Delibia

Privacy policy

Version 1.3 — February 17, 2026

What is the purpose of our Privacy Policy?

Solyne SAS, publisher of the Delibia platform, attaches essential importance to the protection and confidentiality of personal data. This Privacy Policy reflects our commitment to comply strictly with the rules applicable to the protection of personal data, and in particular the General Data Protection Regulation ("GDPR").

It is intended to inform you of how we collect, use, retain, and protect your personal data in connection with use of the Delibia platform and its various features (search, AI, spaces, publication, and so on).

Who is our Privacy Policy addressed to?

Our Privacy Policy is addressed to you, wherever you live, provided that you are at least 15 years old and that you are a user of our platform Delibia.

If you are under the legal age set out above, you are not permitted to use our services without the prior and explicit consent of one of your parents or of the holder of parental authority. That consent must be sent to us by email at dpo@delibia.fr.

If you believe that we hold personal data concerning your children without having consented to it, please contact us at the dedicated address set out above.

What are the roles and responsibilities (GDPR)?

In connection with use of the Delibia platform:

  • The client authority is the controller within the meaning of the GDPR.
  • Solyne SAS acts as processor, in accordance with Article 28 of the GDPR.

Solyne processes personal data only on the documented instructions of the authority and never uses them for its own purposes.

Why do we process your personal data, and on what basis?

We process your personal data essentially for the following reasons:

  • To use and benefit from our service and all of its features, on the basis of our terms of use.
  • To manage user accounts (for example: account creation, access to the service, and deletion of accounts), on the basis of our terms of use.
  • To write free-form comments on the management of your files, on the basis of our terms of use.
  • To communicate with our support service through our internal messaging, on the basis of our terms of use.
  • To receive our technical emails (for example: password changes, and so on), which are essential to the proper operation of our service, on the basis of our terms of use.
  • To guarantee and strengthen the security and quality of our services day to day (for example: statistics, data security, and so on), on the basis of the legal obligations incumbent on us, our terms of use, and our legitimate interest in ensuring the proper operation of our services.

Your data are collected directly from you once you are a user of our Delibia platform, and we undertake to process your data only for the reasons described above.

What personal data do we process, and for how long?

We summarize below the categories of personal data and their respective retention periods:

  • Professional identification data (for example: last name, first name, position, company, and so on) and contact details (for example: professional email address and telephone number, and so on), retained throughout the period during which the service is provided, plus the statutory limitation periods, which are generally 5 years.
  • Email address used to receive our technical messages, retained until your account is deleted.
  • Connection data (for example: logs, IP address, and so on), retained for 12 months.
  • Input data ("AI prompts") and generated content, retained for 30 days for unsaved content, and for 12 months for prompts associated with a negative rating.
  • Internal data imported by the authority (for example: PDF and DOC files), retained until the end of the contract or until deleted by the user.
  • Support exchanges and technical data, retained for 12 months.

When the applicable retention periods expire, deletion of your personal data is irreversible, and we will no longer be able to provide them to you after that deadline. At most, we may retain only anonymous data for statistical purposes.

Please also note that, in the event of litigation, we are required to retain all data concerning you for the entire time the matter is being handled, even after the retention periods described above have expired.

What rights do you have to control the use of your personal data?

The regulations applicable to data protection grant you specific rights that you may exercise, at any time and free of charge, in order to control the use we make of your data.

  • Right of access to and to a copy of your personal data, provided that the request does not conflict with business secrecy, confidentiality, or the secrecy of correspondence.
  • Right of rectification of personal data that are inaccurate, outdated, or incomplete.
  • Right to request erasure ("right to be forgotten") of your personal data that are not essential to the proper operation of our services.
  • Right to restriction of your personal data, which makes it possible to freeze the use of your data where the lawfulness of a processing operation is contested.
  • Right to portability of your data, which allows you to recover part of your personal data in order to store it or to transmit it easily from one information system to another.
  • Right to give instructions on the fate of your data in the event of death, either yourself or through a trusted third party or a beneficiary.

For a request to be taken into account, it must be made directly by you at dpo@delibia.fr. Any request that is not made in this way cannot be processed.

Requests cannot come from anyone other than you. We may therefore ask you to provide proof of identity where there is doubt as to the identity of the requester.

We will respond to your request as soon as possible, subject to a maximum period of three months from its receipt where the request is technically complex or where we receive a large number of requests at the same time.

Please note that we may always refuse to respond to any excessive or unfounded request, in particular in view of its repetitive character.

Who may have access to your personal data?

Your personal data are processed by our teams and by our technical providers for the sole purpose of operating our service.

We specify that we review all of our technical providers before engaging them, in order to ensure that they scrupulously comply with the rules applicable to the protection of personal data.

FURTHERMORE, WE GUARANTEE THAT WE NEVER TRANSFER OR SELL YOUR DATA TO THIRD PARTIES OR TO COMMERCIAL PARTNERS.

Who are our authorized processors?

The following providers may be involved in the service:

  • Hosting: OVHcloud
  • AI engine (LLM): Mistral AI (European models, Zero Data Retention - immediate deletion after processing)
  • Disaster-recovery backup: Acronis
  • Transactional email: Mailjet
  • External DPO / register: Dipeeo
  • Support / customer chat: Intercom
  • Webinar: Livestorm
  • CRM: HubSpot
  • Professional email: Google Workspace
  • Cookie consent (CMP): Axeptio
  • IT services company: Asserina

Each of them:

  • acts only on instruction,
  • has no autonomy of use,
  • provides guarantees consistent with Article 28 of the GDPR.

Can your personal data be transferred outside the European Union?

Personal data processed by our Delibia platform are hosted exclusively on servers located within the European Union.

We also do our utmost to use only technical tools whose servers are likewise located within the European Union. If that is not the case, we take scrupulous care to ensure that they implement the appropriate safeguards required to ensure the confidentiality and protection of your personal data.

How do we protect your personal data?

We implement the following technical and organizational measures to guarantee the security of your personal data day to day and, in particular, to guard against any risk of destruction, loss, alteration, or disclosure.

Technical measures

  • Encryption of data in transit (TLS 1.2/1.3)
  • Complex, encrypted passwords
  • Automatic logout
  • HTTPS protocol
  • Segregation of environments
  • Logging and monitoring
  • Anti-spam / antivirus
  • Regular backups

Organizational measures

  • IT charter
  • Security training twice a year
  • Management of access rights
  • Secure offices
  • Incident-management procedures

What happens to the data at the end of the contract

When the contract between the authority and Solyne SAS ends:

  • Internal data and projects are deleted,
  • Personal data are either deleted or anonymized,
  • An export may be provided at the authority's request.

Do we use cookies when you browse our platform?

We inform you that we use cookies when you browse our platform. For further information, please see our Cookie Policy.

Who can you contact for more information on the use of your personal data?

In order to ensure the best possible protection and integrity of your data, we have officially appointed an independent Data Protection Officer ("DPO") with our supervisory authority: dpo@delibia.fr.

How can you contact the CNIL?

You may at any time contact the "Commission nationale de l'informatique et des libertés" or "CNIL" at the following address: Service des plaintes de la CNIL, 3 place de Fontenoy - TSA 80751, 75334 Paris Cedex 07, or by telephone at 01.53.73.22.22.

Can the Privacy Policy be amended?

We may amend our Privacy Policy at any time in order to adapt it to new legal requirements and to new processing that we might implement in the future.