Privacy policy
FR·EN
Last updated: 28 July 2026. This policy describes how MargiPro processes personal data in connection with the website margipro.com, the related software solution, and interactions with our prospects and customers.
Data controller
- Company name
- MargiPro, SAS
- Registered office
- 55 Rue du Clos des Lys, 26750 Génissieux, France
- Privacy contact
- contact@margipro.com
For any questions about this policy or to exercise your rights, please contact us at the address above and state the subject of your request.
MargiPro has not appointed a data protection officer, as this is not required given its activities. contact@margipro.com is the single point of contact for all personal data matters.
MargiPro’s dual role: controller and processor
MargiPro acts in two distinct capacities, which carry different obligations:
- As a data controller, for the processing whose purposes it determines itself: prospects, invoicing, security and fraud prevention, the content of support exchanges, audience measurement, and management of the contractual relationship, which relies on user accounts’ identification and login data.
- As a processor acting for the business customer, for documents uploaded to the application, the business data derived from them, and the data of the users designated by the customer, insofar as that data is processed in order to deliver the service. The customer remains the controller of that data and retains ownership of it; MargiPro processes it solely on the customer’s documented instructions.
Account data therefore falls under both regimes depending on the purpose pursued: processing on the customer’s behalf where it serves to deliver the service, and own controllership where MargiPro uses it for its own invoicing, security, and contract management needs.
This second capacity is governed by the Data Processing Agreement entered into with the customer under Article 28 of the GDPR, which sets out the subject matter, duration, nature, and purposes of the processing as well as the parties’ respective obligations.
Data we collect
Depending on how you use our services, we may process in particular:
- Account data: first and last name, business email address, phone number, password stored as a hash, role, company, and assigned sites.
- Login data: date and time of last login, technical logs.
- Documents uploaded by the customer: supplier invoices, delivery notes, and traceability tickets, including suppliers’ identity, address, SIRET number, and phone number. This information constitutes personal data where the supplier is a natural person or a sole trader.
- Raw output of the automated analysis of those documents.
- Business data: prices, margins, recipes, yields.
- Support exchanges: content of conversations between the customer and MargiPro.
- Contact request data: name, role, company, contact details, and content of messages sent via the contact form or to our sales team.
- Browsing data: pages viewed, referral source, and device type, as necessary for the website to function and for audience measurement (see the relevant section).
Purposes and legal bases
We process your data to:
- Respond to your enquiries and contact you again (legitimate interest or, where applicable, pre-contractual steps taken at your request).
- Manage our commercial and contractual relationship, invoicing, and support (performance of a contract).
- Provide, secure, and improve the MargiPro solution (performance of a contract; legitimate interest for security and fraud prevention).
- Measure audience on the website and the application in order to improve the service (legitimate interest).
- Comply with legal and regulatory obligations (legal obligation).
- Send you communications about similar products or services where permitted by law (legitimate interest); you may object at any time.
Uploaded documents and the business data derived from them are processed on behalf of the business customer, on the basis of the Data Processing Agreement referred to above.
Recipients and processors
Data are disclosed only to MargiPro staff who need access. We use the following processors, who process data on our behalf and on our instructions under a data processing agreement compliant with Article 28 of the GDPR:
| Processor | Role | Data concerned | Location | Agreement |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All data: accounts, uploaded documents, business data, messaging | European Union, Paris region | Data processing agreement |
| Mistral AI SAS | Optical character recognition of uploaded documents | Content of invoices, delivery notes, and traceability tickets submitted for analysis | Company established in France; international transfers covered by standard contractual clauses | Data processing agreement |
| Vercel Inc. | Hosting of the website and the application, audience measurement | Browsing data, technical logs | United States; standard contractual clauses | Data processing agreement |
This list is kept up to date. The customer is informed of any addition or replacement of a processor and may then raise objections.
Messages you send us via the contact form or by email are received in MargiPro’s business mailbox, hosted by a provider of online messaging and office productivity services acting as a processor, under its data processing agreement and, for transfers outside the European Union, standard contractual clauses.
Access by MargiPro staff
The MargiPro team has administrative access allowing it to view customer data for support, technical supervision, and activity monitoring purposes, including users’ last login date. This access is restricted to authorised staff and subject to a confidentiality obligation.
Transfers outside the European Union
- Application data — accounts, uploaded documents, business data, messaging — is hosted in the European Union, in the Paris region.
- Application delivery and technical logs transit through Vercel Inc. in the United States, on the basis of the European Commission’s standard contractual clauses.
- Optical analysis of documents is entrusted to a provider established in France; any transfers outside the European Union carried out by that provider are covered by standard contractual clauses.
Audience measurement
The website and the application use Vercel Web Analytics across all their pages, as follows:
- Cookie-free solution: no data is stored on or read from your device.
- No cross-site tracking and no advertising profiling.
- Aggregated data only: pages viewed, referral source, device type.
- IP addresses are not retained in clear form.
- Purpose: audience measurement and service improvement.
- Legal basis: legitimate interest.
Cookies and similar technologies
The website and the application use only cookies or similar technologies that are strictly necessary for the service to operate, in particular to maintain your login session. No advertising cookies and no audience measurement trackers are placed (see the “Audience measurement” section). You can configure your browser to refuse some cookies; some features may then not work as intended.
Retention periods
We keep data only as long as needed for the purposes described:
- User accounts: for the term of the contract, then deleted within 3 months.
- Uploaded documents and business data: for the term of the contract, then made available for retrieval for 30 days, then permanently deleted.
- Raw output of document analysis: 5 years from the upload of the document, capped at the term of the contract. This retention serves an evidential and traceability purpose in relation to the automated processing: it allows us to verify after the fact whether the information automatically extracted from a document matches the data validated by the user, in the event of a dispute over a margin calculation or a price. This period corresponds to the general statutory limitation period. This data is not used for any other purpose.
- Support exchanges: 3 years after the conversation is closed.
- Login logs and last login date: 6 months.
- Prospects: 3 years from the last contact.
- MargiPro accounting records: 10 years, in accordance with Article L123-22 of the French Commercial Code.
On termination, the customer is informed in writing of the deadline for retrieving their data. It is the customer’s responsibility to retrieve their documents in order to meet their own accounting retention obligations, supplier invoices having to be kept for 10 years by the receiving business.
Security
We implement appropriate technical and organisational measures, including:
- Encryption of communications over HTTPS.
- Data segregation by company and by site at database level.
- Role-based access control.
- Passwords stored as hashes.
- File access through temporary signed links.
- Data hosting within the European Union.
Your rights
Under Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act, you have the right of access, rectification, erasure, restriction of processing, objection (including to direct marketing), and, where applicable, data portability.
Requests may be sent to contact@margipro.com. We respond within one month of receipt.
For data contained in documents uploaded to the application, the request must be addressed to the business customer who is the controller of that data. MargiPro, acting as a processor, assists that customer in handling the request.
Deletion of a user account is requested by the business customer, as users do not have that capability within the application. MargiPro carries it out within a maximum of thirty (30) days from receipt of the request.
You may lodge a complaint with the CNIL, the French data protection authority.
Changes
We may update this policy to reflect changes in our practices or in the law. The update date appears at the top of this page. Please review it periodically.