Skip to main content
Olympe AIFR
Product
For every ambitionSmall businessMid-sized companyLarge enterpriseIndependent
PricingDocumentation
Resource centreDocumentationArticlesSecurity & dataStatus
Contact
Choose language12 planned languages
FrançaisFranceFREnglishUnited KingdomEN
Log inGet started
Olympe AI
ProductPricingResourcesDocumentationArticlesContact

Solutions

Small businessMid-sized companyLarge enterpriseIndependent
LanguagesFR and EN available
FrançaisEnglish
Get startedLog in
Home/Legal/Privacy policy
Olympe LegalVersion dated 21 September 2026

Privacy policy

Data processed by Olympe AI, purposes, providers, verified retention settings and ways to exercise your rights.

Controller
OLYMPE AI
Announced hosting
France · OVHcloud
Contact
privacy@olympe-ai.fr
Legal documents01Legal notice02Terms of use03Terms of sale04Privacy policy05Cookie policy
In this document01Controller and contact02Roles by processing activity03Privacy contact and DPO04Data concerned05Purposes and legal bases06Required and optional data07Video, voice, people and sensitive data08Indirect collection and people in footage09Recipients, subprocessors and DPA10Location and transfers11Retention12Model training13Security and breaches14Automated decisions15Your rights16Exercise rights and complain to the CNIL17Policy changes18Official references
Readable and complete version

Key points are summarised above. The detailed text below remains the reference for understanding each rule.

01

Controller and contact

For website, commercial relationship and account-management processing, the controller is OLYMPE AI, 2 route de Cresnes, 60119 Hénonville, France. Privacy questions and rights requests can be sent to privacy@olympe-ai.fr.

02

Roles by processing activity

OLYMPE AI acts as controller for its own administrative, commercial and security needs. For video content uploaded by a business customer, OLYMPE AI generally acts as processor on the customer’s documented instructions, while the customer remains controller for people appearing in footage. OLYMPE AI’s own duties do not disappear because of that allocation.

03

Privacy contact and DPO

Send requests to privacy@olympe-ai.fr or dpo@olympe-ai.fr. You may also write to the registered office. dpo@olympe-ai.fr is a contact mailbox; no DPO is formally appointed at this time.

04

Data concerned

Depending on use, OLYMPE AI may process identity and contact data, company and billing information, connection and security data, support requests, preferences, and footage, voices, faces, screen captures, audio files and brand assets uploaded to a project.

05

Purposes and legal bases

Each purpose relies on an identified basis and data must not be reused incompatibly.

  • Contract or pre-contractual steps: account, demo request, projects, rendering, contractual support and billing.
  • Legal obligation: accounting, invoicing, legally required authority responses and mandatory retention.
  • Documented legitimate interests: security, fraud prevention, legal claims and non-intrusive improvement after balancing against individual rights.
  • Separate consent: non-essential trackers and any optional secondary-use programme where consent is the appropriate basis.
06

Required and optional data

Fields marked as required are needed to create an account, answer a request or perform an edit. Without them, OLYMPE AI cannot provide the requested action. Unmarked fields, marketing data and participation in an improvement programme are optional and their absence does not block the main service.

07

Video, voice, people and sensitive data

An image or voice identifying a person is personal data. It is biometric data under Article 9 GDPR only when specific technical processing aims to uniquely identify that person. Subject tracking, reframing and transcription are not intended to create or retain biometric templates. Biometric identification or sensitive-data inference is prohibited by default and would require a separate feature, assessment and legal basis.

08

Indirect collection and people in footage

When a customer uploads a third party’s image, voice or speech, OLYMPE AI does not receive it directly from that person. The customer must provide the required information, establish its legal basis and organise rights requests. The DPA sets out OLYMPE AI assistance, including locating, exporting or deleting a relevant project, without excluding information duties directly applying to OLYMPE AI.

09

Recipients, subprocessors and DPA

Access is limited to authorised people and providers who need it to deliver, secure or support the service. An Article 28-compliant DPA must be accepted before footage is processed for a customer. It covers instructions, confidentiality, security, rights and incident assistance, audits, transfers, onward processors and return or deletion at termination. The current list must identify each provider’s service, country, data and transfers.

  • OVHcloud: website, studio and video-project hosting in France.
  • Sweego (MINDBAZ): transactional email delivery; recipient address, message contents and delivery data.
  • Stripe: payments, billing data and fraud prevention.
  • Google and Microsoft: optional sign-in, provider identifier, name and email according to granted permissions.
  • Umami: self-hosted analytics software; Umami Cloud is not used.
  • Google Analytics: optional external analytics with separate consent; page views, cookie identifiers and technical connection data. Advertising parameters are disabled in the tag.
10

Location and transfers

The website, studio and video projects are hosted with OVHcloud in Gravelines, France (GRA9 and GRA11). Stripe handles payments and Sweego (MINDBAZ) delivers transactional studio emails. Google and Microsoft are involved when you choose their sign-in option: they do not receive footage for editing. These providers may process account or payment data outside France. Video hosting location therefore does not mean all service processing takes place in France. Contact the privacy team for the safeguards applicable to any transfers outside the European Economic Area.

