Privacy Policy
What personal data Asrar collects when you use Playfair, why, on which legal basis, for how long, who we share it with and how to exercise your rights.
What changed in 1.1: Described how AI features process questions and schema metadata, and named our AI provider (§5); added retention periods for query logs by plan and for consent records (§8); added the right to object to product analytics and clarified how to withdraw marketing consent (§10).
On this page (14 sections)
- 1. Who is responsible
- 2. Controller and processor: an important distinction
- 3. The data we collect
- 4. Why we use your data and our legal bases
- 5. AI features
- 6. Who we share data with
- 7. International transfers
- 8. How long we keep data
- 9. Security
- 10. Your rights
- 11. Children
- 12. Cookies
- 13. Changes to this policy
- 14. Contact
This Privacy Policy explains how Asrar SAS (“Asrar”, “we”) processes personal data when you visit our websites, create an account, use Playfair (the “Service”) or contact us. We wrote it to be read, not skimmed past; if anything is unclear, write to privacy@asrar.example.
1. Who is responsible
For the personal data described in this policy, the controller is Asrar SAS, 12 Rue de l’Exemple, 75002 Paris, France. You can reach our Data Protection Officer at dpo@asrar.example.
2. Controller and processor: an important distinction
We act in two different roles:
- As controller for the data we need to run our business: your account, your workspace settings, billing, security logs, support conversations, marketing preferences and consent records. This policy covers that processing.
- As processor for the personal data that may be contained in the data sources you connect and the files you upload (“Customer Data”). For that data, your organisation decides what is processed and why, and our Data Processing Addendum applies. If you are a person whose data appears in a customer’s database, please contact that customer first.
3. The data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash, profile photo, language, time zone | You |
| Workspace data | Workspace name, members and roles, invitations, settings | You and your team |
| User content | Questions, saved questions, dashboards, descriptions, metric definitions, corrections | You and your team |
| Consent records | Documents and versions accepted, the exact wording shown, date and time, IP address, user agent, locale, time zone, page | Collected when you accept |
| Usage and log data | Pages and features used, queries executed (SQL text, duration, row counts), errors, device and browser type, IP address | Collected automatically |
| Security data | Sign-in events, active sessions, IP addresses, suspicious-activity signals | Collected automatically |
| Billing data | Plan, seats, invoices, billing contact. Card data is handled by our payment provider and never stored by us | You |
| Communications | Support requests, feedback, emails you send us | You |
| Cookies | See the Cookie Policy | Your browser |
We do not intentionally collect special categories of personal data. Please do not include them in questions, descriptions or support requests.
4. Why we use your data and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and secure your account, provide the Service and its features | Performance of our contract with you (Art. 6(1)(b)) |
| Send transactional emails: verification, sign-in links, password resets, security notices, invitations, scheduled reports you configure | Performance of contract (Art. 6(1)(b)) |
| Keep evidence of the documents you accepted and your consent choices | Legal obligation and legitimate interest in demonstrating compliance (Art. 6(1)(c) and (f)) |
| Prevent fraud and abuse, protect the Service, enforce our terms | Legitimate interest (Art. 6(1)(f)) |
| Understand how the Service is used in aggregate and improve it | Legitimate interest (Art. 6(1)(f)); consent where cookies are required |
| Send product news and tips | Consent (Art. 6(1)(a)), which you can withdraw at any time |
| Billing, accounting and tax records | Performance of contract and legal obligation (Art. 6(1)(b) and (c)) |
| Respond to legal requests and defend legal claims | Legal obligation and legitimate interest (Art. 6(1)(c) and (f)) |
Where we rely on legitimate interest, we have balanced it against your rights; you can ask us for details and you can object (see §10).
5. AI features
When AI features are enabled, we send the minimum needed to answer: your question, the relevant part of the schema (table and column names, descriptions, metric definitions) and, for descriptions and narratives, a small number of sample values or aggregated results. Columns marked as personal data are redacted from samples. Our AI provider processes this data on our behalf, under contractual terms that prohibit using it to train models and that limit retention to what is needed for abuse monitoring. We never use your data to train our own models. Read more in the AI Policy.
6. Who we share data with
- Subprocessors that help us run the Service (hosting, email delivery, object storage, AI inference, authentication). The current list, with locations and purposes, is on the Subprocessors page.
- Your organisation. If you use a workspace administered by an organisation, its Owners and Admins can see your membership, your activity in that workspace and the content you create there.
- People you share with. Anyone who receives a share link or a scheduled report can see what you chose to share.
- Authorities, when required by law, and only after checking the request is legally valid.
- Successors, in the event of a merger or acquisition, under the same protections.
We do not sell personal data and we do not share it for cross-context behavioural advertising.
7. International transfers
We host the Service in the European Union (Frankfurt, Germany). Some subprocessors are located outside the European Economic Area, in particular in the United States. In those cases we rely on an adequacy decision (such as the EU–US Data Privacy Framework, for certified providers) or on the European Commission’s Standard Contractual Clauses, together with supplementary measures such as encryption in transit and at rest.
8. How long we keep data
| Data | Retention |
|---|---|
| Account data | For the life of the account, then deleted within 30 days of account deletion |
| Workspace content | Until deleted by the workspace, or within 30 days of workspace closure |
| Query log (SQL, timing, row counts) | 30 days on Free, 1 year on Pro |
| Cached query results | Until their cache expires (hours to days, configurable) |
| Security and access logs | 12 months |
| Consent records | 5 years after the end of the relationship, as evidence |
| Email delivery logs | 12 months |
| Billing records | 10 years (legal accounting obligation) |
| Support conversations | 3 years after the last message |
| Demo sessions | Deleted automatically within 24 hours |
Backups are kept for up to 35 days and then overwritten.
9. Security
We encrypt data in transit (TLS 1.2+) and at rest, encrypt database credentials and tokens with a dedicated key, enforce read-only access to your data sources, limit staff access on a need-to-know basis with audit logs, and test our backups. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authority as required by law.
10. Your rights
Under the GDPR and similar laws you have the right to:
- access your data and receive a copy;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict processing in certain circumstances;
- data portability — receive your data in a structured, machine-readable format;
- object to processing based on legitimate interest, including product analytics, and to direct marketing at any time;
- withdraw consent at any time, without affecting processing that happened before;
- not be subject to decisions based solely on automated processing that produce legal effects. Playfair does not make such decisions about you.
You can export your data and delete your account from your account settings, change marketing and cookie choices at any time, or write to privacy@asrar.example. We answer within one month. You also have the right to lodge a complaint with a supervisory authority, in particular the Commission Nationale de l’Informatique et des Libertés (CNIL) or the authority where you live or work.
11. Children
The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
12. Cookies
We use strictly necessary cookies to run the Service and, only with your consent, analytics and marketing cookies on our public pages. See the Cookie Policy and the “Cookie settings” link in the footer.
13. Changes to this policy
When we make material changes, we notify you by email or in the product and ask you to review the new version before you continue. Previous versions remain available in the version history.
14. Contact
Asrar SAS · 12 Rue de l’Exemple, 75002 Paris, France Privacy: privacy@asrar.example · Data Protection Officer: dpo@asrar.example