SAFORA
TermsPrivacyRefunds
Back to Safora
Legal document

Privacy Policy

Version
2026-07-14
Status
Published

Safora Privacy Policy

Version: 2026-07-14 Effective date: July 14, 2026

1. Data controller

The data controller is LE CHEVALIER NOIR, a French single-member limited liability company (EURL) with share capital of EUR 500, registered with the Dax Trade and Companies Register under number 101 146 488, with its registered office at 7 lotissement Val Fleuri, 40530 Labenne, France. The privacy contact is contact@safora.run.

Safora is a B2B service. This Policy covers users of the website and application, as well as people whose professional data appears in sources processed by a customer organization.

2. Data processed

Safora may process the following categories:

  • account data: name, email address, Clerk identifier, and versioned evidence that the Terms were accepted and the Privacy Policy was acknowledged;
  • organization data: name, members, roles, settings, plan, invoices, and Stripe identifiers; Safora does not receive full payment-card numbers;
  • GitHub data: installation, selected repositories, branches, commits, pull requests, files, and excerpts required for ingestion, audits, and fixes;
  • Figma or URL data: source identifiers, accessible content, and connection tokens when the user enables those integrations;
  • Safora outputs: versioned Knowledge Packs, inventories, evidence, findings, scores, governance decisions, job logs, and pull-request references;
  • security and operations data: timestamps, request identifiers, IP addresses, and technical logs generated by Safora or its hosting providers.

Processing may include source code and document excerpts. Sources are read in temporary workspaces during a job. Promoted Knowledge Packs, selected evidence, and output metadata are retained to provide the service. Safora therefore does not describe all processing as strictly in-memory.

3. Purposes and legal bases

Purpose Legal basis
Create accounts and organizations, and provide ingestion, audits, and fix PRs Performance of a contract
Manage roles, integrations, subscriptions, and payments Performance of a contract and accounting obligations
Secure the service, prevent fraud, and diagnose incidents Legitimate interest in protecting Safora and its customers
Measure reliability and improve the product using aggregated data Legitimate interest, following data minimization
Respond to rights requests and retain evidence of the agreement Legal obligations and the establishment, exercise, or defense of legal claims

Safora does not sell personal data or use it for behavioral advertising.

4. Artificial intelligence and decisions

When model-based enrichment or review is enabled for an organization, the necessary source and Knowledge Pack excerpts may be sent to Anthropic to produce an analysis. Disabled features do not trigger such a transfer.

Scores, findings, and proposals do not produce legal or similarly significant effects on a person. A person decides whether to apply a proposal or merge a pull request; Safora does not merge pull requests automatically.

5. Recipients and processors

Access is limited to authorized LE CHEVALIER NOIR personnel, authorized members of the customer organization, and the service providers required to operate Safora:

Provider Main role Main location
Vercel Inc. Web application United States
Render Services, Inc. API, workers, PostgreSQL, and Redis United States
Clerk, Inc. Authentication and sessions United States
Stripe Payments Europe, Ltd. and applicable Stripe entities Payments and billing European Union / United States
GitHub, Inc. Repositories, applications, and pull requests United States
Figma, Inc. Connected Figma sources United States
Anthropic, PBC AI processing when enabled United States

Data may also be disclosed where required by law or to protect the rights and security of the service.

6. International transfers

Some providers process data outside the European Economic Area. Depending on the provider and subscribed service, Safora relies on the contractual mechanisms offered by that provider, including the European Commission's Standard Contractual Clauses and the safeguards described in the provider's data-processing agreement.

7. Retention

Retention periods depend on the purpose:

  • account, organization, Knowledge Pack, audit, finding, and decision data: for the duration of service delivery, then until closure and any verified export or deletion request have been processed;
  • integration tokens: until disconnection, revocation, or deletion of the organization;
  • temporary workspaces and unpromoted candidates: deleted at the end of the job or when a job is resumed;
  • acceptance evidence and contractual records: for the duration of the relationship and then for the period required to establish, exercise, or defend legal claims;
  • invoices and accounting records: for the applicable statutory period;
  • technical logs and backups: according to the security, recovery, and retention cycles of the relevant hosting services.

An organization may request an export or deletion using the contact address. The identity and authority of the requester are verified before any action. Data subject to a retention obligation or required for a dispute may be isolated instead of deleted immediately.

8. Security

Safora uses HTTPS for public communications, Clerk-managed sessions, organization roles for sensitive actions, server tokens that are not exposed to the browser, and access controls for integrations. Code changes are proposed through branches and pull requests and are not merged automatically.

No system is risk-free. If a personal-data breach occurs, Safora follows the applicable notification obligations to authorities and affected people when the legal criteria are met.

9. Cookies

The application uses only strictly necessary cookies and storage mechanisms provided by Clerk for authentication, security, and session continuity. As of this version, the application does not enable advertising cookies or optional audience-measurement cookies.

10. Your rights

Depending on the processing and applicable legal basis, you may request access, rectification, erasure, restriction, or portability, or object to processing. You may withdraw consent without retroactive effect.

Write to contact@safora.run. Safora may request the information needed to verify your identity and authority within the organization. You may also lodge a complaint with the CNIL, the French data-protection authority.

11. Changes

Each version is dated and retained at a distinct URL. Material changes are brought to the attention of affected users by appropriate means. The current version does not retroactively replace a version previously provided to or acknowledged by a user.

Safora/LE CHEVALIER NOIR
contact@safora.run