1. Data controller
Data controller: KAIRISIO.
Registered office: 19 rue Vincent d'Indy 07300 Tournon-sur-Rhône.
Data protection contact: contact@palen.fr.
Last updated : September 3, 2026
Information about personal data processing carried out in connection with the Palen service.
Data controller: KAIRISIO.
Registered office: 19 rue Vincent d'Indy 07300 Tournon-sur-Rhône.
Data protection contact: contact@palen.fr.
This policy applies only to information relating to an identified or identifiable individual. Information that does not directly or indirectly identify an individual is not personal data and falls outside its scope.
Palen is intended for professional users. Where information about a business also identifies an individual, including a sole trader or named contact, it is treated as personal data.
Each processing activity relies on the legal basis stated below. KAIRISIO does not reuse data for a purpose incompatible with the stated purpose.
| Personal data | Purpose | Legal basis | Retention period |
|---|---|---|---|
| Email address and federated account identifier | Create the account, authenticate the user and maintain secure access to the service; when optional audience measurement is accepted, measure platform usage and produce statistics | Pre-contractual steps and performance of the contract; consent for optional audience measurement | Sign-in link: 24 hours. Session: for the applicable security period. Audience measurement: 1 year |
| IP address and session identifier | Secure accounts and the service, prevent fraudulent use, diagnose errors and investigate incidents | KAIRISIO’s legitimate interest in protecting the service and its users | For the period strictly necessary for security, incident analysis and the defence of legal rights, then deletion or anonymisation |
| Name, email address and billing address | Create and administer the subscription, collect payments, and issue mandatory accounting and tax records | Performance of the contract; legal obligation for accounting and tax records | During the commercial relationship, then ten years from the end of the relevant financial year for accounting records |
| First name, last name and email address where provided in a contact or support request | Respond to the request and follow it up | Pre-contractual steps or performance of the contract, depending on the request | While handling and usefully following up the request, then deletion or anonymisation unless evidence must be retained |
Personal data processing carried out by Palen
The email address and authentication data are required to create and use an account. Billing information requested by Stripe is required to subscribe to a paid plan and issue the relevant records.
Users freely choose the messages, documents and information they submit. Palen can only produce an answer from the information provided for the request.
Contact form data is required to handle the request where marked as mandatory.
Until you refuse it, optional browser audience measurement may be linked to your account or to a journey identifier that could make you indirectly identifiable. After you refuse, these trackers are disabled. Palen retains only measurement used to produce anonymised audience statistics, processed separately from your account, without an email address or account identifier.
In both cases, collected data is neither used for cross-site tracking nor sold, and is not shared with any provider other than the one used for audience measurement itself.
Communication action measurement also remains optional.
Palen may measure the display, dismissal and click of the Trustpilot review request without collecting question or analysis content for this purpose. If the request is postponed, it may be shown again after two months. The Trustpilot website opens only after a voluntary action; Palen sends it neither the account email address nor content used in the service.
Messages, documents and information needed for the request may be sent to the AI system to produce the requested analysis or answer. Where possible, the transfer is limited to information useful for fulfilling the request.
Before this transfer, Palen locally replaces some personal data detected with a high level of confidence, including email addresses, phone numbers, social security numbers and explicitly identified names. This measure reduces identification risk without guaranteeing anonymisation of all free-form content.
Users must limit submitted data to what is strictly necessary and hold the required rights or authorisations over the documents and information provided.
Regardless of the cookie choice, server-side AI traces retain previously anonymised prompts and responses, their technical identifiers, and the exact metrics for each generation (provider, model, tokens, cost, currency, duration, status, error and attempts) to improve the service. Secrets, passwords, cookies, authentication tokens and payment data are strictly excluded.
Personal data is available only to authorised KAIRISIO staff and providers that need it for the purpose entrusted to them.
When selecting providers, KAIRISIO gives preference, according to the expected level of performance, first to providers established in France, then to providers established in the European Economic Area. A provider outside the European Economic Area is selected only where no satisfactory solution from either of the first two levels meets the need.
Some providers may process or make available, from the United States or another country outside the European Economic Area, the data needed to provide their service.
Depending on the circumstances, these transfers are governed by an adequacy decision, the EU–US Data Privacy Framework, the European Commission’s Standard Contractual Clauses and, where necessary, supplementary measures.
KAIRISIO verifies that the relevant provider implements appropriate safeguards and sends it only the data necessary for the relevant service.
KAIRISIO implements technical and organisational measures proportionate to the risks, including access controls, limited permissions, encrypted communications, sanitisation of certain technical logs and anti-abuse mechanisms. These measures follow the good practices of the OWASP Top 10, a framework that lists the main security risks for web applications.
As no system can eliminate all risk, users who identify a vulnerability or an incident affecting their data can write to contact@palen.fr.
Depending on the processing concerned, you have rights of access, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests on grounds relating to your particular situation and withdraw consent at any time for processing that depends on it.
To exercise your rights, write to contact@palen.fr. Identity evidence may be requested only where there is reasonable doubt about the requester’s identity. You may also complain to the CNIL.
Users may share certain AI-generated content by enabling the relevant sharing options. Users must ensure that shared content contains no personal or confidential data whose publication is unauthorised.
Deleting the account cancels active subscriptions, deletes or anonymises account-related data and stops communications linked to the account. Only logs and records whose retention remains necessary for security, evidence, accounting or compliance with a legal obligation are retained for the applicable period.
This policy may be updated to reflect changes in processing activities or legal requirements. The date at the top of the page indicates its latest revision.
For any question about personal data protection: contact@palen.fr.