Last updated: 22 July 2026 Version: 1.0
1. Purpose of this Policy
This Privacy Policy explains how Senvarel (“we”, “us” or “our”) collects and uses personal data in connection with senvarel.com, Senvarel, our communications, sales, support and related business activities.
It applies to website visitors, prospective and current customers, authorised users, partners, suppliers and individuals whose publicly available information may be processed by the Service. It should be read with our Cookie Policy and, for Customers, the Business Terms and Conditions of Sale and Use.
2. Data controller and contact
For the processing described in this Policy where we determine the purposes and means, the controller is:
Imad El Ghamdi Entrepreneur individuel (micro-entreprise) 37 rue Etienne Dolet, 95100 Argenteuil, France SIREN: 941517021 VAT: FR24941517021 Privacy email: hello@senvarel.com Data Protection Officer: not appointed unless separately notified by Imad El Ghamdi
Where we process personal data contained in Customer Data solely on a Customer’s documented instructions to provide the Service, we act as a processor and the Customer normally acts as controller. Requests about such data should first be directed to the relevant Customer. Our processing obligations are set out in the applicable Data Processing Agreement.
3. Personal data we collect
Depending on how you interact with us, we may collect the following categories.
3.1 Account and identity data
Name, business email address, telephone number, job title, organisation, account identifier, profile preferences, role, permissions and authentication-related information.
3.2 Contract, billing and transaction data
Company details, billing address, VAT or tax number, subscription plan, invoices, payment status and transaction references. Full card details are collected and processed by Stripe and are not stored by us.
3.3 Customer configuration and connected-service data
Websites, domains, brands, competitors, target markets, keywords, content themes, selected sources, project settings, integration tokens or authorisations, and data retrieved from services connected by the Customer, such as analytics, webmaster or content-management platforms.
3.4 Service content, prompts and Outputs
Instructions, prompts, uploaded materials, draft content, generated content, reports, scores, recommendations, responses from supported AI providers, publication workflows and user feedback.
3.5 Usage, device and security data
IP address, approximate location derived from IP, device and browser type, operating system, pages or features used, timestamps, referring URLs, identifiers, log data, authentication events, diagnostics, errors and security signals.
3.6 Communications and support data
Emails, support requests, call or meeting notes, survey responses, feedback and other communications. Calls are not recorded unless participants are informed in advance and a lawful basis applies.
3.7 Marketing data
Communication preferences, campaign interactions, event participation and information about business interests. Email tracking pixels or equivalent trackers are used only as described in our Cookie Policy or the relevant communication notice and where the required consent has been obtained.
3.8 Public web and third-party platform data
To provide visibility, citation, competitor and opportunity analyses, the Service may process information made publicly available online or supplied through authorised APIs, such as:
webpage URLs, titles, excerpts, structured metadata and publication dates;
brand or domain mentions, citations, search results and public rankings;
public posts, comments, usernames or author names where relevant to the requested analysis;
source, link and authority indicators; and
outputs returned by supported search engines, AI services and other sources.
We seek to limit collection to information relevant to the professional analysis requested. We do not intentionally collect private account content or special-category data from public sources. Public availability does not remove data-protection obligations; where personal data is present, the processing is subject to the safeguards described in this Policy.
3.9 Data received from other people
A Customer administrator may provide a user’s professional contact and access details. Partners, referrals, public business sources or event organisers may also provide professional contact information where permitted by law. Where required, we provide information to the individual within the applicable period.
4. Why we use personal data and our legal bases
We process personal data only where a legal basis applies.
4.1 Provide and administer the Service — performance of a contract
We use account, configuration, Customer Content, integration, transaction and usage data to create accounts, authenticate users, provide requested features, perform analyses, generate Outputs, manage subscriptions, issue invoices, support users and communicate about the Service.
4.2 Secure and operate the Service — legitimate interests and legal obligations
We use device, log, account and security data to prevent fraud and abuse, investigate incidents, maintain availability, enforce usage rules, back up systems and protect our users, systems and rights. Our legitimate interests are providing a reliable and secure business service. We balance those interests against the rights of affected individuals and apply access, retention and security controls.
4.3 Improve and understand the Service — legitimate interests or consent
We analyse feature usage, errors, performance and feedback to improve usability, reliability and functionality. Where non-essential cookies or similar trackers are involved, we rely on consent unless a specific exemption applies. We may use aggregated or irreversibly de-identified information that is no longer personal data.
