Mazlo SAS
Privacy Policy
The short version
- Who you are to us. Customers are businesses. For the account itself, Mazlo SAS is the controller. For traveller data you put in an API call, you are the controller and we process it to route the call.
- What the account is. An email address, the company name given for a new account, the name an identity provider returns, the API key record, and the session that keeps you signed in. Sign-in is passwordless: GitHub, Google, or a one-time email code.
- Calls. The request you send is forwarded to the supplier you selected. We do not sell it, and we do not use it to train models.
- No advertising stack. We do not run analytics, advertising, or session-replay scripts. The cookie that keeps you signed in is strictly necessary.
- Payments. Card payments are not available today. When they are enabled, Stripe processes the card. We do not store the card number.
This summary is for orientation only. The sections below are the policy.
01 Who this covers
This policy explains how Mazlo SAS ("we", "us") handles personal data in the hosted Ancilair service at ancilair.com. Mazlo SAS is a French société par actions simplifiée, SIREN 930 227 665, registered office at 82 rue Pierre Lalumière, 33320 Eysines, France. The full statutory notices, including the host, are on the legal notices.
Two roles sit side by side:
- Controller. For account data, sign-in, API key records, session and security logs, and (when billing exists) the prepaid balance, Mazlo SAS decides the purposes and is the controller.
- Processor. For personal data you include in an API request, such as a traveller's name or a trip, you (or your own customer) decide the purpose. We process that payload only to perform the call and to keep the usage record described below. You must have a lawful basis for sending it. These processor clauses are the terms on which we process that data. There is no separate data-processing addendum.
The controller contact for privacy questions is [email protected]. Data requests, including access, correction, and account deletion, go to [email protected].
Mazlo SAS has not designated a data protection officer. An appointment is not required at our size. Privacy requests go to [email protected].
02 The data we hold
We hold what the product actually stores, and we forward what a call has to forward. We do not ask for a phone number, a postal address, a date of birth, or a payment card.
Account and identity
- Your email address. It signs you in, receives the one-time code, and identifies the account.
- The company name you give when a new account is opened, and the time you confirmed you were signing up on behalf of a business.
- When you use GitHub or Google: the provider's account identifier, the email they return, and the name they return. Google's sign-in scope is openid, email, and profile. GitHub's scope is user:email. A profile image may be included in what the provider sends. We do not store the image.
- We do not store a separate team roster. The account is the business workspace. If we add teammates later, we will update this policy before we store a list of them.
API keys
The database stores which account a key belongs to, and whether it has been revoked. The secret is a signed value the application can show again. It is not written to the application log. Anyone holding the secret can call as the account, so treat a leak as a security event.
Supplier keys
A supplier key you already pay for is, by design, used only for your calls and is never metered. This version does not store one. The connections page has nowhere to add one. When that changes, the key will be stored only to make the calls you ask for, and this policy will be updated before the first key is saved.
Usage and call logs
An API call log records the call id, the supplier, cache state, the settled cost, and a link to a stored result where a result is kept. The request you send, which may contain personal data about a traveller, is forwarded to the supplier selected for that call. We do not sell that payload. API call logs are kept for 12 months.
Sign-in codes
For email sign-in we store the address, a digest of the code, when it expires, and whether it has been used. We do not store the code itself. A code expires after 15 minutes and works once. Production logs do not include the code. The email that carries the code is sent through Postmark, so Postmark sees the address and the message.
Technical and session data
- A session record stores the IP address and user agent of the browser that signed in, and the time.
- The host and Cloudflare process connection data (IP address, user agent, the request line, and the time) as traffic is served. We do not build an advertising profile from it.
03 Why we are allowed to hold it
| Data | Purpose | Basis (GDPR Art. 6) |
|---|---|---|
| Email, company name, name, identity-provider identifier | Provide the account and sign you in | Contract (Art. 6(1)(b)) |
| API key record | Authenticate calls your account makes | Contract |
| Sign-in codes | Prove control of the inbox | Contract |
| Call payload you submit | Perform the call you asked for, on your instructions | Contract, and our processor instructions from you |
| Usage record of a call | Show what was called, settle a price when billing exists, and investigate abuse | Contract, and legitimate interests (Art. 6(1)(f)) in keeping the service secure |
| IP address, user agent, host logs | Security, abuse prevention, and operating the service | Legitimate interests |
| Prepaid balance and invoices, when billing exists | Take prepayment, refund unused balance, and keep accounting records | Contract, and legal obligation for records we must keep |
Legitimate interests are limited to running a secure B2B API. They are not used for advertising. You can object to processing based on legitimate interests, as described in section 10.
