Privacy Policy

Publisher: Caast·Version 1.2·Last updated: 24 June 2026·Effective date: 18 June 2026

Contents
  1. 1Introduction and scope
  2. 2Roles: controller and processor
  3. 3Categories of data collected and data subjects
  4. 4Purposes and legal bases of processing
  5. 5Use of generative artificial intelligence
  6. 6Connecting a third-party AI assistant to Faast's MCP server
  7. 7Hosting, data location and subprocessors
  8. 8International transfers outside the European Union
  9. 9Retention periods
  10. 10Data security
  11. 11Cookies and other trackers
  12. 12Data subjects' rights
  13. 13Automated decision-making and profiling
  14. 14California residents' rights (CCPA / CPRA)
  15. 15Minors
  16. 16Changes to this policy
  17. 17Contact and complaints

1. Introduction and scope

1.1 Who we are

This privacy policy describes how Caast (hereinafter "Caast", "we", "our" or "the Publisher") collects, uses, shares and protects personal data in connection with the operation of the Faast platform, an online (SaaS) service that assists with organizing AI-assisted live commerce events (hereinafter "Faast" or "the Service").

Controller contact details:

  • Name: Caast
  • Legal form: simplified joint-stock company (SAS) with share capital of EUR 101,830
  • Business registration: 528 509 060 RCS Lille Metropole ; SIRET of the registered office: 528 509 060 00026
  • VAT: FR15 528 509 060
  • APE/NAF code: 58.29A (software publishing)
  • Registered office: 165 avenue de Bretagne, 59000 Lille, France
  • Legal representative: Caast is represented by its president, BLAAST (sole-shareholder company, registration No. 912 291 671), itself represented by Mr Antoine Leclercq.
  • Website: https://caast.tv
  • Contact for any data protection question: privacy@caast.tv

Data Protection Officer (DPO):

Caast has not appointed a Data Protection Officer (DPO). For any question regarding the protection of your personal data or to exercise your rights, contact Caast at privacy@caast.tv.

1.2 Scope of application

This policy applies to:

  • Caast's internal users (sales, customer success, administration teams);
  • users on the client brand side who have a Faast account (approvers, invited collaborators);
  • individuals whose data appears in the Service (professional contacts, live participants, hosts and presenters, team members);
  • individuals invited by magic link or by invitation.

This policy is separate from the Service's general terms of use and sale, and from the cookie policy (see section 11).

1.3 Two-layer information

In line with CNIL recommendations, information is structured in two layers: a short summary at the start of each section, followed by full detail. The numbered table of contents above provides direct access to each processing activity.


2. Roles: controller and processor

Caast acts in two distinct capacities depending on the processing concerned.

2.1 Caast as controller

Caast acts as controller within the meaning of Article 4(7) GDPR for the processing it carries out for its own purposes, in particular:

  • managing user accounts and authentication;
  • billing and managing the B2B contractual relationship;
  • Service security, fraud prevention and technical logging;
  • managing its own prospecting and business contacts.

2.2 Caast as processor

For data processed on behalf of client brands in the course of using the Service (live editorial content, product data, brand contacts, collaboration data), Caast acts as processor within the meaning of Article 28 GDPR. In that case, the client brand is the controller and determines the purposes and means of the processing.

Such processing is governed by a data processing agreement (DPA) concluded between Caast and the client brand. Caast's use of sub-processors (notably the AI providers described in section 5) for such data takes place on the controller's instructions and authorization, within the framework of the DPA. Where a data subject exercises their rights over data processed by Caast as a processor, Caast directs or assists the controller (the client brand) in handling the request (see section 12).


3. Categories of data collected and data subjects

3.1 Data subjects

  • Caast team members who are internal Faast users (administrators, sales, customer success, super-administrators);
  • client brand users with an account (client / contributor roles): approvers, invited collaborators;
  • hosts, presenters and live participants (hosts, chat moderators, product presenters), named in project roles and scripts;
  • contacts of client companies (sales, marketing contacts, sometimes imported from Notion);
  • individuals invited by magic link or invitation, identified by their email address;
  • team members who have shared their Google calendar with the Faast service account.

