Naquada is committed to protecting the privacy of its users and website visitors. This policy explains how we collect, use and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
01Data controller
- Company name
- Naquada (SAS)
- Registration
- SIREN 103 856 423 — RCS Amiens
- Registered office
- 118 Rue de Cagny, 80090 Amiens, France
02Data collected
Naquada collects the following categories of data:
Registration and waiting-list data (website)
- Email address collected through the Beta/Alpha Access form
- Anonymous device ID generated locally in your browser
- Browser language and page URL
- Referrer and UTM parameters, when present in the URL
Account data (Naquada platform)
- First name, last name, email address and bcrypt-hashed password
- Profile information (industry, team size and use case)
- Billing address and tax information (VAT) for subscribers
- History of jobs and workflows run
- Files uploaded to the platform
Technical data
- IP address for abuse protection and usage limiting
- Browser type and operating system
- Server access logs retained for 30 days
03Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Managing the Beta waiting list | Consent — Art. 6(1)(a) |
| Providing and improving Naquada services | Performance of a contract — Art. 6(1)(b) |
| Billing and subscription management | Legal obligation and performance of a contract — Art. 6(1)(b) and (c) |
| Security, abuse prevention and fraud control | Legitimate interests — Art. 6(1)(f) |
| Transactional communications | Performance of a contract — Art. 6(1)(b) |
| Website usage analysis and improvement | Consent — Art. 6(1)(a) |
04Retention periods
- Waiting-list data
- 3 years from collection or until consent is withdrawn
- Active user account
- For the account lifetime, then 3 years after deactivation
- Billing data
- 10 years, as required by accounting law
- Security logs
- 30 rolling days
- User files
- While the account is active; deleted on request or after 90 days of account inactivity
05Data recipients
Naquada never sells your personal data. It may be shared with the following processors solely to provide the service:
- Stripe Inc. — payment processing (United States / EU, PCI-DSS certified)
- Railway Corporation — application infrastructure hosting (United States)
- Backblaze B2 — user-file storage (United States, EU Standard Contractual Clauses)
- Mailjet (Sinch) — transactional email delivery (EU)
- PostHog — analytics, session replays, heatmaps, funnels, A/B tests and surveys, only after consent
- AI model providers — OpenAI, Anthropic, Google, Fal.ai, ElevenLabs and others. Input data sent when a workflow runs is subject to each provider’s privacy policy.
For transfers outside the European Union, Naquada ensures that appropriate safeguards are in place, including adequacy decisions, Standard Contractual Clauses or Binding Corporate Rules.
06Your rights
Under GDPR Articles 15 to 22, you have the following rights over your personal data:
Right of access — Art. 15
Obtain a copy of the personal data we hold about you.
Right to rectification — Art. 16
Correct inaccurate or incomplete data.
Right to erasure — Art. 17
Request deletion of your data (“right to be forgotten”).
Right to restriction — Art. 18
Restrict certain processing of your data.
Right to portability — Art. 20
Receive your data in a structured, machine-readable format.
Right to object — Art. 21
Object to processing based on legitimate interests.
To exercise any of these rights, email [email protected]. We will respond within one month at the latest.
If you believe your rights have not been respected, you may lodge a complaint with the French data protection authority, the CNIL. www.cnil.fr.
07Cookies and trackers
The naquada.tech website uses storage required for operation and, with your consent, PostHog to measure website usage:
- naquada_vitrine_lang — stores your language preference in localStorage and remains until manually deleted.
- naquada_vitrine_device_id — anonymous session identifier stored in localStorage to deduplicate waiting-list registrations. It cannot identify an individual.
- naquada_token — JWT authentication token stored in localStorage for signed-in platform users. It expires after 30 days.
- naquada_cookie_consent — stores your PostHog measurement preference in a cookie and localStorage for one year.
- PostHog (ph_*) — analytics, session replays, heatmaps, funnels, A/B tests, insights and surveys. These trackers are enabled only after consent and can be withdrawn through “Manage cookies”.
Naquada does not use advertising cookies. Refusing measurement does not prevent access to the website; necessary cookies remain active.
08Data security
Naquada implements appropriate technical and organizational measures to protect your data against unauthorized access, accidental loss or destruction: encryption of sensitive data (AES-256-GCM for SMTP passwords and bcrypt for user passwords), encrypted communications (HTTPS/TLS), role-based access control, audit logs and rate limiting to prevent abuse.
09Changes to this policy
Naquada may amend this policy at any time. Users will be informed of any material change by email or through a platform notification. The latest update date appears at the top of this page.
10Contact
For any question about this policy or the processing of your personal data, contact us: