Privacy Policy
Last updated: May 25, 2026 โ English version provided for information; the French version is the legally binding reference.
1. Preamble
Neston ("the Service") is an intelligent email assistant integrated with Microsoft Outlook. This policy describes how we collect, use and protect your personal data.
2. Data controller and DPO
The publisher of Neston (administrative information being finalized โ see Legal notice) is the controller of your data.
Data Protection Officer (DPO): Yvan Bosser โ contact@neston.fr
3. Data collected
3.1 Data provided by the user
- Microsoft 365 identity: first name, last name, email address, Microsoft Graph identifier
- Preferences: writing style, signature, default importance, attachments folder
3.2 Data collected via Microsoft Graph (with your OAuth consent)
- Received emails: subject, body, sender, recipients, date, attachments
- Sent emails: subject, body, recipients, date (for style learning)
- Outlook contact book: for To/Cc autocomplete
3.3 Technical data
- Usage logs: timestamp, API endpoint, execution time, user agent
- Metrics: generation volumes, satisfaction (send vs edit)
- Session cookies: 1 HttpOnly cookie, 7-day duration, authentication purpose
4. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Generation of style-adapted emails | Contract performance (Art. 6.1.b GDPR) | Duration of use |
| Learning each contact's profile | Contract performance (Art. 6.1.b) | 12 months after last exchange |
| Deadline detection and follow-ups | Contract performance (Art. 6.1.b) | 12 months after detection |
| Security and abuse prevention | Legitimate interest (Art. 6.1.f) | 6 months (logs) |
| Performance measurement and improvement | Legitimate interest (Art. 6.1.f) | 12 months |
| Billing (future paid phase) | Legal obligation (Art. 6.1.c) | 10 years (French Commercial Code) |
5. Subprocessors and recipients
To provide the Service, we transfer certain data to providers bound by contractual obligations equivalent to the GDPR:
| Subprocessor | Role | Location |
|---|---|---|
| OVH | Infrastructure hosting | France (Gravelines) |
| Microsoft Corporation | OAuth authentication + Graph access to mailboxes | EU if M365 EU tenant, otherwise US (SCCs) |
| Anthropic, PBC | Claude API for reply generation | United States (Standard Contractual Clauses) |
| Sentry | Error detection (no PII) | EU |
| UptimeRobot | Availability monitoring (simple HTTP) | United States |
Important: for each reply generation, the content of the email you are replying to is transmitted to the Anthropic Claude API for processing (governed by Standard Contractual Clauses post-Schrems II). This transmission is strictly necessary to perform the Service.
6. Your GDPR rights
In accordance with the GDPR, you have the following rights:
- Right of access (Art. 15): obtain a copy of all your data
- Right to rectification (Art. 16): correct inaccurate data
- Right to erasure (Art. 17): full deletion of your account
- Right to restriction (Art. 18): temporarily suspend processing
- Right to portability (Art. 20): retrieve your data in JSON format
- Right to object (Art. 21): object to processing based on legitimate interest
- Right to withdraw consent: at any time, without affecting the lawfulness of prior processing
How to exercise your rights: send an email to contact@neston.fr with a copy of an ID document. Reply within 30 days maximum.
CNIL complaint: if you consider your rights are not respected, you may lodge a complaint with the CNIL (French data protection authority).
7. Security
- Encryption in transit: HTTPS (TLS 1.2+) with HSTS
- Encryption at rest: authentication tokens encrypted with AES-128-CBC (Fernet)
- Sovereign hosting: OVH servers in France (Gravelines)
- Multi-tenant isolation: each user has an isolated space
- Monitoring: Sentry (no PII), UptimeRobot, fail2ban
- Backups: daily encrypted backups
- Notifications: in the event of a data breach, CNIL and users are notified within 72 hours in accordance with Art. 33 GDPR
8. Retention periods
- Content data (emails, profiles, deadlines): as long as you use the Service, automatic deletion after 12 months of inactivity
- Technical data (logs, metrics): 6 to 12 months
- Billing data (paid phase): 10 years (accounting obligation)
- Account deletion: full erasure within 30 days of your request
9. Cookies
Neston uses a single strictly necessary technical cookie: session cookie (HttpOnly, Secure, SameSite=Lax, 7-day duration). No advertising, third-party analytics or tracking cookies. No consent banner is required under Article 82 of the French Data Protection Act.
10. Minors
The Service is reserved for persons aged 18 or over. We do not knowingly collect any data from minors.
11. International transfers
As stated in section 5, some subprocessors are located in the United States. Any transfer outside the EU is governed by the Standard Contractual Clauses approved by the European Commission (post-Schrems II, Decision 2021/914), and limited to strictly necessary data.
12. Changes
We may amend this policy. The current version will always be available at this address. Substantial changes will be notified to you by email.
13. Contact
For any question regarding this policy or the exercise of your rights:
- Email: contact@neston.fr
- DPO: Yvan Bosser
This English translation is provided for the convenience of English-speaking visitors. In case of discrepancy, the French version shall prevail as the legally binding reference.