What we know about you, what we do with it, and what you can demand.
Last updated: September 18, 2026
This English version is a translation provided for convenience. The French version is the only legally binding one: if the two ever differ, the French text prevails.
CHECK EASY, 6 rue Albert Difusco, 13007 Marseille, France, processes the data described below. For any question, write to hello@fortiche.io.
When your agent talks to your customers, you are the controller of that processing, and we are your processor: we use those conversations only to provide the service to you. What this commits us to do is set out in black and white in the data processing agreement.
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Account: email, name, encrypted password | Giving you access to the service | Performance of the contract | For as long as the account exists. Deleting it erases everything immediately: all that remains is an irreversible fingerprint of your address, which proves that the erasure took place without making it possible to identify you. |
| Agent content: instructions, documents, methods | Running your agents | Performance of the contract | Until you delete it |
| Conversations held by your agents | Displaying the history and improving your agents | Performance of the contract | Until you delete them |
| Keys and access credentials you entrust to us | Connecting your agents to your tools | Performance of the contract | Until revoked, encrypted at rest |
| Billing: plan, payments, invoices | Collecting payment and keeping records | Legal obligation | 10 years (accounting) |
| Technical logs: IP address, errors | Troubleshooting outages | Legitimate interest | 30 days, then automatic deletion |
| Security events: sign-ins, access granted and revoked | Detecting abnormal access to your account | Legitimate interest | 12 months |
| Journey measurement on public pages (no conversation content) | Understanding what gets in the way of signing up | Legitimate interest | 6 months |
| Google data you connect (chosen or created files, calendar, contacts, tasks, emails sent, YouTube, Search Console and Analytics statistics) | Running the agent you have configured | Performance of the contract | Read for the time it takes to reply, with no copy kept. Exception: a file you ask your agent to learn, whose text is kept until you remove it |
| Notion pages and databases you choose to share | Running the agent you have configured | Performance of the contract | Read for the time it takes to reply, with no copy kept. Exception: a page you ask your agent to learn, whose text is kept until you remove it |
When you connect your Google account, Fortiche only requests the access needed by the capabilities you give your agent, at the moment you add them. Here is the full list, and nothing else:
Access to a Gmail mailbox is not offered today: it requires an annual security assessment imposed by Google, which we have not yet completed. When it has been completed, that access will be subject to separate consent, and the same rules will apply. Nothing is connected by default, and you can disconnect at any time from your settings; the tokens are then erased.
Fortiche’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice: when you ask your agent to work on a file or your calendar — read a figure, add a row, book an appointment — its content is read for the time it takes to produce the reply, and we keep no copy of it. Only your agent’s reply stays in the conversation, like any other message.
There is one exception, and you are the one who triggers it: if you paste the link to a Google file for your agent to learn (the link on its own, or “learn this document”), its text is kept in what your agent knows, so it can use it later. It then appears under “What you taught it”, where you can remove it at any time: it is deleted, together with everything derived from it. As soon as your message asks for something else — adding, calculating, answering a question — the file is handled live, and its text is not kept.
Your agent may also remember know-how drawn from its work, for example the tab where orders are recorded. What it remembers this way appears under “What it figured out on its own”, where you can erase it at any time.
In every case, this content is not resold, not used for advertising, and not used to train a model. It is passed only to the model provider needed to process your request, and to no one else.
Your agent never deletes a file or an appointment, and only writes in a spreadsheet or a calendar when asked to. This limit is built into the code, not just written in this text. You can withdraw access at any time, from your Fortiche settings or from the permissions page of your Google account; in both cases, the tokens are erased from our servers.
When you connect Notion, you choose, in Notion’s own window, the pages your agent will be able to see. It only has access to those pages, their sub-pages and the databases they contain: the rest of your workspace stays closed to it. On those pages only, it can:
It never deletes a page and does not change what is already written in it. The content it reads is used for the time it takes to reply, with no copy kept, with the same exception as for Google: if you paste the link of a Notion page for your agent to learn, its text is kept in “What you taught it”, where you can remove it at any time. This content is never sold, never used for advertising, and never used to train a model.
