Contents
01 Data Controller
The data controller responsible for personal data processed through the Shatale platform is:
623 Rue du Devois, 34160 Saint-Drézéry, France
privacy@shatale.com
This Privacy Policy applies to personal data we collect in connection with the Shatale platform, including shatale.com, our API, and related services.
02 Scope
This Policy covers:
- Visitors to shatale.com
- Users: individuals who register an account and enrol a payment card to have our AI agents make card-on-file payments on their behalf
For all personal data processed to provide the Service — including payment-authorization data — Shatale SASU is the data controller under GDPR. As Merchant of Record and PCI-DSS entity, we determine the purposes (executing your authorized payments, fraud prevention, tax and dispute management) and the means of processing.
03 Legal Basis (GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the Service (account, executing your authorized payments) | Art. 6(1)(b) — Performance of a contract |
| Retaining card data to defend payment disputes | Art. 6(1)(c)/(f) — Legal obligation / legitimate interest |
| Fraud prevention and security | Art. 6(1)(f) — Legitimate interests |
| Marketing communications | Art. 6(1)(a) — Consent |
| Improving the Service | Art. 6(1)(f) — Legitimate interests |
| Regulatory compliance | Art. 6(1)(c) — Compliance with legal obligation |
04 Data We Collect
4.1 Account & Profile Data
Name, email, phone, country of residence; account credentials; the agent-policy configuration and spending limits you set.
4.2 Payment Card Data (as Data Controller)
To execute your first transaction and establish your payment mandate, we collect your card number (PAN), expiry date and CVV. The CVV is used only to authorize the first transaction and is never stored (CNIL Délibération 2018-303, PCI DSS). Your PAN and expiry are stored in encrypted/tokenized form for the duration of your active mandate so our agents can execute the off-session payments you authorized.
4.3 Transaction & Authorization Data
Merchant name, amount, currency; transaction timestamp and outcome; the policy applied and its evaluation result; authentication (3-D Secure) logs and mandate parameters.
4.4 Website Data
IP address (anonymized after processing); browser type, OS, device type; pages visited, time on page, referrer; form submissions (early access applications).
4.5 Communications
Email content and metadata; support ticket history.
05 How We Use Your Data
| Data category | Purpose |
|---|---|
| Account data | Account creation, authentication, billing |
| Transaction & log data | Service delivery, debugging, capacity planning, billing |
| Authorization data | Processing payment decisions, audit trail, compliance |
| Website data | Analytics, fraud detection, improving user experience |
| Communications | Customer support, product updates |
We do not sell personal data to third parties. Executing your card-on-file payments within the limits you configure is the core function of the Service; you retain the right to obtain human intervention, express your point of view and contest a payment decision by contacting us.
06 Cookies
| Category | Purpose | Opt-out? |
|---|---|---|
| Strictly necessary | Session management, security | No |
| Analytics | Understanding usage patterns (anonymized) | Yes |
| Marketing | Measuring campaign effectiveness | Yes |
Strictly-necessary cookies (authentication, security, billing configuration and storing your consent choices) are set without consent. Analytics and marketing cookies are used only after your clear positive act via the cookie banner, and can be refused or withdrawn at any time; you can also manage cookies via your browser settings.
07 Sharing Personal Data
7.1 Service Providers (Processors)
We use third-party processors for cloud hosting, email delivery, analytics, fraud screening, and card payment processing. All processors are bound by data processing agreements and provide appropriate guarantees under GDPR.
7.2 Card Networks
Authorization requests are submitted to Visa/Mastercard networks as part of payment processing. These networks have their own data processing terms.
7.3 Legal and Regulatory Requirements
We may disclose data to regulatory authorities (ACPR, Banque de France), law enforcement, or courts when required by applicable law, including AML reporting obligations.
7.4 Business Transfers
If Shatale SASU is involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction. We will notify affected parties in advance.
08 International Transfers
We are an EU-based company and primarily process data within the EEA. Where we transfer data outside the EEA, we rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR. You may request a copy of applicable transfer safeguards by contacting privacy@shatale.com.
09 Data Retention
| Data type | Retention period |
|---|---|
| Account & profile data | Duration of the account + legal archiving periods |
| Card credential (encrypted PAN + expiry) | Duration of the active mandate; then archived 13 months after each debit (15 months for deferred-debit cards) to defend unauthorized-payment claims (L133-24), access strictly restricted |
| CVV | Never stored — deleted after first-transaction authorization |
| Authorization / transaction logs | 13 months (payment-authorization; CNIL Délibération 2018-303) |
| Website analytics | 13 months (CNIL recommendation) |
| Marketing opt-ins | Until withdrawal of consent + 3 years |
| Support communications | 3 years |
After the applicable retention period, data is deleted or anonymized.
10 Your Rights Under GDPR
Access (Art. 15)
Request a copy of personal data we hold about you
Rectification (Art. 16)
Request correction of inaccurate or incomplete data
Erasure (Art. 17)
Request deletion where no longer necessary or lawfully required
Restriction (Art. 18)
Request restriction of processing in certain circumstances
Portability (Art. 20)
Receive your data in a structured, machine-readable format
Objection (Art. 21)
Object to processing based on legitimate interests
To exercise any right, contact privacy@shatale.com. We will respond within 30 days. Note: certain rights are limited by AML/KYC legal obligations.
10.1 Right to Lodge a Complaint
You have the right to lodge a complaint with your national data protection authority. In France: CNIL — www.cnil.fr
11 Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- PCI DSS compliance for card data handling
- Access controls and least-privilege principles
- Regular security assessments and penetration testing
- Incident response procedures
In the event of a personal data breach posing a risk to your rights and freedoms, we will notify the CNIL within 72 hours and affected individuals without undue delay (Articles 33–34 GDPR).
12 Children
The Service is not directed at individuals under 18. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
13 Changes to This Policy
We may update this Privacy Policy. Where changes are material, we will notify you by email at least 30 days before the effective date. The current version is always available at shatale.com/privacy.
14 Contact
privacy@shatale.com