legal
Privacy policy
This page is an English translation provided for convenience. The French version is the legally binding one.
Data controller#
SICCARDI TECH LEADS, 12 route du Tilleul, 78125 Raizeux, France — contact: pierre@tech-leads.net.
What we collect#
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Email address, team name | Create the account, authenticate, notify | Performance of the contract | Account lifetime; global identity up to 1 year after it is closed, only where a legal basis remains |
| Session tokens (stored as hashes) | Keep you signed in | Performance of the contract | 90 days |
| Uploaded agents: code, prompts, schemas, tests | Deliver the service | Performance of the contract | Account lifetime, then erasure under the deletion procedure |
| Chat content, execution traces and artifacts | Run, debug and keep history for your agents according to their configuration | Performance of the contract | Plan-bounded policy: Free 7 days, Studio 30 days, Enterprise 365 days until the 90-day Studio rollout is enabled |
| Technical logs (IP address, timestamp, errors) | Security, incident diagnosis | Legitimate interest | 90 days |
| Accounting records and payment history (amount, date, last four digits) | Accounting obligation | Legal obligation | 10 years |
| Site audience measurement (pages, sections, clicks, referral source) | Understand how the public site is used | Legitimate interest (audience-measurement exemption) | Event points — about 3 months |
Campaign source (utm_* / af_*) attached to a subscription or an application | Measure how effective our communication is | Legitimate interest | Account lifetime / 12 months |
We set no advertising cookies and use no third-party analytics service. The only cookie on the site remains the language choice, set solely when you click the switcher.
Audience measurement#
The site performs first-party audience measurement, exempt from consent: no cookie, no persistent identifier, no cross-site tracking, no transfer to a third party. An ephemeral identifier, scoped to the current tab and destroyed when you close it, links the pages of a single visit; the data (page views, sections displayed, clicks, campaign source) stays anonymous and statistical, is never cross-referenced with your account, and contains neither IP address nor identifying data. It is kept on our Cloudflare infrastructure as event points for about 3 months. Your browser's Do Not Track and Global Privacy Control signals are honoured: when either is on, nothing is sent.
Campaign attribution#
When you arrive from a campaign link, that link carries URL parameters (utm_*, then af_* carried from one link to the next during your visit). These parameters are never written to your device — no cookie, no local storage: they travel only in the addresses of the pages you open. They are associated with an account only when you subscribe or submit a partner application, so that we can tell which communication works. Legal basis: legitimate interest (measuring the effectiveness of our communication). Retention: for the lifetime of the account for a tenant, 12 months for an application.
Partner applications#
The form on the Partner program page collects your name, your company, your work email, the client volume you expect and your message. Purpose: reviewing your application (manual approval). Legal basis: pre-contractual measures taken at your request. Recipients: the orangeforge.ai operator, and Resend as the processor delivering the notification. Retention: 12 months for an application that is rejected or left without follow-up, purged automatically afterwards; an application followed by contact lives for the duration of the relationship. Access, rectification and erasure rights: by email to the contact address below.
What we do not do#
- We do not train any model on your prompts, data or traces.
- We do not sell or rent your data.
- We access the content of your agents only when indispensable to diagnose an incident you reported, or when required by law.
Data processed by your agents#
For personal data your agents process on behalf of your own users, you are the controller and we act as your processor within the meaning of Article 28 GDPR: we process that data only to deliver the Service, on your instructions as embodied in the configuration of your agents. Sub-processors are those listed below; any change to that list is published on this page before it takes effect. In the event of a data breach affecting such processing, we notify you without undue delay so you can meet your own notification obligations. Deletion follows the terms of the "Deletion" section.
Processors#
The Service relies on the following providers, which process data on our behalf:
| Provider | Role | Region |
|---|---|---|
| Cloudflare, Inc. | hébergement, exécution des agents à l'edge, CDN | Mondial (UE/US) |
| Convex, Inc. | base de données du control plane (comptes, agents, runs) | UE (eu-west-1) |
| Stripe, Inc. / Stripe Payments Europe Ltd | paiement, facturation, TVA (Managed Payments) | UE/US |
| Resend | envoi des emails transactionnels (liens de connexion) | UE/US |
| Vercel AI Gateway / OpenRouter | acheminement des appels aux modèles de langage | US |
| Composio | connecteurs applicatifs tiers activés par l'utilisateur | US |
Some of these providers are established in the United States. Such transfers rely on the European Commission's standard contractual clauses, supplemented where applicable by the EU–US Data Privacy Framework.
Content sent to models#
When one of your agents runs, the content required for it to work — prompt and input data — is sent to the model provider you chose. In prepaid-credit mode, requests pass through a gateway (Vercel AI Gateway or OpenRouter) which routes them to the infrastructure of the selected model's provider: the actual recipient therefore depends on the model configured for each agent. Those providers apply their own retention policies. If that transmission is sensitive in your context, prefer BYOK mode, which lets you contract directly with the provider of your choice.
Security#
Encryption in transit on all exchanges; session tokens and API keys stored as hashes and never redisplayed; agent secrets isolated at the execution worker level; strict separation between teams verified by automated tests; magic-link authentication with a verification code, designed to resist phishing.
Your rights#
You have rights of access, rectification, erasure, restriction, objection and portability. Write to pierre@tech-leads.net: we answer within one month.
Exporting your agents is immediate and requires no request: forge pull retrieves the agents only. To exercise portability over a whole tenant, forge tenant export produces a signed, encrypted archive covering the data listed in its manifest, without credentials.
You may lodge a complaint with the French data protection authority, the CNIL (cnil.fr).
Deletion#
A deletion request immediately freezes access and admissions. The tenant's active resources, agents, workers, content and traces are erased within 30 days at the latest, with absence verified with our processors, except accounting records the law requires us to keep for 10 years and, where a legal basis remains, a global identity kept for up to 1 year.
Encrypted backups are isolated, immutable for their retention period and expire on a documented cycle of 35 daily backups and 12 monthly points. They are never used to re-inject a deleted tenant into the active service; their restoration is tested in an isolated environment.