Mazlo SAS

Privacy Policy

Effective October 8, 2026

The short version

This summary is for orientation only. The sections below are the policy.

01 Who this covers

This policy explains how Mazlo SAS ("we", "us") handles personal data in the hosted Ancilair service at ancilair.com. Mazlo SAS is a French société par actions simplifiée, SIREN 930 227 665, registered office at 82 rue Pierre Lalumière, 33320 Eysines, France. The full statutory notices, including the host, are on the legal notices.

Two roles sit side by side:

The controller contact for privacy questions is [email protected]. Data requests, including access, correction, and account deletion, go to [email protected].

Mazlo SAS has not designated a data protection officer. An appointment is not required at our size. Privacy requests go to [email protected].

02 The data we hold

We hold what the product actually stores, and we forward what a call has to forward. We do not ask for a phone number, a postal address, a date of birth, or a payment card.

Account and identity

API keys

The database stores which account a key belongs to, and whether it has been revoked. The secret is a signed value the application can show again. It is not written to the application log. Anyone holding the secret can call as the account, so treat a leak as a security event.

Supplier keys

A supplier key you already pay for is, by design, used only for your calls and is never metered. This version does not store one. The connections page has nowhere to add one. When that changes, the key will be stored only to make the calls you ask for, and this policy will be updated before the first key is saved.

Usage and call logs

An API call log records the call id, the supplier, cache state, the settled cost, and a link to a stored result where a result is kept. The request you send, which may contain personal data about a traveller, is forwarded to the supplier selected for that call. We do not sell that payload. API call logs are kept for 12 months.

Sign-in codes

For email sign-in we store the address, a digest of the code, when it expires, and whether it has been used. We do not store the code itself. A code expires after 15 minutes and works once. Production logs do not include the code. The email that carries the code is sent through Postmark, so Postmark sees the address and the message.

Technical and session data

03 Why we are allowed to hold it

Data Purpose Basis (GDPR Art. 6)
Email, company name, name, identity-provider identifier Provide the account and sign you in Contract (Art. 6(1)(b))
API key record Authenticate calls your account makes Contract
Sign-in codes Prove control of the inbox Contract
Call payload you submit Perform the call you asked for, on your instructions Contract, and our processor instructions from you
Usage record of a call Show what was called, settle a price when billing exists, and investigate abuse Contract, and legitimate interests (Art. 6(1)(f)) in keeping the service secure
IP address, user agent, host logs Security, abuse prevention, and operating the service Legitimate interests
Prepaid balance and invoices, when billing exists Take prepayment, refund unused balance, and keep accounting records Contract, and legal obligation for records we must keep

Legitimate interests are limited to running a secure B2B API. They are not used for advertising. You can object to processing based on legitimate interests, as described in section 10.

04 What we never do

05 Sign-in with GitHub and Google

GitHub and Google are used only to sign you in. We receive the identity they return for that purpose: an account identifier, an email address, and a name. We do not request YouTube, Gmail, Google Drive, or any other Google API, and we do not post to GitHub or read your repositories.

Each of those companies is an independent controller of the sign-in that happens on its own site. Their handling of your account is described in their own privacy policies. You can stop using a provider by signing in with email instead, and you can revoke Ancilair's access from the provider's own security settings. Revoking it there stops further sign-in with that provider. It does not by itself delete the Ancilair account. Ask us to delete the account if that is what you want.

We do not use Google user data for advertising, and we do not use it to train generalized models. The only humans who would read it are people acting for Mazlo SAS on a support request you asked for, on a security incident, or where the law requires it.

06 Who we share it with

We share personal data with the service providers below, with a supplier when you send a call, and with authorities when the law requires it. We do not share it with advertisers.

