ONNE.MARKETING — Legal
Privacy Policy
ONNE.MARKETING is committed to protecting the privacy of its users. This policy describes what data we collect, why, how we use it, who we share it with, how long we retain it and what rights you have.
Last updated: July 28, 2026
1. Data Controller
ONNE.MARKETING is the data controller for personal data collected via www.onne.marketing.
Contact: contact@onne.marketing
2. Data We Collect
We collect only the data necessary to operate the service:
— Account data: email address, first/last name (optional), bcrypt-hashed password. Via Google OAuth: email and name provided by Google.
— Project data: information entered to describe your business (project name, sector, mission, values, offers, declared competitors, customer personas, budget, team structure).
— Marketing strategy content (Magic Brief): strategic brief, action plan, market analysis, exports.
— Reality Check data: validation questionnaire responses, viability analysis results, potential score.
— VECTOR chat history: messages sent and received through the AI copilot. These messages are transmitted to OpenAI to generate responses.
— Competitive scan data (X-Ray): submitted URLs, data extracted from public web pages, AI analysis results.
— Keyword research results: queries made and results returned by SerpAPI.
— Session and activity data: login timestamps, platform actions (no behavioural advertising tracking).
— Declared expertise level, selected persona, interface preferences.
— Payment data: ONNE stores no banking data. Payments are handled entirely by Stripe. We store only the Stripe customer ID and subscription status.
3. Purposes & Legal Bases
Each processing activity has a legal basis under GDPR Art. 6:
— Performance of contract (Art. 6.1.b): account management, platform access, strategy generation, VECTOR copilot, competitive scans, exports, billing.
— Legitimate interest (Art. 6.1.f): service improvement, abuse detection, platform security, anti-fraud activity logs.
— Legal obligation (Art. 6.1.c): retention of billing data (French accounting requirement: 10 years).
— Consent (Art. 6.1.a): marketing communications (if you have consented). You may withdraw consent at any time.
We never use user data for advertising profiling, sale to third parties, or AI model training without explicit consent.
4. Sub-processors & International Transfers
We use third-party service providers (GDPR sub-processors) to operate the service:
— OpenAI LLC (USA): AI processing of VECTOR messages, strategy generation, competitive analysis, vision. Data transmitted includes chat messages and user-provided project data. Privacy policy: openai.com/privacy
— Stripe Inc. (USA): payment processing and subscription management. Financial data (card number, billing details) only passes through Stripe. Policy: stripe.com/privacy
— Resend Inc. (USA): transactional email sending (signup confirmation, password reset, security notifications). Policy: resend.com/privacy
— SerpAPI LLC (USA): web search for Keyword Research and X-Ray competitive intelligence. Search queries are forwarded to SerpAPI. Policy: serpapi.com/privacy
— Neon Inc. (USA — AWS infrastructure): PostgreSQL database hosting for all platform data. Policy: neon.tech/privacy
— Replit Inc. (USA): web application and source code hosting. Policy: replit.com/privacy
— Cloudflare Inc. (USA/EU): anti-bot protection via Turnstile on sign-up, login and contact forms. IP addresses and form interactions are processed. Policy: cloudflare.com/privacypolicy
All providers are bound by GDPR-compliant data processing agreements. US transfers are covered by Standard Contractual Clauses (SCCs) or the EU-US Data Privacy Framework for certified entities.
5. Retention
— Active account data: for the duration of the relationship and 3 years after account closure.
— Strategic content (briefs, studies, scans): available while account is active; deleted within 30 days of account closure on request.
— VECTOR chat history: retained while account is active. Archived sessions can be deleted from the interface.
— Billing records: 10 years (French legal accounting requirement).
— Security logs (logins, sensitive actions): 12 months.
— Waitlist / contact form data: 3 years from collection if no commercial relationship follows.
6. Security
We implement the following technical and organisational measures:
— Password hashing: bcrypt with random salt; passwords are never stored in plaintext.
— HTTPS enforced: all browser-server communications are TLS-encrypted.
— Strict Content Security Policy (CSP) with per-request nonce to prevent script injection.
— CSRF protection on all data mutations.
— Cloudflare Turnstile anti-bot on all public forms.
— Rate limiting on sensitive endpoints (login, signup, AI).
— Tenant isolation: each user accesses only their own data, enforced server-side on every action.
— Password reset tokens: SHA-256, single-use, valid for 1 hour.
In the event of a data breach posing a risk to your rights and freedoms, we will notify the CNIL within 72 hours and affected users without undue delay.
8. Your Rights
Under GDPR (Articles 15–22) you have the following rights:
— Right of access (Art. 15): obtain confirmation that your data is being processed and receive a copy.
— Right to rectification (Art. 16): correct inaccurate or incomplete data.
— Right to erasure / right to be forgotten (Art. 17): request deletion of your data in cases provided for by law.
— Right to restriction (Art. 18): restrict processing in certain situations.
— Right to data portability (Art. 20): receive your data in a structured, machine-readable format.
— Right to object (Art. 21): object to processing based on legitimate interest.
— Right to withdraw consent: withdraw previously given consent (marketing emails) at any time.
To exercise these rights, email contact@onne.marketing. We will respond within one month.
If you believe your data is being processed in violation of the GDPR, you have the right to lodge a complaint with the CNIL: www.cnil.fr
9. Changes
ONNE.MARKETING may update this policy to reflect legal, regulatory or technical changes. Material changes will be notified to active users by email and the date above will be updated.