Data Protection

GDPR Compliance

Mnemetic is built with privacy at its core. We are fully compliant with the General Data Protection Regulation (GDPR) and committed to protecting your data.

Our GDPR Commitments

EU Data Residency

Your data is stored and processed exclusively within the European Union.

Privacy by Design

Data protection is built into our architecture from the ground up.

Data Minimization

We only collect data that is necessary for providing our services.

Transparent Processing

We are clear about how and why we process your personal data.

Your Rights Under GDPR

The General Data Protection Regulation grants you comprehensive rights over your personal data. Here's how to exercise them with Mnemetic:

Right of Access

Request a copy of all personal data we hold about you.

Download from Settings or contact us

Right to Rectification

Request correction of any inaccurate personal data.

Update in Settings or contact us

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Delete account in Settings or contact us

Right to Restrict Processing

Request that we limit how we process your data.

Contact us directly

Right to Data Portability

Receive your data in a structured, machine-readable format.

Export from Settings

Right to Object

Object to processing based on legitimate interests.

Contact us directly

Data Processing Activities

As Data Controller

For account information, billing data, and usage analytics, Quaintyx SAS (operating under the trade name Mnemetic) acts as the data controller. We determine the purposes and means of processing this data.

As Data Processor

For the data you upload and process through our platform (your documents, conversations, and business data), Quaintyx SAS (operating under the trade name Mnemetic) acts as a data processor. You remain the data controller and we process this data only according to your instructions.

Data Processing Agreement (DPA)

Enterprise customers can request a Data Processing Agreement that documents our commitments as a data processor. Contact us at support@mnemetic.ai

Security Measures

We implement comprehensive technical and organizational measures to protect your data:

  • Encryption: HTTPS in transit. Provider keys, OAuth tokens and connector credentials are encrypted in the database. Document and conversation content is not encrypted at application level today.
  • Access Control: Role-based access, multi-factor authentication, audit logs
  • Infrastructure: Self-hosted in France. We hold no ISO 27001 and no SOC 2 certification, and we do not claim to.
  • Testing: A blocking security test suite gates every deployment. No external penetration test has been conducted to date.
  • Incident Response: 72-hour breach notification commitment
  • Training: Regular GDPR and security training for all employees

Sub-Processors

We use a limited number of sub-processors, all located in the EU or with adequate safeguards:

ProviderPurposeLocation
Quaintyx SASSelf-hosted infrastructure, storage and searchFrance (EU)
Cloudflare, Inc.CDN, TLS termination and traffic protectionUnited States
OpenRouter, Inc.Model gateway used by the default configurationUnited States
StripePayment ProcessingIreland (EU)
BrevoTransactional EmailFrance (EU)
AI Providers*AI Model InferenceUser-selected

*AI providers (OpenAI, Anthropic, Mistral, etc.) are only used when you explicitly choose them. You can opt for EU-only providers like Mistral.

International Transfers

Your documents, their search vectors and your file storage remain on our European infrastructure. Generating an answer, however, calls a model provider, and the default configuration routes through a provider established outside the European Union. You can change that provider, or register your own key. When you use a provider outside the EU (e.g. OpenAI, Anthropic), the following safeguards apply:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Additional technical measures to protect data in transit
  • Clear disclosure before any data is sent outside the EU
  • Option to use EU-only providers (Mistral AI)

Data Retention

We retain personal data only as long as necessary:

  • Account Data: Duration of account plus 2 years
  • Billing Data: 7 years (legal requirement)
  • Your Uploaded Data: Until you delete it or close your account
  • Backups: Encrypted backups retained for 30 days
  • Logs: Security logs retained for 12 months

Exercising Your Rights

To exercise any of your GDPR rights, you can:

  • Use the self-service options in your account Settings
  • Email us at support@mnemetic.ai
  • Contact your local Data Protection Authority

We will respond to all requests within 30 days as required by GDPR. For complex requests, we may extend this by an additional 60 days with prior notice.

Contact Our Data Protection Team

Data Protection Contact

Quaintyx SAS (operating under the trade name Mnemetic)

Paris, France

Email: support@mnemetic.ai

For urgent data protection matters, please include "GDPR" in your email subject line.