Legal information

Privacy policy

Last updated: 22 September 2026

This policy explains what personal data Noki Mind collects, why it collects it, who it is shared with, how long it is kept and which rights you can exercise.

It is written to be read: every processing activity is tied to a purpose and to a legal basis under the General Data Protection Regulation (GDPR).

1. Who is responsible for your data

The data controller is Eco Pulse, SASU, publisher of this site and of the application it hosts. Full details are in the legal notice.

For any question about this policy, to exercise your rights or to report an incident: contact@nokimind.com. No data protection officer has been appointed: neither the size of the company nor the nature of the processing requires one.

2. What this policy covers

The service comes in four shapes, and this policy covers all four.

  • The public site: presentation pages and contact form, plus the questionnaires an agency sends its clients through a private link.
  • Online quotes: a quote opens from a private link, and can be read, commented on and signed without an account.
  • The signed-in areas: the client area (quotes, invoices, task tracking and the discussion threads that go with it, delivered reports with their comment threads, performance metrics tracked for the company, publishing content submitted to the company for approval, messaging, shared credentials, shared files, notifications, and the list of the people at the company who have access to it) and the admin area reserved for the Noki Mind team.
  • The B2B platform: the wholesale catalogues that wholesalers publish and run themselves, the area in which they run them, and the accounts retailers open in order to buy there. That public is neither a client of the agency nor a member of its team: its data lives apart, and no agency has access to it.

It does not cover the shops we build for our clients: each has its own policy, and the retailer answers for it.

3. What data, what for, on what basis

We only collect what the service needs to work, and nothing more. For each situation: what is collected, what it is used for, and what makes it lawful.

