At a glance (non-contractual summary)
This summary is provided for ease of reference; the full text of the articles that follow takes precedence.
- NOZZL SAS is the controller of data related to its business relationships (contacts, quotes, billing, security). For practice sessions, your company is the data controller and NOZZL SAS acts on its behalf.
- Speech is transcribed into text; the application does not retain any call audio files. Transcripts: 180 days by default; call reports: 365 days.
- AI providers process data in the United States, with transfer safeguards described in the list of Sub-processors.
- Audience measurement, partner attribution, and advertising trackers are used only with your consent, given through the cookie banner and changeable at any time using the “Manage my cookies” link.
- Your rights (access, rectification, erasure, objection...): privacy@clozing.example. You may lodge a complaint with the CNIL.
Article 1 — Data controller and contacts
NOZZL SAS, 32 rue de Paris, 92100 Boulogne-Billancourt, France, is the data controller for processing necessary to manage its business relationships, contacts, invoicing, and its own obligations. For questions about personal data or to exercise your rights, contact the representative responsible for these requests at privacy@clozing.example.
For practice sessions organized by your company, it determines the purposes, data subjects, access, and retention periods within the limits of the Service. It is the data controller; the Publisher acts on its behalf as a processor under the DPA. Your administrator or employer can provide the contact details of its data protection representative.
This policy does not replace the information your company must provide about the use of the system in your professional context. The same data may be used for different purposes: for example, a business email address is used to set up access for the Customer and to respond directly to a request sent to the Publisher.
Article 2 — Data subjects and data sources
2.1Sales reps: data provided during registration or invitation, login and usage data, speech transcribed during simulations, results, and exchanges with the coach. Data comes from you, your Organization, and your use of the Service.
2.2Owners, admins, and sales managers: professional identity, job title, role, team, invitations, administrative actions, and interactions with members. The Service records the actions necessary for operation, security, and traceability of administrative decisions.
2.3Business contacts, prospects, and visitors: information provided in the contact form, demo or quote requests, communications with the Publisher, and technical information required to view the site. Forms may ask for your name, company, business address, an optional phone number, sales team size, and message. Only with your consent, this information is supplemented by audience measurement and advertising information described in Article 4 and Article 14.
2.4Billing contacts and people who contact support: business contact details, contract references, invoices, messages, and documents relevant to handling their request. The website does not include an application form; an unsolicited application sent by email is processed to respond to its sender and then deleted no later than two years after the last contact.
2.5Referral partners: identity, contact details, billing information, and program information described in Section 4, provided by the partner when they apply or are invited, and generated by tracking their referrals and commissions.
Article 3 — Data categories and minimization
3.1Account data includes, in particular, name, email address, Organization membership, roles, teams, and information necessary for authentication. Usage data includes practice sessions, their dates and duration, minutes used (including messages to the AI coach), and relevant technical events.
3.2Training data includes scenarios, supplied documents, scorecards, transcripts, call reports, notes, comments, exchanges with the coach, and associated results. Documents and text may contain personal data if the Client or User enters it.
3.3Security and evidence information includes login or administrative events, records of document acceptance, and information necessary to handle an incident. Payment currently relies on quotes and invoices; the website does not collect credit card details for the free trial.
3.4Information identified as necessary is used to respond to a request or provide the requested feature. If it is missing, that feature may not be available. Do not provide sensitive data, access credentials, or information about real customers when fictional examples are sufficient.
Article 4 — Table of the Publisher’s own processing activities
The following table presents the purpose, legal basis, data concerned, and retention period for each processing activity. When an individual enters into a contract directly with the Publisher, pre-contractual measures or the contract provide the legal basis for operations necessary to fulfill that individual’s request. When the individual represents a client legal entity, management of that business relationship is based on the Publisher’s legitimate interest, unless a specific legal obligation applies.
