Back to home

Privacy & GDPR

Privacy policy

Last updated: July 10, 2026

This policy describes how Fulfai processes your personal data when you use fulfai.com and our EU AI Act compliance services. The data controller is Samy JILALI, 25 La Cougue, 31700 Saint-Marcet, France — contact@fulfai.com.

Data we collect

  • Account data: email, name, password (hashed) or OAuth identifiers (Google, GitHub, GitLab, Bitbucket) when you create an account.
  • Access tokens for the connectors you choose to link (GitHub, GitLab, Bitbucket, Google Cloud, Slack, n8n, Hugging Face, Microsoft 365, Databricks), used only to run your scans.
  • Scan results: the inventory of detected AI libraries and agents (name, version, risk level). Your source code is neither retained nor stored.
  • Content of the documents you generate (AI Act reports, DPIA, GDPR notices): the information you enter in the forms.
  • Billing data: payments are handled by Stripe; we only keep the customer identifier and subscription status.
  • Messages sent through the contact form or support.

Purposes and legal bases

  • Providing the service (scans, reports, dashboard) — performance of the contract.
  • Authentication and account security — performance of the contract and legitimate interest.
  • Billing and subscription management — performance of the contract and legal obligations.
  • Transactional emails (confirmations, scan reports, certificates) — performance of the contract.
  • Aggregated, cookieless audience measurement (Vercel Analytics) — legitimate interest.

Processors and transfers outside the EU

We rely on the following processors to operate the service:

  • Vercel Inc. (United States) — hosting of the site and server functions.
  • Neon — Postgres database (accounts, AI inventories).
  • Stripe — payment processing.
  • Resend — transactional email delivery.
  • xAI — form AI assistant: only the information of the relevant form is sent to it, never your code.
  • The platforms you connect (GitHub, GitLab, Atlassian, Google…), according to the OAuth permissions you grant.

Some processors are located outside the European Union; these transfers are governed by standard contractual clauses and/or the EU–US Data Privacy Framework.

Retention periods

  • Account data: until you delete your account.
  • Connector tokens: until you disconnect the connector or delete the account.
  • Scan results and documents: until you delete them or delete the account.
  • Billing data: 10 years (accounting obligations).
  • The analysed code is never retained: it is processed in memory for the duration of the scan and then deleted.

Your rights

Under the GDPR (Articles 15 to 22), you have the rights of access, rectification, erasure, restriction, objection and portability of your data. You can exercise them by writing to contact@fulfai.com; we respond within one month. You may also lodge a complaint with your supervisory authority (in France, the CNIL — cnil.fr).

Cookies

The site uses cookies essential for authentication (session) and, only with your consent, the Google tag for advertising conversion measurement (Consent Mode v2 — everything is denied by default). Audience measurement (Vercel Analytics) works without cookies. You can change your choice at any time via 'Cookies' in the footer.

Security

Exchanges are encrypted (TLS), passwords are hashed and access to data is limited to what is strictly necessary. Our architecture is built on data minimisation: only the AI inventory is retained, never your code.

Changes to this policy

This policy may be updated; the last-updated date appears at the top of the page. Significant changes will be announced on the site.

See also our "no data stored" approach