Codesia

Security & sovereignty documentation

Compliant. Sovereign. French. GDPR AI Act

Preamble

The measures set out below are designed to meet the requirements of European regulation, in particular the GDPR1 and the AI Act1. They remain applicable after the end of the contract, in accordance with articles 17 and 18 of our Terms of Sale (CGV).

This document has, on its own, no legal value. However, every statement in it is precisely sourced and refers to documents signed during each engagement, which make the whole set of commitments described here contractually enforceable (CGV, service contracts, DPA, etc.). Some of these documents, such as the CGV, are freely available on our website. For the others, we can send them to you on simple request to rgpd@codesia.fr, within 48 hours of receiving your message.


01Our working environment

1

Our server is hosted in Paris

We run a virtual private server (VPS2) hosted in a data centre in Paris.

Your operational data is kept in this database, on our servers, and not with a third-party cloud provider. We host and administer it ourselves, in particular :

  • n8n, the orchestrator of our automations
  • PostgreSQL, our database
  • certain AI models (open-source)

No data is transmitted to the publishers of this software.

Relying on an established VPS provider strengthens reliability and continuity of service compared with a self-hosted solution, by reducing outages, the risk of data loss and downtime.

2

We operate in a highly secure environment

Our server is protected by technical measures ensuring a level of security appropriate to the risk, including :

  • access to the server's configuration console controlled by two-factor authentication3 (2FA) and strictly limited to Lény Rolland (CEO) and Jacques Rolland (CTO) ;
  • access to the server itself via a mandatory SSH key4, with password authentication disabled, and strictly limited to Lény Rolland and Jacques Rolland ;
  • encryption of data in transit (TLS/HTTPS) ;
  • regular backups of our entire working environment ;
  • logical separation of the development, test and production environments, as well as logical partitioning of environments between clients ;
  • regular application of security updates and continuous vulnerability management.

Finally, note that you have a right to audit our security measures, which you may exercise yourself or through a third party.

CGV art. 13.3, DPA P2 art. 4.3 and 6.2


02Responsibility for your data

Before detailing the security measures we put in place, we want to clarify who is responsible for which type of data, in the sense of the GDPR.

Three roles, in the sense of the GDPR

Within a processing chain, the GDPR recognises three roles, according to the function actually performed: data controller, data processor, sub-processor. From this categorisation flow our responsibilities over the data.

For the vast majority of our engagements, you remain the data controller, we act as the data processor, and our software providers as sub-processors.

In the sense of the GDPR, the data controller is the one who determines the purposes of a processing operation as well as its means. For your clients' data, you retain this status in all circumstances: it is you who decide the purposes pursued and the conditions under which this data is processed.

It is only for the data concerning you directly (your professional phone number, your professional email address, your SIRET, etc.) that we are the data controller.

1

Processing Codesia carries out as a “data controller”

For the data we process as a data controller, you hold rights of access, rectification, erasure, restriction, portability and objection, which we handle through a formalised procedure. The terms for exercising these rights are set out in our privacy policy.

CGV art. 13.7 ; Privacy policy art. 6 ; Rights-request handling procedure.

2

Processing Codesia carries out as a “data processor”

Article 28 of the GDPR requires the conclusion of a DPA1 between the data controller (you) and the data processor (Codesia), as well as a DPA between the data processor (Codesia) and each of the sub-processors (the third-party software we use).

The DPA concluded between the data controller and Codesia is systematically appended to the service contract. It specifies in particular :

  • the nature and purpose of the processing ;
  • the categories of personal data and of data subjects concerned ;
  • the duration of the processing ;
  • the respective obligations of the Parties ;
3

Processing third-party software carries out as “sub-processors”

The DPAs concluded between Codesia (data processor) and its own sub-processors (the third-party software we use) are also put in place.

The complete list of sub-processors is provided to you in the delivery documentation, together with their role and the location of the processing. You have 15 days from the delivery of this documentation to object, if you wish, to the use of any of them.

DPA P2 art. 2 and 4.4 ; CGV art. 12.3, 13.1, 13.2, 13.3 and 14.7 ; Delivery documentation art. 6


03Securing your data

1

AI models are never trained on your data

None of your data is ever used to train AI models. When using the consumer interfaces of Anthropic, OpenAI, Mistral or Google (Claude, ChatGPT, Le Chat, Gemini), conversations feed model training by default. Our architecture is different : we operate exclusively via APIs1, so that none of your data is used for this purpose.

CGV art. 12.3 ; DPA P2 art. 4.7

2

Transmission and storage of your data to certain AI models

Whenever relevant, we use open-source AI models2, hosted locally on our own servers. As these are limited in power, we often call on external AI models that are too heavy to install and host on our servers. We nevertheless implement a set of measures designed to minimise the risk as much as possible.

