Legal
Privacy Policy
Version 1.0Last updated : 30 July 2026
1. Who is responsible
The controller is DESPII SASU, share capital €1,000, RCS Bobigny 931 078 661, registered office 5 rue Pleyel, 93200 Saint-Denis, France, represented by its President, Mr Aurélien BOKONGO MOZENGANO. DESPII SASU publishes the Matcha website and application (see the Legal notice).
Data protection contact: DPO@despii.com.
We process personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and the French Data Protection Act of 6 January 1978 as amended.
2. Scope
This policy covers two distinct situations:
- the Site (matcha.ganeden.eu), where you can read the pages and leave an email address to request early access;
- the Application (Matcha), where you hold an account and work with your team.
It does not cover the third-party services you connect to Matcha (GitHub, Sentry, Railway, Codemagic and others), which remain governed by their own policies.
3. What we collect
3.1 On the Site
- Email address, when you submit the early-access form. That is the only field the form asks for.
- Technical data attached to that submission: the language of the page (
enorfr), the referring page, and the date and time of the request.
The Site includes no audience measurement, no advertising tag and no third-party tracker.
3.2 In the Application
- Account data: email address, hashed password or third-party sign-in identifier, display name where you provide one, the Organisations you belong to and your role in each.
- Content you create: documents, tickets, comments, checklists, files you upload, alert rules, monitored URLs, source and agent configuration. This content is yours; we host and process it in order to run the Service.
- Alerts received from the services you connect. Their payload may itself contain personal data: the author of a commit, the identifier of a failed build, the user context attached to a Sentry error. We receive whatever the connected service sends and store it in your Organisation.
- Technical logs: IP address, timestamp, HTTP route called, response status, correlation identifier, error traces. They are produced by the backend and are needed to run and secure the Service.
- Billing data (once paid plans open): plan, number of Seats, invoice history, and the payment reference returned by Stripe. We never receive or store your full card number.
3.3 What we do not collect
We do not collect identity documents, location data, biometric data, or any special category of data within the meaning of article 9 of the GDPR. We ask you not to place such data into the Service.
4. Why we process it, and on which legal basis
| Purpose | Legal basis |
|---|---|
| Registering and answering an early-access request | Consent (art. 6.1.a): you submit your address |
| Creating and managing your account, giving access to the Service | Performance of the contract (art. 6.1.b) |
| Hosting and processing your documents, tickets and alerts | Performance of the contract (art. 6.1.b) |
| Transactional emails (invitation, password, security notice, escalation) | Performance of the contract (art. 6.1.b) |
| Subscription billing and payment collection | Performance of the contract (art. 6.1.b) |
| Keeping accounting records and invoices | Legal obligation (art. 6.1.c) |
| Security of the Service, abuse prevention, incident investigation, logging | Legitimate interest (art. 6.1.f): securing the Service |
| Technical support and dispute handling | Legitimate interest (art. 6.1.f) |
| Diagnosing errors and improving the Service | Legitimate interest (art. 6.1.f) |
| Sending AI feature requests to a language-model provider | Performance of the contract (art. 6.1.b), on your instruction: the feature is off until you enable it |
Where processing rests on consent, you may withdraw it at any time, without affecting the lawfulness of what was done beforehand.
We do not sell personal data, do not rent it out, and do not use it for advertising profiling.
5. Who processes data on our behalf
The following processors act on our instructions, under contracts that require them to keep data confidential and to use it only to provide us with their service:
| Processor | Role | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | See note below |
| Railway | Hosting of the backend and of the scheduled jobs | See note below |
| Cloudflare, Inc. | Hosting of the Site (Cloudflare Pages), network and delivery | United States |
| Resend | Sending transactional emails | United States |
| Stripe | Payment processing and invoicing (once paid plans open) | Ireland / United States |
| Make (make.com) | Routing early-access sign-ups collected on the Site | See note below |
| Language-model providers | AI features, only when you enable them and only for the provider you configure yourself | Depends on the provider you choose |
[[À COMPLÉTER : régions d’hébergement exactes (Supabase, Railway, Make) et référence des accords de sous-traitance (DPA) signés avec chacun de ces prestataires]]
Language-model providers. Matcha’s AI features are off by default. When you turn them on and configure a provider, the content you submit to those features, and only that content, is sent to the provider you have chosen, under that provider’s own terms. We do not use your content to train models.
Services you connect. Matcha also connects, at your request, to the services you configure yourself (GitHub, Sentry, Railway, Codemagic, your own endpoints, and others). Those services are not our processors: they are your tools, and the credentials you provide are stored write-only, never returned in clear by the API.
