Privacy policy
AI ARTEDUSA privacy policy: processing of personal and voice data, GDPR compliance, sub-processors, retention periods.
ARTICLE 1 - DATA CONTROLLER
AI ARTEDUSA is the data controller for data related to the client relationship (account and billing of client institutions). For the personal data of callers and end users processed via the Service (audio recordings, transcripts, summaries), the client institution — museum, library, theatre, gallery, or the local authority it falls under — is the data controller, and AI ARTEDUSA acts as a processor within the meaning of Article 28 of the GDPR, on behalf of and on the instructions of the controller. A data processing agreement (DPA) is made available to clients. Contact: support@artedusa.com.
ARTICLE 2 - DATA COLLECTED
As part of the operation of the Service, the following categories of data are collected and processed:
- Identification data: first name, last name, email address, phone number, company name
- Billing data: postal address, SIRET number, banking information (managed by Stripe)
- Voice data: audio recordings of telephone conversations between callers and the AI bot
- Transcript data: text from the voice-to-text conversion of conversations
- Usage data: login logs, call statistics, dashboard navigation data
- Knowledge base data: documents uploaded by the User
ARTICLE 3 - PURPOSES AND LEGAL BASES
Data is processed for the following purposes:
Performance of the contract: Operation of the Service (receiving and processing calls, transcription, summary), user account management, billing.
Legitimate interest: Service improvement, anonymised statistical analysis, fraud and abuse prevention.
Legal obligation: Retention of invoices and accounting data in accordance with applicable legislation.
ARTICLE 4 - SUB-PROCESSORS AND DATA TRANSFERS
Data is processed by the following sub-processors, all contractually bound to comply with the GDPR:
Voice processing (speech recognition and synthesis), semantic search, and data storage are provided on a European infrastructure controlled by AI ARTEDUSA, without recourse to a third-party sub-processor: this data does not leave the European Union.
All sub-processors are established in the European Union. For card payments by private clients (B2B) only, Stripe — as an international group — may use processing in the United States, governed by the European Commission's Standard Contractual Clauses (decision 2021/914).
- OVHcloud (French group, hosting in the European Union): hosting of the application infrastructure and data (servers, PostgreSQL database, Redis cache, Qdrant vector database), telephony connection (SIP trunk), and sending of transactional emails (SMTP)
- Mistral AI (France, EU): language model and embedding computation for conversation processing and augmented search
- Stripe Payments Europe (Ireland, EU): card payment processing, for private clients (B2B) only
ARTICLE 5 - RETENTION PERIODS
Data is retained for the following periods:
- Account data: retained throughout the use of the Service, then deleted upon account closure. Upon erasure request (right to erasure, Art. 17 GDPR), it is deleted within the shortest possible time.
- Voice data (audio recordings): 90 days after the call, unless an early deletion request is made
- Transcripts and summaries: 12 months after the call
- Billing data: 10 years in accordance with accounting obligations
- Login logs: 12 months
ARTICLE 6 - RIGHTS OF DATA SUBJECTS
In accordance with the General Data Protection Regulation (GDPR), you have the following rights:
- Right of access: Obtain a copy of your personal data
- Right of rectification: Correct inaccurate data
- Right to erasure: Request the deletion of your data
- Right to data portability: Receive your data in a structured format
- Right to object: Object to the processing of your data
- Right to restriction: Request restriction of processing