1. Data controller
The data controller is Evoliz SAS, 1666 Chemin de la Planquette, 83130 La Garde, France, registered under number 522 513 233.
For any question about your personal data or to exercise your rights, write to rgpd [at] evoliz [dot] com .
2. What the connector does
The connector lets the AI assistant of your choice read and update, at your request and on your behalf, your company's invoicing data in Evoliz: clients, prospects, suppliers, quotes, invoices, credit notes, delivery notes, sale orders, advances, payments, articles, reminders, users and electronic invoicing.
- The assistant only reaches the companies and features your Evoliz user is entitled to.
- It acts only during a conversation you are holding, never on its own initiative.
- Irreversible actions (assigning a permanent number to a document, sending an email, transmitting a document to the French e-invoicing platform) require your explicit confirmation.
3. Data processed
Authentication data
- Your Evoliz email address and password, entered only on the authorization page hosted by Evoliz, or your Google identity if you choose to sign in with Google. Your password is never transmitted to the assistant provider.
- The OAuth 2.1 tokens issued by Evoliz to the assistant.
Data from your Evoliz account
Read or updated only in response to your requests:
- identity and contact details of your clients, prospects, suppliers and their contacts: name, company name, postal addresses, email addresses, phone numbers, SIREN / SIRET, VAT number;
- commercial and accounting documents: quotes, invoices, credit notes, delivery notes, sale orders, advances, amounts, payment terms and methods, payments, reminders;
- articles, company settings and documents in the purchase reception box;
- company users (name, email address, role) when you manage access;
- your clients' electronic addresses in the e-invoicing directory.
Content of your requests
The information you type into the assistant that it passes to the connector to carry out your request, such as a new client's details or the lines of a quote.
Technical data
IP address, client type, date and time, tool called and response status, recorded in access logs; error messages recorded in the connector's error logs.
Data the connector does not collect
The connector collects no payment card data, no health data and no personal government identifier such as a social security number. It does not process more data than your request requires.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Carrying out your requests in Evoliz | Performance of the contract |
| Authenticating you and securing access to your account | Performance of the contract and legitimate interest (security) |
| Monitoring the service, diagnosing errors and preventing abuse | Legitimate interest |
| Transmitting your invoices to the e-invoicing platform when you ask for it | Legal obligation (electronic invoicing) |
Evoliz does not use this data for advertising, does not sell it, performs no profiling and does not use it to train artificial intelligence models.
5. Recipients
- The provider of the AI assistant you chose, for example OpenAI for ChatGPT or Anthropic for Claude. It receives your requests and the connector's responses to display and process them in the conversation. That processing is governed by its own privacy policy and by your settings with that provider, including those about conversation history and model improvement; Evoliz does not control it.
- Our hosting provider, whose data centres used for Evoliz are located in the European Union (Paris region).
- Our technical monitoring tool, which receives diagnostic information about requests and errors. Authentication headers and passwords are excluded from it.
- The French e-invoicing platform (Plateforme Agréée) and its directory, when you look up an electronic address or transmit a document.
- Authorised Evoliz staff, for support and maintenance, bound by confidentiality.
The data you exchange with the assistant provider may be processed outside the European Union, under that provider's own terms.
6. Retention periods
| Data | Retention |
|---|---|
| Access token | 20 minutes |
| Refresh token (connection kept active without signing in again) | 30 days |
| Access logs | 6 months |
| Connector error logs | 30 days |
| Diagnostic data in the monitoring tool | Limited period, as needed for diagnosis |
| Data in your Evoliz account | As set out in the general privacy policy and by the legal retention obligations for accounting records |
Disconnecting the assistant ends its access but does not delete the data in your Evoliz account, including data created or updated through it.
7. Your controls
- Disconnect the assistant at any time from its settings (in ChatGPT: Settings, then Connectors). Any further request is then refused.
- Revoke every active connection by writing to rgpd [at] evoliz [dot] com .
- Confirm or decline each irreversible action: the assistant shows you the content before acting and waits for your approval.
- Manage how your conversations are used by the assistant provider, in its own settings.
8. Your rights
Under the General Data Protection Regulation, you have the right to access, rectify and erase your data, to restrict its processing, to data portability and to object, as well as the right to set directives on what happens to your data after your death.
To exercise them, write to rgpd [at] evoliz [dot] com . You may also lodge a complaint with the French supervisory authority, the Commission nationale de l'informatique et des libertés (www.cnil.fr).
9. Security
Exchanges between the assistant and Evoliz are encrypted (TLS). Authorization relies on OAuth 2.1 with PKCE, short-lived access tokens and a scope limited to your companies and your rights in Evoliz. Access is logged and irreversible actions require your confirmation.
10. Changes
Any substantial change to this policy is published on this page, with its update date.