1. Data controller
This policy describes how betool ("we") processes personal data through the betool platform and the betool.ai website.
For any data-protection question, or to exercise your rights: privacy@betool.fr.
2. Roles: controller and processor
For data of our own users (accounts, billing, browsing), we act as data controller.
For data you import or process through your pipelines and integrations, we act as data processor, on your behalf and on your instructions.
3. Data we process
Account data: name, work email address, organization, technical identifiers. Usage data: logs, consumption metrics (credits), security and audit data.
Content: the files, messages and data you import or generate, including data from the services you connect. We access this Content only to provide the Service.
4. Data from Google services
When you connect a Google account, betool accesses only the data matching the authorizations (scopes) you grant, and solely to perform the functions you configure in your pipelines. The requested scopes and their purpose are:
Google Ads (advertising campaign management): reading performance and creating, modifying or pausing campaigns and bids, in order to run your advertising actions.
Google Calendar: reading, creating, moving and deleting events across one or more calendars, in order to manage appointments.
Google Analytics (read-only): reading traffic data, for reporting and optimization purposes.
Google Sheets: reading and writing spreadsheets, both as source and destination, in order to read data and produce reports.
Google Drive: reading, importing and creating files (for example downloading a file you select, or publishing a generated report), limited to the files needed for the function you configure.
Google Search Console (read-only): reading your sites' search performance data (clicks, impressions, average position) for SEO reporting.
Google Business Profile: reading and managing your business information — viewing reviews and rating, replying to reviews, publishing posts — to manage your local presence and reputation.
For each scope, the data is used only for the purpose you defined, never beyond it. You can revoke access at any time from betool or from your Google account (myaccount.google.com/permissions); the associated functional data is then deleted in accordance with the "Retention and deletion" section.
5. "Limited Use" commitment (Google API Services User Data Policy)
betool's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: this data is not sold, not used for advertising, and not used to train generalized AI models. Human access to this data is prohibited except: with your explicit consent, for security purposes (investigating abuse), to comply with a legal obligation, or where the data is aggregated and anonymized.
6. Other connected services
Depending on the integrations you enable (for example Stripe, Slack, Jira, GitHub, LinkedIn, Meta, telephony/SMS carriers, banking aggregators), betool processes only the data strictly necessary for the configured function, based on the authorizations you grant.
The same principle applies to future integrations: access limited to the authorized scope, use limited to the configured purpose, no resale, no advertising use, no training of generalized models.
7. Purposes and legal bases
Provision and operation of the Service (performance of the contract); security, abuse prevention and audit (legitimate interest); billing (legal obligation and contract); service-related communications (legitimate interest / consent where applicable).
We do not carry out any solely automated decision producing legal effects without an appropriate legal basis and without oversight.
8. Sharing and sub-processors
We do not sell your data. We use sub-processors for hosting and operating the Service (notably EU-based cloud infrastructure providers, a payment provider for billing, and, depending on your configuration, the AI model providers you designate in BYOK mode).
These sub-processors are bound by contractual confidentiality and security commitments. A detailed list is available on request.
9. International transfers
We favor hosting within the European Union. Where a transfer outside the EU is necessary, it is covered by appropriate safeguards (standard contractual clauses or an equivalent mechanism).
10. Retention and deletion
Data is retained for as long as necessary for the described purposes, then deleted or anonymized. Data from a closed account is deleted within a reasonable period, subject to legal retention obligations (e.g. accounting).
You can request deletion of your data, including data from connected services, by writing to privacy@betool.fr or by revoking the relevant integration.
11. Security
We implement technical and organizational measures: strict multi-tenant isolation, encryption in transit, access control, logging and audit. As no system is infallible, we encourage you to enable the controls available at the organization level.
12. Your rights
Under the GDPR, you have rights of access, rectification, erasure, restriction, objection and portability. You can exercise them at privacy@betool.fr.
Where we act as processor, we relay your requests to the controller (your organization). You may lodge a complaint with the competent supervisory authority (in France, the CNIL).
14. Minors
The Service is not intended for minors and does not knowingly collect data about them.
15. Changes
We may update this policy to reflect legal or functional changes. Material changes will be flagged and the update date above will be revised.
16. Contact
Questions or to exercise your rights: privacy@betool.fr. Operator information: see the Legal notice (/legal).