  • Contact form: name, email address, phone (optional), shop name, profile and message. To answer your request and prepare a proposal. Legal basis: pre-contractual steps taken at your request.
  • Questionnaire sent by an agency: your answers, the email address the link was sent to when it was sent by email, and the dates it was sent, first opened and answered. A questionnaire is always attached to the record of the client it is addressed to: it is never filled in self-service, and what you write in it is read only by the team of the agency that sent it. Sending your answers is flagged to that agency's team, through the channels each of its members chose for their notifications: that notice carries the questionnaire title, the name of the record the questionnaire is attached to and how many questions found an answer, never your answers themselves, which are only read on the screen of your submission. To prepare a diagnosis and a fitting proposal. Legal basis: pre-contractual steps, or performance of the contract once the engagement has started. Your progress is saved as you go: you can close the page and come back later with the same link, with no account to create. That link carries a secret token that cannot be guessed and that grants access: only pass it on to whoever should answer. If you read the questionnaire in a language other than the one it was written in, the question labels, and only those, are sent to our language-model provider to be translated; your answers never are, and the translation obtained is kept so it is not requested again.
  • Signed-in account: email address, name, profile picture (optional: if you come in through “Continue with Google”, your Google account picture stands for you by default, read when displayed and never copied to us; uploading one here replaces it), language, display settings you save yourself (task list views, for instance, with the name you give them), and either a password (never kept in clear) or your Google account identifier if you choose that way in. To open the area, recognise you there and hand it back to you as you left it. Your name and your picture stand for you everywhere the application shows you (a task assigned to you, a message you write), and are therefore seen by everyone who shares those screens with you: the people at your company, and those at the other company on the engagement. Your email address, your language and your display settings, on the other hand, never leave your account. You change that address from your settings: a confirmation link then goes to the new one, and another to the current one, which stays yours until they are opened. An account is created in one of two ways: through the link of a personal invitation, or by yourself from the sign-in page, in which case a confirmation link goes to the address you entered and the account opens nothing until that link is opened. Legal basis: performance of the contract.
  • Agency: the name you give it when creating it, the date it was created, and the list of accounts that are members of it with each one's role (owner, administrator, member). An agency is born from the account that creates it, which becomes its owner; other members join by invitation. That name is the one your clients see in the area you open for them. Everything the agency produces is attached to it, and it is that attachment which means no agency ever sees another's data. Legal basis: performance of the contract.
  • Invitation to a signed-in area: the invited email address, the date it was sent, the date it was accepted or cancelled, and the account that invited. An invitation to a client area comes from Noki Mind, or from someone who already has access to that area and enters a colleague's address: we process that address on behalf of their company, for the sole purpose of sending the link and opening the access. The link only works for the invited address, expires after seven days, and the secret it carries is only ever stored as a fingerprint. The row then stays in the access list, which says how someone got in and why a link no longer works. Legal basis: performance of the contract.
  • Quotes, comments and signature: the signer's declared identity (name, role, email address), selected lines, totals recomputed by the server, date and time, a SHA-256 fingerprint of the document, the verification code sent by email, and the drawn or typed signature. To establish proof of the agreement. Legal basis: performance of the contract and legal retention obligations.
  • Invoices: the PDF of every invoice we send you, exactly as it comes out of our accounting software, plus a copy of its number, issue date, due date, total including VAT and the VAT it contains. The application creates no invoice: it reads the uploaded document to propose those five values, which a member of the Noki Mind team checks and corrects before saving them, the due date being worked out from the issue date when the document states a payment delay rather than a date, and remaining correctable or removable afterwards by the Noki Mind team, and it is that saving which makes the invoice appear in your area and which notifies you, through the channels you chose for your notifications. That notice carries the invoice number and its total, never the document itself nor a link that opens it. On the due date, and on that date only, a reminder is sent to you the same way and through the same channels if no payment has been recorded yet: it carries the invoice number, its total and the day of that due date, it goes out only once for a given due date, the application keeping for that purpose the due date it went out for, and a due date corrected by the Noki Mind team makes a new one go out on the day. An invoice with no due date triggers none, and a due date already past is not caught up. To this is added, once the Noki Mind team records your payment from its bank statement, the date of that payment, entered by hand and correctable or erasable in the same way: it serves the team to know what is still due and to follow up with you, it is what stops the reminder above, it is shown neither in your area nor in any notification, and nothing guesses it on your behalf. The PDF lives in private storage, visible to you and to the Noki Mind team, and is downloaded through a short-lived signed link. To hand you your invoices and keep a record of them. Legal basis: performance of the contract and legal retention obligations.
  • Running the engagement: tasks, the reports the agency delivers to you (their name, the date they were delivered, their content and the media illustrating them), messages written in a task or report thread and the people you name in them, people named in the text of a task or a report itself, with the name they bore at that moment and their account identifier, both written into the text so that the name stays accurate when it changes elsewhere (only people who already see that text can be named in it, the others fall back to plain text and are told nothing; the people named are notified through the channels they chose, and on a report that notice only goes out on publication, since that is when the text reaches you), the passage of the text a message comments on when it targets one (it keeps a copy of that passage, so as to find the spot it speaks of even after a rewrite), the message it replies to, the date of its last correction when its author has revised it, and whether a remark has been marked as handled, with the date and the name of whoever closed it, meeting notes and transcripts produced by our video tools, linked to your record from the email addresses of the participants and of the people invited to the calendar event the meeting comes from, or, where no address points to you, from your company's name where it is spoken in the meeting or carried by its title. A meeting summary, and the tasks the application then suggests to the team, are written automatically from the transcript by a language model (see the list of our providers below); those suggested tasks stay internal until a team member takes one over. The same model reads back what we already hold about you (your record, the custom data we keep on it, the engagement's tasks and our internal notes about you) and suggests to the team the corrections the meeting calls for: a contact detail that has changed, a deadline pushed back, a note that has become wrong. Those suggestions are internal and write nothing: they show the current state next to the suggested value, and a team member accepts them, corrects them before accepting, or dismisses them. Nothing changes in our data without that gesture. To write that summary, the application matches the announced participants against the accounts that exist on our side, those of the Noki Mind team and those you have opened in your area, by comparing their name and their email address; the name of those accounts