4.4 Analyse public professional visibility and opportunities — legitimate interests
We process limited publicly available information to provide Customers with requested SEO, AI-search visibility, citation, competitor, content and public-discussion analyses. Our interests and those of our Customers are understanding how organisations are represented in public sources and identifying relevant professional opportunities. We consider the public context, minimise data, restrict use to analysis, apply retention limits and provide rights mechanisms.
We do not use this basis to conduct intrusive profiling, infer sensitive characteristics or make decisions producing legal or similarly significant effects about individuals.
4.5 Billing, accounting, compliance and disputes — contract and legal obligations
We use contract, transaction and communication data to process payment, maintain statutory accounting and tax records, respond to authorities, establish or defend legal claims, and comply with applicable law.
4.6 Business communications and marketing — legitimate interests or consent
We may send existing business Customers information about similar services where permitted and where they can opt out. For other electronic marketing, we obtain consent where required. You can unsubscribe at any time by using the link in the message or contacting hello@senvarel.com. Transactional and security messages are not marketing and may still be sent while an account is active.
4.7 Manage suppliers, partners and corporate operations — contract and legitimate interests
We process professional contact and communication data to manage supplier and partner relationships, conduct due diligence, obtain professional advice, plan the business and manage corporate transactions.
4.8 Consent-based processing
Where processing relies on consent, you may withdraw it at any time without affecting processing carried out before withdrawal. Refusing or withdrawing optional consent does not prevent access to core Service functions, although the relevant optional feature may no longer work.
5. Whether data is required
Fields marked as required are necessary to create an account, enter into or perform the contract, secure the Service, process payment or comply with law. If required information is not provided, we may be unable to create the account, activate a subscription, provide a feature or respond to a request.
Other information is optional. The collection interface will indicate whether a field is required where this is not otherwise apparent.
6. AI providers and automated processing
When a user requests an AI-assisted feature, relevant prompts, selected website information, instructions and contextual data may be sent to one or more AI infrastructure or model providers listed in our current sub-processor register at https://senvarel.com/subprocessors. Providers may include OpenAI, Google, Groq, Anthropic or other production providers, depending on the configuration enabled for the Service.
We configure providers and contracts to limit their use of submitted data as far as reasonably available for the selected business service. Customer Data is not intentionally submitted for general-purpose model training by us unless the Customer has expressly agreed. Provider retention, location and abuse-monitoring practices may differ and must be reflected in the final sub-processor register.
The Service may automatically score, classify, prioritise or recommend actions relating to websites, brands, content and public visibility. These operations do not produce legal or similarly significant effects about individuals. Users must review Outputs before acting on them.
7. Recipients and service providers
Personal data is accessible only where necessary to:
authorised employees and contractors subject to confidentiality;
hosting, database, storage, security and content-delivery providers;
payment and invoicing providers;
transactional email and customer-support providers;
analytics and error-monitoring providers, subject to cookie choices where applicable;
AI and search-data providers used to generate requested analyses;
professional advisers, auditors, insurers and financial institutions; and
public authorities, courts or regulators where disclosure is legally required.
The final production list must be published at https://senvarel.com/subprocessors and should identify, at minimum, the provider, purpose, processing location and applicable transfer safeguard.
We do not sell personal data. We do not share personal data for third parties’ independent advertising purposes without the required consent.
8. International transfers
We aim to host core Customer Data in France (European Union). Some service providers may process data outside the European Economic Area.
Where personal data is transferred to a country that has not been recognised by the European Commission as providing an adequate level of protection, we use an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. Details of relevant safeguards may be requested at hello@senvarel.com, subject to protection of confidential and security information.
9. Retention periods
We keep personal data only for as long as necessary for the purpose for which it was collected, then delete or irreversibly anonymise it unless law requires longer retention. The following proposed periods must be verified against the production architecture and legal advice:
Account and Service data: while the account is active, then for up to 30 days for export and operational deletion; residual encrypted backups may remain for up to 90 days and are isolated from ordinary use.
Contract and customer-relationship records: for the contractual relationship, then up to five years to establish, exercise or defend legal claims, subject to longer mandatory periods.
Invoices and accounting records: ten years from the end of the relevant financial year or transaction, where required by French law.
Payment references: for the time needed to process the transaction and manage disputes; complete card details are retained by the payment provider under its own rules.
Sales prospects: three years after collection or the last meaningful contact, unless the individual objects earlier or another legal basis applies.
Support and business communications: for the time needed to handle the request, then up to three years, or longer where needed for a dispute.
Security and technical logs: 6-12 months, unless a longer period is needed to investigate an incident or comply with law.
Raw crawl, search or third-party response data: 90 days unless retained as part of a Customer-requested report or needed to document an analysis.
