Privacy policy — Marto.AI
Last updated: October 9, 2026
The French version prevails. This English text is provided for convenience only. In the event of any discrepancy, the French version (version française) is the authoritative one (Terms, art. 16).
This policy describes the processing of personal data carried out within the Marto.AI service (the "Service"), the purposes pursued and the rights available to data subjects. It applies to all users of the Service, irrespective of their place of residence: Regulation (EU) 2016/679 (the "GDPR") is applied as a common baseline, including where local legislation is less demanding.
1. Controller
The Service is published by LCB LA COMPAGNIE BASQUE, a French simplified joint-stock company with a sole shareholder (SASU) registered with the Paris trade and companies register under number 980 885 073, whose registered office is at 15 rue de la Présentation, 75011 Paris, France (the "Publisher"). The Publisher can be reached through the support form (https://www.marto.ai/en/support) or by post at its registered office. No data protection officer has been appointed to date.
The allocation of roles varies according to the category of data:
| Data | Controller | The Publisher's role |
|---|---|---|
| Account data, settings, billing, exchanges with support | The Publisher | Controller |
| The organization's inventory Content (photographs, lots, clients), for the provision of the Service | The user organization | Processor |
| Content used to improve the Service and train the Publisher's models (§4), and the production of de-identified or aggregated data | The Publisher | Controller |
The terms applicable to the processor role are set out in the data processing annex.
2. Data processed
- Account data: name, email address, Google or Apple identifier (the only sign-in methods of the Service), language, affiliated organization(s) and role. Providing this data is a condition of creating an account.
- Inventory Content: photographs of lots, descriptions, sections, documents, auctioneers' signatures, together with the information recorded by the organization about its own clients (the "Data Subjects concerned": sellers, heirs, debtors, etc.).
- Exchanges with the inventory assistant: the text of the messages dictated or typed by the user and of the assistant's replies, including the detail of the lots the assistant created, edited or displayed during the exchange. These conversations are stored so that the user finds them again from one screen to the next; their list is shown only to their author. A copy of each message and each reply is also kept in the audit journal described below. Their retention period appears in section 7.
- The assistant's audit journal: a copy of the exchanges with the assistant — each message of the user, each reply, each tool called with its parameters and its result, each confirmation given or refused. It makes any change made by the assistant explainable. It can be read by its author, and by the organization's owner and auctioneers, for as long as they are active members. Its retention period appears in section 7.
- Billing data (where a paid plan is subscribed): billing details and transaction identifiers. Payment card numbers do not pass through the Service's servers; they are collected directly by Stripe.
- Technical data: connection and activity logs, IP address, device type,
application error reports, page performance measurements, and an aggregated
audience measurement (page views, referrer) which assigns no individual
identifier and whose page addresses are redacted in the browser before
transmission (record identifiers replaced with
[id], search parameters removed). See section 9.
The Service does not collect continuous geolocation data and carries out no analysis of Content for advertising purposes.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Provision of the Service: account, storage, exports, support | Performance of the contract (the Terms) |
| Security, abuse prevention, technical logging | Legitimate interests (1) |
| Billing and accounting (paid plans) | Legal obligation and performance of the contract |
| AI assistance features triggered by the user | Performance of the contract |
| Improvement of the Service and training of the Publisher's AI models | Legitimate interests (2), subject to the safeguards in §4 |
| Publication or reuse of Content (catalogue, promotion) | The organization's consent (Terms art. 8.5), revocable |
| Informing users of changes to the Service and to the terms | Legitimate interests (3); legal obligation where one exists |
| Stability and performance diagnostics for the mobile application | Legitimate interests (4) |
Legitimate interests pursued: (1) fraud prevention and the integrity of the Service, in the interests of the Publisher and of users; (2) the development and improvement of the Service's features by the Publisher; (3) informing users of changes to the Service; (4) detecting and fixing crashes, hangs and terminations of the mobile application, in the interests of the users whose field work depends on it.
What mobile diagnostics covers. The iOS application uses MetricKit, a service of Apple's operating system, which delivers a device-aggregated report once a day: number of crashes, number of interface hangs, and number of times the system terminated the application for exceeding its memory limit. These indicators are sent to Sentry alongside the error reports described above. They describe how the software behaves and contain no inventory content, no photograph and no data relating to a party.
This purpose is distinct from security and technical logging: a memory termination produces no crash report and leaves no trace anywhere else. Without this counter the application would vanish from the screen with no way for the Publisher to know it happened, let alone fix it.
