Myrmid
---
title: "Privacy Policy: Myrmid"
description: "Data flows, lawful basis, retention windows, and how to exercise your data-subject rights under the GDPR. Operator-mediated DSR workflow at MVP-0; 30-day SLA."
canonical: https://www.myrmid.ai/en/privacy-policy/
---

Privacy

# Privacy policy

Last updated: 2026-09-16

This privacy policy explains what personal data Myrmid processes through this site, on which lawful basis, for how long, and how to exercise your data-subject rights under the GDPR and the French Loi Informatique et Libertés.

## Controller

The data controller is **Myrmid SAS** (in formation), 138 Avenue Victor Hugo, 75016 Paris, France.

For all data-subject-rights requests (access, rectification, erasure, portability, restriction, objection), contact: [privacy@myrmid.ai](mailto:privacy@myrmid.ai).

We respond to data-subject-rights requests within **30 days** of receiving a verifiable request, in line with NFR-C1 of our internal compliance baseline. If your request is unusually complex we may extend the response window by up to two further months and will tell you in the initial reply.

## Data flows

This site processes personal data through four flows. Each flow is listed below with the data captured, the purpose, the lawful basis, and the retention window.

### 1\. Plausible Analytics (page views, web-vitals)

-   **Data captured:** anonymous page views and Core Web Vitals samples (LCP, INP, CLS, TTFB, FCP). No cookies, no fingerprinting, no IP addresses retained, no cross-site tracking.
-   **Purpose:** site quality + understanding which pages help visitors find what they need.
-   **Lawful basis:** legitimate interest (GDPR Art. 6(1)(f)). The processing is privacy-preserving by design (cookieless, consent-exempt under ePrivacy guidance), serves a legitimate operational purpose, and the visitor's reasonable expectations are met by the no-cookies, no-fingerprinting design.
-   **Retention:** Plausible aggregates indefinitely; no individual session record is retained beyond the beacon hop.
-   **Recipient:** Plausible Insights OÜ, Estonia (EU-resident processor).

### 2\. Sentry error monitoring

-   **Data captured:** runtime error stack traces, browser version, page URL, anonymous session identifier. **Only fires after the visitor explicitly opts in** via the privacy-preferences dialog.
-   **Purpose:** diagnosing site bugs that visitors encounter in production.
-   **Lawful basis:** explicit consent (GDPR Art. 6(1)(a)). Sentry processing is gated behind opt-in; the visitor's choice is stored locally and can be reversed any time via the persistent privacy-preferences trigger.
-   **Retention:** Sentry default retention (90 days) on the EU data region.
-   **Recipient:** Functional Software Inc. d/b/a Sentry, EU data region.

### 3\. Enquiries (contact form, waitlist, support, partner applications)

-   **Data captured:** what you put in the enquiry form, on the site or in the chat with Lucie: the subject (waitlist, support or information), your name, your email address, your company and role if you give them, your message, and the language you wrote in. When the enquiry comes out of a conversation with Lucie, a short summary she writes of that conversation is stored with it, so the colleague who answers knows the context once the conversation itself is gone.
-   **Purpose:** answering you, by email or by opening the conversation you asked for; keeping the waitlist and the partner-cohort applications that come through the same form.
-   **Lawful basis:** steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)). You wrote to us; we process the enquiry to reply.
-   **Retention:** enquiries are kept for **12 months** from submission, then deleted automatically, whether or not they were answered. Ask us and we will delete yours sooner.
-   **Recipient:** Myrmid staff read and answer enquiries through our own staff console. The confirmation email is sent through Scaleway's transactional email service (Scaleway SAS, France, EU-resident processor).

### 4\. Lucie conversations (when the widget is enabled)

-   **Data captured:** the conversation itself — everything you write to Lucie and everything she answers — together with your IP address, the language and page you started from, and what Lucie notes about you as you talk: your company's size, your use case and how urgent it is, your role, how you came to the site, and a way to reach you if you give one. Anything you enter in a form she opens is covered by the flow that form belongs to: an enquiry by section 3, an account request by the paragraph below.
-   **Purpose:** answering you in the moment; letting a colleague at Myrmid read the conversation and step in to help; following up if you asked us to; and preventing abuse of the widget, which is what your IP address is kept for.
-   **Lawful basis:** legitimate interest (GDPR Art. 6(1)(f)) in answering visitors, supporting them and keeping the service safe. If you give us contact details, we use them only for the follow-up you asked for.
-   **Retention:** conversations are kept for **90 days** after their last message, then deleted automatically along with the messages, the IP address and what Lucie noted about you. We may delete one sooner. Ask us and we will delete yours. **What survives a deletion is a small set of statistics** about how the exchange went — a sentiment, a score, and whether a colleague should have stepped in — kept against the conversation's internal identifier so we can count and improve. They hold none of what you wrote, no contact details and no IP address; the identifier is meaningless once the conversation it pointed to is gone. Ask us and we will delete those too.
-   **Recipient:** Myrmid staff can read conversations and reply through them. Processing runs on the Enterprise Mesh under European jurisdiction, and the model that writes Lucie's replies is reached through our own gateway; no conversation is sold, and none is used to train a third party's model.

**Account requests.** When you ask for an organization on Myrmid — through the form on this site or the one Lucie opens — we take your name, work email, company, the organization's name, your role, and optionally your company's website and sector. From the chat, Lucie also drafts a summary of what you told her; you see it on the form and can edit or clear it before sending. The request is passed to the Myrmid platform, which sends you a confirmation email and opens your organization when you confirm; from then on it is held under the platform's own terms, not this notice. On this site, the request leaves only the conversation it came from, deleted with it after 90 days.

## Your rights

Under the GDPR and the French Loi Informatique et Libertés, you have the right to:

-   **Access** the personal data we hold about you.
-   **Rectify** inaccurate or incomplete data.
-   **Erase** data we hold about you ("right to be forgotten") subject to applicable retention obligations.
-   **Restrict** processing in specific circumstances.
-   **Object** to processing based on legitimate interest.
-   **Portability:** receive your data in a structured, commonly-used, machine-readable format and have it transmitted to another controller where technically feasible.
-   **Lodge a complaint** with the Commission Nationale de l'Informatique et des Libertés (CNIL), [www.cnil.fr](https://www.cnil.fr/), if you believe your rights are not being respected.

## Operator-mediated DSR workflow at MVP

We operate the data-subject-rights workflow as a documented operator process at MVP-0:

1.  You email [privacy@myrmid.ai](mailto:privacy@myrmid.ai) with your request.
2.  We confirm receipt within 2 business days.
3.  We verify your identity to the extent the request requires it.
4.  We satisfy the request (or explain why we cannot, with the legal basis for the refusal) within 30 days from the original request.

This process is operator-mediated rather than self-service at this stage of the company. As we scale the platform, in-product self-service tooling will follow; the email contact above remains valid throughout.

## International transfers

We do not transfer personal data outside the European Economic Area for the data flows described above. Where a flow would require such a transfer (for example, a visitor accessing the site from outside the EEA), the transfer rests on the standard contractual safeguards (Art. 46 GDPR) negotiated between us and the relevant processor.

## Updates

This policy is updated as our processing changes. The "last updated" date at the top reflects the most recent change. Material changes are surfaced in the privacy-preferences dialog so existing visitors are not surprised.