Skip to content
[Legal]

Privacy Policy

What personal data Asrar collects when you use Playfair, why, on which legal basis, for how long, who we share it with and how to exercise your rights.

v1.1Effective 1 September 2026View previous versions

What changed in 1.1: Described how AI features process questions and schema metadata, and named our AI provider (§5); added retention periods for query logs by plan and for consent records (§8); added the right to object to product analytics and clarified how to withdraw marketing consent (§10).

On this page (14 sections)
  1. 1. Who is responsible
  2. 2. Controller and processor: an important distinction
  3. 3. The data we collect
  4. 4. Why we use your data and our legal bases
  5. 5. AI features
  6. 6. Who we share data with
  7. 7. International transfers
  8. 8. How long we keep data
  9. 9. Security
  10. 10. Your rights
  11. 11. Children
  12. 12. Cookies
  13. 13. Changes to this policy
  14. 14. Contact

This Privacy Policy explains how Asrar SAS (“Asrar”, “we”) processes personal data when you visit our websites, create an account, use Playfair (the “Service”) or contact us. We wrote it to be read, not skimmed past; if anything is unclear, write to privacy@asrar.example.

1. Who is responsible

For the personal data described in this policy, the controller is Asrar SAS, 12 Rue de l’Exemple, 75002 Paris, France. You can reach our Data Protection Officer at dpo@asrar.example.

2. Controller and processor: an important distinction

We act in two different roles:

  • As controller for the data we need to run our business: your account, your workspace settings, billing, security logs, support conversations, marketing preferences and consent records. This policy covers that processing.
  • As processor for the personal data that may be contained in the data sources you connect and the files you upload (“Customer Data”). For that data, your organisation decides what is processed and why, and our Data Processing Addendum applies. If you are a person whose data appears in a customer’s database, please contact that customer first.

3. The data we collect

CategoryExamplesSource
Account dataName, email address, password hash, profile photo, language, time zoneYou
Workspace dataWorkspace name, members and roles, invitations, settingsYou and your team
User contentQuestions, saved questions, dashboards, descriptions, metric definitions, correctionsYou and your team
Consent recordsDocuments and versions accepted, the exact wording shown, date and time, IP address, user agent, locale, time zone, pageCollected when you accept
Usage and log dataPages and features used, queries executed (SQL text, duration, row counts), errors, device and browser type, IP addressCollected automatically
Security dataSign-in events, active sessions, IP addresses, suspicious-activity signalsCollected automatically
Billing dataPlan, seats, invoices, billing contact. Card data is handled by our payment provider and never stored by usYou
CommunicationsSupport requests, feedback, emails you send usYou
CookiesSee the Cookie PolicyYour browser

We do not intentionally collect special categories of personal data. Please do not include them in questions, descriptions or support requests.

PurposeLegal basis (GDPR)
Create and secure your account, provide the Service and its featuresPerformance of our contract with you (Art. 6(1)(b))
Send transactional emails: verification, sign-in links, password resets, security notices, invitations, scheduled reports you configurePerformance of contract (Art. 6(1)(b))
Keep evidence of the documents you accepted and your consent choicesLegal obligation and legitimate interest in demonstrating compliance (Art. 6(1)(c) and (f))
Prevent fraud and abuse, protect the Service, enforce our termsLegitimate interest (Art. 6(1)(f))
Understand how the Service is used in aggregate and improve itLegitimate interest (Art. 6(1)(f)); consent where cookies are required
Send product news and tipsConsent (Art. 6(1)(a)), which you can withdraw at any time
Billing, accounting and tax recordsPerformance of contract and legal obligation (Art. 6(1)(b) and (c))
Respond to legal requests and defend legal claimsLegal obligation and legitimate interest (Art. 6(1)(c) and (f))

Where we rely on legitimate interest, we have balanced it against your rights; you can ask us for details and you can object (see §10).

5. AI features

When AI features are enabled, we send the minimum needed to answer: your question, the relevant part of the schema (table and column names, descriptions, metric definitions) and, for descriptions and narratives, a small number of sample values or aggregated results. Columns marked as personal data are redacted from samples. Our AI provider processes this data on our behalf, under contractual terms that prohibit using it to train models and that limit retention to what is needed for abuse monitoring. We never use your data to train our own models. Read more in the AI Policy.

6. Who we share data with

  • Subprocessors that help us run the Service (hosting, email delivery, object storage, AI inference, authentication). The current list, with locations and purposes, is on the Subprocessors page.
  • Your organisation. If you use a workspace administered by an organisation, its Owners and Admins can see your membership, your activity in that workspace and the content you create there.
  • People you share with. Anyone who receives a share link or a scheduled report can see what you chose to share.
  • Authorities, when required by law, and only after checking the request is legally valid.
  • Successors, in the event of a merger or acquisition, under the same protections.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

7. International transfers

We host the Service in the European Union (Frankfurt, Germany). Some subprocessors are located outside the European Economic Area, in particular in the United States. In those cases we rely on an adequacy decision (such as the EU–US Data Privacy Framework, for certified providers) or on the European Commission’s Standard Contractual Clauses, together with supplementary measures such as encryption in transit and at rest.

8. How long we keep data

DataRetention
Account dataFor the life of the account, then deleted within 30 days of account deletion
Workspace contentUntil deleted by the workspace, or within 30 days of workspace closure
Query log (SQL, timing, row counts)30 days on Free, 1 year on Pro
Cached query resultsUntil their cache expires (hours to days, configurable)
Security and access logs12 months
Consent records5 years after the end of the relationship, as evidence
Email delivery logs12 months
Billing records10 years (legal accounting obligation)
Support conversations3 years after the last message
Demo sessionsDeleted automatically within 24 hours

Backups are kept for up to 35 days and then overwritten.

9. Security

We encrypt data in transit (TLS 1.2+) and at rest, encrypt database credentials and tokens with a dedicated key, enforce read-only access to your data sources, limit staff access on a need-to-know basis with audit logs, and test our backups. No system is perfectly secure; if a breach affects your personal data, we will notify you and the competent authority as required by law.

10. Your rights

Under the GDPR and similar laws you have the right to:

  • access your data and receive a copy;
  • rectify inaccurate data;
  • erase your data (“right to be forgotten”);
  • restrict processing in certain circumstances;
  • data portability — receive your data in a structured, machine-readable format;
  • object to processing based on legitimate interest, including product analytics, and to direct marketing at any time;
  • withdraw consent at any time, without affecting processing that happened before;
  • not be subject to decisions based solely on automated processing that produce legal effects. Playfair does not make such decisions about you.

You can export your data and delete your account from your account settings, change marketing and cookie choices at any time, or write to privacy@asrar.example. We answer within one month. You also have the right to lodge a complaint with a supervisory authority, in particular the Commission Nationale de l’Informatique et des Libertés (CNIL) or the authority where you live or work.

11. Children

The Service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.

12. Cookies

We use strictly necessary cookies to run the Service and, only with your consent, analytics and marketing cookies on our public pages. See the Cookie Policy and the “Cookie settings” link in the footer.

13. Changes to this policy

When we make material changes, we notify you by email or in the product and ask you to review the new version before you continue. Previous versions remain available in the version history.

14. Contact

Asrar SAS · 12 Rue de l’Exemple, 75002 Paris, France Privacy: privacy@asrar.example · Data Protection Officer: dpo@asrar.example

Questions about this document? Write to legal@asrar.example.

Privacy Policy · version 1.1 · published 1 Sep 2026 · Asrar SAS