  • Only strictly necessary data is transmitted to providers.
  • For the majority of tasks without great complexity, we use Mistral, a French provider, and therefore outside the scope of the US Cloud Act3 (which, as a reminder, allows the American authorities to demand access to data held by a US provider).
  • For US providers, your data is not kept beyond 30 days (except in exceptional situations imposed on the provider, such as a legal obligation or a court injunction requiring longer retention). This is what using APIs allows : via the standard web interface, this data would be kept far longer (18 months by default at Gemini, up to 5 years at Anthropic).
  • For sub-processors established outside the EU, we ensure either their certification under the Data Privacy Framework4, or the implementation of appropriate safeguards within the meaning of the GDPR (standard contractual clauses in particular).

CGV, art. 3.4, 12.3 and 13.5 ; Contrat P3 art. 8.2 ; DPA P2 art. 4.5

3

Your data remains strictly confidential

We are bound by a contractual confidentiality obligation, including on precontractual exchanges of information, notably during the discovery call. Any medium (oral, written, electronic, visual), whether or not designated as confidential, including what is observed on site during the diagnosis, is covered. This obligation remains after the end of the commercial relationship and applies to our sub-processors and any providers.

CGV articles 12.1, 12.2 and 12.5 ; DPA P2 articles 4.2 and 4.4

4

Use and retention of your data by Codesia

The use of your data is strictly limited to the performance of the contract, and access to it is reserved for Lény Rolland (CEO) and Jacques Rolland (CTO). You remain the owner of all of your data, over which we hold no right outside this performance.

  • We never use your information to design competing solutions, nor to reproduce or transpose your business processes at other clients.
  • If you decide to end the follow-up contract, you choose between the return and the destruction of the data we hold about you. This operation is attested in writing within 30 days for confidential information. The return is carried out in a structured, commonly used and machine-readable format. In addition, we deactivate all the access we had to your tools.

CGV articles 11.6, 12.2, 12.6, 18.2 and 18.3 ; DPA P2 article 7

5

We rigorously record all processing activities

We keep an up-to-date record of processing activities, listing all the personal-data processing we carry out, both as a data controller and as a data processor. This record is available on request to the competent authorities.

CGV art. 13.6 ; DPA P2 art. 6.1

We remain attentive to your data-sovereignty requirements. If you wish us to use only European models, so that no data ever leaves the EU, we comply.


04Measures concerning AI specifically

1

Classification of the risk level of our automations

We systematically classify our automations according to the four levels described by the AI Act (unacceptable, high risk, limited and minimal). This classification, its justification and the recommended terms of use are provided to you in the documentation delivered at handover.

We refuse to design or deploy any automation falling under prohibited practices. The use of automations classified as “high risk”, within the meaning of the AI Act, is systematically subject to a contractual stipulation.

If such an automation is deployed, we make it compliant with all the obligations specific to the “high risk” classification : registration in the EU database, use in accordance with providers' instructions, retention of logs, etc.

CGV articles 9.3, 14.2, 14.6 and 14.7, Service contract articles 8.1 and 8.2, Acceptance report article 4, Delivery documentation article 3

2

Human-oversight mechanisms (“human in the loop”)

From the design stage, we integrate control and oversight mechanisms proportionate to the risk level. The list of cases where human oversight is required is provided to you in the delivery documentation.

CGV art. 8.5 and 14.5 ; Contrat P2 art. 8.3 ; Delivery documentation art. 4

3

Transparency regarding the use of AI systems

From the design stage, we integrate the mechanisms needed to signal interaction with an AI or the AI-generated nature of content.

We do everything possible to ensure that users led to interact with an AI are informed as early as possible ; operational implementation, however, is your responsibility.

People asked to use automations classified as “high risk” are systematically informed.

CGV articles 9.6, 14.2, 14.3 and 14.6 ; Delivery documentation art. 5.


05To conclude

1

Continuous regulatory monitoring

We conduct continuous regulatory monitoring1 of the evolution of the legal frameworks applicable to our activity, in order to anticipate upcoming obligations and adapt our services accordingly. This document, but also and above all the set of legally enforceable documents that constitute its sources, are regularly updated to reflect the latest applicable requirements.

Likewise, all the security measures presented above are re-assessed periodically, according to the state of the art and the evolution of risks.

2

Environmental and social commitment

Our VPS is hosted in a data centre located in France, whose electricity consumption is covered 100 % by renewable electricity from local sources. The infrastructure is certified ISO 14001 and ISO 50001, the two international standards for environmental and energy management. At end of life, 100 % of the servers are reused or recycled by certified partners. Our provider also implements carbon offsetting across its data centres and publishes an annual sustainability report since 2023.

AI must be at your service, never the other way around. It is a tool meant to remove tasks that are foreign to your expertise and devoid of formative value, in favour of precious time to think and innovate, to develop new working methods, to build connections with your colleagues ; time to grow and rediscover meaning.

To ensure that AI integrates harmoniously into your environment, we take the AI Literacy recommendations of the AI Act very seriously. We include a systematic transfer of skills when deliverables are handed over, as well as ongoing support, in order to answer your questions and ensure that you retain full understanding and command of these tools.

CGV art. 3.3, 8.4, 14.4 and 9.2 ; Contrat P2 art. 7 ; Acceptance report P2 art. 6 ; Contrat P3 art. 6. AI Act compliance : article 4.

For any questions: rgpd@codesia.fr