Translation provided for information only, pending a dedicated legal review. In the event of any discrepancy, ambiguity or difference of interpretation, the French version prevails.
Data protection

Privacy policy

How Sellavi collects, uses and protects your personal data, in accordance with the GDPR and the French Data Protection Act. This English version is provided for convenience — in case of discrepancy, the French version prevails.

Last updated: May 11, 2026

1. Introduction

This privacy policy describes how CORTEXIA GROUP SAS ('we', 'our', 'Sellavi') collects, uses, shares and protects your personal data when you use the platform https://sellavi.ai.

We are committed to complying with Regulation (EU) 2016/679 (GDPR) and the amended French Data Protection Act of January 6, 1978.

2. Data controller

Controller
CORTEXIA GROUP SAS
Representative
JA CORPORATION, President
Headquarters
5 rue du Colonel Moll, 75017 Paris, France
SIRET
10696540300012
DPO contact
contact@sellavi.ai

3. Data collected

3.1 Identification data

Last name, first name, company name, postal address, email, phone, login credentials. This data is collected at registration and when updating your profile.

3.2 Connection data

IP address, browser type and version, operating system, connection dates and times, pages viewed. This data is collected automatically for security and statistical analysis purposes.

3.3 Usage data

Product catalog, orders, suppliers used, connected marketplaces, exchanges with support, interactions with the AI agents. This data powers the service's features.

3.4 Payment data

Card data is neither collected nor stored by CORTEXIA GROUP. It is processed directly by our provider Revolut Merchant (Revolut Payments UAB, licensed by the Central Bank of Lithuania). We only keep a transaction identifier and non-sensitive metadata (amount, date, status).

4. Purposes of processing

Your data is processed for the following purposes:

  • Service provision : account creation, subscription performance, synchronization with marketplaces and suppliers;
  • Billing and accounting : invoicing, payment tracking, legal and tax obligations;
  • Customer support : answering your requests, resolving incidents, training;
  • Security : fraud prevention, anti-money laundering, access logging;
  • Service improvement : usage analysis, A/B testing, development of new features;
  • Commercial communications : sending information about services and news (consent required for prospecting outside existing customers).

5. Legal basis for processing

  • Performance of the contract (Art. 6.1.b GDPR): for service provision, support and billing;
  • Legal obligation (Art. 6.1.c): accounting retention (10 years), AML/CFT, judicial requisitions;
  • Legitimate interest (Art. 6.1.f): security, service improvement, fraud prevention;
  • Consent (Art. 6.1.a): non-essential cookies, commercial prospecting outside the existing customer base.

6. Data recipients

Your data may be shared with:

  • authorized internal departments of CORTEXIA GROUP (support, billing, technical);
  • our technical processors: Supabase (database, USA - Standard Contractual Clauses), Netlify (frontend hosting), Revolut (payments), OpenAI / Anthropic (AI agents - ephemeral processing without training);
  • the marketplaces and suppliers you chose to connect with;
  • administrative or judicial authorities, upon legal requisition.

7. Data transfers outside the EU

Some processors are established outside the European Union (notably in the United States). All transfers are governed by the Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where appropriate by additional technical measures (encryption, pseudonymization).

8. Retention periods

Data typeLongevity
Active accountAs long as the account is active
Inactive account3 years after the last login
Invoices and accounting data10 years (Article L.123-22 of the French Commercial Code)
Connection logs12 months
Prospecting data3 years from the last contact
Cookies13 months maximum

9. Your rights

Under the GDPR, you have the following rights:

  • Right of access to your data;
  • Right of rectification of inaccurate or incomplete data;
  • Right to erasure ('right to be forgotten') in the cases provided by law;
  • Right to restriction of processing;
  • Right to portability of your data in a structured format;
  • Right to object on legitimate grounds or to commercial prospecting;
  • Right to set directives regarding the fate of your data after your death.

To exercise these rights, contact contact@sellavi.ai providing proof of your identity. We reply within 30 days at most.

If our reply is unsatisfactory, you can lodge a complaint with the CNIL : www.cnil.fr.

10. Data security

CORTEXIA GROUP implements appropriate technical and organizational measures to guarantee the security of your data:

  • TLS 1.3 encryption in transit, AES-256 at rest;
  • strong authentication (MFA) available;
  • access logging and alerts in case of suspicious activity;
  • encrypted backups with at least 30 days' retention;
  • regular penetration tests, security audits;
  • RLS (Row Level Security) policy on the database.

11. Cookies

For more details on the use of cookies, see our cookie policy.

12. Changes to this policy

This policy may be modified to adapt to changes in the service or regulations. Any substantial change will be notified to you by email with reasonable notice.

13. Contact

DPO
contact@sellavi.ai
General contact
contact@sellavi.ai
Postal address
CORTEXIA GROUP SAS — 5 rue du Colonel Moll, 75017 Paris
Supervisory authority
CNIL — www.cnil.fr
Sellavi Newsletter

Stay ahead
in e-commerce.

Get marketplace best practices and Sellavi news straight to your inbox.

  • 1 email per month maximum
  • Unsubscribe in 1 click
  • No commercial use
Security GDPR compliant Hosted in the European Union Encrypted data