Analysis results, reports and generated content: while the relevant Customer account is active, followed by the deletion period stated above.
Cookie consent choices: Account and content data: account lifetime; jobs and job errors: 90 days; security audit logs: 12 months; support records: 24 months; billing records: statutory accounting retention period., subject to regulatory guidance and technical necessity.
Audience-measurement data: according to the Cookie Policy and provider configuration; where relying on the French consent exemption, tracker life should not exceed thirteen months and collected information should not be retained for more than twenty-five months.
Suppression and objection lists: as long as necessary to respect the request and avoid contacting the person again.
Retention may be suspended where data is placed under a legal hold for a dispute, investigation or binding request.
10. Security
We use technical and organisational measures appropriate to the nature of the data and risks, which may include:
role-based access controls and least-privilege principles;
encryption in transit and, where appropriate, at rest;
password hashing, secure authentication and session controls;
logical tenant separation;
logging, monitoring, alerting and incident-response processes;
backups, continuity measures and tested restoration procedures;
vulnerability, dependency and patch management;
supplier assessment and contractual data-protection obligations; and
staff and contractor confidentiality obligations.
No system is completely secure. If you believe an account or data has been compromised, contact hello@senvarel.com immediately and do not disclose the issue publicly until we have had a reasonable opportunity to investigate, unless law requires otherwise.
11. Personal-data breaches
We maintain procedures to assess and respond to suspected personal-data breaches. Where required, we will notify the competent supervisory authority and affected individuals within the applicable legal timeframes. Where we act as a processor, we will notify and assist the relevant Customer in accordance with the Data Processing Agreement.
12. Your rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
access your personal data and obtain a copy;
correct inaccurate or incomplete data;
request deletion of your data;
restrict processing;
object to processing based on legitimate interests, including public-data analysis where your situation warrants it;
object at any time to direct marketing;
receive data you provided in a structured, commonly used and machine-readable format where the right to portability applies;
withdraw consent at any time for consent-based processing; and
give instructions concerning the handling of personal data after death where French law provides this right.
To exercise a right, contact hello@senvarel.com and identify the relevant account, URL, public source, username or other context needed to locate the data. We may request proportionate proof of identity where reasonably necessary. Do not send identity documents unless requested; if one is required, unnecessary information should be masked.
We will respond without undue delay and normally within one month. This period may be extended by two months for complex or numerous requests, in which case we will explain the extension. Requests are generally free, but manifestly unfounded or excessive requests may be refused or subject to a reasonable fee as permitted by law.
If we process data only on behalf of a Customer, we may refer the request to that Customer and assist it as required.
13. Public-data rights requests
If your information appears in a public page, post, comment or citation processed by the Service, provide the source URL and enough context for us to locate the record. Where we cannot identify you from the stored data, we may need additional information to connect you to the relevant record. We will not collect additional identifying data solely to identify a person where this would be disproportionate, but we will explain available options.
Removal from our Service does not delete the original content from the source website or search engine. You must contact the original publisher or platform for removal at source.
14. Complaints
Please contact us first at hello@senvarel.com so we can try to resolve your concern.
You also have the right to lodge a complaint with the French supervisory authority:
Commission Nationale de l’Informatique et des Libertés (CNIL) 3 Place de Fontenoy, TSA 80715 75334 Paris Cedex 07, France
If you live or work in another EEA country, you may also contact your local data-protection authority.
15. Cookies and similar technologies
We use cookies and similar technologies as described in the Cookie Policy. Non-essential trackers are not placed or read before valid consent where consent is required. You can reject non-essential cookies as easily as accepting them and change your choices at any time through the cookie preference centre.
16. Children
The Service is designed for professional users and is not directed to children. Users must be at least eighteen years old and able to enter into a business agreement. If we learn that a child’s data has been submitted without an appropriate basis, we will take reasonable steps to delete it.
17. Third-party websites
Our website and Service may link to or integrate with third-party services. Their processing is governed by their own privacy notices. We encourage you to review those notices. We are not responsible for processing independently determined by third parties.
18. Corporate transactions
If we are involved in a merger, financing, acquisition, restructuring or sale of assets, relevant personal data may be disclosed under confidentiality and transferred as part of the transaction, subject to applicable law and continued protection. We will provide notice where required.
19. Changes to this Policy
We may update this Policy to reflect changes in law, the Service or our processing. The current version will be posted with its effective date. We will provide appropriate notice of material changes and obtain consent where a new consent is legally required.
20. Contact
For questions or requests relating to privacy, contact:
Imad El Ghamdi — Privacy 37 rue Etienne Dolet, 95100 Argenteuil, France hello@senvarel.com