3.2 Categories of data

CategoryData concerned
Account identifiersEmail address, username, role (admin / sales / success / client / contributor), notification preferences
Contact details of individuals and contactsFirst name, last name, primary and secondary email, phone, photo, job title, LinkedIn URL, postal address, gender, notes, associated company
Authentication and session dataRefresh tokens, last login date, JWT claims, Google OAuth tokens (Drive / Calendar) stored for users who have connected these services, personal access tokens (PATs) and OAuth authorization codes for connecting a third-party AI assistant (see section 6)
Avatars and profile photosAvatar URL, photo URL
AI-generated live editorial contentScripts, named speaking parts ("Name:" format), SMS, debrief emails, contests, polls, marketing content
Client brand product dataName, price, image, URL, reference (SKU), description, including data extracted by scraping merchant sites
Client brand and company dataName, contact email, associated Caast app, live billing data (quotes, purchase orders, invoices, payments, reminders)
Comments and collaborationComments on lives and media, mentions, video timecodes, collaboration activity, task assignments
Outgoing email queueRecipients and content pending validation
Live and calendar dataTitles, dates, participants, teams (hosting, client, Caast), team members' calendar availability
Technical, error and audit logsExternal API call logs, 5xx / panic alerts sent by email, audit log of tool calls via the MCP server (user identifier, tool name, argument fingerprint, decision, IP address, user agent)
Imported Google metadataDrive files and metadata (read-only), Calendar events and busy time ranges, for connected users only

Messaging (Gmail) feature not deployed. The Service includes a technical foundation for email synchronization (sender, recipients, copies, subjects, bodies, participants, thread identifiers) that is neither enabled nor configured in production to date. No third-party email is synchronized, ingested or processed. Google (Gmail) is therefore not an active subprocessor and does not appear in the register in section 7.2. This data category would only become relevant after the integration is actually enabled, which would be reflected in an update to this policy.

3.3 Sources of data (indirect collection, Art. 14 GDPR)

Some data is not collected directly from the data subject. In accordance with Article 14 GDPR, the main sources are:

  • Client brands: user accounts, contacts and live data are often entered or imported by the client brand or by Caast teams.
  • Notion: certain contacts and live billing data are imported from Caast's Notion databases (CLPM).
  • Merchant sites: product data (name, price, image, description) is extracted by scraping the client brands' merchant sites.
  • Caast platform: the identity of the logged-in user is obtained via OAuth SSO (Caast Admin), and live, product and statistics data are synced from the Caast platform.
  • Google (Drive / Calendar): when a user connects these services, the corresponding metadata and availability are imported.


5. Use of generative artificial intelligence

5.1 Summary

Faast uses generative AI models to produce, at the user's request, the content of a live package (scripts, SMS, contests, marketing content) and marketing visuals, to generate editorial concepts and plans for lives from the public analysis of a brand (observed social media handles, history of operations), to respond in a conversational assistance chat feature, and to extract product information from PDF documents. Two providers process data for this purpose: Anthropic (Claude) and Google (Gemini).

5.2 How it works and data transmitted

Anthropic (Claude) is used to generate the live package, for the conversational assistance chat feature, and to extract products from PDFs (multimodal capability). By default, Faast mainly uses Claude Sonnet 4.6 (via the API) or Claude Opus (via the local Claude Code client, selected first when available); a lighter model (Claude Haiku) may be used for short tasks. The model receives, in each request (prompt), everything sent for the requested task: brand briefs, product names, live editorial content, chat messages, and potentially names of individuals (hosts, contacts) present in briefs or scripts.

Technically, depending on the task, text generation and chat may transit either through a local "Claude Code" client, selected by default when available, or through the Anthropic API (api.anthropic.com). In both cases, data is sent to Anthropic's servers (United States). Multimodal extraction (PDF) goes through the Anthropic API. Responses are also delivered from those servers.

Google (Gemini API, gemini-2.5-flash-image model) is used to generate and edit marketing visuals. It receives the visual creation text prompt and reference images (brand or product visuals) which are downloaded and then transmitted to the Gemini endpoint (generativelanguage.googleapis.com, United States). Depending on their content, these reference images may contain personal data (for example, people, models or faces appearing in a visual).

