Privacy policy
Last updated: 2026-08-01
This document is translated for information. In case of divergence, the French version prevails.
What personal data we process, why, on what legal basis, who it is shared with and how long it is kept. Written to be read rather than to be long.
1. Controller
Elni Consulting SRL, Rue Grande Coyarde 7, 1367 Ramillies, Belgique — BE 1002.511.925.
Questions, or to exercise your rights: privacy@climatememory.com.
We have not appointed a data protection officer: our activity falls under none of the cases where the GDPR requires one (article 37).
2. What we process, and why
Account: email address, display name if any, language, and the identity provider's opaque identifier if you use Google or GitHub. Purpose: to authenticate you and reach you. Basis: performance of the contract.
Billing: country, optionally company name and VAT number, and the index of your invoices. Purpose: to issue compliant invoices and charge the right VAT. Basis: legal obligation.
API usage: key identifier, minute-resolution timestamp, endpoint called and cost in credits. Purpose: billing, quotas, abuse detection. Basis: contract and legitimate interest. These records contain neither your request parameters nor the coordinates you asked about.
Security: a truncated, salted fingerprint of your IP address at sign-in and at sensitive actions, plus the user agent. Purpose: spotting abnormal use. Basis: legitimate interest. We do not keep the addresses themselves.
Consents: timestamped proof that the contractual documents were accepted and, where applicable, that the right of withdrawal was waived. Basis: legal obligation (GDPR art. 7(1) and CEL art. VI.53).
3. What we do not do
We do not sell or rent your data. We do not use it for targeted advertising. We make no automated decisions producing legal effects concerning you, and we do not profile.
We keep no passwords, because we use none.
4. Recipients
Hosting: OVHcloud SAS, 2 rue Kellermann, 59100 Roubaix, France. Servers and databases are in the European Union.
Content delivery and protection: Cloudflare, Inc., which processes visitors' IP addresses to filter attacks.
Payment: Stripe Payments Europe, Ltd., Dublin, Irlande, which acts as controller for payment data and is the only party holding card details.
Transactional email: Amazon Web Services EMEA SARL (Amazon SES, Paris region), Luxembourg. Mailboxes: OVHcloud (Zimbra), France.
These providers act on instruction and under contract. No data is transferred outside the European Economic Area, except by Cloudflare, Stripe and Amazon Web Services under their own legally framed transfer mechanisms.
5. Retention
Account: for as long as it exists, then erased on request.
Invoices and billing data: seven years from the close of the financial year, as Belgian accounting law requires. This retention survives an erasure request (GDPR art. 17(3)(b)), but the retained invoice is no longer attached to a live account.
Usage logs: a rolling thirteen months.
Sessions: thirty days after last use.
Sign-in links: fifteen minutes, then deleted within seven days at the latest.
Raw payment events received from Stripe: ninety days, and immediately when the account concerned is erased.
6. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability under articles 15 to 22 of the GDPR.
Erasure is triggered from your account area, with no request to file and no waiting: it revokes your keys, deletes your sign-in identities and sessions, overwrites your account's identifying data and detaches your invoices, which remain with no personal data attached. It cannot be undone.
You may also write to privacy@climatememory.com. We answer within one month.
7. Complaints
If our answer does not satisfy you, you may complain to the Autorité de protection des données (APD/GBA), Rue de la Presse 35, 1000 Bruxelles, Belgique — https://www.autoriteprotectiondonnees.be.
The competent authority is Belgian, not French: our main establishment is in Belgium.
8. Security
API keys and session tokens are never stored in the clear: only their cryptographic fingerprint is kept, which makes a copy of the database useless for signing in.
Database roles are separated: the process answering API requests has no read access to the tables holding personal data. That is not an internal guideline but a constraint enforced by the server.
Traffic is encrypted in transit. In case of a breach likely to create a risk to your rights, we notify the authority within 72 hours and inform you where the risk is high.
9. Changes
Any substantial change to this policy is notified by email. The version in force carries the date shown at the top of the page.