Privacy policy
This policy describes the personal-data processing Action Flow actually performs. It complements the terms of use.
Controller
Action Flow is published by Traindy, 86 rue Damrémont, 75018 Paris, France. Traindy is the controller for platform accounts. For participants, support contacts and pedagogical email recipients, the customer organisation is the controller and Traindy acts as processor (Article 28).
Contact
To exercise your rights or ask a question about this policy: privacy@traindy.io.
People we process
Platform users (trainers, organisation admins, app admins); people and participants in a training session; support-network contacts (manager, peer); transactional email recipients; product-update marketing contacts; organisation DPO contacts.
Processing
- User account: identity, email, sign-in method, language and timezone. Legal basis: contract (acceptance of the terms and this policy). The terms-acceptance timestamp is kept after anonymization as proof (Article 7.1).
- Pedagogy: identity, email, optional phone, external id, activity answers, implementation intention, transfer profile, end-of-session review (Likert scores and free-text), pedagogical notes written by the team (free text, visible on the Audit tab; optional inclusion in the sponsor report), completion proofs, scores. Legal basis: the contract between the customer organisation and Traindy, performed by the trainer.
- Product updates and onboarding tips: email, first name, last name, organisation name, only if the email is verified, the account is not suspended, and the profile toggle is on. The list is synced to Mailtrap. You can opt out at any time from your profile.
- Organisation DPO contact: email, organisation name, only if the organisation has filled in the contact. The list is synced to Mailtrap. You can change it at any time from the organisation settings.
- Support network: a contact is reached only after a consent request. A refusal, expiry or withdrawal purges the contact. Legal basis: consent.
- Transactional email (activities, visio, consent, alerts, billing): address, name, subject, delivery metadata. Legal basis: contract or legitimate interest (pedagogical digests).
- Billing: organisation name, admin email, VAT, Stripe customer id, consumed credits. Legal basis: contract and accounting duties. Card payments are handled by Stripe; Action Flow does not store card numbers. The Stripe customer is not deleted when an organisation is removed: it is kept for about 10 years.
- AI flow generation: text extracted from documents you upload (PDF, DOCX, PPTX, images) is sent to an AI provider (OpenAI by default). Do not upload participant lists or other personal data. Legal basis: legitimate interest / pre-contractual steps at your request. See also the notice shown before send.
- Visio and calendar: information needed to schedule and cancel events. Legal basis: the trainer’s consent. Upcoming events are cancelled when the account or session is deleted.
- Quality tracking (KPIs, Excel / PDF exports, activity report for the sponsor): scores, technical ids, and where applicable review quotes (first name) and shared notes (trainer name). Anonymized people are excluded from exports. Legal basis: legitimate interest and, where applicable, training-evidence duties.
- Technical logs needed to operate and secure the service. Legal basis: legitimate interest.
- Marketing attribution: a first-party cookie (af_utm) may store UTM parameters from a guest visitorʼs first click (source, medium, campaign, content, term) for 30 days, then attach them to the organization created at sign-up. Legal basis: legitimate interest.
Retention
Training sessions: 3 years after the end date, then purge (activity emails, proofs, support contacts, pedagogical notes, anonymization or deletion of the person if they are no longer active elsewhere). The training catalogue is never deleted by this job. User account: anonymization on request rather than a hard delete, so the history we still need (credits, files, audit) survives. The terms-acceptance timestamp is kept as proof. Language, timezone and appearance are reset to defaults. Invitations addressed to the account email are deleted. Technical events (AI usage, email) are kept for as long as needed to operate the service. Credit-consumption proofs are detached from the session and kept for accounting. The Stripe customer (id, billing email, organisation name) and billing records are kept for about 10 years to meet French accounting duties, including after an organisation is deleted.
Processors
Stripe (payments); Mailtrap (email delivery and, when enabled, the marketing list); OVH object storage (France) for files and proofs; OpenAI or another configured AI provider for flow generation; Google, Microsoft and LinkedIn for sign-in and, where used, calendars. On Stripe, the customer and billing records are kept for about 10 years (accounting duties). Retention on the other providers is outside Action Flow’s scope.
Your rights
You can access and rectify your data from your profile (account) or the participant / support space. Deleting an account anonymizes your row. A participant may leave a session; their identity is then anonymized if they have no other active participation. For a consolidated access, portability or objection request, write to privacy@traindy.io. You may also lodge a complaint with the CNIL.
Transfers outside the EU
Some processors (payments, sign-in, AI) may process data outside the EU. Those transfers rely on the safeguards required by applicable law. File storage is in France.
Changes
This policy may be updated to match the product. The date at the top of the page prevails. Material changes will be signalled to signed-in users when reasonable.