Last updated: July 20, 2026
<aside>
π«π·
Disponible ici
[pepline.ai β Politique de confidentialitΓ©](https://initventures.notion.site/pepline-ai-Politique-de-confidentialit-39f6ffe0e769806a97e7ec11d5118ad1)
</aside>
Pepline is an embeddable AI intake and qualification agent for service businesses. This policy explains what personal data we handle, why, and what your rights are. It is written to describe what the product actually does β not generic boilerplate.
Who we are. Pepline is operated by INIT VENTURES, a French SARL, 4 rue d'Angoumois, 44000 Nantes, France, RCS Nantes 999 592 793 ("Pepline", "we"). Contact for anything privacy-related: [email protected].
1. Our two roles: controller and processor
Pepline handles personal data in two distinct capacities:
- Data controller for the data of our customers β the businesses that create a Pepline account ("owners"). Sections 2a, and the owner-related parts of this policy, describe that processing.
- Data processor for the data of visitors β the people who chat with an agent embedded on a customer's website ("visitors" or "leads"). That data is collected for and on behalf of the customer, who is the data controller. The customer decides why the widget is on their site and is responsible for the lawful basis of that collection; we process visitor data only to provide the service to them.
If you chatted with a Pepline-powered agent on a business's website, that business is the controller of your data. You can exercise your rights either with them or directly with us (Section 7) β we assist either way.
2. What data we collect
2a. Customer (owner) account data β Pepline as controller
- Identity and authentication: email address, name (optional), password (stored only as a bcrypt hash β never in plaintext), language preference, timestamp of terms acceptance, email verification status.
- Organization data: organization name, sending identities for outbound email (display name, reply-to, copy-to address, signature), billing-related fields.
- Access data: roles and per-agent access grants; API keys (stored as SHA-256 digests; the plaintext key is shown once and never stored).
- Support access log: if our staff accesses your account for support, the access is recorded permanently (who, when, and the stated reason) β see Section 8.
2b. Visitor (lead) data β Pepline as processor for the customer
When a visitor chats with a customer's agent (via the embedded widget or a hosted chat page), we process:
- The full conversation transcript β every visitor and agent message, verbatim.
- Extracted lead details β the agent turns the conversation into structured fields: email address (collected conversationally, with consent, when the visitor agrees to receive their brief), name, company, budget range, timeline, decision role, and free-text project details.
- Fit assessment β an AI-generated evaluation of how well the project matches the criteria the business configured (fit / partial / no fit, with a written rationale). This produces a score for the business owner to review; the owner can correct it. It does not produce any automated legal decision about the visitor β a human at the business decides what to do with the lead.