1. Introduction
This privacy policy describes how CORTEXIA GROUP SAS ('we', 'our', 'Sellavi') collects, uses, shares and protects your personal data when you use the platform https://sellavi.ai.
We are committed to complying with Regulation (EU) 2016/679 (GDPR) and the amended French Data Protection Act of January 6, 1978.
2. Data controller
- Controller
- CORTEXIA GROUP SAS
- Representative
- JA CORPORATION, President
- Headquarters
- 5 rue du Colonel Moll, 75017 Paris, France
- SIRET
- 10696540300012
- DPO contact
- contact@sellavi.ai
3. Data collected
3.1 Identification data
Last name, first name, company name, postal address, email, phone, login credentials. This data is collected at registration and when updating your profile.
3.2 Connection data
IP address, browser type and version, operating system, connection dates and times, pages viewed. This data is collected automatically for security and statistical analysis purposes.
3.3 Usage data
Product catalog, orders, suppliers used, connected marketplaces, exchanges with support, interactions with the AI agents. This data powers the service's features.
3.4 Payment data
Card data is neither collected nor stored by CORTEXIA GROUP. It is processed directly by our provider Revolut Merchant (Revolut Payments UAB, licensed by the Central Bank of Lithuania). We only keep a transaction identifier and non-sensitive metadata (amount, date, status).
4. Purposes of processing
Your data is processed for the following purposes:
- Service provision : account creation, subscription performance, synchronization with marketplaces and suppliers;
- Billing and accounting : invoicing, payment tracking, legal and tax obligations;
- Customer support : answering your requests, resolving incidents, training;
- Security : fraud prevention, anti-money laundering, access logging;
- Service improvement : usage analysis, A/B testing, development of new features;
- Commercial communications : sending information about services and news (consent required for prospecting outside existing customers).
5. Legal basis for processing
- Performance of the contract (Art. 6.1.b GDPR): for service provision, support and billing;
- Legal obligation (Art. 6.1.c): accounting retention (10 years), AML/CFT, judicial requisitions;
- Legitimate interest (Art. 6.1.f): security, service improvement, fraud prevention;
- Consent (Art. 6.1.a): non-essential cookies, commercial prospecting outside the existing customer base.
6. Data recipients
Your data may be shared with:
- authorized internal departments of CORTEXIA GROUP (support, billing, technical);
- our technical processors: Supabase (database, USA - Standard Contractual Clauses), Netlify (frontend hosting), Revolut (payments), OpenAI / Anthropic (AI agents - ephemeral processing without training);
- the marketplaces and suppliers you chose to connect with;
- administrative or judicial authorities, upon legal requisition.
7. Data transfers outside the EU
Some processors are established outside the European Union (notably in the United States). All transfers are governed by the Standard Contractual Clauses (SCC) approved by the European Commission, supplemented where appropriate by additional technical measures (encryption, pseudonymization).
8. Retention periods
| Data type | Longevity |
|---|---|
| Active account | As long as the account is active |
| Inactive account | 3 years after the last login |
| Invoices and accounting data | 10 years (Article L.123-22 of the French Commercial Code) |
| Connection logs | 12 months |
| Prospecting data | 3 years from the last contact |
| Cookies | 13 months maximum |
9. Your rights
Under the GDPR, you have the following rights:
- Right of access to your data;
- Right of rectification of inaccurate or incomplete data;
- Right to erasure ('right to be forgotten') in the cases provided by law;
- Right to restriction of processing;
- Right to portability of your data in a structured format;
- Right to object on legitimate grounds or to commercial prospecting;
- Right to set directives regarding the fate of your data after your death.
To exercise these rights, contact contact@sellavi.ai providing proof of your identity. We reply within 30 days at most.
If our reply is unsatisfactory, you can lodge a complaint with the CNIL : www.cnil.fr.
10. Data security
CORTEXIA GROUP implements appropriate technical and organizational measures to guarantee the security of your data:
- TLS 1.3 encryption in transit, AES-256 at rest;
- strong authentication (MFA) available;
- access logging and alerts in case of suspicious activity;
- encrypted backups with at least 30 days' retention;
- regular penetration tests, security audits;
- RLS (Row Level Security) policy on the database.
11. Cookies
For more details on the use of cookies, see our cookie policy.
12. Changes to this policy
This policy may be modified to adapt to changes in the service or regulations. Any substantial change will be notified to you by email with reasonable notice.
13. Contact
- DPO
- contact@sellavi.ai
- General contact
- contact@sellavi.ai
- Postal address
- CORTEXIA GROUP SAS — 5 rue du Colonel Moll, 75017 Paris
- Supervisory authority
- CNIL — www.cnil.fr