Privacy policy

Last updated: June 2026

1. Data controller

Suleiman Mulla, sole proprietor (SIRET: 985 226 299 00040), publisher of the Phano platform (hereinafter "Phano", "we"), is the controller of the personal data collected through the platform (hereinafter "the Service").

Contact: privacy@phano.ai

Roles under GDPR: for website visitor and Service user data, Phano is the data controller. For your customer account data imported from your connected tools (contacts, exchanges, documents), your organization is the data controller and Phano acts as a data processor (Art. 28 GDPR). Data subjects concerned by that data exercise their rights with your organization; we relay any request we receive.

2. Data we collect

We collect the following categories of data:

  • Identification data: first name, last name, professional email address
  • Connection data: IP address, user-agent, login timestamps
  • Usage data: interactions with the Service, analyzed accounts, generated diagnostics
  • Calendar data: events from connected calendars (Google Calendar, Microsoft Outlook), metadata only (title, date, attendees)
  • CRM data: account and contact information synced from your CRM (HubSpot, Salesforce, Pipedrive, Attio, and Zoho CRM) with your explicit consent
  • Email data: metadata and a content preview of synced emails (sender, recipient, subject, date, excerpt) from Gmail or Outlook, with your explicit consent
  • Meeting data: when Meeting Intelligence is enabled, recording, transcription and summary of online meetings joined by the assistant (see section 7)

3. Purposes of processing

  • Providing the Service: customer account analysis, signal detection, diagnostic generation and delivery
  • Improving the Service: aggregated and anonymized usage analytics
  • Security: fraud detection, audit logs, rate limiting
  • Communication: transactional emails (confirmations, notifications, alerts)

4. Legal basis

  • Performance of the contract (Art. 6.1.b GDPR): processing necessary to provide the Service
  • Consent (Art. 6.1.a GDPR): connecting third-party calendars, email and CRM
  • Legitimate interest (Art. 6.1.f GDPR): security, fraud prevention, meeting recording (Meeting Intelligence), together with the right to object

5. Processing by artificial intelligence

The Service uses third-party artificial intelligence providers to analyze data and generate contextual content. Before any data is sent to an AI provider:

  • Identifying data (names, emails, phone numbers) is anonymized automatically before anything is sent to an AI provider.
  • Data is sent on a per-request basis and is never used to train models.
  • The AI providers we use are SOC 2 Type II compliant and offer contractual guarantees of data non-retention.

6. Use of Google data

The Service accesses the following Google APIs with your explicit consent:

  • Google Calendar API (read-only): to import your customer meetings and generate contextual briefs before each appointment
  • Gmail API (read and send): to sync your customer emails and allow sending emails from the Service
  • Google UserInfo: to identify your sign-in email address

Use: Google data is used exclusively to provide the Service features described above. It is never used for advertising or profiling purposes, nor sold to third parties.

Sharing: Google data is not shared with any third party, except for the subprocessors listed in section 9, strictly for the purpose of providing the Service.

Retention: when a calendar integration is disconnected, future meetings are automatically deleted. Past meetings and their associated data (briefs, summaries, notes) are kept as CRM business data. All calendar data is permanently deleted when your account is deleted. Email data is deleted 30 days after the corresponding integration is disconnected: this grace period lets a reconnection keep the history without a full resync.

Revocation: you can revoke Phano's access to your Google data at any time from the Settings > Integrations page of the Service, or from myaccount.google.com/permissions.

The use of data received through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

7. Meeting recording (Meeting Intelligence)

When you enable Meeting Intelligence, an assistant joins the online meeting to record it, transcribe it and produce a summary. This assistant is never deployed without your knowledge.

Consent announcement

On joining, the assistant announces in the meeting that it is being recorded and transcribed by an AI, and that any participant can object at any time. If someone objects, the assistant leaves the meeting.

Legal basis

Recording relies on legitimate interest (Art. 6.1.f GDPR), together with the right to object. Since an employee's consent is rarely valid due to the subordinate relationship, legitimate interest is the appropriate basis, in line with the EDPB 05/2020 guidelines on consent.

Retention periods

  • Recordings and transcripts: 183 days maximum (about 6 months), then purged from the database and deleted from the recording provider.
  • Summaries and diagnostics derived from the meeting: 365 days maximum (about 12 months).
  • Raw verbatim: 30 days, cleared as soon as a structured summary exists (minimization).

Your rights

Meeting data is included in your GDPR export (Art. 15 and 20) and in account deletion (Art. 17), which also erases the media kept at the recording provider.

8. Retention periods

  • Account data: duration of the contractual relationship + 3 years
  • Audit logs: 90 days (API) and 12 months (administration), purged automatically
  • Calendar data: future meetings deleted on disconnection; past meetings kept as business data (deleted when the account is closed)
  • Email data: deleted 30 days after the integration is disconnected (cancelled if you reconnect within that window)
  • CRM data: kept as business records for the life of the account (they carry your diagnostics and history), deleted when the account is closed
  • Meeting data (Meeting Intelligence): see the detailed periods in section 7
  • Technical caches: 30 days maximum

9. Subprocessors

SubprocessorPurposeLocation
Cloud hostDatabase, authenticationEU (Ireland)
Application hostHosting and CDNEU
AI providers (SOC 2 Type II)Analysis and content generationUS (DPA signed)
StripePaymentsUS (SCC)
Transactional email providerNotification emailsUS (SCC)
OAuth managerSecure connections to third-party servicesEU

10. Your rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15): get a copy of your data
  • Right to rectification (Art. 16): correct your data
  • Right to erasure (Art. 17): delete your account and all associated data
  • Right to restriction (Art. 18): suspend the use of your data while a request is being verified
  • Right to portability (Art. 20): export your data in JSON format
  • Right to object (Art. 21): object to processing based on legitimate interest

These rights can be exercised directly from your profile in the Service (Export my data, Delete my account) or by email at privacy@phano.ai. Response time: 30 days.

11. Security

  • Encryption in transit (TLS 1.3) and at rest (AES-256), third-party tokens encrypted server-side
  • Strict data isolation per organization (Row Level Security)
  • Connections through an OAuth manager, no stored passwords, mostly read-only
  • No alteration of your existing data: writes limited to dedicated fields and notes, data corrections validated by hand
  • Audit logs for every sensitive operation (12 months)
  • Multi-factor authentication (MFA) available
  • No measurement tag loaded without your consent, revocable at any time

12. Cookies

Strictly necessary cookies (no consent required):

  • Supabase session: authentication (strictly necessary)
  • OAuth state: CSRF protection during third-party connections (temporary)
  • Language preference: next-intl cookie
  • Consent choice: phano_consent cookie (6 months), stores your decision

Trackers subject to your consent (banner, no tag loaded before you agree):

  • Google audience measurement: Google Analytics 4
  • Advertising conversion measurement: Google Ads tag and first-party phano_gclid cookie (90 days), used to attribute sign-ups to ads

You can withdraw your consent at any time via the Cookies link in the footer. Refusing does not affect any feature of the Service.

Anonymous audience measurement exempt from consent (Art. 82 of the French Data Protection Act): on the public pages of the site, Phano measures traffic with PostHog, hosted in the EU, configured to produce anonymous statistics strictly on our behalf: page views only, no cookie (local storage), no identification, no cross-referencing or sharing with third parties, IP address not retained. You can object here:

13. Contact and complaints

For any question about the protection of your data: privacy@phano.ai

If a dispute remains unresolved, you can contact the French supervisory authority, the CNIL(Commission Nationale de l'Informatique et des Libertés):
www.cnil.fr/fr/plaintes