| Processing activity | Purpose | Legal basis | Data | Retention period |
|---|---|---|---|---|
| Website inquiries | Respond to a contact, demo, or quote request. | Pre-contractual measures taken at your request if you are personally a party to the contract; otherwise, legitimate interest in handling the business inquiry received. | Name, company, email, optional phone number, sales team size, message. | Three years (1,095 days) from receipt of the form; documents that become part of a contract are subject to their own retention period. |
| Business relationship management | Prepare and manage the Order and communicate with authorized contacts. | Contract for an individual Customer; legitimate interest in managing the contract for representatives of a legal entity. | Business contact details, job title, correspondence, quotes, and contract. | For the duration of the active relationship, then limited archiving of documents needed as evidence for up to five years after it ends, subject to any litigation or different statutory retention period. |
| Billing and accounting | Issue invoices, track payments, and meet accounting obligations. | Legal obligation for accounting records; contract or legitimate interest for tracking payments, depending on the contact’s capacity. | Billing identity, address, tax references, invoices, and payments. | Ten years from the end of the fiscal year for accounting records and supporting documents. |
| Support | Answer a question and resolve an incident. | Contract or legitimate interest in supporting Service users; training content provided for troubleshooting continues to be processed on behalf of the Customer. | Contact details, message, technical context, and relevant documents. | While handling the request, then for up to three years after it is closed for follow-up, excluding documents needed for a dispute; copies of training content not needed for troubleshooting are deleted without waiting for this period to end. |
| Security and abuse prevention | Secure access, prevent abusive registrations, and investigate incidents, including the anti-bot check for the call trial without an account, which is handled by a specialized provider. | Legitimate interest in securing the Service and, as applicable, compliance with legal security obligations. | Account credentials, events, technical request information, and logs. | 365 days for ordinary audit logs; technical logs are replaced through rotation depending on their volume. Items isolated for an incident are retained while it is being handled and, if necessary, to defend rights. |
| Evidence of acceptances and deletions | Demonstrate contractual agreement, the version presented, and fulfillment of a request. | Legitimate interest in establishing evidence and complying with accountability obligations under data regulations. | Version, date, identity of the person who performed the action, IP address at the time of acceptance, acceptance records, and deletion certificate. | For the duration of the active relationship, then for up to five years after it ends or after the operation if later, subject to any litigation. The IP address associated with consents is deleted when the person’s data is erased. |
| Rights requests | Verify, handle, and document a GDPR request. | Legal obligation. | Contact details, subject of the request, response, and, only if necessary, proportionate proof of identity. | Processing the request, then retaining evidence for a limited period of up to five years; identity documents are not retained beyond verification unless a demonstrated legal necessity applies. |
| Campaign measurement | Identify which campaign led to demos, trials, and subscriptions, and count these results by campaign. For internal use only, with no disclosure to third parties. | Consent, both to read and write the cookie and to use the data (Article 82 of the French Data Protection Act, Article 6.1(a) of the GDPR). | Labels for the campaign that brought you to the site (source, medium, name, content, keyword), landing page without its parameters, and date; linked to the trial workspace if you open one. | Cookie: 30 days. Labels linked to a workspace: for as long as the workspace exists, unless you withdraw your consent while signed in to your account, which erases them. Demo counts, without personal data: 25 months. |
| Advertising on Meta services | Measure the results of the Provider’s ads on Facebook and Instagram (public website page views, completed demo, opened trial, first subscription payment) and allow Meta to optimize their delivery. Only when ad measurement is enabled on the website (Article 14). | Consent, both to read and write cookies and to use the data (Article 82 of the French Data Protection Act, Article 6.1(a) of the GDPR), obtained through the cookie banner and withdrawable at any time. | Event and date, page address without its parameters, advertising identifiers _fbc and _fbp, IP address, and browser; when a trial is opened and when the first payment is made, the email address and workspace identifier are hashed (SHA-256) before being sent, along with the payment amount excluding VAT. | Cookies: 90 days. Identifiers are kept with the trial workspace for as long as it exists; withdrawing consent while signed in to your account erases them and stops all data transfers. At Meta: according to its own policy. |
| Partner program | Manage referral partners, attribute a registered organization using a partner code, then calculate, approve, and pay commissions. | Performance of the partner program terms for partner data; the Publisher’s legitimate interest in compensating referrals for information about the referred customer; accounting and tax obligations. | Partner: identity, contact details, billing data, attributions, commissions, payments, proof of acceptance of the terms (date, version, IP address), and login tokens for the partner portal. Attributed customer: organization name, partner code used (entered, carried in the link, or retained for 90 days by the partner_ref cookie if you consent to the “Partner attribution” purpose in the Cookie Policy), attribution date, and the pre-tax amount of the first three paid invoices. Clicks on partner links counted by day, without IP addresses or visitor identification. | Accounting data, including referrals and commissions it substantiates: ten years. Other partner data: up to five years after their participation ends, then anonymized. |
| Proof of cookie choices | Demonstrate the choice made in the cookie banner. | Obligation to be able to demonstrate consent (GDPR Article 7.1). | Random choice identifier, not linked to an account, banner version, date, and accepted or rejected purposes. | Cookie: 6 months. Server-side record: 13 months. |
Article 5 — Table of processing activities carried out for the Client
For the activities in the table below, the Client is the data controller and chooses its legal basis before deploying the Service (it is therefore not listed for each row). Depending on its context, the Client may, in particular, assess its legitimate interest in training its teams, verifying necessity, proportionality, and employees’ rights. An employee’s acceptance of the Terms of Service is not sufficient to provide a legal basis for all processing activities organized by the employer.