is sent to the model along with the transcript, so that the summary names people as you name them and so that a suggested task can be handed to a team member. That matching is not stored, it is redone on each read, and it never hands a task to one of your contacts. To carry out the work and keep a record of it. A report is an internal note of the Noki Mind team (see the next line) that we publish to you: it only shows up in your area from that moment, in the shape it had then, and any later correction reaches you at the next publication. We may withdraw it from your area, which also closes its thread and its media without deleting anything on our side. A task or report thread is shared by everyone who can see the task or the report: when they are open to you, what is written there is readable by you, and what you write there is readable by the team. On a report, that sharing only covers what is written from its publication onwards: the exchanges the team held under the note before it was delivered to you stay internal to it, as do the replies later made to them. Everyone edits and deletes the messages they wrote themselves, and only those: an edit shows, the thread carrying an “edited” mark next to the message's date, and a deletion is final, the row being erased from our databases. A message that has already been replied to can no longer be deleted, so that other people's replies do not go with it; it stays editable. A message is formatted text: it carries headings, lists, links, images placed inside it and attached files, exactly like the text it comments on. Those images and files live in separate storage spaces, described below with shared files, and only open to whoever can already read the message carrying them. Marking a remark as handled is a gesture of the Noki Mind team. On a report, the closed question then leaves your area along with its replies: nothing is deleted on our side, your right of access applies to it as to everything else, but it no longer shows and can no longer be written in. On a task, it stays readable, simply filed behind its counter. Legal basis: performance of the contract.
  • Decisions: what the Noki Mind team has settled over the course of the engagement, with the wording of the decision, the reasoning that carried it, the option that was ruled out where there was one, the day it was taken, the name of the person at your company it was taken with where it was taken with you, the meeting or the note it comes from, the passage that establishes it, and the team member who recorded it. A decision is never rewritten: when it changes, a new one is written and the earlier one is marked as superseded, pointing to it, so that yesterday's reasoning stays readable; a decision abandoned with nothing put in its place is marked the same way. These decisions are internal to the Noki Mind team and do not appear in your area: what you are told of them comes through the reports we deliver to you. They are read by the language model that assists the team (see the list of our providers below), so that it does not suggest what has already been ruled out and so that it recognises a reversal instead of adding a contradictory decision. To carry out the work and keep a record of why it took this path. Legal basis: performance of the contract.
  • Performance metrics (KPIs): the indicators Noki Mind tracks for your company (revenue, conversion rate, average basket, number of orders, or any other the engagement calls for), with their name, their unit, what they cover, and the series of recorded values, each carrying the period it describes (a day, a week, a month, a quarter, a year or a free range) and possibly carrying a note that explains it. These figures come from you or from your tools, and it is the Noki Mind team that records them, one value at a time or by importing a CSV file it has prepared: the application fetches them from nowhere, connects to no shop and computes none of them. To measure what the engagement produces and show it to you. A metric and its readings are visible in your area as soon as they are saved, and follow the retention period of your company data. Legal basis: performance of the contract.
  • Publishing content: the posts Noki Mind prepares for your company's social accounts, with their internal title, the copy as it will ship, the tags that sort them (the account they go out on, their format, the campaign they belong to), the stage they are at, the planned publishing day and time, the assets they are made of along with the order they will go out in, the link to the live post, the date they went live, and the Noki Mind team members writing them. The copy may name someone from the Noki Mind team or from your company, under the same rules as a task's text: their name at that moment and their account identifier are written into the text, they are notified through the channels they chose, and someone from your company can only be named there once the content has been submitted to you. An asset is one of two kinds. Either it is an image or a video we upload: it then lives in the same private storage as your shared files and counts towards the same quota, but it does not appear in your space's folder, because it was not sent to you, it makes up a post. We may have uploaded it before we even knew who the post would be for: it then belongs to Noki Mind alone, and only joins your storage and your quota when we attach that post to your company. Or it is an address we cite, pointing at an image that lives elsewhere (your own online storage, a photographer's): we then keep only the address, we host no copy of it, and opening it takes you to whoever hosts it, whose own rules then apply. Both kinds are ordered in the same list and read under the same conditions: they only become available to you from the moment we submit the content, and they disappear along with it. To prepare, get approval for and schedule what will be published in your name. A piece of content only appears in your space from the moment we submit it to you: what we write before that stays internal, so you never see a draft in progress. The link copied on a post, on your side as on ours, carries a token that shows its title and its first visual to whoever holds that link, with no account: that is what makes a link pasted into a conversation say which post it is about. It shows nothing else (neither the copy, nor the thread, nor your company, nor the stage it has reached), it does not open the service, and it is only valid for the post it names. Legal basis: performance of the contract.
  • The thread of a piece of publishing content: your feedback and ours, in the order it was written. On your side, your decision (approved, or to improve), the comment you attach to it, the date of your reply and the name your account carries at that moment, kept as it was so the exchange stays readable even if that account is closed later. A rejection must say what needs reworking: the comment is then required. On our side, the comments the Noki Mind team writes under the content at any stage of its preparation, with their author's name and their date; the team never renders a decision, approving or sending back a piece of content stays your gesture. These exchanges are written in the editor, on both sides: they carry lists, links, images placed inside them and attached files, which live in the same separate storage spaces as those of a task thread and only open to whoever can already read the message carrying them. A comment we write before submitting the content to you is an internal note and stays one: it is not shown to you, and submitting the content afterwards does not open it to you retroactively. What we write once the content is in your space is readable by you, and our screen tells us so before we write. These exchanges are read by the Noki Mind team and, for whatever is open to you, by the people who have access to your space; they are neither erased nor rewritten, and the whole thread stays attached to the content: that is what makes it possible to know why a post was reworked. Each reply is flagged to us through the channels you chose for your notifications, and each piece of content we submit to you is flagged to you the same way. Legal basis: performance of the contract.
  • Notes of the Noki Mind team: the texts we write to run the engagement and keep track of it (meeting notes, methods, a history of what was tried), along with the name of their author, the date they were written, the exchanges we hold below them (including the passage of the text a remark targets, when it targets one, and the date it was closed), the folder we file them in, and the client record they relate to when they relate to one. They may therefore speak of your company and of the people working there. They are written for ourselves and are readable by the Noki Mind team only, except when we decide to publish one to you: it then becomes the report you read in your area, described in the previous line, and its comment thread opens to you from that point on, whatever was said under it before publication remaining internal. Your rights, starting with access, apply to these notes as to everything else, whether or not they have been published to you. Legal basis: our legitimate interest in organising our work.
