Privacy Policy - Phacet

Phacet is a trading name of SPX Software SAS.
Version : v2.0
Effective date : 09 September 2026

Who Are We?

This Privacy Policy applies to the phacetlabs.com website and to the Phacet platform accessible at https://app.phacetlabs.com (the "Platform"), operated by SPX SOFTWARE SAS, a simplified joint-stock company registered with the Créteil Trade and Companies Register under number 985 300 250, whose registered office is located at 14 avenue du Général de Gaulle, 94160 Saint-Mandé, France ("SPX Software" or "We").

Under the conditions set out below, SPX Software acts:

  • as a Data Controller for the Personal Data processed via the website and the Platform for its own purposes;
  • as a Data Processor for the Personal Data processed via the Platform as part of the services provided to its clients (the “Service” for “Our Clients”).

Who Is This Privacy Policy Intended For?

This Privacy Policy applies to any person whose Personal Data may be processed by SPX Software through the use of the website and the Platform, including:

  • visitors to the phacetlabs.com website;
  • SPX Software clients;
  • end users (employees, collaborators, partners, or clients of Our Clients) accessing the Platform;
  • anyone whose Personal Data appears in documents shared with Us as part of the provision of the Service.

When SPX Software acts as a Data Processor, the processing is carried out on behalf of Our Clients, who act as the Data Controllers. In such cases, We encourage you to contact the relevant Data Controller directly (typically, the entity that provided you with access to the Platform) for any request regarding the processing of your Personal Data via the Platform.

What Is “Personal Data”?

Under Regulation (EU) 2016/679 (General Data Protection Regulation, or “GDPR”) and amended French Law No. 78-17 of 6 January 1978 (“Informatique et Libertés”), Personal Data means any information relating to an identified or identifiable natural person (the “Data Subject”), such as a name, email address, phone number, or IP address.

An “identifiable” natural person is someone who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.

What Personal Data Do We Process?

In the context of using the website and the Platform, We may process the following Personal Data:

  • First and last name
  • Email address
  • Messages exchanged via the Platform
  • Connection and activity logs
  • User journey data (pages visited, actions performed)
  • Documents submitted through the Platform
  • Postal address (for billing purposes)
  • Payment methods and banking information (the latter being processed exclusively by our partner Stripe, whose privacy policy is available here)
  • Data from third-party services you connect to the Platform (Gmail, Google Sheets, Google Drive), under the conditions described in the "Google User Data" section.
  • Data submitted through our contact and demo request forms on the phacetlabs.com website: first name, last name, email address, phone number, company and the content of your message.

Why and on What Legal Basis Is Your Personal Data Processed?

To ensure transparency, We have outlined below the purposes for which your Personal Data is collected and used via the website and the Platform, along with the legal bases on which We rely in accordance with Article 6 of the GDPR:

Purposes as Data Controller and legal basis
Purposes as Data ControllerLegal Basis
Improving the Platform, based on technical and aggregated usage data, excluding the content of Our Clients' Data Legitimate Interest
Billing and payment processing Legitimate Interest
Handling contact and demo requests received via the website Legitimate interest
Purposes as Data Processor and legal basis
Purposes as Data ProcessorLegal Basis
Providing the Service to Our Clients (Platform access, account management, request handling, document hosting) Contract
Responding to messages sent via the Platform Contract

Who May Access Your Personal Data?

Your Personal Data is processed by authorized personnel of SPX Software, as well as by authorized sub-processors acting on Our behalf, including:

  • Stripe, our secure payment provider, for transaction processing
  • HubSpot, our customer relationship management tool, for handling requests submitted through the website.
  • Our hosting (Amazon Web Services, Google Cloud Platform), AI inference (OpenAI, Anthropic, Mistral, Google Gemini), monitoring and observability (Datadog, Posthog, Braintrust), and other IT service providers. The full list of Our sub-processors is set out in Appendix 2 of the data processing agreement entered into with Our clients.

