Last updated: 13 January 2026
Privacy policy
Protecting personal data and privacy is a priority for PEAS. This privacy policy describes how PEAS collects, processes, stores and protects personal data in connection with the use of its website, platform and services (the “Services”). It supplements the legal notice and contractual documents applicable to the Services. PEAS processes personal data in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and the amended French Data Protection Act.
1. Data controller
The data controller for processing carried out for its own purposes is: TODA PEAS, a French simplified joint-stock company (SAS), registered with the Paris Trade and Companies Register under number 977 506 211, registered office: 37 rue Meslay – 75003 Paris – France (hereinafter “PEAS”, “we”, “our”). Personal data contact: privacy@peas.studio
2. Role of PEAS – Controller / Processor
When you browse the website, or for sales, administrative and marketing management, PEAS acts as a data controller. When providing the Services to its business customers, PEAS processes personal data on behalf of its customers. In this context: • the Customer is the data controller, • PEAS acts as a data processor within the meaning of Article 4 of the GDPR. The Customer remains solely responsible for the lawfulness of the data it processes through the Services.
3. Personal data collected
3.1 Data collected directly PEAS may collect, in particular, identification data, professional data and browsing data. 3.2 Data processed through the Services When the Services are used, PEAS may process on behalf of the Customer: • data entered, imported or generated through the platform • content, instructions, prompts or workflows • usage logs and technical metadata The Customer undertakes not to process sensitive data (health data, banking data, government identifiers, etc.) unless expressly authorised by law.
4. Purposes and legal bases of processing
4.1 Performance of the contract • provision and operation of the Services • account creation and management • customer support and technical assistance 4.2 Legitimate interest of PEAS • improving and securing the Services • usage and performance analysis • prevention of abuse and fraud 4.3 Consent • marketing communications • use of non-essential cookies 4.4 Legal obligations • accounting and tax obligations • handling of data subject rights requests • responses to competent authorities
5. Artificial intelligence and third-party models
The PEAS Services rely on the use of third-party artificial intelligence models (LLMs). • PEAS does not train any artificial intelligence model on its Customers' data. • Submitted data is used solely to produce the results requested by the Customer. • No Customer data is reused by PEAS for model training purposes. The use of these third-party models is governed by the contractual terms and privacy policies of their respective providers. The Customer remains responsible for the lawfulness of the data transmitted, for informing the data subjects, and for compliance with the applicable regulations.
6. Data recipients
Personal data may be shared with: • hosting and infrastructure providers • billing and payment tools • CRM and customer support tools • analytics and security providers • AI technology and API providers These providers act as data processors and are subject to contractual data protection obligations. PEAS does not sell or rent any personal data.
7. Retention periods
• Account and Services data: contract duration + 3 years • Marketing data: 3 years after the last contact • Evidentiary data: applicable statutory limitation period • GDPR rights data: 3 years
8. Hosting and transfers outside the EU
Data is primarily hosted within the European Union. Where transfers outside the EU are necessary (in particular due to third-party providers or AI model providers), PEAS implements appropriate safeguards, notably European Commission adequacy decisions or standard contractual clauses.
9. Security
PEAS implements appropriate technical and organisational measures, including: • access control • encryption of data in transit • logging and monitoring • least-privilege principle In the event of a data breach, PEAS will notify the parties concerned in accordance with its legal obligations.
10. Rights of data subjects
In accordance with the GDPR, you have the following rights: • right of access • right to rectification • right to erasure • right to restriction • right to portability • right to object • right to withdraw consent • right to lodge a complaint with the CNIL Requests may be sent to: privacy@peas.studio Response time: 30 days.
11. Cookies
PEAS uses cookies necessary for the operation of the website, as well as analytics or marketing cookies subject to your consent. Preferences can be changed at any time via your browser settings or the cookie management tool.
12. Changes to this policy
PEAS reserves the right to modify this privacy policy at any time. Any substantial change will be subject to reasonable prior notice.
13. Contact
For any question relating to data protection: TODA PEAS – 37 rue Meslay – 75003 Paris – France privacy@peas.studio