Who processes your data?

The BizzyTrainer service is published by KEAJY, a French SAS with a share capital of €2,000, 24 rue Garnier Pagès, 94100 Saint-Maur-des-Fossés, France — SIREN 920 396 090.

KEAJY acts in two distinct capacities:

  • as data controller for the management of its commercial relationship: creation and administration of customer accounts, invoicing, transactional emails, technical operations and security logs, and for the public website;
  • as data processor, on the instructions of the customer organization, for the data processed within the service: member accounts, training sessions, catalogs and content. The customer organization — employer or educational institution — is then the data controller: it determines the purposes, informs its users and answers their requests, with KEAJY's assistance.

Contact — data protection

For any question or request regarding personal data: privacy@bizzytrainer.ai. KEAJY has not appointed a data protection officer.

Data processed

On the public website: none. The website sets no cookies, contains no trackers and has no data collection form.

Within the service:

  • Account and authentication — name, email address, job title, role; cryptographic hash of the password (never stored in clear text); IP address and browser of the open session, for security purposes.
  • Training sessions — audio recording of the conversation (the user's voice and the synthetic voice), full written transcript, detailed analysis and score, scenario played, duration and timestamps. Recording is inherent to the service and cannot be disabled.
  • Created content — simulated counterparts, scenarios, events and assignments. When a preparation concerns a real prospect, the information entered (identity, company, meeting context) may be kept in the organization's catalog; informing that third party is the responsibility of the customer organization, as data controller.
  • Subscription — company name, billing details, subscription identifiers. KEAJY stores no payment card data.
  • Activity log — structuring actions (sign-in, session launch, content publication), with no conversation content whatsoever. This log is immutable, for traceability and security purposes.

Purposes and legal bases

  • Providing the service — simulations, analyses, accounts, quotas: performance of the contract.
  • Invoicing and bookkeeping: legal obligation.
  • Securing — logs, rate limiting, traceability: legitimate interest in protecting the service and the data.
  • Writing to you — transactional emails strictly related to the service (address verification, invitation, analysis notification): performance of the contract. No newsletter or automated prospecting is in place to date.

Mandatory nature of the data

The name and email address are required to create the account and use the service: without them, the account cannot be opened. The other data arises from use itself (sessions, content) or from the subscription.

Automated scoring

At the end of a simulation, the platform automatically produces an analysis and a score, without human intervention prior to their display. These results are training aids: BizzyTrainer makes no decision and is connected to no decision-making system.

Depending on the role assigned by the customer organization, a supervisor may view the sessions and scores of the organization's members. If the organization bases on these scores a decision that produces legal effects or similarly significantly affects the person, article 22 of the GDPR applies to the organization: it is responsible for guaranteeing human intervention, the right to express one's point of view and to contest the decision.

Recipients

Data is accessible:

  • to the members of the customer organization, according to their role — a member accesses their own sessions; a supervisor accesses the organization's sessions;
  • to authorized KEAJY personnel, for operations and support. Any support access under a user's identity is recorded in the organization's activity log, which the customer can consult;
  • to processors, within the limits of their assignment: Microsoft Azure (hosting of the entire infrastructure, in the European Union), Stripe (payment), as well as artificial intelligence model providers, a web search provider and a transactional email delivery provider. The named, up-to-date list of processors is provided to customers in the contractual documentation, and on request at privacy@bizzytrainer.ai.

No data is sold, rented or shared for advertising purposes.

Transfers outside the European Union

Hosting, the database and the storage of recordings are located in the European Union, where the data is kept. Artificial intelligence processing relies on resources created in the European Union, some deployments of which may nevertheless route the processing of requests — including session audio and transcripts — outside the Union. Some providers also belong to groups whose processing may take place outside the Union. These transfers are governed by the safeguards specific to each provider, in particular standard contractual clauses. Details per processor are given in the documentation provided to customers.

No artificial intelligence model is trained on customer data.

Retention periods

  • Sign-in session, with associated IP address and browser: 7 days.
  • One-time verification code: 5 minutes.
  • Invitation to join an organization: 7 days.
  • Technical operations logs: 30 days.
  • Database backups: 30 days.
  • Session data (recordings, transcripts, analyses, scores) and content: kept for the duration of the customer organization's contract. Specific periods may be agreed contractually; early deletion is available on request.
  • Billing data: statutory accounting retention periods.

Security

Each organization's data is isolated at the database engine level, by a partitioning that the application account cannot bypass, verified by an automated test before every production release. Communications are encrypted (HTTPS, encrypted connection to the database), data is encrypted at rest, passwords are stored as cryptographic hashes. Audio recordings reside in private storage with no direct access, relayed by the application after rights verification. The activity log is immutable. Secrets are kept in a vault and injected at runtime.

Cookies

The public website sets no cookies. The application sets a single session cookie, strictly necessary for authentication (7-day lifetime, Secure and SameSite attributes). No advertising or analytics tracker is used, either on the website or in the application — which is why no consent banner is displayed.

Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to set directives regarding the fate of your data after your death.

If you use the service within an organization (employer, educational institution), that organization is the data controller: address your request to it first; KEAJY assists it in responding. You can view your sessions, recordings, transcripts and analyses directly in the application, and change your name and password.

For any other request, write to privacy@bizzytrainer.ai, specifying the organization concerned and the right exercised. You may lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).