  • Conversations with the assistant of the admin workspace: what a Noki Mind team member asks the assistant in their workspace, what it answers, the actions it took on their request and what it went on to read from our data in order to answer, which may therefore include what we hold about your company and the people who work there. The thread is kept so that its author can find it again and pick it up later, under a title we have summarised from its first message; only they can read it, not even the other members of the team, and they rename or delete it whenever they want. What goes to the provider routing those exchanges to a language model is described further down, in the list of our providers. Legal basis: our legitimate interest in organising our work.
  • Custom data on a client record: the details the agency chooses to track about each of its clients, on top of those the record already asks for. The agency defines these entries itself (your shop address, a director's professional profile, a due date, a checkbox) and fills in what it knows: they may therefore concern your company as well as the people working there. They are readable by the Noki Mind team only, never appear in your area, and follow the retention period of your company data; your rights, starting with access, apply to them as to everything else. Legal basis: our legitimate interest in running the engagement.
  • Connected calendar of a Noki Mind team member: the authorised Google address, the account identifier, the state of the connection and the date of the last sync. The Google authorisation grants read-only access to the upcoming events of that calendar (title, time, list of guests and their answer, meeting link), the guests of a recorded event serving to work out which client record the meeting belongs to, without that list being kept, and, where recording of meetings opened on the fly is turned on, to the name and link of the meetings that member hosts, for the sole purpose of spotting the meetings to record. It also grants the right to open a video call room in that member's name, and only when they ask for it from the meetings screen: a room opened this way is added to no calendar, invites nobody, and its link is handed back to them only so they can share it. The app never writes to a calendar, and reaches neither the contents of a meeting nor those of a message. The token issued by Google is handed to our recording provider and kept on our side encrypted, under a key that does not live in the database, for that sole use. Legal basis: our legitimate interest in keeping a record of the engagement's meetings, and the authorisation can be withdrawn at any time.
  • Messaging: the subject of each conversation, the messages exchanged about it, their date, the name their author had when writing, the state of the conversation, and the files attached to messages. To discuss the engagement and keep a record of it. A conversation is shared between your company and the Noki Mind team: what you write there is readable by us, and what we reply is readable by everyone who has access to your area. A message is formatted text: it carries headings, lists, quotes, tables and links. A file attached to a message is a shared file and follows exactly the same rules: it joins the folder in your area, where you find it and remove it like the others, including when you drop it by pasting it into the area where you write. They follow the retention period of your company's data. Legal basis: performance of the contract.
  • Shared credentials: the access to your tools (shop, host, ad account) that you entrust to us so we can work. It is encrypted at rest, every read is logged, and it can be revoked at any time. Legal basis: performance of the contract.
  • Shared files: the documents, images and videos added to the folder in your area, attached to a message in a conversation or added as media of a report, along with their original name, type, size, the date they were added, which side added them, the folder they are filed in and, where applicable, the message or the report carrying them. To exchange whatever the engagement needs. They live in a private storage space, visible to you and to the Noki Mind team, and you can remove anything that came from your side at any time. Filing into folders is kept by the Noki Mind team: it alone creates, renames, moves and deletes those folders, you see all of them, and you add files to the one you have open. Deleting a folder deletes no file: what it held moves up one level. The media of a report differ on two points: they do not appear in the folder in your area, and they are only readable to you for as long as the report is. Whatever is placed inside a text follows a third path: images, and files attached to a message in a task or report thread, whether we or you add them. They live in two separate storage spaces, they do not appear in your folder either, they do not count against the space allowed to your company, and they only open to whoever can already read the text carrying them: removing the report or the task from your area closes what they carried in the same gesture. A file attached to a text is never executed by the service, and those a browser could interpret are downloaded instead of being displayed, as in the shared folder. At a team member's request, the assistant in their admin workspace, or an assistant the agency has plugged into that workspace, may read the TEXT of a file that has been added (a PDF that carries one, a text file) in order to summarise it or look something up in it: that text is then routed to the language model answering them, under the same conditions as everything else that assistant reads in our data (see the list of our providers below), and we keep no copy of it. The file itself does not leave that way: neither the bytes nor a link is handed to an assistant for it to read. A file may however be SENT to a service the agency has connected to its workspace, when a team member asks for it (placing your visuals on your shop, for instance): the application then creates a temporary download link, which that service follows to come and fetch the file itself. That link opens that one file, it lasts thirty minutes and ten downloads, it is published nowhere, and every download checks that whoever asked for it still has access to your folder: their departure from the agency is enough to close it. Every addition to the shared folder is flagged to the other side through the channels it chose for its notifications, the notice carrying the file name, the name of the person who added it when the addition comes from you, and “Noki Mind” when it comes from us. Files added within the same fifteen minutes give a single notice, which then states how many there are and the name of the last one to arrive: for that purpose the application keeps, for the length of that window, how many files have arrived and for which person to notify, keeping nothing of what was added. Legal basis: performance of the contract.
  • Notifications: channel preferences, email address and, if you turn it on, your browser's push subscription. To this is added, for events that arrive in batches, the count of those within the same fifteen minutes, which serves to send a single notice rather than one per file and clears itself at the end of the window. To tell you about what concerns you. Legal basis: performance of the contract, and your consent for push, which you can withdraw from your account at any time.