| Processing | Purpose | Data | Retention period |
|---|---|---|---|
| Access and administration | Create accounts, assign roles, administer teams, and authenticate users. | Professional identity, organization membership, permissions, invitations, and login information. | While access is active, followed by deletion or restriction in response to a request to end access; evidence and security logs are retained for their respective periods. |
| Simulation and transcript | Enable dialogue with the fictional customer and produce a text record of the exercise. | Audio stream processed during the conversation, transcript, scenario, and context. | The application does not retain audio recordings; transcripts are retained for 180 days by default, configurable from 30 to 1,095 days starting with Business. |
| Call report and training progress | Analyze the text using the scorecard, present the results, and track progress. | Scores, excerpts, recommendations, comments, and team results. | Call reports are retained for 365 days by default, configurable from 30 to 1,095 days starting with Business; results may be used to generate aggregate statistics as described in Article 9. |
| AI coach | Explore feedback in greater depth and prepare for another attempt. | Messages, transcript excerpts, and necessary training context. | AI coach conversations follow the transcript retention period; access rights remain those of the relevant role. |
| Documents and customization | Extract useful information, generate or prepare scenarios, and tailor practice sessions to their context. | Documents, extracted text, instructions, and customized content. | Until deletion or the end of processing for the Organization; source documents are not automatically deleted when transcripts are purged. |
| Exports | Return data to the User or an authorized Client. | Data included in the authorized scope of the export. | Downloadable archive available for seven days; after that, the recipient is responsible for the downloaded copy. |
Article 6 — Audio, AI, and no automated HR decisions
6.1The voice stream is sent to the AI provider needed for the conversation and transcription. No call audio file is retained in the application. For the voicemail feature, audio is temporarily processed in memory for transcription and then deleted from memory.
6.2Scores are based on the text of the conversation. The Service does not recognize emotions, perform voice-based biometric identification, or use acoustic characteristics to score individuals. It does not make hiring, compensation, disciplinary, or termination decisions.
6.3The Publisher does not train any AI models using Customer Data and does not instruct AI providers to reuse it for a purpose independent of the requested function; the Publisher does not attest on their behalf to how they use the data beyond their contractual commitments. These providers are used through their interfaces for professionals and receive only the data necessary to perform the requested functions, under the DPA. The absence of an audio file in the application is not a guarantee that these providers do not perform any processing or technical retention.
6.4The AI Notice describes the information displayed, possible errors, and human oversight measures. Errors in a transcript or call report may be reported to your manager and support.
Article 7 — Recipients and access permissions
7.1Data is accessible to authorized Organization Users according to their roles, teams, and privacy settings. Owners and admins manage access; sales managers view results within the authorized scope. Private feedback mode restricts certain individual access without necessarily removing aggregate statistics. When the Client enables rankings among sales reps, scores are visible to Organization members in the format chosen by the Client.
7.2At the Provider, only people who need the data to perform their duties may access it, including for support, security, billing, or processing a request. To provide support, a Provider admin may open a session on behalf of an active member for up to thirty minutes; the session is indicated by a persistent banner and recorded in the audit log. Technical service providers receive the data necessary to provide their services in accordance with the list of Sub-processors.