4. Processing relating to artificial intelligence
The Service uses artificial intelligence in two distinct ways.
a. Features triggered by the user. When an assistance feature is used (suggested description or estimate, rewording of a report's observations, assistant), the necessary textual information is transmitted to the Publisher's model provider, Mistral AI (France, European Union), for the duration of the processing: the description and estimate of the lot concerned, the messages addressed to the assistant, an overview of the inventory in progress — its record and the list of its sections, which may include the name of the client attached to it — as well as the list of the organization's clients. When the user asks the assistant to count their inventories or to find one, the list of the organization's inventories is transmitted to it: the title, status and number of lots of each, up to fifty. When the user asks the assistant to look up, create or edit a client record, that record's information is transmitted to it: name, contact details, addresses and, where applicable, date of birth. When the user asks the assistant to search for, count or display a lot, the description of the matching lots is transmitted to it; that search may span all of the organization's inventories rather than only the one currently open, and the answer may then include the title of the inventory holding the lot found. When a report (constat) is open in the assistant, or the assistant creates one, its content is transmitted to it: title, type and location, room names and dictated observations, annex labels, names and roles of the parties. When the user asks the assistant to open a report and the request does not designate a single one, the list of the organization's reports is transmitted to it so that it can offer the right one: the title, location and status of each, up to twenty. When the user asks for the observations of a room of a report to be reworded, a feature separate from the assistant, the transcribed text of their dictations for that room and the observations already validated are transmitted to Mistral AI. No photograph is transmitted to Mistral AI to date.
Mistral AI acts as the Publisher's processor. The contract between them,
which complies with Article 28 of the GDPR, imposes on it data protection
obligations at least equivalent to those described in this policy (see also
the data processing annex, § 4).
Article 4.2 ("Training")
of Mistral AI's commercial terms,
read on legal.mistral.ai/terms/commercial-terms-of-service on 2026-09-25,
makes the use of customer data for training dependent on the setting of the
product used: it is excluded unless the customer opts in, or fails to opt out
on a product that enables it by default. On Marto.AI's production account, that
setting is disabled: no customer data is used to train the models.
Voice dictation relies on the speech recognition of the user's operating system or browser (Apple or Google depending on the device); the voice is processed by that provider under its own terms and does not pass through the Service's servers. Only the transcribed text is recorded there, and it is transmitted to Mistral AI in the cases described above: a report open in the assistant, or the rewording of observations.
b. Improvement of the Publisher's models. The Publisher uses the Service's content for the purpose of developing and improving its features and training its own models (object recognition, assistance with description and estimation). This data is obtained from the user organization, in the course of the inventories it carries out (Article 14(2)(f) GDPR); as the Publisher does not hold the contact details of the Data Subjects concerned, this publicly accessible policy ensures they are informed in accordance with Article 14(5)(b) GDPR, and the user organization relays it to its clients. This processing is subject to the following safeguards:
- any organization — and any user, as regards the content they have uploaded — may at any time exclude their content from the improvement and training uses described in this paragraph b (opt-out), through a setting or through the support form; the exclusion applies to all subsequent training and has no effect on models already built;
- any disclosure of data outside the Service (datasets, sector statistics) relates exclusively to de-identified or aggregated data, incapable of being linked to a person, an organization or a file;
- the Publisher neither sells nor rents personal data or identifiable content to third parties;
- none of this processing produces a solely automated decision producing legal effects concerning a person.
5. Recipients and sub-processors
Data is disclosed only to the providers necessary for the operation of the Service, under contractual arrangements:
| Provider | Role | Location |
|---|---|---|
| Supabase (SUPABASE PTE. LTD., Singapore) | Database, authentication, storage | Data hosted in the European Union; the provider itself is established in Singapore |
| Vercel | Application hosting, page performance measurement, cookieless audience measurement | United States; server functions executed in the European Union |
| Mistral AI | AI models for on-demand features | France (EU) |
| Sentry (Functional Software) | Application error monitoring and mobile stability metrics | European Union — Sentry EU region |
| Stripe | Payment of paid subscriptions | EU / United States |
| Google, Apple | Authentication — the only way to create an account since 2026-09-24 | United States |
Where an organization activates an integration with a third-party platform (for example publishing a catalogue to Drouot), the content it chooses to publish is transmitted to that platform at its request; the platform operator then acts as a separate recipient, responsible for its own processing.