  • B2B platform seller account: one account runs as many catalogues there as it likes, and each carries the identity of the company that runs it (its legal name, its company registration number and the nine-digit number derived from it), asked when it is opened and without which a catalogue cannot be published: the service hosts third-party catalogues, and it must be able to name whoever publishes what it hosts. To this is added, for each catalogue, the catalogue's name, address and language, its welcome line, the logo and the two colours of its livery, that logo being either an address at its own host or a file it uploads to us, the email address and phone number its customers reach it on, its minimum order, whether or not it is published, and, when it chooses to open it only to whoever holds the link, that private link's token. To this is added what it puts in its catalogue: its aisles (with their subtitle, the note that goes with them and the way their price table reads), its products (name, reference, description, image, selling unit, packing, stock state, the badges it attaches to them and the tags it puts on them), the catalogue's own tag vocabulary, each word there carrying the icon and the colour it chooses for it and serving as many products as it likes, the images it uploads for them, like the logo it uploads for its catalogue, living in a PUBLIC storage space, served from an address carrying a randomly drawn identifier and its volume price grid. To this are added three free texts it writes and formats itself, one introducing the catalogue at the top, one of reassurance after its first aisle, and a last one at the bottom whose content it alone decides. It can build that catalogue by importing it from a file, a spreadsheet or a PDF. A spreadsheet is read inside its own browser, and only its text reaches us. A PDF is read the same way first; when its browser cannot manage, the device being too small for the document, the file is then placed in a private storage space for as long as it takes us to read it, then DELETED as soon as the reading is over: it is nobody's document, it appears on no screen, and it is read once. We take its text from it, and that text goes to the language model when its shape cannot be parsed (a printed price table), on the same terms as everything else we entrust to it (see the list of our providers below); we keep no copy of it. When the document carries no text at all, that is, when it is a scanned catalogue, the document itself is handed to the model through a temporary download link built for that call and expiring with it. What comes back is shown to it before anything is written, and nothing is saved until it has accepted it. Conversely it exports its catalogue as a spreadsheet or a PDF whenever it wants. To this is added who runs that catalogue: a catalogue is run by one or more people, and each of them is recorded with the date they came in and, when they were invited, the account that brought them in. Someone is brought in by inviting their email address, which is kept along with the date it was sent, the date the link stops being worth anything, the language of the message, the account that invited and the fingerprint of that link's token, never the token itself; the invitation then stays in the catalogue's list, accepted or cancelled, so that how someone came in can always be read. Anyone leaves whenever they want, and the last one cannot: a catalogue is never left with nobody to run it. To this is finally added the language it reads its own screens in, which is not its catalogue's: the latter is read by its retailers, the former is its own alone, on every device it uses, and does not leave its account. To this is added, in the same way, which of the three order notices described below it still wants and through which channel: for each notice, for each channel that notice offers and for its account alone, we keep whether it switched it off or left it on, a preference that only exists from the day it touches it and that no more leaves its account. Notices that reach the platform's bell leave a line there, which we keep: it carries the notice's type, its date, whether it has been read, and what is needed to write its sentence again on each reading (the order number, the catalogue's address, the buyer's legal name or the declared state), never an amount and never the sentence itself, which is rebuilt in the language of the moment. Anyone clears their own, one at a time or every read one at once. And if they allow notifications on a device, we keep the subscription their browser gives us to reach it: the push service's technical address, the two encryption secrets that come with it and the name the browser gives itself, so the device can be named in the list of those that ring. That subscription belongs to the browser installation rather than to the account, it is removed from the account screen or by refusing notifications in the browser, and it is the same one the agency's areas use when the same person signs in there from the same browser: a browser only ever has one. To run the catalogue and serve it to its visitors. A published catalogue is readable by everyone, prices included; until it is, only those who run it see it, and publishing one does not publish the others. You sign in with the same account as on the rest of the site, and that account by itself opens neither an agency's area nor one of its clients': those are separate accesses, granted separately. Legal basis: performance of the contract.
  • B2B platform buyer account: your company's legal name, its company registration number and the nine-digit number derived from it, its VAT number, its delivery address, the name and phone number of the person to contact, and your email address. The registration number is the only condition for opening an account, and none of this is asked before the point of ordering: these catalogues sell wholesale, to businesses, and reading a shop window requires no account. To identify you as a business and let the wholesaler deliver and invoice you. You have no account to create beforehand and no password to choose: your email address is entered with the rest of the details, we send a six-digit code to it, and copying that code in is what opens your account. That address is where your order acknowledgement and its progress notices arrive, and how you find your orders again afterwards; it also serves as your sign-in identifier. The code is valid for one hour and can only be used once. You can look your company up in the public business register from the form: the name or number you type there is then sent to that public state API (INSEE and RNE data), which answers us, and we only store what you keep. When the details are saved, the registration number you entered is also sent to that same register to check that it exists and that the establishment is open, and an unknown or closed number is refused; when your company is established in another European Union country, your intra-community VAT number is required and sent to the European Commission's VIES service, which tells us whether it is registered. In both cases only the number concerned is sent, and we keep nothing of these checks but their result. Legal basis: performance of the contract, and our legal obligation to check the buyer's business status.
  • B2B platform orders: the products ordered with their quantity and their price at the time of the order, its total, its number, its date, the state it is at, the message you leave the seller and the one they send back. To this are added, copied onto the order as it is placed, the buyer's identity (legal name, registration number, delivery address, and the contact's name, email and phone) and the name of the catalogue it was placed with. That copy is deliberate: an order is a commercial record, it must stay readable and enforceable when the account has been closed or the company has changed its name. An order is read by the wholesaler it targets and by the buyer who placed it, and by nobody else: no other wholesaler sees it, and no agency does either. The wholesaler can only rewrite its progress and their own message, never the amount or your identity. No payment takes place here: payment and delivery are settled between you and them, outside the service. Placing an order sends two emails, each carrying its detail: one to the wholesaler, at their catalogue's contact address, with your legal name, registration number, delivery address, name, email, phone and the message you leave them; the other to you, as an acknowledgement, without your registration number or address, which you already know. Each step the wholesaler declares sends you a third. An incoming order and each step are also told in the platform's bell and, where a device has been allowed, by a notification on it: those two channels address a person rather than an address, so each person who runs the catalogue is told according to their own settings. The acknowledgement only comes by email: it answers the action you have just taken, and you have the confirmation screen in front of you. All of it can be switched off from the “Notifications” tab of your account, which the foot of every message links to, notice by notice and channel by channel: what is addressed to you stops as soon as you ask; the wholesaler's email, which goes to their catalogue's contact address and may therefore be read by several people, only stops once nobody who runs that catalogue still wants it. Switching an email off changes nothing about the order itself, which stays readable from both sides inside the service. Legal basis: performance of the contract and the legal obligation to keep commercial records.
  • Technical logs: IP address, timestamp, browser and pages requested, kept by our hosts. For security, abuse prevention and fault diagnosis. Legal basis: our legitimate interest in keeping the service secure.

