessary cookies / identifiers (session, language preference) and, where applicable, audience-measurement trackers subject to your consent. A consent banner lets you accept or decline audience-measurement cookies (Google Analytics); no analytics cookie is set without consent.

Contact / DPO

To exercise your rights or for any question: contact@nemmi.group. No data protection officer is appointed, as the nature and volume of processing do not require one.