04 What we never do
- We do not sell personal data, supplier keys, or the contents of a call.
- We do not use account data, call contents, or supplier keys to train machine learning models, ours or anyone else's.
- We do not run analytics, advertising, or session-replay scripts on the marketing site or in the signed-in app. Fonts are files we serve ourselves. There is no third-party analytics tag.
- We do not use a supplier key, once we store one, for anything other than the call you initiated and a check that the key still works.
- We do not take payment data today. No card number is stored.
05 Sign-in with GitHub and Google
GitHub and Google are used only to sign you in. We receive the identity they return for that purpose: an account identifier, an email address, and a name. We do not request YouTube, Gmail, Google Drive, or any other Google API, and we do not post to GitHub or read your repositories.
Each of those companies is an independent controller of the sign-in that happens on its own site. Their handling of your account is described in their own privacy policies. You can stop using a provider by signing in with email instead, and you can revoke Ancilair's access from the provider's own security settings. Revoking it there stops further sign-in with that provider. It does not by itself delete the Ancilair account. Ask us to delete the account if that is what you want.
We do not use Google user data for advertising, and we do not use it to train generalized models. The only humans who would read it are people acting for Mazlo SAS on a support request you asked for, on a security incident, or where the law requires it.
08 How we protect it
- Traffic is served over HTTPS, with the site proxied by Cloudflare.
- The session cookie is HTTP-only. The API key secret is not written to the application log. Sign-in codes are stored as a digest, and production mail logs omit the code.
- OAuth sign-in checks the state value before accepting the callback.
- Database access is limited to the application on the hosted server.
No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify affected customers and, where the GDPR requires it, the CNIL, without undue delay.
09 How long we keep it
| Data | Retention |
|---|---|
| Account, identity, API key record | Until you delete the account, or until you revoke the key for the key record |
| Sign-in codes | Until they expire (15 minutes) and are no longer needed to reject a replay. They are single use. |
| Session record (IP address, user agent) | Until you sign out or the session is destroyed |
| API call logs | 12 months |
| Infrastructure and CDN logs (Cloudflare, Infomaniak) | The provider's default period, and up to 30 days where we control the retention |
| Backups | 30 days |
| Accounting records, once billing exists | As long as French accounting law requires us to keep them |
To delete the account, email [email protected]. We process the request within 30 days. Deletion removes the live account, identity, sessions, sign-in codes, and API key records. A backup copy can remain until the 30-day backup window ends.
10 Your rights
If the GDPR applies to you, you can ask us to access, correct, erase, or export the personal data we control, to restrict processing, and to object to processing based on legitimate interests. You can also ask us to send you a copy in a portable form where the basis is contract. We will respond within one month. We do not charge for a reasonable request, and we will not treat you differently for asking.
Where we process call data as your processor, your request about a traveller should go to the controller first, which is you. We will help you answer it, as a processor must.
You can revoke an API key and sign out yourself. Access, correction, and deletion requests go to [email protected]. We respond within one month, and we delete an account within 30 days of that request.
You can lodge a complaint with a supervisory authority. Ours is the Commission nationale de l'informatique et des libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France. You may also complain to the authority of the EU or EEA country where you live or work.
We honour access, correction, and deletion requests from people outside the EEA as well. We do not sell personal information.
11 Children
The Service is for businesses. It is not directed at anyone under 16, and we do not knowingly create an account for a child. If you believe a child has an account, email [email protected] and we will delete it.
12 Changes to this policy
We will update this page when our practices change, and the "last updated" date will change with it. For a material change, such as a new category of data, a new recipient, or a new purpose, we will notify account holders by email or an in-app notice before the change takes effect.
13 Contact
Controller and general privacy questions: [email protected].
Data requests and account deletion: [email protected].
Security vulnerabilities: [email protected].
See also the Terms of Service.