↓ Skip to main content
  1. Legal information/

node.this Privacy Policy

Version of 1 October 2026.

This English version is provided for convenience. In case of discrepancy, the French version prevails.

This policy describes how TYO DATA processes the personal data of people who use the online node.this service (node-this.tyo-data.fr), and of people who write to us through the contact form of the tyo-data.fr website. It does not cover an installation of node.this on a customer’s own infrastructure, where TYO DATA has no access to any data.

1. Two roles, depending on the data
#

datawho decidesTYO DATA’s role
your account: email address, display name, sign-in methodTYO DATAcontroller
the content you import and produce: files, tables, flows, resultsyou, or the organisation you work forprocessor

This policy covers the first case. For content, TYO DATA processes data only to provide the Service, on your instructions, and does not know its nature: it is up to you, or your organisation, to determine whether it contains personal data and on what basis you process it. TYO DATA’s commitments as a processor are set out in section 6 of the Terms of Use, whatever your plan; a paying customer may also request a data processing agreement (DPA).

2. The data we process
#

To identify you:

  • your email address, whether it has been verified, and your display name;
  • a password, stored in hashed form, or the link to your Google account if you signed up that way;
  • a technical identifier assigned by the authentication service.

To run the Service:

  • the date of your last sign-in, recorded at most once a day;
  • for a free-plan space, the end date of its trial and the computation time consumed by its runs;
  • your display preferences;
  • the history of your actions in your projects: who saved a flow and when, the history of runs started (date, duration, operations used, success or error);
  • for a project shared read-only, who viewed it and when, which its owner can see;
  • for the notices a project sends at the end of an automatic run (email to members, webhook), the log of each delivery: the event, the recipient, the date, the state and any error.

For security: the servers’ technical logs, which record for each request its date, the address of the page requested and the identification of the browser. They do not contain your IP address: node.this’s servers only see the internal address of the host’s load balancer. The host’s own services, including that load balancer, keep their own logs, which we do not control and which it retains for 7 days (section 4).

For invoicing, if you subscribe to a paid plan: your organisation’s company name, billing details and VAT number. Paid plans are paid by bank transfer: no bank card data is requested.

If you write to us through the website’s contact form: your name, your email address, your organisation if you give it, the type of request and your message. They reach us by email and are stored nowhere else: the form keeps nothing, not even your IP address. As for any page of the website, the website’s host keeps its own connection logs.

We collect no audience-measurement, advertising or profiling data.

An email address is required to create an account; without it, the Service cannot be provided. No automated decision producing legal effects concerning you is made from your data.

3. Why, and on what legal basis#

purposelegal basis
creating and managing your account, providing the Serviceperformance of the terms of use
notifying you of maintenance, a change to the terms, or deletion for inactivityperformance of the terms of use
securing the Service, preventing abuseTYO DATA’s legitimate interest
measuring the use of the Service to size it and design its plans, from the history of runs, never from their content; these measurements are made per account, without email address or name, and serve only for statisticsTYO DATA’s legitimate interest
invoicing a paid planperformance of the contract, and the legal obligation to keep invoices
documenting every data breach, whether notified or notlegal obligation (GDPR, Article 33(5))
keeping the register of the requests you send us in writing (deletion, viewing of your projects, exercise of a right) and of what we did with themlegal obligation to respond to your rights, and TYO DATA’s legitimate interest in proving that it did
notifying by email or webhook that an automatic run has ended, when the project asks for itperformance of the terms of use, at your request
the AI assistant, if you use itperformance of the terms of use, at your request
answering the message sent through the contact form, and preparing the demonstration or quote you ask forpre-contractual steps taken at your request, or TYO DATA’s legitimate interest in answering the messages it receives

4. How long
#

dataperiod
account and related dataas long as the account exists
log of notices sent (email, webhook)as long as the project exists
run history (date, duration, operations used, outcome), with their resultsper flow, the latest 30 started automatically; of those started by the user, only the latest state and the latest started by hand; a pinned run, as long as the account exists
inactive free space, including one frozen at the end of its trialdeleted after 12 months without a sign-in by any member, after an email warning 30 days beforehand
deleted data, in backupserased within 30 days of deletion at the latest
invoices10 years, as required by the French Commercial Code
register of data breaches5 years after the incident is closed
register of written requests (your email address, the request, its answer), including after your account is deleted5 years after the request is closed, the ordinary limitation period
the servers’ technical logsuntil the next update of the component producing them, and at most 50 MB per component, beyond which the oldest are deleted (in practice, from a few days to three months)
technical logs of the host’s services7 days
messages received through the contact formthe time needed to handle your request, then at most 3 years after our last exchange; if you become a customer, they follow the business relationship

You can delete your account at any time from the interface. Deletion erases your projects, their data and your sign-in identity. An account that owns projects shared with other people cannot be deleted until those projects have been deleted or handed over.

5. Who has access
#

Within the Service, your projects are visible only to you, to the members of your team and to the people you share them with.

