Privacy Policy
Kapteev · Version 1.0.1 · Last updated: 2 August 2026
Applies to Kapteev's websites and services: www.kapteev.com, app.kapteev.com and the related applications.
Translation provided for convenience — the French version prevails.
1. Who is responsible for your data
Kapteev, a French single-member limited liability company (société à responsabilité limitée à associé unique) with a share capital of €3,000, registered with the Paris Trade and Companies Register (RCS Paris) under number 894 464 056, whose registered office is at 9 rue des Colonnes, 75002 Paris, France, is the controller of the personal data described in this policy.
- General contact: contact@kapteev.com · +33 1 84 16 33 87
- Data protection contact: dpo@kapteev.com
2. Who this policy applies to — and the case of imported contacts
This policy covers: visitors to our websites, people who contact us, and users of the Kapteev platform.
The specific case of contacts imported by our clients. Kapteev is a business platform: our clients may import their own contacts (their customer base, for example) to prepare and send their communications. For that data, the client remains the controller and Kapteev acts as a processor (Article 28 GDPR), under the data processing agreement entered into with the client. If you receive a communication sent by a client through Kapteev, the processing of your data is governed by that client's privacy policy; Kapteev acts only on the client's instructions.
3. What we process, why, on what basis, and for how long
| Processing | Data concerned | Legal basis | Retention |
|---|---|---|---|
| Website operation and security | Technical data: IP address, connection logs, device and browser type | Legitimate interest (security, abuse prevention) | Logs: 12 months — up to 24 months for audit logs — then pseudonymised or deleted |
| Audience measurement and trackers | See section 6 | Consent | See section 6 |
| Contact requests | Identity, contact details, content of your message | Legitimate interest (responding to your request) | 3 years after the last exchange |
| Account and authentication | Email, name, language, sign-in identifiers (including via a third-party account), security logs | Performance of the contract | Life of the account; see section 9 |
| Connecting third-party services (Google, social networks…) | Technical identifiers and access tokens, content you choose to import or publish | Performance of the contract; consent for certain authorisations | Duration of the connection, revocable at any time |
| Subscription and billing | Identity, billing details, payment history — card data is processed by our payment provider and never passes through our servers | Performance of the contract; legal obligations | Accounting records: 10 years |
| Digital clone (voice and face) | Biometric data — see section 4 | Explicit consent (Article 9 GDPR) | Until revocation — see section 4 |
| Content and campaigns | Briefs, media, texts and settings of your campaigns | Performance of the contract | Life of the account |
| Kapteev newsletter | Consent | Until withdrawal, at most 3 years after the last contact |
4. The digital clone: our commitments
This section applies as soon as the cloning feature is available in your account.
Creating your digital clone (your voice, your face) involves processing biometric data — so-called "special category" data (Article 9 GDPR), subject to the highest level of protection. Kapteev applies the following rules, without exception:
- Explicit consent, revocable at any time. No clone is created without your explicit consent, collected separately for this specific purpose. You can withdraw it at any time from your account.
- Live capture only. Your clone is built exclusively from a capture performed live, with liveness detection — never from an uploaded file. It is therefore impossible to create a clone of a third party from an existing video or recording.
- A solo capture. If several faces are detected during the capture, it is rejected and must be redone alone.
- Storage exclusively in the European Union. Your biometric fingerprints and models are stored on servers located in the EU, without exception.
- Never used to train third-party models. Your biometric data is never used to train third-party artificial intelligence models.
- Immediate and effective revocation. Revocation — or deletion of your account — triggers the immediate purge of the clone and its derived elements, including the interruption of uses in progress.
- Marking of generated content. Content generated with your clone carries a machine-readable technical mark and a visible notice indicating AI-generated content (see section 12).
- Your uploaded files remain campaign assets. Music or a recording you upload is used as an element of your campaign — never as a cloning source. You warrant that you hold the necessary rights to the content you upload.
5. Connecting Google accounts and social networks
When you connect a third-party account (Google, LinkedIn or another network), we receive the information strictly necessary for authentication (account identifier, email address, name and profile picture depending on the service), together with technical tokens allowing us to act on your instruction only — for example publishing content you have approved, or accessing a file you have explicitly selected. We never publish without your action. You can revoke a connection at any time, from Kapteev or from the service concerned.
