Privacy Policy
Last updated: 3 June 2026 โ GDPR compliant (EU Regulation 2016/679)
This policy describes how Digital Pharma Lab (hereinafter "DPL") collects, uses and protects your personal data in connection with the website aicompass.digitalpharmalab.com. If you have any questions, please write to us at aicompass@digitalpharmalab.com.
1. Data Controller
The data controller is Digital Pharma Lab, whose full contact details are set out in our legal notice.
2. Data Collected
Depending on your interactions with the site, we collect the following categories of data:
2.1 AI Act Readiness Diagnostic
- Identity: first name, surname
- Professional contact details: email, company, job title
- Questionnaire responses and calculated score (information about your organisation's AI maturity)
2.2 Contact / Appointment Request Form
- Identity: first name, surname
- Professional contact details: email, phone (optional), company, job title
- Desired topic, availability, free-text message
2.3 AI Regulatory Assistant
- Content of questions asked and responses generated (analysed in aggregate to improve the quality of the platform โ see section 4)
2.4 Technical Data
- Authentication cookie
aic_auth(HttpOnly, strictly necessary for the operation of the site in restricted-access mode โ no consent banner required) - Standard server logs (IP address, user agent, timestamp) retained technically by our host for security purposes
3. Purposes and Legal Bases
- Commercial qualification and contact
- Legal basis: DPL's legitimate interest (Article 6.1.f GDPR) โ a B2B commercial approach explicitly initiated by your submission of a form. You may object to this at any time (see section 8).
- Delivery of the diagnostic report and complimentary 1-hour workshop
- Legal basis: performance of pre-contractual measures at your request (Article 6.1.b GDPR).
- Improvement of the AI Compass platform
- Legal basis: DPL's legitimate interest. Conversations and diagnostic responses are analysed in aggregate and anonymised form to improve the diagnostic questions and the quality of the regulatory framework.
- Compliance with legal obligations
- Legal basis: legal obligation (Article 6.1.c GDPR) โ retention for accounting, tax or rights-defence purposes.
4. Recipients and Sub-processors
Your data is accessible to DPL senior consultants involved in your engagement. It is never sold. To operate the site, we rely on the following sub-processors โ each bound by a GDPR data processing agreement:
| Sub-processor | Role | Location |
|---|---|---|
| Vercel Inc. | Website hosting and code execution | United States (Data Privacy Framework) |
| Supabase | Database: RAG knowledge base, pseudonymised conversation logs, diagnostics, compliance documents and admin sign-ins | European Union |
| Google (via Supabase Auth) | Administrator authentication (SSO sign-in) | United States (Data Privacy Framework) |
| Resend | Transactional emails (internal lead notifications) | United States (Data Privacy Framework) |
| Close (Elastic Inc.) | CRM โ lead storage and exchange history | United States (Data Privacy Framework) |
| Mistral AI | Generative AI model (assistant) and embeddings (document search) | European Union (France) |
4.1 Transfers Outside the European Union
Some sub-processors process data in the United States (Vercel, Close, Google, Resend), governed by the EU-U.S. Data Privacy Framework. The artificial intelligence provider, Mistral AI, hosts data exclusively within the European Union: no transfer outside the EU takes place for AI processing.
4.2 AI Provider Policy
Mistral AI commits to not using data sent via its API to train its models . Mistral AI hosts data within the European Union. Content may be retained temporarily (up to 30 days) for security and abuse-prevention purposes, then deleted; a "Zero Data Retention" option is available.
5. Retention Periods
| Data | Retention period |
|---|---|
| Commercial leads (Close) | 3 years from the last active contact, in accordance with the CNIL recommendation for B2B prospecting |
| Diagnostic responses | 3 years, then automatic deletion or anonymisation for aggregated statistics |
| Conversations with the assistant | 13 months maximum, anonymised thereafter |
| Technical logs | 30 days |
| Accounting data (invoices, contracts) | 10 years (legal obligation) |
6. Security
- TLS 1.3 encryption across the entire site (Let's Encrypt)
- HttpOnly + Secure + SameSite=Lax authentication cookies
- Access to Close CRM restricted to named and authorised DPL consultants
- Supabase service role isolated, never exposed client-side โ requests transit exclusively through our backend
- Encrypted database backups
7. Cookies
The site uses a single strictly necessary cookie for its operation:
aic_authโ pre-launch gate authentication cookie, HttpOnly, Secure, SameSite=Lax, 30-day duration.
No analytics, advertising or audience-measurement cookies are set. A consent banner is therefore not required at this stage.
8. Your Rights
Under GDPR, you have the following rights:
- Right of access โ obtain a copy of the data we hold about you
- Right of rectification โ correct inaccurate data
- Right to erasure ("right to be forgotten") โ request the deletion of your data
- Right to restriction of processing
- Right to object โ object to processing based on legitimate interest (including commercial prospecting)
- Right to data portability โ receive your data in a structured format
- Right to set post-mortem instructions
To exercise these rights, write to us at aicompass@digitalpharmalab.com specifying the nature of your request. We will respond within 1 month (Article 12.3 GDPR).
If you consider that your rights are not being respected, you may lodge a complaint with the CNIL(the French data protection authority).
9. Updates
This policy may be updated (change of sub-processor, new processing activity, etc.). The date of the last update is shown at the top of the page. We invite you to consult it regularly.