Privacy policy (version of September 9, 2026)
Due to the nature of its activity, Dixit Platform SAS and its team are particularly committed to complying with current laws and regulations related to the protection and security of personal data.

Dixit Platform SAS. Version 1.0, effective 9 September 2026. Replaces the undated page that preceded it.
This policy describes the personal data Dixit Platform processes, in which capacity, with whom, for how long, and how to exercise your rights. It covers the website, the platform, its application programming interface and its MCP connector.
Three documents complete it: the information page established under article 14 of the GDPR, addressed to the people whose public data we process, published in French; the cookies and trackers policy, provided on request; and, for our clients, the data processing agreement annexed to our general terms and conditions of sale.
1. Who is responsible
Dixit Platform SAS, a simplified joint-stock company with a share capital of 14,000 euros, registered with the Nanterre trade and companies register under number 882 900 590, registered office at 146 boulevard Voltaire, 92600 Asnières-sur-Seine, France.
Contact point for any question or request relating to personal data: dpo@dixitplatform.com. Dixit Platform is not required to appoint a data protection officer within the meaning of article 37 of the GDPR; the contact point function is held internally by the Managing Director.
2. Our two capacities, and why the distinction matters
Dixit Platform acts in two distinct capacities, and your rights are exercised differently in each.
As controller, for the processing of public data relating to the institutional activity of public office holders and interest representatives, which is the substance of the service, and for the management of our own commercial relationships.
As processor, for the account and usage data of our clients' users, for the monitoring parameters they configure and for the profile each user fills in. In that case the controller is the client organisation that subscribed: we process those data on its instructions, under the data processing agreement concluded with it, and a request to exercise rights over those data is passed on to it.
3. The data we process
3.1 Public institutional data
Public identity and mandates, political or organisational affiliations made public, public professional contact details, institutional output (speeches in session, amendments, bills, parliamentary questions, reports, votes), transcripts of public debates with attribution to the speaker, social media posts from official accounts in the course of political or interest representation activity, public declarations filed with transparency registers.
No private-life data that has not been made public is processed. The sources, the legal bases, the categories of data subjects and the applicable retention periods are detailed in the information page under article 14.
3.2 Account and usage data of platform users
Identity and professional contact details: last name, first name, professional email address, job title, organisation, role and permissions, and where applicable a telephone number.
Usage data: date and time of connection, IP address, user agent, authentication events, product usage events.
Monitoring parameters defined by the client: topics, keywords, legislative files followed, alert settings and saved searches. These parameters may name natural persons.
User profile: free text in which the user describes their function and their stakes, so that the summaries and alerts sent to them are personalised.
The platform has no feature allowing you to upload your documents, your files or your audio recordings. The only personal data we process on behalf of a client are those listed above.
3.3 Queries and calls
Searches run in the platform, calls made to the application programming interface and calls received by the MCP connector are logged with the user identifier, the timestamp and the content of the query, for the purposes of security, detection of abnormal use, support and, where applicable, billing.
The content of a query reveals what a public affairs team is looking for. We treat it as confidential information of the client: article 8.2 of our general terms and conditions of sale prohibits us, and our employees, from using or disclosing the substance of those data, save where required by law or by a judicial order.
3.4 Prospects and commercial contacts
Professional contact details, organisation, job title, exchanges and relationship history. An objection to commercial prospecting is a right, requires no justification, under article 21.2 of the GDPR, and brings any solicitation to an immediate stop. Subscription to our newsletter rests on consent, with confirmation by email.
4. Legal bases
Processing of public institutional data: Legitimate interests, article 6.1.f, with a written balancing test; public interest task, article 6.1.e, for the purposes of informing about political life
Public data of interest representatives: Legal obligation, article 6.1.c, combined with legitimate interests, article 6.1.f
Transcription of public debates and attribution to the speaker: Data manifestly made public by the data subject, article 9.2.e, with sources strictly limited to official public portals
Accounts, usage, monitoring parameters and user profile: Performance of the contract concluded with the client organisation, article 6.1.b
Logging and security: Legitimate interests, article 6.1.f, security of the information system and compliance with article 32 of the GDPR
Commercial prospecting: Legitimate interests, article 6.1.f, with the right to object under article 21.2
Newsletter: Consent, article 6.1.a
5. Authentication and access
Authentication relies on a self-hosted Keycloak instance in the European Union, in the Google Cloud europe-west1 region (Saint-Ghislain, Belgium). Accounts are personal to each user; no shared account is allowed. The minimum password length is twelve characters with enforced complexity. Multi-factor authentication is mandatory on all our critical tools and on any access to production. SSO through Google and Microsoft is supported.
Every account is personal and sharing it is prohibited. Any use made with a user's credentials is deemed to be made by the client organisation to which that user belongs.
6. The MCP connector
The MCP connector lets a user query the platform from their organisation's conversational assistant, following the Model Context Protocol. It is exposed at https://mcp.dixitplatform.com/mcp.
How access is established. The user authorises the assistant from their own Dixit account, through a delegated authorisation with our identity provider, with the same credentials and the same permissions as web access. There is no shared key. The two accounts are matched on the email address: the connection is only possible if the address of the user's account with the assistant's provider is the address of their Dixit account. A different address prevents the match and access is refused. The authorisation can be revoked at any time, by the user from their assistant and by us.
The connector is read-only. None of its tools writes, modifies or deletes any data on the platform, and none allows a document to be uploaded to it.
What the connector returns. The queryable scope is strictly that of the client organisation's subscription. Two sets of data come out, and they do not have the same status.
