Legal

Privacy policy

Last updated: 26 June 2026

This English translation is provided for convenience. The French version is the legally binding text: Politique de confidentialité (French).

This policy describes how Salesia processes personal data through its salesia.fr website and its platform, in accordance with Regulation (EU) 2016/679 (the GDPR, RGPD in French) and the French Data Protection Act (loi « Informatique et Libertés »).

Data controller

The data controller is Salesia (see the Legal notice). For any question about your data or about exercising your rights: hello@salesia.fr.

The data we collect

1. Demonstration request / prospect

When you request a demonstration or leave your details on the landing page, we collect:

  • your work email address and your telephone number (both required);
  • the name and website URL of your brand, where they are provided;
  • the record of your consent, together with technical data (IP address, browser type) for security and evidential purposes.

Purpose: to get back to you, arrange a demonstration and present the service. Legal basis: your consent (and Salesia's legitimate interest in developing its B2B business).

2. User account (customers)

When an account is created, we process your email address, your identity and your sign-in data (including through Google if you choose that option). Purpose: to provide and secure access to the service. Legal basis: performance of the contract.

3. Business data processed on your behalf

As part of the use of the platform (CRM, orders, catalogue, pharmacies, agents), Salesia processes data on behalf of the client brand. For that data, the brand is the data controller and Salesia acts as a processor, under the conditions set out in the contract (article 28 of the GDPR).

4. Personalised demonstration

When you enter the URL of a website to personalise the demonstration, Salesia retrieves publicly accessible information from that site (name, logo, images and product prices) to populate the demo. Those elements are stored locally in your browser and do not create an account; you can erase them at any time with the “Réinitialiser” (reset) button or by clearing local storage.

Recipients and processors

Your data is never sold. It is accessible to the authorised Salesia team and to our technical processors, strictly for the purposes above:

  • Neon — database (hosted in the EU, Frankfurt);
  • Render — hosting of the website and the API;
  • Supabase — authentication;
  • Resend — transactional email delivery;
  • Mapbox — map display.

Transfers outside the European Union

The main database is hosted in the European Union. Some processors are established in the United States; any transfers are framed by the European Commission's standard contractual clauses and/or by certification under the Data Privacy Framework, which guarantee an adequate level of protection.

Retention periods

  • Prospects: 3 years from the last contact (recommendation of the CNIL, the French data protection authority, for B2B prospecting).
  • Accounts and business data: for the term of the contractual relationship, then archived in line with the applicable legal obligations.
  • Sign-in data / logs: 12 months maximum.

Your rights

You have the rights of access, rectification, erasure, restriction of processing, objection and portability, as well as the right to withdraw your consent at any time and to set instructions on what happens to your data after your death.

To exercise them, write to hello@salesia.fr or by post to Salesia, 16 rue de Picardie, 75003 Paris. You may also lodge a complaint with the CNIL (cnil.fr).

Cookies and trackers

The website uses only cookies and local storage that are strictly necessary for it to work: authentication (session) and remembering how the demonstration was personalised. No advertising cookie and no third-party tracker for targeting purposes is set to date. [If an audience-measurement tool is added, a consent banner will be put in place.]

Security

Salesia implements appropriate technical and organisational measures: encryption of data in transit (TLS), hosting of the database in the European Union, strict separation of the data of each brand and access restricted to authorised people.