Legal
Privacy policy
One policy for both this website and the aersyn.ai service. Who we are, what we collect, what the service processes on your behalf, who processes it, and what you can ask us to do with it. No tracking cookies, no consent banner, and the calculators on this site never send your inputs anywhere.
Last updated 15 July 2026
Data controller
aersyn.ai (legal name AE JP Morice 948 312 954, registered office 6 bis rue Relin, 34500 Béziers, France) is committed to protecting your privacy in compliance with the EU General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertés). For your account and billing information, and for the data this website collects, aersyn.ai acts as the data controller. For the business data the service processes on your behalf, the content of your mailbox, quotes, parts and contacts, aersyn.ai acts as a data processor under your instructions. aersyn.ai is established in France and the core platform is hosted within the European Union; the Data transfers section below describes how email and document content is processed by AI providers. As a business-to-business service provider, the personal data we process relates primarily to professional contacts and business operations. Our data protection contact is reachable atjp.morice@aersyn.com.
Data we collect
We process data in two contexts: what this website collects from visitors, and what the aersyn.ai service processes for you once you are a customer. Technical data such as IP addresses is handled transiently by our hosts. We do not collect sensitive data such as health or biometrics.
On this website: the demo form
When you ask for a demo, we store what you type into the form and the campaign parameters that brought you here. The stored fields are youremail, your monthly RFQ volume (rfq_month), and the UTM parameters on the link you followed (utm_source,utm_medium,utm_campaign and the relatedutm_ fields). Nothing beyond those fields is taken from the form.
On this website: analytics
As you move through the pages, we record a small set of events, for example demo_click when you open the demo form,video_play when you start the product tour, andpricing_view when you reach the pricing grid. These events measure how the site is used. They carry no direct personal data, no name and no email attached, and they are recorded without cookies.
In the service: account and billing data
To create and run your account we process contact details (name, professional email, phone number, company address), business credentials (company name, VAT number), the identity of your users and their roles, and billing information. We are the data controller for this data.
In the service: business data processed on your instructions
To do the work you ask of it, the service processes the content of your business correspondence and the data attached to it: incoming and outgoing emails handled by the workflows, quotes, purchase orders, part numbers, prices, and your customer and supplier contacts. We process this data only as a processor, on your instructions, to operate the service for you, including reading and quoting incoming requests, the follow-up workflows, the pricing suggestions, and the supplier ranking. We never use it for any other purpose, never disclose it to any third party, and never use it to train or improve any AI model. This mirrors the confidentiality commitments of your Terms and NDA.
In the service: usage analytics
We also record a small set of product-usage events inside the application (which screens are opened, which actions are completed) to measure how it is used and improve it. These events carry no customer trading data.
Third parties and sub-processors
We rely on the processors below to run the site, follow up on demo requests, and operate the service. Each one handles a defined slice of your data under a data processing agreement, and each is bound to process it only for its stated purpose, never to disclose it, and never to use it to train AI models. Most operate within the EU; where a provider processes data outside the EEA, the transfer is covered by the safeguards described in the Data transfers section below.
| Sub-processor | Purpose | Legal basis (GDPR Art. 6) | Retention | Subject requests |
|---|---|---|---|---|
| PostHog | Product analytics, EU cloud, cookieless. | Legitimate interest, Art. 6(1)(f). Audience measurement without cookies. | PostHog EU default retention. | Deletion on request. |
| Calendly | Demo booking and the booking webhook. | Pre-contractual measures, Art. 6(1)(b), or consent, Art. 6(1)(a). | Duration of the sales cycle. | Access and deletion on request. |
| Resend | Transactional email sent from send.aersyn.ai. | Legitimate interest, Art. 6(1)(f). Commercial follow-up. | Duration of the sales cycle. | Deletion on request. |
| Stripe | Payment processing for subscriptions, EU. | Contractual necessity, Art. 6(1)(b). | Duration of the commercial relationship. | Access and deletion on request. |
| Supabase | Application database, authentication, and file storage for the service, plus the lead store (site_leads) in the separate aersyn.biz project. EU region (AWS). | Pre-contractual and contractual measures, Art. 6(1)(b). | Aligned with the lead and account lifecycle. | Row deletion on request. |
| Microsoft 365 (Graph) | Connection to your own Outlook mailbox and files, inside your own Microsoft tenant, through delegated access you grant. | Contractual necessity, Art. 6(1)(b). | The mailbox stays yours; we store what the workflows process. | Revoke delegated access at any time. |
| AI processing providers | Reading and structuring the content of emails and documents so the service can quote, suggest pricing, and rank suppliers. Current list available on request. | Contractual necessity, Art. 6(1)(b). | Bound to process solely to deliver the service; never to train models, never to disclose. | Contact us for the current provider list. |
| Hostinger | Web hosting, EU region. | Legitimate interest, Art. 6(1)(f). Serving the website. | Duration of hosting. | No direct personal data store. |
The lead store (site_leads) sits in our business operations project, aersyn.biz, kept fully separate from the production environment where customer trading data lives. The two never mix.