5.3 On-demand triggering, limited access

AI is never triggered in the background over all your data. It runs only on demand, during a content generation action, a visual generation action, a chat exchange or a PDF extraction. Generative AI has no direct access to the database: it only receives the context specifically assembled for each call.

5.4 Retention and training on the provider side

  • Anthropic: Anthropic does not train its models on data sent through its commercial API and provides a Data Processing Addendum (DPA). Data may be processed in the United States; transfers are governed by the European Commission's Standard Contractual Clauses (SCC). By default, content is not retained beyond what is necessary to process the request, and a zero-data-retention option is available; limited retention may apply for legal or abuse-prevention reasons. Anthropic acts as a processor under its DPA.
  • Google (Gemini): Google does not use data sent through the paid Gemini API to train its models and acts as a processor under its Cloud Data Processing Addendum. Google LLC is certified under the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses. Logging is limited to abuse prevention and legal obligations; a zero-data-retention option is available. Images generated by Gemini carry a SynthID digital watermark.

5.5 AI transparency (Article 50 of the AI Act)

In accordance with Article 50 of Regulation (EU) 2024/1689 ("AI Act"), whose transparency obligations apply from 2 August 2026, Caast implements the following transparency measures:

  • Interaction with AI: for conversational features or agents exposed in Faast's interface, you are or will be informed, by the applicable deadline at the latest, that you are interacting with an AI system. Where the conversational interaction takes place in a third-party AI assistant connected via the MCP server (see section 6), the transparency obligation for that chatbot lies with the assistant's provider.
  • Marking of generated content:
    • Images: visuals generated by Gemini carry the SynthID watermark applied by Google.
    • Text: AI-generated text content (scripts, SMS, emails, marketing content) is identified as AI-generated within the Faast interface. A machine-readable text marking is not implemented to date; Caast monitors the evolution of applicable standards (notably the Code of Practice on marking AI-generated content) and will incorporate it once technical standards are stabilized, ahead of the 2 August 2026 deadline.
  • Publication of content of public interest: if AI-generated text is published to inform the public on matters of public interest, its AI origin is disclosed, except where there is substantial human editorial review.

5.6 AI-generated content may be inaccurate

Content produced by AI (scripts, SMS, product descriptions, visuals, chat responses, PDF extractions) may contain errors, inaccuracies or incorrect elements. It is provided as a production aid and must undergo human review before any use or distribution. Caast does not guarantee the accuracy of generated content.

5.7 AI-specific right to object

In accordance with the CNIL recommendations on the development of AI systems (19 June 2025), you have a right to object enabling you to request that certain of your data not be reused in the AI context. Any request may be sent to privacy@caast.tv (see section 12).


6. Connecting a third-party AI assistant to Faast's MCP server

6.1 Principle (actual direction of the flow)

Faast exposes its own remote MCP (Model Context Protocol) server, accessible over HTTP (Streamable HTTP). This server lets a third-party AI assistant that you choose to connect (for example OpenAI's ChatGPT or Anthropic's Claude) call Faast's API on your behalf.

The flow does not consist of Faast "pushing" data to a third-party assistant. It is the reverse: once you have authorized it, the third-party assistant connects to Faast and reads and writes data in Faast at your request.

To authorize this connection, Faast acts as its own OAuth 2.1 authorization server (Dynamic Client Registration RFC 7591, Authorization Code flow with PKCE S256). You authenticate to Faast and explicitly approve the connection. A connection using a personal access token (PAT) that you paste into your assistant's connector is also possible.

6.2 Data flow, scope of access and consequences

Once the connection is authorized, the third-party AI assistant can access, with exactly the same rights as your account, all the data and features you have access to in Faast, both for reading and writing: products, scripts, contacts and persons, billing, comments and collaboration, etc. The MCP server exposes a function per API endpoint as well as a generic gateway allowing any /api/... endpoint to be called with your permissions. Access is not limited to reduced per-task "scopes": the authorizable scope corresponds to everything you can do yourself in Faast.