First, public institutional data: public figures we track (elected representatives, government members, senior civil servants), interest representatives listed on transparency registers, bodies and institutions, legislative procedures and initiatives, documents, amendments, published legal acts, parliamentary questions, meetings and agendas, speeches and minutes with attribution to the speaker, contributions to public consultations, institutional communications, declared interest representation activities, and posts from the official social accounts of the people we track.
Second, data from the user's account: their alerts and their configuration, the keywords and monitoring scopes defined by their organisation, their saved searches, and the items their alerts have delivered. Those data belong to the client organisation.
Who answers for what. The user chooses the assistant and triggers every call. The conversational assistant is supplied by a third-party provider with which the client organisation has its own contract and its own data processing agreement: that provider acts on behalf of the client organisation and is not our processor. What is routed to the assistant is processed there under the terms of that contract, including as regards the location of processing and the training of models. We answer neither for the content produced by the assistant from the data returned, nor for the rephrasing, summaries or inferences it performs.
Logging. Connector calls are logged under the same conditions as other access to the platform, for the periods set out in section 8.
7. Artificial intelligence
Some of the platform's analysis features rely on language models, to which the free-text user profile and the monitoring parameters defined by the client are sent, in order to personalise summaries, analyses and alert emails.
Two providers are actually called: OpenAI, whose processing takes place in the United States, and Google Gemini, called exclusively through Vertex AI in the europe-west1 region, therefore within the European Union.
We have obtained from each of them a contractual commitment not to train on our clients' data. We also undertake not to use our clients' data to train, retrain, fine-tune or improve any model, whether developed by us or by a provider, save with the specific, prior written agreement of the client concerned.
8. Retention periods
Public institutional data: the retention period is aligned on the availability of the official public sources. As long as the public source keeps the data, we keep it. As soon as the source withdraws it, we withdraw it within ninety days at most of the unavailability being confirmed. Monitoring of a person's social accounts stops immediately when their term of office ends. The breakdown by category is set out in the information page under article 14.
Account and usage data: for the duration of the client organisation's contract. At its end, the client states within thirty days whether it requests the return or the deletion of the data; failing any indication, we delete. Deletion from active systems takes place within thirty days.
Logs: twelve months at most for detailed authentication logs, three months at most for usage and navigation logs, including the content of queries and of connector calls, seven days for infrastructure logs.
Backups: seven days for daily database backups, up to three months for the offline snapshot. During that period the data are excluded from any active processing and kept solely for restoration in the event of an incident.
Prospects and commercial contacts: three years from the last contact.
9. Hosting, processors and transfers
The platform is operated exclusively within the European Union, on Google Cloud, europe-west1 region (Saint-Ghislain, Belgium). No principal storage of client data is located outside the European Union.
Seven processors handle our clients' data. Five process within the European Union: the hosting provider, the European language model provider, application error monitoring, technical logging and product usage analytics. Two process outside the European Union: the American language model provider and the transactional email delivery service.
Those transfers only take place on the basis of an adequacy decision of the European Commission, the standard contractual clauses adopted on 4 June 2021, or another instrument recognised under chapter V of the GDPR, together with supplementary measures: encryption in transit and at rest, restriction of the data transmitted, pseudonymisation where the purpose can be achieved that way, and a contractual no-training commitment from the model providers.
The list of processors by name, with the country of processing and the basis of the transfer for each, is provided on request at dpo@dixitplatform.com. Our clients receive it as an annex to the data processing agreement, and any change is notified to them thirty days before it takes effect.
10. Security
Encryption in transit through HTTPS with TLS 1.2 as a minimum, encryption at rest with AES-256 on the database and on object storage, full disk encryption on every workstation. Application-level segregation by client organisation. Strict separation of environments, with copies of production data outside production prohibited. Access to production restricted to expressly authorised individuals, through an encrypted tunnel, with a monthly review of rights. Logging of sensitive operations with automatic alerts on unusual connections, mass exports and repeated authentication attempts. Daily backups and a documented restoration test at least once a year.
In the event of a data breach affecting a client's data, we notify that client within twenty-four hours of the incident being qualified, and we notify the supervisory authority within seventy-two hours where that obligation falls on us.
11. Your rights
In accordance with articles 15 to 22 of the GDPR, you have a right of access, rectification, erasure, restriction, portability and objection, as well as the right not to be subject to an automated decision. Dixit Platform carries out no automated individual decision-making within the meaning of article 22.
How to exercise your rights. Write to dpo@dixitplatform.com. Your request is handled within one month of receipt, extendable by two months for a complex request, in which case you would be informed within the initial month.
Two cases differ. If your request concerns public data that we process, we handle it directly, following the terms detailed in the information page under article 14. If it concerns your user account or your use of the platform, the controller is your organisation: we pass the request on to its contact point and we assist it in handling the request.
If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
12. Cookies and trackers
The website and the platform place cookies necessary for their operation and for authentication, as well as product usage measurement cookies. The cookies and trackers policy, which details every tracker, its purpose and its lifetime, is provided on request at dpo@dixitplatform.com. Cookies that are not necessary for operation can be blocked from the browser settings, and any request concerning trackers can be sent to dpo@dixitplatform.com. The regime applicable to trackers is set out in article 7 of our general terms of use.
13. Changes to this policy
We update this policy whenever a significant change to our processing activities warrants it, and we review it at least once a year. The effective date appears at the top of the page. Any substantial change is brought to our clients' attention through the means provided for in the contract.
*Version in force since September 9, 2026. Every published version is archived at a permanent address, listed on the Legal documents page.*