11

Retention

Retention depends on the data category and storage used. The periods below distinguish verified technical settings and record-keeping obligations. Deleting a project and deleting every copy are separate operations.

  • Prospects: three years from collection or the last active contact initiated by the prospect; requests needed for a contractual relationship follow their own purpose.
  • Account and contract: for the contract term; data needed as evidence may be archived for up to five years under the applicable limitation period.
  • Video-processing files in organisation object storage: expiry configured 30 days after object creation. This does not apply to every project, local file or backup.
  • Temporary music uploads in the staging area: expiry configured after 1 day.
  • Older object versions, other video backups, security logs and support requests: this version does not guarantee one complete-deletion period. Request the conditions for your scope before uploading content that requires a specific contractual retention period.
  • Transactional email bodies and detailed delivery-event payloads in the application: deletion configured after 7 days. This does not cover every header, log, support exchange or copy held by the email provider.
  • Invoices and accounting records: ten years under French commercial law.
  • Browser analytics choice: 180 days. Umami statistics: 13 months with daily deletion; Umami backups: 14 days.
12

Model training

OLYMPE AI does not reuse your videos, audio tracks, images or renders to train, improve or evaluate artificial intelligence models. Processing is limited to the requested service and customer instructions. A change of purpose would require prior information and a separate lawful basis; it cannot be inferred from your use of the service.

13

Security and breaches

The security programme must cover, according to risk, access limitation and review, encryption in transit, environment separation, logging, backups, restoration and incident management. Every announced measure must be verified in production and supported by dated evidence. A breach must be documented; OLYMPE AI notifies the CNIL within 72 hours where the risk requires it, informs people where risk is high and alerts the customer without undue delay when acting as processor.

14

Automated decisions

Editing suggestions are not intended to make a decision producing legal or similarly significant effects on a person. Within the scope described here, OLYMPE AI does not make solely automated decisions under Article 22 GDPR. Any change would require prior assessment and notice.

15

Your rights

Depending on the processing and legal basis, you may request access, rectification, erasure, restriction, objection and portability, and withdraw consent for the future. Direct-marketing objection may be exercised at any time. Identity evidence is requested only where needed to avoid disclosure to another person.

16

Exercise rights and complain to the CNIL

Write to privacy@olympe-ai.fr and identify the relevant account, file or project. Requests are free in principle. OLYMPE AI responds within one month; this may be extended by two months due to complexity or volume, with a reasoned notice during the first month. If the response is unsatisfactory, you may complain directly to the CNIL.

17

Policy changes

This policy is updated when processing, subprocessors, features or applicable law change. Material changes are brought to users’ attention by an appropriate method before taking effect when required.

18

Official legal references

These links point to the official versions used to review this document. They make the reasoning verifiable without replacing assessment of the actual context.

EUR-LexGeneral Data Protection Regulation (GDPR)

Core European text on processing principles, lawful bases, transparency, data-subject rights, security and processor relationships.

Service Public EntreprendreGDPR obligations for businesses

Official guide covering notices, lawful bases, records of processing, security, processors and transfers outside the European Union.

CNILDefinition of personal data

Explains direct and indirect identification and confirms that a person’s voice, image or IP address may constitute personal data.

CNILAI: selecting a lawful basis

Guidance for choosing the appropriate lawful basis when personal data is processed in the development or deployment of an AI system.

CNILAI: checking the lawfulness of reused data

Describes checks expected before data is reused, including its provenance, associated rights and the absence of manifest unlawfulness.

CNILGDPR — rights of the data subject

Sets out the rights of access, rectification, erasure, restriction, objection and portability that the privacy policy and product processes must support.

CNILInformation and transparency requirements

Explains collection-time information on purposes, lawful bases, recipients, retention, rights, transfers and automated decisions.

CNILPersonal-data retention periods

Confirms that a period or genuinely determinable criterion must be set, implemented and documented for every purpose.

A question about this document?

Include the relevant page and clause to clarify your question.

Prepare my question
Next documentCookie policy
Olympe AI

The French automated post-production platform that turns footage into videos ready to publish.

FRFrench company · Principal video processing stated in France

Product

Product & featuresPricingSecurity & data

Solutions

Small businessMid-sized companyLarge enterpriseIndependent

Resources

Resource centreDocumentationArticlesStatusContact

Legal

Legal noticeTerms of useTerms of salePrivacyCookies
© 2026 Olympe AI · SIREN 102 023 496Contact & enquiries
Privacy policy | Olympe AI