SPX Software ensures that any data transfers to these sub-processors are secure, GDPR-compliant, and meet high standards of confidentiality and data protection.

Transfers outside the European Economic Area (EEA) are only carried out under strict legal conditions, such as an adequacy decision adopted by the European Commission under Article 45 of the GDPR and/or contractual provisions ensuring an equivalent level of protection for your Personal Data (e.g., Standard Contractual Clauses adopted by the European Commission).

Google User Data

Phacet's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

This section applies if you connect Gmail, Google Sheets or Google Drive to the Platform. It covers the Google user data We receive through those Google APIs after you grant access. It does not cover Phacet's use of Google as a vendor for its own operations.

We access Google user data only with the explicit OAuth consent of you or your organization, and only for the Google services you choose to connect. You can use the Platform without connecting Google.

What We Access

Gmail (optional) - Gmail API v1. Scopes requested: gmail.readonly, gmail.modify. Mailbox profile, messages, threads, labels, drafts, attachments and settings reads; compose, send, label, archive, star, trash and untrash. We do not request permanent delete or Gmail settings write scopes.

Google Sheets (optional) - Google Sheets API v4. Scopes requested: spreadsheets, drive. Spreadsheet metadata, tabs and cell values; create, read, update and delete spreadsheets.

Google Drive (optional) - Google Drive API v3. Scope requested: drive. Read, create and manage Drive files as needed for the workflow you requested.

We do not request Google Sign-In, Google Calendar or Contacts. Connectors are granted separately in Integrations.

How We Use It

Only to provide the features you request: search and read mail, draft and send messages you approve, label or archive; read or update the spreadsheets you designate; read, create and manage the Drive files you point us to.

We do not sell Google user data; we do not use it for advertising or for credit-worthiness assessment; we do not use the Gmail, Sheets or Drive APIs to develop, improve or train generalized or non-personalized AI or ML models.

When the AI agent runs on connected Gmail, Sheets or Drive data, that content is processed to fulfill your request. That is a user-facing feature, not model training.

Human Access

We do not allow humans to read your Google user data, except:

  • with your prior explicit consent, for specific messages or files, for example when you ask our support team to investigate an issue;
  • where your organization has appointed a Phacet account manager, under the terms of your agreement;
  • where necessary for security purposes, such as investigating abuse or a suspected incident;
  • where required by applicable law;
  • where the data has been aggregated and anonymized, for internal operations.

Access is restricted to authorized staff on a need-to-know basis and is logged.

How We Store It

OAuth tokens are stored encrypted and deleted when you disconnect the integration or close your account. We never receive or store Google passwords. Message, spreadsheet or Drive file content is processed to carry out the requested action; we keep a copy only where it is written into a table, conversation or file you created, until you delete that object or the contract ends. Execution traces used to debug the Service are retained for up to one hundred and eighty (180) days by our observability provider. Data is encrypted in transit (TLS) and at rest.

How We Share It

We share Google user data only in the following cases: with our hosting and AI inference providers used to run the agent on the content you asked us to process, under contracts that limit use to providing our service and that prohibit the use of your content to train their models; with people in your organization who have access to the same workspace, according to the roles you configure; where required by law. The list of our sub-processors is set out in the section "Who May Access Your Personal Data?".

We do not send Google user data to advertising or web-analytics tools. Our monitoring and observability providers may process it solely to operate, secure and debug the Service, subject to the human-access limits set out above.

Your Controls

You can disconnect the integration at any time in the Platform, under Integrations, which deletes the stored OAuth tokens. You can revoke access from your Google Account, under Security then Third-party apps. You can delete the copies retained in the Platform or write to contact@phacetlabs.com.

Limited Use

The use of information received from Google APIs and Google Workspace scopes will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How Long Do We Keep Your Personal Data?

OAuth tokens for connected third-party services (Gmail, Google Sheets, Google Drive) are deleted as soon as the integration is disconnected or the account is closed.

