Skip to main content

Privacy policy

Last updated: August 18, 2026. We handle your data carefully, in compliance with the GDPR.

Data controller

AudiScale SAS is the controller for data collected through the website and application.

For any question about your data or to exercise your rights, write to contact@audiscale.com.

Data collected

We collect the data you provide and technical data required for the operation and security of the service.

  • Account data : Name, email and billing information.
  • Site data : URLs and audit results of the sites you connect.
  • Security data : IP address and device type (User-Agent), recorded at account creation and sign-in.
  • Usage data : Technical logs required for the operation of the service.

Purposes and legal bases

Each processing activity relies on a specific legal basis.

  • Service provision : Account creation, audits and action execution. Legal basis: performance of the contract.
  • Security and fraud prevention : We log the IP address and device at account creation and sign-in to detect abuse (multiple accounts, intrusions) and protect accounts. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
  • Legal obligations : Accounting and billing. Legal basis: compliance with a legal obligation.

Retention and deletion

Account data (name, email, connected sites): kept while your account is active, then deleted or anonymized without delay when you delete your account.

Security logs (IP address, device): each entry is automatically anonymized 12 months after it was collected, whether your account is active or not. It is also anonymized without delay if you delete your account — whichever comes first. The activity history (action type, date) is kept, but without personal data beyond that point.

Billing data: kept for the legally required accounting and tax periods.

Subprocessors and transfers

We rely on contractually bound providers for hosting, payment, email delivery and AI processing, who access your data only to perform those services.

Where a provider processes data outside the European Union, appropriate safeguards (standard contractual clauses) are put in place.

Security and protection of your data

The data you entrust to us, including sensitive data obtained through Google APIs, is protected by the technical and organisational measures described here without ambiguity.

All data in transit is encrypted with TLS 1.2 or above; no cleartext access is possible over the network. OAuth access and refresh tokens are encrypted at rest with AES-256-GCM, using a key held outside the database; they are never written to our logs, never exposed to the browser, and never shared with a third party.

Our servers are hosted in the European Union. Administrator access is restricted to those who need it and logged: server access uses named SSH keys, with password authentication and direct root login disabled; access to the administration back-office requires two-factor authentication (TOTP). Each customer’s data is partitioned by account: a query can never read another customer’s data. Passwords are stored as salted hashes, never in cleartext. The server is backed up weekly, with backups retained within the European Union, and we apply security patches to our dependencies continuously.

In the event of a data breach likely to create a risk to your rights, we notify the supervisory authority within 72 hours and inform you without delay where the regulation requires it.

  • Encryption in transit : TLS 1.2 or above on every communication, without exception.
  • Encryption at rest : OAuth tokens encrypted with AES-256-GCM, key held outside the database; application secrets isolated from the code.
  • Restricted access : Servers reachable through named SSH keys only (password and root login disabled); administration back-office protected by two-factor authentication.
  • Partitioning and EU hosting : Data isolated per customer account; servers in France and weekly backups retained within the European Union.

Google data (Search Console, Analytics & Ads) and Limited Use

When you connect your Google Search Console and Google Analytics 4 properties, AudiScale reads your search-performance and audience data and — on your explicit action — submits your sitemap and requests reindexing of your URLs. When you connect your Google Ads account, AudiScale only reads your advertising performance metrics (cost, clicks, impressions, conversions, conversion value, per campaign): no campaign, ad, bid or budget is created, modified or deleted. These accesses are used solely to produce your audits, action plan, dashboards and the fixes you approve.

Data obtained through Google APIs is protected by the measures described in the “Security and protection of your data” section: encryption in transit and at rest, restricted and logged administrator access, per-account partitioning. We retain only the aggregates needed for your dashboards; they are deleted when you revoke the connection or delete your account. You can revoke access at any time from AudiScale or from your Google account security settings.

AudiScale’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data — raw, aggregated or derived — to develop, train or improve generalized or foundational AI/ML models. Our AI features are limited to analyzing your own data to advise you; that data is neither shared with nor sold to third parties.

Your rights

Under the GDPR, you have rights of access, rectification, erasure, objection, restriction and portability. To exercise them, write to contact@audiscale.com.

You may also lodge a complaint with your supervisory authority (in France, the CNIL).

Cookies

The site uses strictly necessary cookies (including remembering your language and session) and, where applicable, analytics cookies with your consent.