GDPR compliant

Privacy Policy

Last updated: 1 September 2026

What data VSME OS collects when you use VSME OS, how we use it, and your rights under the GDPR.

1. Who We Are (Data Controller)

The data controller is VSME OS, operating from France. For privacy enquiries contact privacy@vsmeos.fr. Our supervisory authority is the CNIL(Commission Nationale de l'Informatique et des Libertés).

Note: VSME OS is currently pre-incorporation. This Privacy Policy will be updated to reference the registered legal entity (with SIRET number) immediately following incorporation. In the meantime, all GDPR obligations under this Policy are binding; data subject requests are actioned under the same Article 12 timelines described below.

2. What Data We Collect and Why

2.1 Account Data (via Clerk)

Full name, email address, authentication tokens. Legal basis: Contract — necessary to create and secure your account.

2.2 Company Profile Data

Legal company name, country, industry sector, annual revenue (optional), reporting year, authorised signatory name. Legal basis: Contract — required to generate your carbon declaration.

2.3 Carbon Assessment Data

Fuel consumption, electricity usage, travel distances, employee commuting estimates, refrigerant quantities. Legal basis: Contract — this is the core data that produces your report.

2.4 Evidence Files

PDFs, images, spreadsheets uploaded to the Evidence Vault (utility invoices, maintenance logs, etc.). Stored in encrypted EU-based storage. Legal basis: Contract — supports audit verification.

2.5 Technical Data

Browser type, device type, IP address (90 days, security only). Legal basis: Legitimate interest (security and abuse prevention).

Product analytics — which pages you reach and where you stop — recorded against your account identifier, not your name. This is pseudonymous, not anonymous: we can tie it back to your account, so we treat it as personal data. Legal basis: Consent. Nothing is loaded until you accept the analytics banner, and declining costs you nothing.

3. Third-Party Sub-Processors

These are every third party that processes data on our behalf. This list is complete — if it is not on it, we do not send your data there.

Each is an established provider operating under its own published data processing terms. We are putting the executed Data Processing Agreements for this chain on file as part of incorporation, and we will say so here when that is done rather than before. If you need the chain for a procurement review today, ask us and we will send you exactly where each one stands.

ServicePurposeDataLocation
SupabaseDatabase and file storageEverything you enter: company details, the name of your authorised signatory, every activity figure, every disclosure answer, and every evidence file you upload.European Union — Frankfurt
ClerkSign-in and account securityYour name, your email address, and the session tokens that keep you signed in.Confirming region — treated as a transfer under Standard Contractual ClausesStandard Contractual Clauses
VercelApplication hostingRequest logs and IP addresses — and, because it runs the application, every request in transit.European Union — Paris
ResendSending invitation and notification emailSupplier email addresses, and the buyer and supplier company names in the message.Confirming region — treated as a transfer under Standard Contractual ClausesStandard Contractual Clauses
AnthropicThe VESQ3 reduction recommendationsCarries no identifiers. Industry, country, reporting year, currency, your four scope figures, your country grid factor, and up to five emission-source labels chosen from a fixed list — nothing else. No company name, no person’s name, no email address, no site address, no uploaded file, and no free text you typed. The industry benchmark makes no model call at all.United States — Standard Contractual ClausesStandard Contractual Clauses
PostHogProduct analyticsWhich pages you reach and where you stop, recorded against your account identifier. Nothing is loaded or stored until you accept the analytics banner, and declining costs you nothing.European Union
HostingerDomain name and DNSNo personal data. DNS records only.European Union

This list last changed on 1 September 2026. It is also published on its own page, so you can link to it, bookmark it and see when it moves: vsmeos.fr/subprocessors.

4. Who We Share Your Data With

We do not sell your data. We share it only in these circumstances:

  • With your buyer (if invited): The buyer who invited you sees your scope totals, your Scope 2 method, and which of the eleven disclosures you answered — nothing more. Your underlying activity figures (litres of fuel, kWh, kilometres), your uploaded evidence files, and your PDF declaration are never sent to them. What you hand a buyer beyond that is your decision, not ours: the PDF is yours to send.
  • With sub-processors: As listed in Section 3, solely to deliver the service.
  • Legal obligation: If required by law, court order, or regulatory authority (CNIL, tax authorities).
  • Business transfer: If VSME OS is acquired, data may transfer under the same privacy commitments.

5. How Long We Keep Your Data

Account data (name, email)Until deletion + 30 days
Company profile & assessment data7 years (CSRD audit requirement)
Uploaded evidence files7 years (CSRD audit requirement)
Generated PDF reports7 years (CSRD audit requirement)
Security / access logs90 days
Anonymised analyticsIndefinitely (no personal data)

6. Your Rights Under GDPR

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

Request deletion ("right to be forgotten"), subject to legal retention obligations.

Right to Portability (Art. 20)

Receive your data in a machine-readable format (JSON/CSV).

Right to Restriction (Art. 18)

Restrict how we process your data in certain circumstances.

Right to Object (Art. 21)

Object to processing based on legitimate interests.

Withdraw Consent

Where processing is consent-based, withdraw it at any time.

Lodge a Complaint

File a complaint with the CNIL at cnil.fr if you believe your data was mishandled.

To exercise any right, email privacy@vsmeos.fr. We respond within 30 days (GDPR Article 12).

7. Data Security

  • Encryption at rest: AES-256 (Supabase, Frankfurt EU)
  • Encryption in transit: TLS 1.3 on all connections
  • Row Level Security: database access scoped per user
  • Evidence files stored in private Supabase Storage (not publicly accessible)
  • Authentication via Clerk with MFA support
  • Data breach notification to CNIL and affected users within 72 hours (GDPR Art. 33)

8. Cookies

No advertising cookies and no tracking pixels. Everything below is either required to run the service or set only after you accept the analytics banner \u2014 and the analytics cookies are not written at all until you do.

CookieTypePurposeDuration
__clerk_*EssentialAuthentication session (Clerk)30 days
sb-*EssentialSupabase auth tokenSession
_vercel_*TechnicalLoad balancingSession
ph_*ConsentedProduct analytics (PostHog, EU) — only after you accept12 months
vsme_analytics_consentEssentialRemembers your analytics choice so we stop asking12 months

9. Changes to This Policy

Material changes will be notified by email and in-app banner at least 30 days before taking effect. The "last updated" date at the top reflects the current version.

Questions or Requests?

For any privacy enquiries, data access requests, or to exercise your GDPR rights:

privacy@vsmeos.fr

Or file a complaint with the CNIL: cnil.fr