Personal Data processed in connection with the provision of the Service and your use of the Platform is retained in active databases until you request its deletion or, failing that, until the end of the contractual relationship binding you or Our Client to Us.

Where applicable, contractual, billing and account identification data may then be archived for a further period of 5 years in accordance with applicable statutory limitation periods.

Data submitted through our contact forms is retained for 3 years from our last exchange.

Backups containing Personal Data are automatically purged within a maximum of ninety (90) days.

Execution traces used to debug the Service are retained for up to one hundred and eighty (180) days by our observability provider.

Connection logs and technical data are retained for a maximum of 12 months from the date of collection.

Billing-related data is retained for the legally required period (10 years).

How Do We Protect Your Personal Data?

The security of your Personal Data is a key concern for Us.

SPX Software has implemented a range of technical and organizational measures to ensure the security of your Personal Data and protect it from unauthorized access. We monitor our systems 24/7 and regularly test for vulnerabilities.

These measures include:

  • Encryption of data in transit (TLS) and at rest
  • Regular backups enabling data recovery in the event of an incident
  • Strict access control on a need-to-know basis, with strong authentication
  • Access logging
  • Continuous security monitoring to prevent data loss, misuse or alteration

What Are Your Rights?

Under the GDPR and the French “Informatique et Libertés” law, you have the right to:

  • Access your Personal Data
  • Correct any inaccuracies in your Personal Data
  • Request the deletion or removal of your Personal Data
  • Restrict the processing of your Personal Data
  • Object to the processing
  • Request the portability of your Personal Data
  • If the processing is based on your consent, withdraw your consent at any time

You may exercise your rights by writing to: contact@phacetlabs.com

As mentioned above, for certain processing activities, We act as a Data Processor on behalf of Our Clients. In such cases, your request will be forwarded to the relevant Client acting as Data Controller, who is responsible for responding to it.

Please note that exercising some rights (e.g., deletion requests) may affect your ability to access or use the Platform and/or part of the Service.

To learn more about your rights, you may contact Us or lodge a complaint with the competent supervisory authority (e.g., the CNIL in France: www.cnil.fr).

Information About Cookies and Other Trackers

A “cookie” is a small file sent to your browser by the website you visit. Your browser stores the cookie for a period of time and sends it back to the server on subsequent visits. For more information, you may consult the CNIL website.

On the phacetlabs.com website and on the Platform, we use different types of cookies for several purposes, under the conditions specified for each category:

  • Functional and technical cookies: These are essential to the operation of the Platform. Disabling them may impair certain features of the Platform.
  • Analytics cookies: We use these to assess and improve the website and the Platform. For example, they help us track statistics such as time spent on a page, page views, repeat visits and popular services. We use Google Analytics on the phacetlabs.com website and Posthog on the Platform. Disabling these cookies will not affect your experience on the Platform. These cookies only measure interface events (clicks, navigation) and do not capture the content of data processed via the Platform.
  • Marketing cookies: on the phacetlabs.com website only, and with your explicit consent, these cookies are used to tailor advertising to your browsing behavior. No marketing cookies are placed on the Platform. Disabling these cookies will have no impact on your use of the website.

We use Google Analytics cookies to measure and analyze traffic on the phacetlabs.com website. For more information on how Google processes personal data, please consult Google’s Privacy Policy.

Once you have set your cookie preferences via our cookie banner, you can update your preferences at any time.

You can also manage your cookie settings directly in your browser. Most browsers allow you to accept or reject cookies either globally or on a per-site basis. Below are links to browser-specific guidance:

How to Contact Us?

If you have any questions about this Privacy Policy, you may contact Us at: contact@phacetlabs.com

For any question relating to data protection, you may also write to william@phacetlabs.com.

Updates

This Privacy Policy may be updated periodically to reflect changes in our services, technology, or applicable regulations. These updates will take effect as soon as they are published on the phacetlabs.com website and on the Platform.

In the event of a material change, We will inform Our clients by any appropriate means before it takes effect.

‍