Data obtained through these services is never sold, never used for advertising purposes, and never used to train generalised artificial intelligence models.
Kapteev's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
6. Cookies and audience measurement
To date, our pages only use strictly necessary trackers (session, security, language preference), which do not require consent.
Once audience measurement is activated on www.kapteev.com:
- a banner will let you accept, refuse or configure trackers — refusing will be as easy as accepting;
- audience measurement (Google Analytics) and, where applicable, advertising trackers will only be set after your consent;
- your choices will be kept for 6 months and can be changed at any time via the "Cookies" link in the footer; trackers will not live longer than 13 months.
7. Who accesses your data: recipients and processors
Your data is accessible only to authorised Kapteev personnel, and to our processors within the strict limits of their assignment. Currently active processors:
| Provider | Assignment | Data location | Safeguards |
|---|---|---|---|
| Supabase | Database, authentication, storage | European Union (Ireland) | Data processing agreement (DPA), Standard Contractual Clauses |
| Vercel Inc. | Hosting of the websites and application | United States / global network | DPA, Standard Contractual Clauses |
| Bunny (BunnyWay d.o.o.) | Content delivery (CDN, video) | European Union | DPA |
| Resend | Transactional emails (account activation, notifications) | United States | DPA, Standard Contractual Clauses · Data Privacy Framework certified |
| Stripe | Payments and billing | United States / European Union | DPA, Standard Contractual Clauses |
| Google sign-in (authentication), Kapteev's business email, audience measurement (once activated) | United States / European Union | DPA, Standard Contractual Clauses |
The artificial intelligence model providers used for content generation will be added to this list when they go live, with their location and safeguards — the list is versioned and each update is dated. Biometric data, for its part, is only entrusted to providers processing exclusively in the European Union (see sections 4 and 8).
8. Transfers outside the European Union
Two distinct perimeters:
- Biometric perimeter: no transfer outside the EU. Voice and face fingerprints and models are stored and processed exclusively in the European Union.
- General perimeter: some providers (hosting, email, payments) are established in the United States. These transfers are governed by data processing agreements incorporating the European Commission's Standard Contractual Clauses — a standard contract imposing the European level of protection on the provider — and, where applicable, by the Data Privacy Framework, the adequacy framework between the EU and the United States.
9. How long we keep your data
- Profile and content: deleted when your account is closed.
- Proof of consent and of acceptance of contractual documents: 3 years after the end of the relationship.
- Accounting records and invoices: 10 years (French Commercial Code).
- Technical and security logs: 12 months — up to 24 months for audit logs — then pseudonymised or deleted.
- Biometric data: immediate purge upon revocation or account deletion (section 4).
When an account is closed, items kept under a legal obligation are stored separately, dissociated from your profile.
10. Your rights
You have the rights of access, rectification, erasure, restriction and objection, the right to data portability, the right to withdraw your consent at any time (without affecting the lawfulness of processing already carried out), and the right to give instructions on what happens to your data after your death (a right under French law).
To exercise them: dpo@kapteev.com (or contact@kapteev.com). We respond within one month; proof of identity may be requested where necessary. You may also lodge a complaint with the CNIL, the French data protection authority: www.cnil.fr — CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.
11. Security
Kapteev applies technical and organisational measures proportionate to the risk, including: encryption of data in transit and at rest, access segregation per workspace, logging of sensitive actions, and hosting of application and biometric data in the European Union.
12. Artificial intelligence: transparency
Kapteev is a platform of artificial intelligence agents. When you interact with an agent, this nature is clearly indicated. AI-generated content produced through Kapteev carries a machine-readable mark and, for content reproducing a real person's image or voice, a visible notice — in accordance with Article 50 of Regulation (EU) 2024/1689 on artificial intelligence.
13. Minors
Kapteev is a professional service, reserved for adults acting in a professional capacity.
14. Changes to this policy
Each version of this policy is numbered, dated and archived. In the event of a substantial change — a new purpose, a new category of recipients — account holders are informed before it takes effect.
Kapteev privacy policy — v1.0.1 (EN) · 2 August 2026