Privacy policy
Last updated : July 19, 2026
Data controller
The data controller is NeMMi Group (SASU), whose registered office and contact details appear in the Legal notice. For any question about your data: contact@nemmi.group.
Data we collect
We only collect data necessary to operate the service:
- Email address and account identifier (via Supabase Auth), when you create an account or sign in.
- Feedback / contact messages: message content, email address, session id, user id and the page of origin.
- Simulation inputs you type: society description, question and segments. These free-text fields may contain personal or confidential data; include only what is necessary.
- IP address: used for a country lookup (geolocation) and stored only as a non-reversible hash for abuse prevention (anti-spam / quotas).
- Usage analytics events: page views, sign-ins, simulation launches, report views and downloads, country, referrer host.
Purposes and legal bases
In line with GDPR articles 6, 13 and 14, each processing activity relies on a legal basis:
- Providing the service (account, running simulations, reports), basis: performance of the contract.
- Security, abuse prevention and rate limiting (IP hash, quotas), basis: legitimate interest.
- Responding to contact / feedback requests, basis: legitimate interest / pre-contractual steps.
- Audience measurement and service improvement, basis: legitimate interest or consent, depending on cookie/tracker settings.
- Billing and fraud prevention for credit purchases, basis: performance of the contract and legal obligations (accounting).
Hosting and data location (EU)
Account and application data are stored with Supabase in the eu-north-1 region (European Union). Some sub-processors (see below) are located outside the EU; these transfers are covered by appropriate safeguards: the EU-US Data Privacy Framework adequacy decision for certified processors, and Standard Contractual Clauses (SCCs) for the others.
Sub-processors / recipients
We use the following sub-processors to provide the service. This list must be kept up to date, and every non-EU transfer must be covered by a data processing agreement (DPA) and, where applicable, standard contractual clauses (SCC).
| Sub-processor | Role | Location / transfer |
|---|---|---|
| Supabase | Database and authentication | EU (eu-north-1) |
| LLM gateway (OmniRoute) and Anthropic models (Claude) | Generates the debates and reports: your simulation inputs, the prompts and the reports pass through these models | International (outside EU); signed DPA; Standard Contractual Clauses (SCCs) |
| Tavily | Web search from queries derived from your inputs | United States (outside EU); DPA + SCCs |
| Resend | Email delivery (including contact messages) | United States (outside EU); DPA + SCCs |
| Stripe | Payment and applicable tax calculation (credit purchases) | International (outside EU); Stripe DPA; EU-US Data Privacy Framework adequacy decision |
| Sentry (EU region) | Technical error monitoring (browser and server error logs, no simulation data) | EU (European Union region) |
| Google (Sign-in) | Authentication via 'Sign in with Google' (OAuth), when you choose that sign-in method | International (outside EU); DPA; EU-US DPF adequacy decision |
| Google Analytics / Google Tag Manager | Audience measurement, set only after your consent (Consent Mode v2) | International (outside EU), consent only; EU-US DPF adequacy decision |
| IP-based country lookup | Disabled by default, no transfer. If enabled, the IP is anonymized (last octet dropped) and sent over HTTPS only; target: EU/local solution (MaxMind GeoLite2) | No transfer by default |
Retention periods
- Account data: for the lifetime of the account, then 30 days after deletion.
- Simulation data and reports: 24 months unless deleted at your request.
- Contact / feedback messages: 24 months.
- Analytics events: 13 months.
- Billing data: the legal accounting retention period (generally 10 years in France).
Your rights
Under the GDPR, you have the following rights, exercisable at contact@nemmi.group:
- Right of access to your data.
- Right to rectification of inaccurate data.
- Right to erasure (the 'right to be forgotten') and right to portability / export of your data.
- Right to object and right to restriction of processing.
- Right to withdraw consent at any time, where processing relies on it.
- Right to lodge a complaint with the CNIL (www.cnil.fr) or your local supervisory authority.
Cookies and trackers
The site uses strictly necessary cookies / identifiers (session, language preference) and, where applicable, audience-measurement trackers subject to your consent. A consent banner lets you accept or decline audience-measurement cookies (Google Analytics); no analytics cookie is set without consent.
Contact / DPO
To exercise your rights or for any question: contact@nemmi.group. No data protection officer is appointed, as the nature and volume of processing do not require one.