Tootela is operated by Tootela SAS, a French company. This page is provided in English for convenience; in case of dispute, French law applies as set out in our Terms of Service.
What is the GDPR?
The General Data Protection Regulation (Regulation (EU) 2016/679) is the EU's framework for personal data protection. It applies whenever an organisation processes personal data of people in the EU, regardless of where the organisation is based.
How Tootela complies
1. Lawful basis for processing
For each processing activity, we identify a legal basis under Article 6 of the GDPR : contract, legitimate interest, consent, or legal obligation. The mapping is in our Privacy Policy.
2. Transparency
Our Privacy Policy describes, in plain language, what data we collect, why, who we share it with, and how long we keep it. No dark patterns, no buried clauses.
3. Data subject rights
Every right granted by the GDPR is supported : access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent. To exercise any of them, email our DPO at contact@tootela.net : we respond within 30 days. You can also lodge a complaint with the CNIL (cnil.fr).
4. Data minimisation
We collect only what we need to run the product. We don't ask for date of birth, social security numbers, or other sensitive identifiers unless the feature genuinely requires them (e.g. payslips in the HR module).
5. Storage limitation
We have explicit retention periods for every category of data. See the retention table.
6. Security
Encryption in transit and at rest via our infrastructure providers, email-code two-factor authentication, role-based access inside workspaces, row-level tenant isolation, daily provider backups, vendor reviews. Full picture on the Security page.
7. Data Processing Agreement (Article 28)
Every customer has a GDPR-compliant DPA in place by default : the online DPA is incorporated into our Terms of Service. A counter-signed PDF is available on request at contact@tootela.net.
8. International transfers
Storage is in the EU (eu-west-3 (Paris, France)). When we use non-EEA subprocessors (notably US providers), we rely on EU Standard Contractual Clauses (SCCs) plus supplementary measures. The current subprocessor list is in Annex C of the DPA.
9. No training on customer data
We do not use customer content to train AI models. Our AI provider (Google Gemini) processes content only to generate the response for the feature you're using, and our agreement with Google prohibits training on it.
10. Breach notification
If a personal data breach affects you, we notify you within 48 hours of becoming aware, and the CNIL within 72 hours where required, in line with Articles 33-34.
11. Privacy by design and default
New features go through a privacy review. Defaults err on the side of less sharing, less collection, more user control. Analytics on the marketing site run only after consent.
12. Data Protection Officer
Our DPO can be reached at contact@tootela.net for any data protection concern.
Documents you can request
- Counter-signed DPA (PDF)
- List of subprocessors (live version in the DPA)
- Written responses to your security or privacy questionnaire
- Standard Contractual Clauses (Module 3, processor-to-processor)
Send requests to contact@tootela.net.
Questions about your specific use case?
If you're processing sensitive data (health, financial, biometrics) or operating in a regulated industry (healthcare, banking, public sector), we're happy to talk through the specifics. Email contact@tootela.net.