When the assistant reads Faast data, that data is ingested into the processing context of the assistant's provider (for example OpenAI or Anthropic, in the United States), which processes it under its own terms of use and privacy policy, and not under this policy. This flow sends personal data (contacts, named scripts, billing data, etc.) out to a system you have chosen to connect.

In this case, the third-party assistant's provider is not a subprocessor of Caast: it is a third-party recipient that you choose to connect and for whose use you (or the client brand) are responsible. We encourage you to read that assistant's privacy policy and to only authorize trusted assistants, given the scope of access granted.

6.3 Security, logging, control and revocation

  • Authorization is per user: each connection is tied to your identity and your rights, with no shared organizational token.
  • The access token issued to the assistant is a short-lived signed Faast session JWT; a refresh token (with rotation) may also be issued to it to extend access until revocation. Authorization codes, personal access tokens (PATs) and refresh tokens are stored in hashed form (SHA256), never in clear text.
  • Every tool call via the MCP server is logged (user identifier, tool name, argument fingerprint, decision, IP address, user agent) for traceability and security (see retention in section 9).
  • Revocation: you can revoke a personal access token (PAT) from Faast's settings. For a standard OAuth connection, revoke access from your third-party assistant and/or by disconnecting your Faast sessions (token rotation). A dedicated screen for managing connected OAuth clients within Faast is not available to date.

Caast is not responsible for processing carried out by the third-party assistant's provider once data is read at your request.


7. Hosting, data location and subprocessors

7.1 Primary hosting (European Union)

Faast's production is hosted by OVHcloud (a French company), on a single-node Kubernetes cluster. All application data at rest is hosted in this cluster: PostgreSQL database (CloudNativePG, SSL required), backend, frontend, WebSocket server, collaboration sidecar and scraper, all self-hosted.

OVHcloud, a French company whose main datacenters are located in France (Gravelines, Roubaix, Strasbourg). The application is hosted within the European Union. No transfer outside the EU for application hosting.

7.2 Subprocessor register

Caast uses the following subprocessors, which process personal data for the purposes described. We do not use any browser-side analytics or error-tracking tools (no Google Analytics, Sentry, PostHog, Datadog or equivalent). The WebSocket server and collaboration sidecar are self-hosted in the OVHcloud cluster and involve no third party. As the Gmail messaging integration is not active in production, Google (Gmail) does not appear as an active subprocessor (see section 3.2). The third-party AI assistant providers you connect via the MCP server (for example OpenAI / ChatGPT, Anthropic / Claude) are not subprocessors of Caast but third-party recipients (see sections 6 and 8).