Recipient What they get Why Where
Infomaniak Network SA, on the server that runs the application, Postgres, and Dokploy The stored account data in the database, and server logs Hosting the Service Switzerland (Geneva). The registered address is on the legal notices.
Cloudflare Connection data as requests are proxied: IP address, user agent, URL, and time. DNS and CDN for the site. Deliver and protect the site Cloudflare's global network. Cloudflare, Inc. is established in the United States.
Postmark The recipient email address and the body of a transactional message, including a sign-in code Send sign-in codes United States
GitHub The OAuth sign-in itself. We then store the identifier, email, and name GitHub returns. Sign-in, if you choose GitHub United States. GitHub is an independent controller for its own service.
Google The OAuth sign-in itself. We then store the identifier, email, and name Google returns. Sign-in, if you choose Google United States. Google is an independent controller for its own service.
Stripe, when payments are enabled The card payment you make, and the account details Stripe needs to take it. We do not store the card number. Process card payments for a prepaid Balance United States. Stripe is not used while payments are off, which they are today.
The supplier selected for a call The request you send for that call The call you asked us to make Wherever that supplier processes it. Their terms and privacy notice apply to their service.

Switzerland is covered by a European Commission adequacy decision. For transfers to Cloudflare, Postmark, GitHub, Google, and Stripe outside the EEA, we use the European Commission's standard contractual clauses and, where it applies, the EU-US Data Privacy Framework.

We also disclose data where the law requires it, or where it is necessary to respond to a current security threat to the Service or its users. If we are compelled to hand over data about you, we will tell you unless the law bars us from doing so.

If Mazlo SAS is acquired or merged, account data may transfer with the business. You would be told in advance, and this policy would keep applying until a replacement policy that is no less protective takes over.

07 Cookies

We use two first-party cookies, both required to sign you in. There is no advertising cookie and no analytics cookie, so there is no consent banner for a measurement tool we do not run.

Blocking these cookies means sign-in will not work. That is the opt-out.

08 How we protect it

No system is perfectly secure. If we become aware of a breach that affects your personal data, we will notify affected customers and, where the GDPR requires it, the CNIL, without undue delay.

09 How long we keep it

Data Retention
Account, identity, API key record Until you delete the account, or until you revoke the key for the key record
Sign-in codes Until they expire (15 minutes) and are no longer needed to reject a replay. They are single use.
Session record (IP address, user agent) Until you sign out or the session is destroyed
API call logs 12 months
Infrastructure and CDN logs (Cloudflare, Infomaniak) The provider's default period, and up to 30 days where we control the retention
Backups 30 days
Accounting records, once billing exists As long as French accounting law requires us to keep them

To delete the account, email [email protected]. We process the request within 30 days. Deletion removes the live account, identity, sessions, sign-in codes, and API key records. A backup copy can remain until the 30-day backup window ends.

10 Your rights

If the GDPR applies to you, you can ask us to access, correct, erase, or export the personal data we control, to restrict processing, and to object to processing based on legitimate interests. You can also ask us to send you a copy in a portable form where the basis is contract. We will respond within one month. We do not charge for a reasonable request, and we will not treat you differently for asking.

Where we process call data as your processor, your request about a traveller should go to the controller first, which is you. We will help you answer it, as a processor must.

You can revoke an API key and sign out yourself. Access, correction, and deletion requests go to [email protected]. We respond within one month, and we delete an account within 30 days of that request.

You can lodge a complaint with a supervisory authority. Ours is the Commission nationale de l'informatique et des libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France. You may also complain to the authority of the EU or EEA country where you live or work.

We honour access, correction, and deletion requests from people outside the EEA as well. We do not sell personal information.

11 Children

The Service is for businesses. It is not directed at anyone under 16, and we do not knowingly create an account for a child. If you believe a child has an account, email [email protected] and we will delete it.

12 Changes to this policy

We will update this page when our practices change, and the "last updated" date will change with it. For a material change, such as a new category of data, a new recipient, or a new purpose, we will notify account holders by email or an in-app notice before the change takes effect.

13 Contact

Controller and general privacy questions: [email protected].

Data requests and account deletion: [email protected].

Security vulnerabilities: [email protected].

See also the Terms of Service.