Legal basis
We process personal data on four grounds under Article 6 of the GDPR:
- Pre-contractual and contractual measures, Art. 6(1)(b).Handling your demo request and the lead created from it, providing and managing your subscription, configuring and operating the service, and processing the business data you entrust to it on your instructions.
- Legitimate interest, Art. 6(1)(f). Measuring site and product usage without cookies, following up commercially on a demo request, sending transactional notifications, improving our platform, and processing payments via Stripe. You can object to this at any time.
- Legal obligation, Art. 6(1)(c). Keeping account and billing records for the period required by French commercial law.
- Consent, Art. 6(1)(a). Where a third-party embed needs it, and only once you click to load it.
The table above maps each processor to its basis.
Retention
We keep data only as long as it serves the purpose it was collected for. Account and billing records are retained for 10 years to comply with French commercial law (Article L.123-22 of the Commercial Code). Beyond that legal obligation:
- Business data processed by the service (mailbox content, quotes, purchase orders, parts, and contacts): kept for as long as your subscription is active. On termination you may export all of it; export is available for 30 days, then the data is securely deleted after 90 days, in accordance with the Terms.
- Leads (site_leads in Supabase): kept for the lead lifecycle, then deleted.
- Demo bookings (Calendly) and follow-up email (Resend):kept for the duration of the sales cycle.
- Analytics events (PostHog): kept under PostHog's EU default retention, with no direct personal data attached.
Data security
We implement appropriate technical and organisational measures to protect your personal data:
- encryption of data in transit via TLS/HTTPS on all communications between your browser and our services;
- encryption of data at rest provided by our infrastructure partners (Supabase, hosted on the AWS EU region), which apply AES-256 disk-level encryption by default;
- role-based access controls limiting data access to authorised personnel only;
- authentication and session management enforced at the infrastructure level.
We do not currently implement application-level field encryption. No system can guarantee absolute security; we nonetheless commit to maintaining measures commensurate with the risk and nature of the data processed.
Data transfers
Your account and billing data and the core platform (database, authentication, and file storage) are hosted in the European Union (Supabase, AWS EU region; Hostinger EU for this website). To read and structure the content of your emails and documents, the service relies on AI processing providers; where such a provider operates outside the European Economic Area (EEA), the transfer is carried out under appropriate safeguards, such as the European Commission's Standard Contractual Clauses, together with a contractual commitment that your data is processed solely to deliver the service, never used to train AI models, and never disclosed. The same applies to website processors operating outside the EEA, such as Calendly. The current list of AI providers and their locations is available on request atjp.morice@aersyn.com.
Incident response
In case of a personal data breach, we:
- notify the French Data Protection Authority (CNIL) within 72 hours;
- inform affected users via email.
Your rights
Under the GDPR you can, at any time:
- access the personal data we hold about you,
- rectify anything that is inaccurate,
- ask for erasure of your data,
- restrict processing or object to profiling,
- request data portability,
- make a subject access request (SAR) and receive a copy of what we hold.
You can also lodge a complaint with the CNIL, the French supervisory authority. To exercise any of these, emailjp.morice@aersyn.com. We answer within the one-month statutory window, free of charge.
Third-party integrations
Your data may be shared with ERP or other business systems at your direction. We are not responsible for the privacy practices of those systems.
Cookies and consent
aersyn.ai sets no tracking cookies and shows no consent banner. The application itself uses only the strictly necessary cookies required to keep you signed in and secure your session. Analytics run cookieless, on this site and in the application. Third-party embeds, Calendly and the product video, load only when you click to open them, never before. The estimator and the ROI figures are computed in your browser and never leave it, so your inputs to those tools are never sent to us or to anyone else. We do not profile you for advertising and we do not sell your data.
Updates and governing text
This policy may change. Updates will be posted on https://aersyn.ai. This English version prevails; for a French translation, contact us. For any question about this policy or your personal data, emailjp.morice@aersyn.com. We reply within one month, the statutory deadline under the GDPR.