We collect no special category data under Article 9 GDPR and never ask for any. The service is aimed at professionals: it is not intended for minors, and we do not knowingly collect their data.

4. Cookies and local storage

This site sets no advertising cookie, no social network tracker and no analytics tool. The only cookies it sets are strictly necessary to run the service, which is why you are not shown a consent banner.

  • Session cookies: set when you sign in to keep your session open, cleared when you sign out or when they expire.
  • Client area preview cookie: set on a Noki Mind team member's browser when they open a client's area to see it the way that client sees it. It holds nothing but the identifier of the record being viewed, grants no access by itself, and is cleared when the preview is left or the browser is closed.
  • Browser local storage: your light or dark theme, and the name you leave on a quote comment. None of it leaves your device, and clearing the site's data removes it.
  • A wholesale catalogue's private link: when you open a catalogue through a private link, that link's token is copied into a cookie, so that the catalogue does not close again on the second link you follow. It holds nothing but that token, it is scoped to that catalogue's address, it lasts twelve hours, and it grants nothing by itself: the right to open is checked on every page, server-side.
  • A wholesale catalogue's basket: what you put in it before ordering (the products kept and their quantities, nothing else) lives in your browser's local storage, one basket per catalogue. That is what lets you build an order without opening an account. It is never sent to us until you order, it does not follow you from one device to another, and clearing the site's data removes it.

Should an analytics tool ever be added, it would be announced here and subject to your prior consent.

5. Who has access to your data

Your data is accessible to the Noki Mind team, limited to what each person needs to see, and to our technical providers, who act on our instructions and on our behalf alone.

