Privacy policy
Last updated: 7 August 2026
This policy explains what data Margéo processes, why, for how long, and what your rights are. It applies to the site and the service, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.
1. Who is responsible for your data?
AgenIA is the controller for account management and billing data (credentials, contacts, subscription). Its full details appear in the legal notice.
For the business data you entrust to us (supplier invoices, sales, dishes, recipes), we act as a processor within the meaning of article 28 of the GDPR: you remain the controller and the owner, and we process it only to provide you with the service, on your instructions.
Contact for any question about data: contact@agenia.pro
2. What data, and what for?
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name, password (encrypted) | Creating and securing the account, authentication | Performance of the contract |
| Name of the business, billing details | Managing the subscription and invoicing | Performance of the contract, legal obligation |
| Supplier invoices uploaded (PDF/photo) and the data extracted from them | Automated extraction, calculation of costs and margins | Performance of the contract |
| Till sales, dishes and recipes | Calculating margins by dish and by month | Performance of the contract |
| Questions put to the assistant, technical logs | Providing the assistant, security, incident diagnosis | Legitimate interest |
| Service emails and alerts | Account-related information, margin alerts, reports | Performance of the contract |
We collect no sensitive data within the meaning of article 9 of the GDPR, and carry out no profiling and no solely automated decision-making producing legal effects concerning you.
3. Processing by artificial intelligence
The invoices you upload are sent to an artificial intelligence service (Anthropic) in order to extract their data automatically (supplier, amounts, product lines). This processing is necessary to provide the service.
These documents are not used to train AI models. We recommend uploading supplier invoices only, and no document containing personal data that is not needed.
The results produced by AI may contain errors: it is for you to check them (see article 11 of the Terms).
4. Who has access to your data?
Your data is neither sold, rented nor transferred to third parties for commercial purposes. It is accessible to the members you invite into your organisation, and to the following technical sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Hébergement de la base de données, authentification, stockage des factures | Union européenne (Irlande) |
| Vercel Inc. | Hébergement et diffusion de l'application | États-Unis — Clauses Contractuelles Types (CCT) |
| Anthropic PBC | Extraction des données de factures et assistant conversationnel (traitement par IA) | États-Unis — Clauses Contractuelles Types (CCT) |
| Stripe Payments Europe, Ltd. | Traitement des paiements et facturation des abonnements | Union européenne (Irlande) |
| Hostinger International Ltd. | Hébergement du moteur d'automatisation des traitements | Union européenne |
| Google Ireland Ltd. (Gmail SMTP) | Envoi des emails transactionnels (bienvenue, alertes, rapports) | Union européenne |
Transfers outside the European Union are governed by the European Commission's Standard Contractual Clauses. Any change to this list is notified to you.
5. How long do we keep your data?
- Account and business data: throughout the subscription, then 12 months after its termination (so you can come back without loss), before permanent deletion.
- Immediate deletion possible at any time from “Settings” — the operation is irreversible.
- Subscription invoices and accounting records: 10 years, pursuant to article L.123-22 of the French Commercial Code.
- Technical logs: 12 months maximum.
- Activity log for internal accounts: 12 months. This log concerns only the publisher's own team accounts, never customer accounts.
6. Security
The following measures are in place:
- encryption in transit (HTTPS/TLS) and at rest;
- strict separation between organisations at database level (Row-Level Security): each customer accesses only its own data;
- passwords stored as non-reversible hashes;
- invoices stored in a private space that cannot be listed publicly;
- access to production data limited to the people strictly required.
In the event of a data breach likely to create a risk to your rights, we will notify the CNIL within 72 hours and inform you as soon as possible.
7. Cookies
The service uses no advertising cookies and no third-party analytics trackers. Only strictly necessary cookies are set:
- authentication cookies (Supabase), to keep your session signed in;
- demonstration cookie (
mr_demo), set only if you view the demo, lasting 7 days.
As these cookies are essential to the operation of the service, they do not require your prior consent. You may delete them at any time through your browser settings — signing in to the service will then no longer be possible.
8. Your rights
You have rights of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions as to what happens to your data after your death.
Two of these rights are exercised directly from the application, under “Settings”: the full export of your data in a structured, machine-readable format (portability), and the permanent deletion of your account and your data (erasure).
For any other right, write to contact@agenia.pro. We reply within one month. You may also lodge a complaint with the CNIL, the French data protection authority (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr).
9. Amendment of this policy
This policy may change. Any substantial amendment is notified to you by email at least 30 days before it takes effect. The date of the last update appears at the top of the page.