Beyond these processors, data may be disclosed to the competent authorities in response to a legal request, and to our lawyers, auditors or accountants in the course of their professional duties.
6. Transfers outside the European Union
Some processors are established outside the European Union, in particular in the United States (Cloudflare, Resend, Stripe for part of its operations), and possibly the language-model provider you choose.
Those transfers are covered by the safeguards provided in chapter V of the GDPR, in particular the European Commission’s standard contractual clauses, incorporated in the data processing agreements of the providers concerned, together with the additional measures they document (encryption in transit, access control, transparency reporting).
You may obtain a copy of the safeguards applicable to a given transfer by writing to DPO@despii.com.
7. How long we keep it
| Data | Retention |
|---|---|
| Early-access address (Site) | Until the invitation is sent and at most 24 months after the request, or until you withdraw consent |
| Account and Organisation membership | For as long as the account is open |
| Your content (documents, tickets, alerts, files) | For as long as the account is open, then deleted after the account is closed |
| Deletion after the account is closed | [[À COMPLÉTER : délai de rétention et de purge définitive après clôture du compte]] |
| Technical logs | [[À COMPLÉTER : durée de conservation des journaux techniques et des traces d’erreur]] |
| Invoices and accounting records | 10 years from the end of the financial year (art. L123-22 of the French Commercial Code) |
| Evidence needed to defend a claim | For the duration of the applicable limitation period |
Once those periods have elapsed, data is deleted or irreversibly anonymised.
8. Security
Data travels over encrypted connections. Passwords are never stored in a readable form. Access to production systems is restricted and authenticated.
Data is partitioned per Organisation, and that partitioning is enforced in the database itself, by row-level security, in addition to the application layer. An API key belongs to one Organisation and cannot reach outside it. Files are stored under a path scoped to the Organisation and served through time-limited signed URLs.
Secrets you entrust to the Service (tokens for connected services, provider keys) are stored write-only and are never returned in clear by the API.
No transmission or storage method offers absolute security. We undertake to notify the competent supervisory authority, and you where required, of any personal data breach likely to create a risk, within the time limits set by the GDPR.
9. Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction of processing, portability, objection to processing based on our legitimate interest, withdrawal of consent, and the right to give directions on the fate of your data after your death.
To exercise them, write to DPO@despii.com, or to DESPII SASU, for the attention of the DPO, 5 rue Pleyel, 93200 Saint-Denis, France.
We answer within one month of receiving the request. That period may be extended by two months where the request is complex or where requests are numerous; you will be told within the first month. We may ask for proof of identity where there is reasonable doubt as to who is making the request.
Where the data belongs to your employer’s workspace. Where you use Matcha through an Organisation belonging to a company, that company decides what goes into the Service and how long it stays: it is the controller for that content, and we act as its processor. Address your request to them first; we will forward it and assist them in answering it.
If you consider your rights have not been respected, you may lodge a complaint with the French supervisory authority, the CNIL, at cnil.fr, or with the authority of the Member State in which you live.
10. Cookies
This Site sets no cookie.
It is a static site: no audience measurement, no advertising tag, no social plug-in, no third-party tracker. Fonts are self-hosted and no external resource is loaded. Nothing is written to your browser’s local storage. That is why you are not shown a consent banner: there is nothing to consent to.
Our host, Cloudflare, may set strictly necessary cookies for security and anti-abuse purposes when its protections are engaged. Such cookies are exempt from consent under article 82 of the French Data Protection Act, as clarified by the CNIL, because they are strictly necessary to deliver the service you request.
The Matcha application is a native desktop application: it holds your session locally on your machine and does not use browser cookies.
Should audience measurement ever be added to the Site, this policy will be updated beforehand and the applicable consent rules will be followed.
11. Minors
The Service is a professional tool and is not intended for minors. We do not knowingly collect data relating to a person under the age of 16. Should such data have been collected, it will be deleted on request to DPO@despii.com.
12. Automated decision-making
We take no decision producing legal effects concerning you, or significantly affecting you, on the basis of automated processing alone.
13. Changes to this policy
This policy may change as the Service does. Substantial changes are notified by email or in the Service before they take effect. The date at the top of this page shows the version in force.
14. Contact
- Personal data and GDPR requests: DPO@despii.com
- Legal enquiries: legal@despii.com
- Product and commercial enquiries: hello@ganeden.eu
- Postal address: DESPII SASU, 5 rue Pleyel, 93200 Saint-Denis, France