  • Vercel: hosting of the site and the application.
  • The public business register (the French state's “Recherche d'entreprises” API, INSEE and RNE data): queried when you look your company up to fill in a client record or a B2B platform buyer account, and again when a buyer account is saved, to check that the registration number entered exists and that the establishment is open. Only the name or number concerned is sent to it, never the rest of the record.
  • The European Commission's VIES service: queried when a B2B platform buyer account carrying an intra-community VAT number is saved, to check that the number is registered in its member state. Only that number is sent to it, and nothing else; we keep nothing but the answer. This check only happens on the B2B platform, where a delivery between businesses in two member states is reverse-charged and requires a valid number.
  • Supabase: database, authentication and file storage.
  • Resend: delivery of service emails (invitations, notifications, verification codes, B2B platform order notices, and account security links: address confirmation, password reset, sign-in address change).
  • Google: if you choose “Continue with Google” to enter your area, for reading the calendar of a team member who has connected theirs, and for the notice telling us one of their meetings has just opened.
  • Recall.ai: recording and transcription of video calls, and tracking of connected calendars. This provider is the one holding the Google authorisation for a connected calendar, and the one telling us which meetings to record.
  • OpenRouter: routing a meeting transcript to the language model that writes its summary, suggests its tasks, and draws from it the corrections to make to your record, to our notes and to the tasks in progress. What we already hold about you is sent along with the transcript, so the model knows which line it is talking about and what that line says today. The same provider also routes, whenever a team member asks for it, the title and text of a note, a task, a meeting summary or a social media content to the model that translates them into another language, as the team does not all speak the same one: nothing is rewritten that way, the original text stays as it was written. It likewise routes the labels of a questionnaire (its section titles, its questions and their options, never the answers received) to the model that translates them, when the person it was sent to reads it in a language other than the one the agency wrote it in. The same provider finally routes what a team member writes to the assistant in their admin workspace, and what that assistant goes on to read from our data in order to answer them, which may include what we hold about you: that conversation is kept on our side so that its author can find it again and pick it up, in a thread only they can read, not even the other members of their team, and which they rename or delete whenever they want. Its first message is sent a second time, to a model that sums it up in a few words to give that thread its name in their list, and nothing more. Our routing no longer excludes model providers that keep or reuse what is sent to them: what becomes of a text once it reaches them is a matter of each provider's own policy, which our provider publishes provider by provider. The same provider finally routes, whenever a team member asks for it from the Studio, their media generation workshop, the prompt they write and the images they attach to it, to the model that draws the image or shoots the video requested: what goes out is what they wrote and chose, never what we hold about you, and the render comes back to us, into private storage. The first prompt of a conversation in that studio goes out a second time, to a model that boils it down to a few words to give that conversation its name in our list, and nothing more. Video is the one exception, and it is a technical one: because its generation is deferred, the provider keeps the render until we come and fetch it, which no setting on our side can prevent. We can restore that exclusion by configuration alone, without changing anything about the service, and this document will say so on the day we do.
  • The services the agency connects to its own admin workspace: the team can plug in the tools it uses elsewhere (a workspace, a shop, a management tool) so that the assistant in that workspace knows how to query them. Whatever a team member then asks the assistant to send to one of those services goes to that service, under its own terms, and may include what we hold about you, including a file from your folder, which that service then comes and fetches itself through a temporary download link (see “Shared files” above); what the assistant brings back is not kept beyond the conversation. Those services are chosen by the agency and not by us: an up-to-date list is available on request at contact@nokimind.com.
  • The software the agency gives an API key to: it can open its admin workspace to an outside tool (an automation, its own management software) using a key it creates and revokes from that workspace. That software then calls the service in the name of the team member who created the key, sees only what that person sees, and only the actions the key allows. What it does with that afterwards is a matter for the agency and that tool's publisher, not for us; the list of live keys, and of what each one opens, is available on request at contact@nokimind.com.

The Noki Mind team can open your client area to see it the way you see it, to help you set it up or to understand what you are reporting. It does not take on your identity there: whatever it writes stays signed with its own name, and the data shown is data it can already reach from its own area.

We neither sell nor rent your data, and we pass it to no advertiser. It can only be disclosed to a third party upon a request from a competent authority.

Data received from Google APIs is subject to Google's API Services User Data Policy, including its Limited Use requirements: it serves only the features described here, it is neither sold, nor rented, nor used for advertising or profiling, and nobody reads it outside the cases that policy allows (your request, the security of the service, a legal obligation).

6. Transfers outside the European Union

Some of our providers are established in the United States or may run support operations there. Those transfers rely on the European Commission's standard contractual clauses, complemented where applicable by the provider's certification under the EU - US Data Privacy Framework, and by technical measures such as encryption.

Details of the applicable safeguards are available on request at contact@nokimind.com.

7. How long we keep it

Nothing is kept out of habit: every retention period answers a reason.

