Elocia — Legal

Privacy Policy

Last updated: July 27, 2026

Elocia is a LinkedIn editorial copilot that helps professionals identify topics, write and publish posts. This Privacy Policy describes what personal data we collect when you use our service, for what purpose, with whom we share it, how long we keep it, and your rights regarding this data.

1. Data controller

The controller for the personal data collected via Elocia is:

[COMPANY_NAME], [LEGAL_FORM] with share capital of [SHARE_CAPITAL], registered with the French Trade and Companies Register under n° [SIREN], with its registered office at [ADDRESS].
Contact: [CONTACT_EMAIL]

For any question about the processing of your data or to exercise your rights, you may contact our Data Protection Officer (DPO) at: [DPO_EMAIL].

2. Personal data we collect

We only collect data necessary to operate the service. It falls into five categories:

2.1 Identification and account data

  • Email address (used as login identifier)
  • First name, last name, display name
  • Password (stored hashed by Supabase Auth, never accessible in plaintext)
  • Account creation date, last login date

2.2 Professional profile data

  • Job title, seniority, company, industry, country
  • LinkedIn profile URL (if you choose to provide it)
  • Editorial goals, target audiences, editorial posture, tone
  • Editorial pillars, key messages, evidence, guardrails
  • Topics followed, watchlist keywords, target weekly cadence

2.3 Content produced

  • Generated LinkedIn posts, drafts, successive versions
  • Publishing statistics you enter (impressions, reactions, comments)
  • Images uploaded as post visuals
  • Feedback you submit through the dedicated form

2.4 Data from LinkedIn

If you connect LinkedIn or import your LinkedIn data export, we collect:

  • Your name, profile picture, headline, and about section
  • Your recent published posts (for style analysis)
  • Work experience and education items (for profile audit)
  • An encrypted OAuth access token, solely to publish on your behalf when you explicitly ask

We do not collect or store your contacts, private messages, invitations, or any other data not needed to generate your posts.

2.5 Technical data

  • IP address, application logs (access, errors), to secure the service
  • AI usage traces (number of generations, tokens consumed) for billing and abuse prevention

3. Purposes and legal bases

We process your data for the following purposes, on the GDPR legal bases indicated in parentheses:

  • Provide and operate the Elocia service (account, authentication, post generation, saving your drafts) — performance of the contract (art. 6.1.b).
  • Personalize suggestions and scores based on your profile and declared preferences — performance of the contract (art. 6.1.b).
  • Publish posts on LinkedIn on your behalf, only when you explicitly click "Publish now" or "Schedule" — consent (art. 6.1.a), revocable at any time.
  • Ensure security and prevent abuse (access logs, anomaly detection) — legitimate interest (art. 6.1.f).
  • Improve the service from anonymized feedback — legitimate interest (art. 6.1.f).
  • Comply with legal obligations (billing, accounting, responses to authorities) — legal obligation (art. 6.1.c).

We do not use your data for advertising profiling, do not sell it, and do not share it with third parties for marketing purposes.

4. Use of the LinkedIn API

Elocia uses the LinkedIn APIs (Sign In with LinkedIn, Share on LinkedIn, and the OpenID Connect API) in strict compliance with LinkedIn's Terms of Use and the platform's Data Usage Policy.

What we do via the LinkedIn API:

  • Retrieve identification information (name, email, picture) when you sign in with LinkedIn
  • Publish a text or image post to your profile, only when you explicitly instruct us to do so
  • Analyze your recent public posts (content, format, approximate engagement) to refine our personalized suggestions

What we never do:

  • Publish without your explicit action
  • Read your private messages or invitations
  • Extract your contacts
  • Share LinkedIn data with third parties other than the technical processors listed in section 5
  • Retain LinkedIn tokens beyond the period necessary to publish or until you revoke consent

You may revoke Elocia's access to your LinkedIn account at any time from your LinkedIn account settings (Data privacy → Permitted services) or by contacting us directly.

5. Processors and recipients

We share your data only with technical processors strictly necessary to run the service. Each is bound by a data processing agreement (DPA) and complies with the GDPR or, for non-EU providers, with the European Commission's Standard Contractual Clauses.

ProcessorRoleLocation
Supabase (Supabase Inc.)Database, authentication, storageEuropean Union (eu-west-1, Ireland)
Vercel Inc.Application hosting, CDNUnited States (European edge nodes)
Anthropic PBCGenerative AI model (Claude)United States
Perplexity AI Inc.Web search for the news watchUnited States
Unsplash Inc.Royalty-free image libraryCanada
LinkedIn (Microsoft)Authentication and publishingIreland / United States

We only transmit to Anthropic and Perplexity the context strictly needed for the requested generation (your profile, the topic, the week's signals) — never your email, password, or access tokens.

6. Transfers outside the European Union

Some processors (Vercel, Anthropic, Perplexity) are based in the United States. Transfers to these recipients are governed by:

  • The Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914)
  • For certified companies: the EU–US Data Privacy Framework
  • Additional technical measures (encryption in transit, minimization of transmitted data)

You may obtain a copy of these safeguards by contacting us at the address in section 12.

7. Data retention

Data categoryRetention
Account and profileAs long as the account is active, then 30 days after deletion
Content produced (posts, drafts)Same as account, unless manually deleted earlier
LinkedIn OAuth tokensUntil you revoke, or 90 days of inactivity
Technical logsMaximum 12 months
Billing data10 years (accounting obligation, art. L123-22 French Commercial Code)

8. Your rights (GDPR)

In accordance with articles 15 to 22 of the GDPR, you have the following rights over your data at any time:

  • Right of access — obtain a copy of your data
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request deletion of your account and data
  • Right to restriction — temporarily freeze processing
  • Right to portability — receive your data in a structured, readable format (JSON), or have it transmitted to another service
  • Right to object — object to processing on legitimate grounds, except processing necessary to perform the contract
  • Right to withdraw consent at any time (e.g. for LinkedIn publishing)
  • Right to define post-mortem directives regarding the storage, erasure, and communication of your data after your death (art. 85 of the French Data Protection Act)

To exercise any of these rights, write to [CONTACT_EMAIL] with your request. We will respond within a maximum of one month (extendable by two months for complex cases, with notice given promptly).

If you believe the processing of your data violates the GDPR, you have the right to lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr/en/plaintes.

9. Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (HTTPS/TLS 1.2+) for all communications
  • Encryption at rest for data stored at Supabase
  • Data isolation per user via PostgreSQL Row Level Security
  • Passwords stored hashed (bcrypt) by Supabase Auth
  • Encrypted OAuth tokens in the database
  • Access logs and alerts on anomalies
  • Data access limited to strictly authorized personnel

In case of a data breach likely to result in a risk to your rights and freedoms, we will inform you promptly, in accordance with article 34 of the GDPR.

10. Cookies

Elocia uses only strictly necessary technical cookies, exempt from consent under the guidelines of the French Data Protection Authority (CNIL):

  • Supabase session cookies — maintain your authenticated session, expire at logout or after 7 days of inactivity
  • UI preferences — remember your local choices (compact mode, sort) in your browser's localStorage, never transmitted to our servers

We use no advertising cookies, third-party analytics (Google Analytics, Hotjar…), tracking pixels, or retargeting solutions.

11. Changes to this Policy

We may update this Policy to reflect changes in our practices or regulations. Any substantial change will be brought to your attention via an in-app message or email at least 15 days before it takes effect. The last update date is shown at the top of this page.

12. Contact

For any question about this Policy or the processing of your data, please write to: [CONTACT_EMAIL]. We commit to responding promptly.