Privacy

SeveUp processes personal data to run SeveUp App. This page describes exactly what is actually collected today — not a generic template.

Data controller

SeveUp, contact@seve-up.com — same details as the legal notice.

Data collected

  • Account: email and organisation, entered at sign-up — needed to create and secure your account.
  • Session cookie: an authentication token (httpOnly, not readable from JavaScript), valid up to 7 days or until the token expires — strictly necessary, no consent required.
  • Language cookie: remembers FR/EN — strictly necessary, no consent required.
  • Business content (IFC models, BIM requirements, dashboards): uploaded by your organisation, processed on your organisation's behalf — SeveUp does not use it for its own purposes.

Behavioural analytics (PostHog)

SeveUp App integrates PostHog (EU hosting) to understand product usage by logged-in accounts: click paths, and session replay with input fields masked. As of this page, this measurement is NOT active in production — the activation key is not set. If it ever is, this page will be updated before activation, together with the required consent collection.

Purposes

Providing the service, authenticating accounts, support, and — if activated — improving the product. No data is sold or used for advertising.

Subprocessors and hosting

Vercel Inc. (site hosting), Render (API hosting), Supabase (database), Modal (processing of uploaded IFC files). Each acts as a subprocessor on SeveUp's behalf.

Retention period

Tied to your account's lifetime. A detailed retention policy per data type is not yet formalised — available on request at contact@seve-up.com in the meantime.

Your rights

Access, rectification, erasure, portability and objection, on simple request at contact@seve-up.com. You can also lodge a complaint with the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr) or your local data protection authority.