  • Contact request with no follow-up: 3 years from the last exchange.
  • Questionnaire sent and left unanswered: 12 months, then deleted. An answered questionnaire follows the retention period of the client record it is attached to.
  • Data of a client under contract: for the duration of the relationship, then 5 years under the commercial limitation period.
  • Signed quotes, invoices and accounting records: 10 years, as the law requires.
  • Shared credentials: until revoked or until the engagement ends; their access log is kept for 12 months.
  • Connected calendar: until it is disconnected, which clears the connection and the token on our side, withdraws the meeting-opened notice at Google and the authorisation at our recording provider. Recordings, transcripts and summaries already produced follow the retention of the data of the client concerned.
  • Shared files: until whoever added them deletes them, and at the latest 12 months after the engagement ends. The temporary link created so that a third-party service can come and fetch one of them lasts thirty minutes and ten downloads; the row carrying it, along with the date it was created, the date of each download and the name of the team member who asked for it, is erased within twenty-four hours of its expiry.
  • Notes of the team, published or not: the retention period of the data of the client they speak about, and until the team deletes them when they speak about no client.
  • Conversations with the assistant of the admin workspace: kept until their author deletes them, and at the latest when their account is closed, which takes them all with it. Only they can read them.
  • Notifications in your area, and on the B2B platform: until you clear them from the notification drawer, and at the latest when your account is closed. A device's push subscription lives the same way, until you remove it, until the browser stops recognising it, or until the push service tells us it no longer exists, in which case it is deleted on the first send that finds out.
  • A translation of a text requested by the team: kept for as long as the text it translates has not changed, solely so it need not be redone on every read, and deleted along with that text. It never replaces the original, which follows its own retention period.
  • A connector plugged into the agency's assistant: its address is kept until it is removed, which erases it. What opens it depends on the service: either an access token copied over by the agency, kept encrypted and erased with the connector; or an OAuth authorisation given by each member of the team for their own account with that service, in which case the tokens issued are encrypted under a key that does not live in the database, kept until that person disconnects or the connector is removed, and the application's registration with that service is kept for as long as the connector. Whatever has already been sent to the service so connected follows that service's own retention, over which we have no say.
  • Wholesale catalogues and the seller account that runs them: each catalogue is kept for as long as the wholesaler runs it, then deleted within 30 days of it being closed, the images uploaded for its products going with the product they illustrate, the same account's other catalogues each following their own period. Orders already placed do not go with it: they follow their own period, below.
  • B2B platform orders: 10 years, like any commercial record. That is why the buyer's identity is copied onto them: the order must stay readable even if the account that placed it has been closed in the meantime.
  • Technical logs: 12 months at most.
  • Signed-in account: until the access is closed, then deleted within 30 days, except for records the law requires us to keep longer.

8. Your rights

The GDPR grants you rights over your data, and they are all exercised at the same address: contact@nokimind.com.

  • Access: know whether we process data about you, and get a copy of it.
  • Rectification: have inaccurate or incomplete information corrected.
  • Erasure: have your data deleted where no legal ground requires us to keep it.
  • Restriction: ask for processing to be frozen while a dispute is settled.
  • Objection: object, on grounds relating to your situation, to processing based on our legitimate interest.
  • Portability: receive, in a machine-readable format, the data you provided to us.
  • Withdrawal of consent: at any time, for whatever rests on it, without affecting what was done before.
  • Post-mortem instructions: set what happens to your data after your death.

We answer within one month, extendable by two months for complex requests, in which case we tell you. Proof of identity is only requested where there is reasonable doubt about who is asking.

If our answer does not satisfy you, you may lodge a complaint with the French data protection authority (CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr) or with the supervisory authority of your country of residence.

9. How we protect it

Security is not a promise but a set of measures. These are the main ones.

  • All traffic runs over HTTPS, without exception.
  • Passwords are never stored in clear, and nobody at Noki Mind can read them.
  • An account's sign-in address is only replaced after confirmation by link: a session left open is not enough to move an account over to someone else's address.
  • The credentials you entrust to us are encrypted at rest, under a key that is rotated, and every read is logged.
  • Files you add live in a private storage space: no public address leads to them, and every opening goes through a temporary link issued to whoever is entitled to see that file. Such a link may be handed to a service the agency has connected to its workspace, when it asks that service to come and fetch a file: it then lasts half an hour and ten downloads, it carries that one file, and the entitlement of whoever asked for it is checked again at every download.
  • The database enforces row-level separation: an account only ever sees the record, quotes and tasks that concern it.
  • Team access follows least privilege and is withdrawn when someone leaves.
  • An API key is never kept in the clear: the database holds only a fingerprint, nobody can display it again, and it carries permissions limited to what it was created for. It is revoked in one gesture, and the date of its last call is visible, so a forgotten key can be spotted and cut off. The role of the account it belongs to is rechecked on every call: withdrawing access closes the key at the same time.

Should a data breach pose a risk to your rights, we would notify the CNIL within 72 hours and tell you directly in the cases the GDPR provides for.

10. Automated decisions

No decision producing legal effects concerning you is taken solely on automated processing, and we build no advertising profile. The assistive tools that help us draft or summarise are always reviewed by a human before anything reaches you.

11. Changes to this policy

This policy may change as the service or the regulation does. The date of the last update is at the top of the page, and any substantial change is announced by email or on your next sign-in, before it takes effect.

12. Write to us

A question, a request to exercise your rights, a concern: contact@nokimind.com. The publisher's postal details are in the legal notice.