At TYO DATA, the people in charge of technical operations have, as with any hosting provider, technical access to the servers, databases and storage. They use it to keep the Service running and secure, without viewing the content of your projects. They view that content only at your written request, for example to diagnose a problem you report, and within the limits of what you ask: the viewing covers only the project, or the space, that your request designates, and each one is recorded in the register of requests. The only exception is a legal obligation, such as a binding order from a judicial authority; you are then informed, unless the law forbids it. The application’s administration functions do not allow reading the content of a project.

Our processors:

processorfor whatwhere
Scaleway SAShosting of the Service, its databases and filesFrance (Paris region)
Scaleway SASsending verification and password reset emails, the end-of-run notices you turn on, and notices about our terms (change of processor, change of terms)France
Scaleway SASthe AI assistantFrance
OVH SAShosting of the tyo-data.fr website, and delivery of its contact form messages to our mailboxFrance
Googleonly if you choose “sign in with Google”outside the European Union

This table names our direct processors, what we entrust to them, and the region where they process your data. We do not publish the list of their own sub-processors: each of them is bound by contract to the obligations of the GDPR, including the choice and the oversight of those it calls on in turn. Any change of direct processor is announced to you before it takes effect.

The provider you choose by entering your own key in the assistant (Mistral AI, OpenAI or Anthropic, section 6) is not our processor: it is your own service provider, with whom you contract and whose terms you accept. We only pass your request on to it, at your request.

We neither sell nor rent your data.

6. The AI assistant
#

The assistant provided by TYO DATA is included in paid plans. If you use it, it sends to Scaleway’s AI service, in France: your request, the names of the project’s tables and the names and types of their columns, and the current flow including the configuration of each node, which may contain values (a filter value, or a table typed in by hand). The content of imported tables is never sent. A column name alone can reveal a lot: do not use the assistant on a project whose very structure is confidential.

If you enter your own key in the assistant panel, the only option on the free plan, the same elements are sent to the provider you chose, under your account with that provider and on its terms: Mistral AI (European Economic Area), OpenAI (United States) or Anthropic (United States). The panel shows that country before you enter the key. At Mistral AI, the use of your requests to train its models is on by default for the API, paid plans included: turn it off in your Mistral console (Privacy, Anonymous improvement data). At OpenAI and Anthropic, it is off by default for the API (as published by these providers on 16 September 2026). Your key is used only for the duration of the request: it is stored neither in the database nor in the logs.

7. Transfers outside the European Union
#

All of the Service’s data is hosted in France. Two transfers outside the European Union are possible, and only you trigger them: using your own OpenAI or Anthropic key in the assistant (section 6), and signing in with a Google account: Google then learns that you are signing in to node.this.

Where personal data is transferred to a country outside the European Union, TYO DATA puts in place the appropriate safeguards provided for by the applicable regulation, to frame and secure that transfer.

Both transfers are avoidable, and you decide: if you want no transfer outside the European Union, create your account by email rather than through Google, and use neither an OpenAI key nor an Anthropic key in the assistant. The Service works without either, and the assistant provided by TYO DATA relies on an AI service hosted in France (section 6).

8. Security
#

Communications are encrypted (HTTPS). Databases and file storage are encrypted at rest. Download links are signed and expire after 15 minutes. Access to projects is checked on every request.

In the event of a data breach. Every personal data breach is recorded in a register, whether or not it is notified, and that register is kept for 5 years after the incident is closed. If the breach presents a risk to your rights and freedoms, we notify the CNIL within the regulatory period of 72 hours. If it presents a high risk, we inform you as soon as possible of what happened, which data is concerned and the measures taken.

You can also report a security vulnerability to us yourself: how to do so, and what we commit to, are on the Reporting a security vulnerability page.

9. Cookies and local storage
#

The Service uses no audience-measurement or advertising cookies. It uses:

  • the cookies of the authentication service (auth.tyo-data.fr), needed to sign in and stay signed in;
  • your browser’s local storage, for display preferences (last project opened, panel sizes).

These are strictly necessary for the Service to work and therefore do not require consent.

10. Your rights
#

You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data. You can exercise most of them directly in the Service: export your projects, delete your account. Your email address and display name come from the authentication service and are updated at each sign-in. To correct them, and for any other right, write to rgpd@tyo-data.fr. We reply within one month.

Write to us from the email address of your account. If you write from another address, we will ask you for what it takes to establish that it is indeed you: this is what prevents your data from being handed to someone impersonating you.

You may also set directives on the retention, erasure and communication of your data after your death, and appoint the person who will carry them out (Article 85 of the French Data Protection Act). Send them to the same address.

If you believe your rights are not respected, you can lodge a complaint with the CNIL, the French data protection authority (cnil.fr).

For data contained in your projects, first contact the organisation that imported it, which is responsible for it.

11. Changes to this policy
#

Any change is published on this page, with its date. A significant change is announced at least 30 days in advance, under the same conditions as the terms of use.

12. Contact
#

TYO DATA, 59 rue Voltaire, 92800 Puteaux, France.