Elocia — Legal
Privacy Policy
Last updated: July 27, 2026
Elocia is a LinkedIn editorial copilot that helps professionals identify topics, write and publish posts. This Privacy Policy describes what personal data we collect when you use our service, for what purpose, with whom we share it, how long we keep it, and your rights regarding this data.
1. Data controller
The controller for the personal data collected via Elocia is:
[COMPANY_NAME], [LEGAL_FORM] with share capital of [SHARE_CAPITAL], registered with the French Trade and Companies Register under n° [SIREN], with its registered office at [ADDRESS].
Contact: [CONTACT_EMAIL]
For any question about the processing of your data or to exercise your rights, you may contact our Data Protection Officer (DPO) at: [DPO_EMAIL].
2. Personal data we collect
We only collect data necessary to operate the service. It falls into five categories:
2.1 Identification and account data
- Email address (used as login identifier)
- First name, last name, display name
- Password (stored hashed by Supabase Auth, never accessible in plaintext)
- Account creation date, last login date
2.2 Professional profile data
- Job title, seniority, company, industry, country
- LinkedIn profile URL (if you choose to provide it)
- Editorial goals, target audiences, editorial posture, tone
- Editorial pillars, key messages, evidence, guardrails
- Topics followed, watchlist keywords, target weekly cadence
2.3 Content produced
- Generated LinkedIn posts, drafts, successive versions
- Publishing statistics you enter (impressions, reactions, comments)
- Images uploaded as post visuals
- Feedback you submit through the dedicated form
2.4 Data from LinkedIn
If you connect LinkedIn or import your LinkedIn data export, we collect:
- Your name, profile picture, headline, and about section
- Your recent published posts (for style analysis)
- Work experience and education items (for profile audit)
- An encrypted OAuth access token, solely to publish on your behalf when you explicitly ask
We do not collect or store your contacts, private messages, invitations, or any other data not needed to generate your posts.
2.5 Technical data
- IP address, application logs (access, errors), to secure the service
- AI usage traces (number of generations, tokens consumed) for billing and abuse prevention
3. Purposes and legal bases
We process your data for the following purposes, on the GDPR legal bases indicated in parentheses:
- Provide and operate the Elocia service (account, authentication, post generation, saving your drafts) — performance of the contract (art. 6.1.b).
- Personalize suggestions and scores based on your profile and declared preferences — performance of the contract (art. 6.1.b).
- Publish posts on LinkedIn on your behalf, only when you explicitly click "Publish now" or "Schedule" — consent (art. 6.1.a), revocable at any time.
- Ensure security and prevent abuse (access logs, anomaly detection) — legitimate interest (art. 6.1.f).
- Improve the service from anonymized feedback — legitimate interest (art. 6.1.f).
- Comply with legal obligations (billing, accounting, responses to authorities) — legal obligation (art. 6.1.c).
We do not use your data for advertising profiling, do not sell it, and do not share it with third parties for marketing purposes.
4. Use of the LinkedIn API
Elocia uses the LinkedIn APIs (Sign In with LinkedIn, Share on LinkedIn, and the OpenID Connect API) in strict compliance with LinkedIn's Terms of Use and the platform's Data Usage Policy.
What we do via the LinkedIn API:
- Retrieve identification information (name, email, picture) when you sign in with LinkedIn
- Publish a text or image post to your profile, only when you explicitly instruct us to do so
- Analyze your recent public posts (content, format, approximate engagement) to refine our personalized suggestions
What we never do:
- Publish without your explicit action
- Read your private messages or invitations
- Extract your contacts
- Share LinkedIn data with third parties other than the technical processors listed in section 5
- Retain LinkedIn tokens beyond the period necessary to publish or until you revoke consent
You may revoke Elocia's access to your LinkedIn account at any time from your LinkedIn account settings (Data privacy → Permitted services) or by contacting us directly.
5. Processors and recipients
We share your data only with technical processors strictly necessary to run the service. Each is bound by a data processing agreement (DPA) and complies with the GDPR or, for non-EU providers, with the European Commission's Standard Contractual Clauses.
| Processor | Role | Location |
|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, storage | European Union (eu-west-1, Ireland) |
| Vercel Inc. | Application hosting, CDN | United States (European edge nodes) |
| Anthropic PBC | Generative AI model (Claude) | United States |
| Perplexity AI Inc. | Web search for the news watch | United States |
| Unsplash Inc. | Royalty-free image library | Canada |
| LinkedIn (Microsoft) | Authentication and publishing | Ireland / United States |
We only transmit to Anthropic and Perplexity the context strictly needed for the requested generation (your profile, the topic, the week's signals) — never your email, password, or access tokens.
6. Transfers outside the European Union
Some processors (Vercel, Anthropic, Perplexity) are based in the United States. Transfers to these recipients are governed by:
- The Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914)
- For certified companies: the EU–US Data Privacy Framework
- Additional technical measures (encryption in transit, minimization of transmitted data)
You may obtain a copy of these safeguards by contacting us at the address in section 12.
7. Data retention
| Data category | Retention |
|---|---|
| Account and profile | As long as the account is active, then 30 days after deletion |
| Content produced (posts, drafts) | Same as account, unless manually deleted earlier |
| LinkedIn OAuth tokens | Until you revoke, or 90 days of inactivity |
| Technical logs | Maximum 12 months |
| Billing data | 10 years (accounting obligation, art. L123-22 French Commercial Code) |
8. Your rights (GDPR)
In accordance with articles 15 to 22 of the GDPR, you have the following rights over your data at any time:
- Right of access — obtain a copy of your data
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten") — request deletion of your account and data
- Right to restriction — temporarily freeze processing
- Right to portability — receive your data in a structured, readable format (JSON), or have it transmitted to another service
- Right to object — object to processing on legitimate grounds, except processing necessary to perform the contract
- Right to withdraw consent at any time (e.g. for LinkedIn publishing)
- Right to define post-mortem directives regarding the storage, erasure, and communication of your data after your death (art. 85 of the French Data Protection Act)
To exercise any of these rights, write to [CONTACT_EMAIL] with your request. We will respond within a maximum of one month (extendable by two months for complex cases, with notice given promptly).
If you believe the processing of your data violates the GDPR, you have the right to lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr/en/plaintes.
9. Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit (HTTPS/TLS 1.2+) for all communications
- Encryption at rest for data stored at Supabase
- Data isolation per user via PostgreSQL Row Level Security
- Passwords stored hashed (bcrypt) by Supabase Auth
- Encrypted OAuth tokens in the database
- Access logs and alerts on anomalies
- Data access limited to strictly authorized personnel
In case of a data breach likely to result in a risk to your rights and freedoms, we will inform you promptly, in accordance with article 34 of the GDPR.
11. Changes to this Policy
We may update this Policy to reflect changes in our practices or regulations. Any substantial change will be brought to your attention via an in-app message or email at least 15 days before it takes effect. The last update date is shown at the top of this page.
12. Contact
For any question about this Policy or the processing of your data, please write to: [CONTACT_EMAIL]. We commit to responding promptly.