A customer writing to your agent cannot make it read or change your Notion, unless you have allowed it in the “Toucher à tes données” (touch your data) setting. We keep the name of your Notion workspace, to show you what your agent is connected to, but neither your email address nor the list of your pages. When you disconnect it, the access token is erased from our servers and we ask Notion to revoke it. You can also remove the access from Notion’s settings, under “My connections”.
The retention periods above are not intentions: they are enforced by an automatic purge, and the text you are reading is built from the values that drive it. If one of them changed, this page would change with it.
Running the service requires service providers. Each one acts only for what concerns it, under a data processing contract. Transfers outside the European Union are governed by the European Commission’s standard contractual clauses.
| Provider | Role | Location |
|---|---|---|
| Hostinger | Hosting of the application, the database and scheduled tasks | France (server in Paris; company established in Cyprus) |
| Stripe | Payment collection and invoicing | Ireland and United States |
| Anthropic | Language models: generating agents’ replies | United States |
| OpenAI | Language models: generating agents’ replies | United States |
| Language models, and connection to the Google services you authorize | European Union and United States | |
| Resend | Sending transactional emails (verification, invitations) | United States |
| Twilio | Routing WhatsApp and SMS messages, if you turn these channels on | European Union and United States |
| Meta Platforms | Routing WhatsApp Business messages, if you turn this channel on | Ireland and United States |
| Evolution API | Technical gateway linking a WhatsApp account to your agent, if you choose this connection | European Union |
| Telegram | Routing Telegram messages, if you turn this channel on | Outside the European Union |
| Discord | Routing Discord messages, if you turn this channel on | United States |
| Slack | Routing Slack messages, if you turn this channel on | European Union and United States |
If you use your own key with a model provider, the exchanges go directly to that provider, under your contract with them.
When you subscribe to a creator’s fortiche, your subscription email address is only passed on to them if you ticked the box that offers it. They then become responsible for it. You can withdraw this consent at any time, at the top of your conversation with that fortiche. What you write yourself in that conversation, an address included, they can read, like the rest of the exchange.
The site sets no advertising cookie, no audience measurement tracker and no third-party tracker. Pages you can view without an account set none at all, of any kind. What follows is the complete inventory, kept up to date with the code.
| Name | Type | What it is for | Duration |
|---|---|---|---|
refresh_token | Cookie | Keeps you signed in without asking for your password again. Unreadable by the browser (httpOnly) and sent only to the path that renews the session. | 30 days |
agenthub_token | Local storage | Key for the current session, which authenticates each request. | Until you sign out |
agenthub_current_agent | Local storage | Remembers the agent you were looking at, to reopen it for you. | Until you sign out |
hub_api_key | Local storage | Keeps the access key you entered, on your device only. | Until you delete it |
All of them are strictly necessary for the service you request by signing in. Article 82 of the French Data Protection Act (loi Informatique et Libertés) exempts these trackers from consent: that is why you do not see a cookie banner on this site. If we ever added audience measurement, it would be subject to your prior consent, with refusing as simple as accepting.
When a business installs the Fortiche chat bubble on its own website, its visitors’ browsers store three pieces of information, locally and solely to make the chat work: agenthub_session_… (resuming the ongoing conversation), agenthub_identity_… (if the visitor has identified themselves) and agenthub_expanded_… (keeping the bubble open or closed). Nothing is sent to an advertiser, and nothing makes it possible to track that visitor on another site. It is the business installing the widget that informs its visitors: it may reuse this paragraph as is.
Exchanges go over HTTPS, passwords are hashed, and the keys you entrust to us are encrypted before being stored. Access to systems is restricted to the people who need it. In the event of a data breach likely to harm you, we notify you and inform the CNIL (the French data protection authority) within 72 hours.
You can request access to your data, its rectification, its erasure, the restriction of its processing, its portability, and object to processing based on our legitimate interest. Write to hello@fortiche.io: we reply within one month.
If you are not satisfied with the reply, you can lodge a complaint with the CNIL, cnil.fr.
When someone chats with an agent you have published, it is up to you to inform them about the processing of their data, as for any form on your website. We keep these conversations on your behalf and delete them when you delete them.