Data may further be disclosed where required by law (in particular pursuant to a judicial order) or in connection with the transfer of the Service to the company being incorporated or to any successor, which shall assume the undertakings of this policy.
6. International transfers
Where data is transferred outside the European Union (Vercel, Stripe, Google, Apple, and Supabase — Sentry stays within the Union), the transfer relies, depending on the recipient: on the EU–United States adequacy decision of 10 July 2023 (Data Privacy Framework), where the recipient is certified under it; failing that, on the standard contractual clauses adopted by the European Commission, supplemented where appropriate by additional measures. A copy of the applicable safeguards may be obtained on request, through the means set out in section 13. The Publisher applies the GDPR as a common baseline for all users, irrespective of their place of residence.
7. Retention periods
| Data | Period |
|---|---|
| Account data | For the life of the account, plus 30 days |
| Exchanges with support | For the life of the account, plus 30 days |
| Exchanges with the inventory assistant | For the life of their author's account. These exchanges form part of the organization's data: after 90 days with no new message the conversation is removed from its author's list, but it is not deleted. Deleting its author's account erases the conversation; the copy kept in the audit journal remains (next row) |
| The assistant's audit journal | For the life of the organization. When its author's account is deleted, the journal is no longer linked to them, but its content is kept with the organization's data |
| Inventory Content | For the life of the account or the organization, plus the backup purge period (90 days at most) |
| Technical logs | 12 months |
| Billing data | 10 years (accounting obligation) |
| De-identified / aggregated data | Without time limit, provided the de-identification meets the anonymisation criterion of recital 26 GDPR; failing that, the periods above apply |
8. Rights of data subjects
Every person has, irrespective of their place of residence, the following rights: access, rectification, erasure, portability, restriction of processing, objection to processing based on legitimate interests, and withdrawal of consent at any time. These rights overlap with those provided for by the laws of the countries where the Service is available (GDPR in the European Union; Moroccan, Senegalese, Ivorian, Nigerian, Kenyan and South African law, among others).
Requests should be addressed through the support form (https://www.marto.ai/en/support) or by post to LCB LA COMPAGNIE BASQUE, 15 rue de la Présentation, 75011 Paris, France; they are answered within one month. Any person may also lodge a complaint with the competent supervisory authority — in France, the Commission nationale de l'informatique et des libertés (cnil.fr).
Data Subjects concerned by inventories (for example an heir whose assets have been inventoried): the user organization is the controller for that data; the request should be addressed to it in the first instance, with the Publisher providing assistance. A request may also be addressed directly to the Publisher.
Deceased persons: any person may lay down directives concerning the retention, erasure and communication of their data after their death (article 85 of the French Data Protection Act). In the absence of directives, heirs may exercise the rights provided for by law, to the extent necessary for the administration and settlement of the estate, upon production of supporting evidence.
9. Cookies
The Service uses only cookies strictly necessary for its operation: authentication (session), active organization, language preference. No advertising cookie and no cross-site tracking device is implemented.
Two measurement tools provided by Vercel are in place — Speed Insights
(loading times) and Web Analytics (page views). Neither sets a cookie,
assigns an individual identifier, or follows the user from one site to
another. Page addresses transmitted to Web Analytics are redacted in the
browser, before anything is sent: record identifiers are replaced with
[id] and search parameters are removed, with the sole exception of campaign
parameters (utm_*, ref) — so that a name typed into a search never leaves
the device. The possible introduction of audience measurement cookies would be
preceded by the implementation of a consent collection mechanism.
Full detail is in the Cookie Policy.
10. Security
The measures implemented include in particular: encryption in transit (TLS) and at rest, isolation of data between organizations enforced at database level and verified by automated tests, access logging, management of technical secrets outside the code, regular backups. Data breaches are notified under the conditions provided for by the applicable regulations, in particular Articles 33 and 34 GDPR.
11. Minors
The Service is reserved for adults. No account is knowingly opened for the benefit of a minor.
12. Amendments
Any substantial amendment to this policy, in particular to sections 4 and 5, is notified at least thirty (30) days before it takes effect, by email or within the Service. The date of last update appears at the top of the Service's legal pages.
13. Contact
Through the support form (https://www.marto.ai/en/support), or by post to LCB LA COMPAGNIE BASQUE, 15 rue de la Présentation, 75011 Paris, France.