7.3Authorities or authorized advisors may receive information required by a legal obligation, proceeding, or the defense of a right. The Publisher does not sell personal data. It uses advertising trackers only with your consent and under the conditions set out in Article 14; Meta then receives the data described in Article 4.
7.4When an organization creates its account using a partner code, the relevant referral partner receives, after the organization’s first invoice is paid, its name and the pre-tax amount of its first three paid invoices, solely to verify their commission. The partner is bound by confidentiality and receives no data about the organization’s users. The partner program terms describe this program.
Article 8 — Hosting and international transfers
8.1The application is hosted in France. The database is hosted in the European Union, and its encrypted backups are stored under European storage jurisdiction.
8.2Some processing takes place outside the European Union: AI model providers process data primarily in the United States, although locations are not guaranteed for all providers, and the email delivery provider may process data according to the sending region configured. Some providers that store data in the European Union are established in the United States: any remote access by them constitutes a transfer governed as described in Article 8.3. European hosting therefore does not rule out international transfers.
8.3Transfers to the United States are governed by the Data Privacy Framework when they fall within the scope of an adequacy decision and the recipient’s applicable certification, as well as by standard contractual clauses under the relevant contractual commitments. Outside the scope of an adequacy decision, the clauses and, where necessary, supplementary measures govern the transfer.
8.4The categories of recipients, data categories, and locations are listed in the list of sub-processors, annexed to the DPA. The identity of each provider is disclosed to customers in their account. You may obtain it, along with information about the safeguards and a copy of those that can be disclosed, by writing to privacy@clozing.example (any data subject and any prospective customer in the contracting process). Confidential information that is not necessary to inform you will be redacted.
8.5When you accept advertising, data sent to Meta Platforms Ireland Limited may be transferred to Meta Platforms, Inc. in the United States. This transfer is governed by the Data Privacy Framework, to which Meta Platforms, Inc. has adhered, and by the standard contractual clauses set out in Meta’s terms. Meta is not a processor for the Provider in this processing activity, so it does not appear in the list of sub-processors (see Article 14).
Article 9 — Retention, statistics, and backups
9.1The retention periods in Articles 4 and 5 relate to distinct purposes. Data deleted from the practice environment may remain in an invoice or legally retained contractual evidence, without being reused for practice. A dispute or legal obligation may justify restricted archiving beyond the usual period.
9.2Purging call reports may retain aggregate statistics without a direct identifier for an individual or session. Deleting a member removes, in particular, their individual transcripts and call reports; some session and usage metadata remains necessary to administer the Organization. In a small team, some results may be recognizable through cross-referencing; these statistics are not represented as anonymous in all circumstances.
9.3Encrypted database copies are retained for 30 days in remote storage, with local copies retained for seven days; the database hosting provider also retains a limited restoration history, depending on its plan. Deleting data from the active database therefore does not immediately remove it from every backup. These copies are used for restoration and are not used as a regular access environment.
9.4Backup copies of files (documents, export archives, certificates) are retained for no more than thirty days after the original file is deleted or replaced, and then deleted. If a backup is restored, the Provider reapplies deletions already requested before making the data available again, in accordance with Article 17 of the DPA.
Article 10 — Security
10.1Measures include encrypted communications in transit, encryption of database backups, isolation between Organizations, role-based permissions, session controls, two-factor authentication, audit logs, rate limiting, and periodic purges.
10.2Certain governance features, including SSO, organization-wide mandatory two-factor authentication, and retention settings, are available starting with Business. With SSO, the Client manages the security requirements of its identity provider. Appendix 2 to the DPA details the measures and their scope.
10.3No system can guarantee zero risk. You can help protect data by securing your access and avoiding the transmission of unnecessary information. To report a vulnerability or incident: security@clozing.example.
Article 11 — Your rights
11.1Subject to the conditions set out in applicable regulations, you have the right to access, rectify, erase, and restrict the processing of your data. You may object to processing based on legitimate interests for reasons relating to your particular situation and, without providing a reason, to direct marketing.
11.2The right to data portability applies to data you have provided when automated processing is based on your consent or a contract with you. It does not automatically extend to all company data or third-party analyses.
11.3When processing is based on consent, you may withdraw it without affecting the lawfulness of prior processing. For cookies, the “Manage my cookies” link lets you withdraw your consent as easily as you gave it. You may also set instructions about what happens to your data after your death under French law.
