Legal
Privacy Policy
What we collect, why, on what legal basis, who it goes to, how long we keep it, and what you can require of us. Written to be checked against Article 13 rather than skimmed.
Last updated 27 August 2026
1.Who we are
FillTrust provides software that drafts answers to security questionnaires from documents its customers upload. This policy explains what we do with personal data and applies to our website and to the product.
For data about our own users and visitors we are the controller. For the documents and questionnaires a customer uploads we act as a processor on that customer's instructions; the terms of that processing are in our Data Processing Agreement, which applies automatically and does not need to be requested or signed separately.
Contact for anything in this policy: privacy@filltrust.com. We are established in France and answer every message. Postal address: 1 rue Marguerin, 75014 Paris, France.
2.What we collect
Four categories, and nothing beyond them.
Account data. Your name, work email address, company name if you give one, a hashed password, and, if you enable two-factor authentication, an encrypted TOTP secret. You give us these directly.
Customer content. The documents you upload to your knowledge base and the questionnaires you upload to be answered, together with the answers produced from them and every revision to those answers. This may contain personal data if your documents do; we handle it as a processor under the DPA.
Usage and diagnostic data. Server logs, error reports, and records of actions taken in the product (who changed an answer, and when). The audit trail is a product feature: it is what lets you answer “who approved this?” about your own questionnaires.
Where you came from. When you create an account we record the page you were on immediately before signing up. For our own pages we keep the path; for anywhere else, the site’s name and nothing more. It is read from the referrer your browser already sends with the request, so we store nothing on your device to obtain it, there is no cookie and no identifier, we never keep the query string, and it is deleted with your account.
3.Why we process it, and on what basis
Each purpose has one legal basis under Article 6 of the UK and EU GDPR.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the service you signed up for | Account data, customer content | Performance of a contract |
| Authenticating you and protecting accounts | Account data, usage data | Performance of a contract; legitimate interests in securing the service |
| Billing and tax records | Account data, payment metadata | Performance of a contract; legal obligation |
| Service email: verification, password reset, review requests | Account data | Performance of a contract |
| Keeping the service working and diagnosing faults | Usage and diagnostic data | Legitimate interests in operating a reliable service |
| Understanding which pages lead people to sign up | Where you came from | Legitimate interests in knowing what to write next |
Where we rely on legitimate interests we have considered whether that interest is overridden by your rights. You can object to any of it; see your rights below.
We do not sell personal data, we do not share it for advertising, and we do not use customer content to train models. That last point is contractual as well as a statement of intent: see AI providers.
4.AI providers and model training
Answering a questionnaire means sending the question text and the specific excerpts retrieved from your documents to a model provider. We send the excerpts used to answer, not whole documents, and we do not send your account data.
We call Google and OpenAI through their standard business APIs, whose terms exclude API content from training their models. To be precise about what that does and does not mean: it is a contractual commitment not to train on your content, and providers may still retain it briefly for abuse monitoring under their own published policies. We do not hold a zero-retention agreement with either provider, and we would rather say so than imply a guarantee we have not bought.
No decision with a legal or similarly significant effect is made about you by automated means. The product drafts text for a person to review; it does not decide anything about anybody.
6.Where data is held, and international transfers
Documents are stored in Google Cloud in Paris and the database is hosted in Frankfurt, both of them in the EU.
Question text and the specific excerpts used to answer are sent to AI providers in the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, which are annexed to our Data Processing Agreement along with the transfer impact information a reviewer usually asks for.
7.How long we keep it
| Data | Kept |
|---|---|
| Account data | While the account is open, then deleted on closure |
| Customer content | While the account is open, or until you delete it, whichever is sooner |
| Answer revision history | With the questionnaire it belongs to; deleted with the account |
| Server and error logs | Rolling window, then discarded |
| Billing and tax records | As long as tax law requires, independently of account closure |
Deleting your account cancels billing, removes every uploaded document and generated questionnaire from storage, and deletes your records. If any part of that cannot be completed the deletion is aborted and reported rather than partially applied, because a deletion that reports success without finishing is worse than an error.
8.Your rights
Under the UK and EU GDPR you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent where processing relies on it.
Account deletion in your settings exercises erasure directly and immediately. For anything else, write to privacy@filltrust.com. We respond within one month, and we do not charge for it.
If you are an end user whose data appears inside a customer's documents, that customer is the controller and we act on their instructions. Send your request to them; if it reaches us first we will pass it on and tell you we have.
You also have the right to complain to a supervisory authority. In France that is the CNIL. We would rather you told us first, but that is your right and not conditional on it.
10.How it is protected
Encryption in transit and at rest, tenant isolation derived server-side from your session, rate-limited authentication with optional two-factor, least-privilege service accounts, an append-only audit trail, and versioned storage. The full description is on our security page and the contractual version is Annex II of the DPA.
If you believe you have found a vulnerability, write to security@filltrust.com. We will acknowledge it and tell you what we are doing about it.
11.Children
The service is sold to businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, write to privacy@filltrust.com and we will delete it.
12.Changes to this policy
We update this policy when what we do changes. The date at the top moves only when the substance does, not on every deploy, so that a version you compared against still means something. For a change that materially reduces your rights we give notice by email to account holders before it takes effect.
See also our Terms of Service, Data Processing Agreement, sub-processor list and security overview.