All legal pages

Privacy policy

Last updated: August 4, 2026

This policy explains what personal data Zeldia collects through Stack32, why, and what your rights are.

This document is a structured legal draft intended to inform users. It has not been reviewed by a lawyer and does not constitute legal advice. If in doubt, consult a qualified legal professional.

1. Data controller

The data controller is Zeldia (SIREN 951 022 094, 951 022 094 R.C.S. Evreux). Contact: hello@stack32.com.

2. Data we collect

Account data (email, name, password hash); profile data provided during onboarding (first name, phone number, role, discovery source, use case); content you submit (prompts, conversations, documents); usage data (features used, technical logs); and billing data processed by our payment provider.

3. Why we process it

To provide the service (create and run your agents), to secure accounts, to improve the product, to provide support, to handle billing, and to comply with legal obligations. Legal bases include contract performance, legitimate interest and legal obligations.

4. AI processing

Your prompts and connected documents are processed by AI model providers acting as processors, strictly to generate your agents' answers. We do not use your private content to train our own models.

5. Sharing

Data is shared only with processors necessary to run the service (IONOS hosting, database, AI model providers, payment provider, analytics), under data-processing agreements. We do not sell personal data.

6. Retention

Account data is kept while your account is active, then deleted or anonymized within the legal limitation periods. You can request deletion at any time.

7. Your rights

You have rights of access, rectification, erasure, portability, restriction and objection, and the right to lodge a complaint with the CNIL (French supervisory authority). To exercise your rights, contact hello@stack32.com.

8. Security

We apply appropriate technical and organizational measures: encryption in transit, access controls, isolation of customer data and least-privilege access.

9. Transfers outside the EU

Some processors may be located outside the European Union. In that case, transfers are protected by appropriate safeguards such as the European Commission's standard contractual clauses.