11.4These rights may be limited by the rights of others, the need to defend a right, or a legal obligation to retain data. Any refusal or restriction will be explained; it will not be based simply on the professional nature of the Service.
Article 12 — How to exercise your rights
12.1Email privacy@clozing.example or write to NOZZL SAS, 32 rue de Paris, 92100 Boulogne-Billancourt, France, specifying your request, the email address associated with your account, and, where applicable, your Organization. Do not send an identity document or password unless specifically requested.
12.2For data processed on behalf of your company, you may contact its designated point of contact first. If the Provider receives the request directly, it forwards it to the relevant Client and assists in accordance with the DPA. The account export and deletion features supplement these channels but do not replace them.
12.3For requests within its responsibility, the Provider responds within one month of receipt. An extension of two months may be necessary due to the complexity or number of requests; you will be informed of this and the reason within the first month.
12.4A proportionate verification may be requested if there is reasonable doubt about the requester’s identity. Exercising your rights is free of charge, subject to legal exceptions for requests that are manifestly unfounded or excessive.
Article 13 — Complaints to the CNIL
You may lodge a complaint with the French Data Protection Authority (Commission nationale de l’informatique et des libertés, CNIL), including through its online complaints service at www.cnil.fr, or by mail to CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or with the supervisory authority competent in your country of residence, place of work, or the place of the alleged infringement.
You may contact the Provider first to request an explanation or seek a solution, but doing so is not a prerequisite to your right to contact the supervisory authority.
Article 14 — Cookies, audience measurement, and advertising
14.1The site uses cookies necessary for authentication, security, language, and remembering your choices; these do not require consent. Campaign audience measurement, partner attribution, and advertising operate only with your consent, given separately for each purpose through the cookie banner, stored for 6 months (or until a new version of the banner is introduced), and changeable at any time using the “Manage my cookies” link. Refusing has no effect on access to the site or the Service. The Cookie Policy details each cookie, its purpose, and its duration.
14.2Meta tools (pixel and Conversions API) are used only when advertising measurement is enabled on the site. Only in that case does the banner offer the purpose “Advertising (Meta).” If this purpose does not appear in the banner or under “Manage my cookies,” no data is sent to Meta.
14.3For these tools, the Provider and Meta Platforms Ireland Limited (Merrion Road, Dublin 4, D04 X2K5, Ireland) are joint controllers for collecting data on the website and transmitting it to Meta, under the Controller Addendum attached to the Meta Business Tools Terms (full text: www.facebook.com/legal/controller_addendum). The Provider provides the information and obtains your consent; Meta Platforms Ireland Limited is responsible for rights requests relating to the data it holds. You may exercise your rights with the Provider or Meta; a request sent to the Provider is forwarded to Meta when it concerns Meta’s processing. Subsequent processing by Meta, including ad delivery and targeting, is Meta’s sole responsibility and is described in its Privacy Policy (www.facebook.com/privacy/policy).
14.4Any cookies from an identity provider selected by the Customer when signing in with SSO are also covered by the information provided by that provider.
Article 15 — Changes to and history of the policy
A material change will be brought to the attention of data subjects through a means appropriate to the relationship, including in the Service or by message. Where consent is legally required for a new purpose, it will be obtained separately before that purpose is implemented. Updating this policy alone does not authorize new processing that is incompatible.
Information about a previous version may be requested at privacy@clozing.example. The Data Processing Agreement (DPA), Sub-processors, and AI Notice specify the processing carried out on behalf of the Customer.
| Version date | Nature of change | Version recorded in the Service |
|---|---|---|
| October 10, 2026 | Policy overhaul: distinction between roles and categories of individuals, and details on purposes, retention periods, transfers, and rights. | 2026-10-10 |
| October 11, 2026 | Cookie banner: campaign audience measurement and Meta advertising, subject to your consent (Articles 4, 7, 8, and 14); Meta as joint controller; transfer to the United States; record of choices; partner program (Articles 2.5, 4, and 7.4); recipients presented by category (Article 8), with provider identities disclosed to customers and upon request. | 2026-10-11 |
| October 12, 2026 | Partner program: partner code retained for 90 days by an affiliate cookie, with your consent to “Partner attribution” (Article 4). | 2026-10-12 |