SubprocessorPurposeData concernedLocationTransfer safeguard
Anthropic (Claude)AI generation of the live package (script, SMS, contests, marketing); conversational assistance chat; product extraction from PDFPrompts: brand briefs, product names, editorial content, chat messages, names of individuals in briefs / scriptsUnited StatesSCC 2021 + TIA (Anthropic DPA). DPF status to be verified (see section 8)
Google (Gemini API)Generation and editing of marketing visualsVisual creation prompt, reference images (brand / product visuals, possibly containing people)United StatesSCC 2021 + TIA; EU-US DPF status to be verified (see section 8)
Amazon Web Services (SES)Sending transactional emails (magic link, invitations, notifications, reminders, debriefs, alerts)Recipient emails, names, email content; internal Caast audit BCCEuropean Union (eu-west-3 region, Paris)Processing in the EU (eu-west-3, Paris), no transfer outside the EU
Cloudflare R2Storage of uploaded media files and documents (served via CDN); target for PostgreSQL WAL / PITR backupsMedia files and documents (may contain personal data); full database backupsCloudflare, Inc. (United States); public media URL clpm-media.caast.frTransfers governed by the EU-US Data Privacy Framework (Cloudflare self-certified) and Standard Contractual Clauses, under the Cloudflare DPA
Caast (live shopping platform)Live synchronization (apps, sellers, stats, products, contests, polls, promo codes, campaigns); OAuth SSO; short-link generationLogged-in user identity (OAuth), product data (name, price, image, URL, SKU), contests, polls, campaignsCaast infrastructure (api-k8s.caast.tv, admin.caast.tv); European UnionIntra-group processing: Caast, a French company, is the publisher of Faast and controls this infrastructure (European Union)
NotionLive synchronization (CLPM), billing import, reading contacts and companiesLive data, contacts (Notion identifier on persons), billing dataNotion Labs, Inc. (United States)Certified under the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses and a DPA
Google Calendar API (service account)Live calendar synchronization; reading free/busy availability of team members who shared their calendarLive events (titles, dates, participants); busy ranges of shared calendarsUnited States (calendar hosted on Caast Google Workspace)SCC 2021 + TIA; EU-US DPF status to be verified (see section 8)
Google Drive API (OAuth, read-only)Read-only access to files and metadata to preview / import assets, upon user connectionDrive files and metadata authorized by the user (drive.readonly + drive.metadata.readonly scopes)United StatesSCC 2021 + TIA; EU-US DPF status to be verified (see section 8)
Bright DataScraping proxy / unlocker for client merchant product pagesURLs of product pages to scrape. No personal data of Faast users is transmitted; outbound traffic routed via proxiesResidential proxies (exit may be geolocated)Infrastructure subprocessor (proxy), no user personal data
OVHcloudKubernetes hosting of all production (backend, frontend, WS, PostgreSQL database, scraper)All application data at rest and in processingFrance (European Union)Processing in the EU
DopplerStorage and injection of infrastructure secrets (API keys, credentials)Technical secrets only; no end-user personal dataDoppler (United States), secrets and configuration managementTransfers governed by Standard Contractual Clauses and a DPA (no DPF certification)

Caast keeps this register up to date and undertakes to conclude an Article 28 GDPR-compliant agreement with each subprocessor.


8. International transfers outside the European Union

8.1 Principle

The core of the data (database, files) is hosted in the European Union (OVHcloud, France) and at AWS in the eu-west-3 region (Paris) for email sending: these processing activities do not involve any transfer outside the EU.

Some subprocessors are, however, located in the United States: Anthropic, Google, Cloudflare, Notion and Doppler. Transfers to these subprocessors are framed in accordance with Chapter V GDPR.

Third-party recipients at your initiative (not subprocessors). When you connect your own third-party AI assistant to Faast's MCP server (see section 6), personal data is transmitted to that assistant's provider, notably OpenAI / ChatGPT and Anthropic / Claude, located in the United States. These providers are not subprocessors of Caast: they are third-party recipients you choose to connect and that process the data under their own privacy policy. You (or the client brand) are responsible for this use. The EU-US DPF status of each of these providers must be verified on the official list before being relied upon.

8.2 Transfer mechanisms

Transfers outside the EU rely, depending on the subprocessor, on one or more of the following mechanisms:

  • Standard Contractual Clauses (SCC 2021) of the European Commission, supplemented by a Transfer Impact Assessment, used as the primary safeguard or as an additional safeguard. Anthropic's DPA incorporates SCCs (EU) and a UK IDTA; the exact version binding on Caast remains to be confirmed (see section 5.4).
  • EU-US Data Privacy Framework (DPF) adequacy decision: European Commission adequacy decision of 10 July 2023, confirmed by the General Court of the European Union on 3 September 2025 (Latombe case, T-553/23). This safeguard only applies to subprocessors actually certified and active on the official list (dataprivacyframework.gov/list). The DPF status of each US subprocessor must be individually verified on this list before being invoked; Caast does not presume such status.

Caast maintains Standard Contractual Clauses as a primary or additional safeguard, including for subprocessors otherwise DPF-certified, given the persistent legal uncertainty (Latombe appeal pending before the Court of Justice of the European Union, case C-703/25 P).

8.3 Information and access to safeguards

You can obtain a copy or details of the safeguards applicable to a transfer by writing to privacy@caast.tv. The active DPF status of each subprocessor can be checked at dataprivacyframework.gov/list.


9. Retention periods

In accordance with Article 5(1)(e) GDPR, data is kept only for as long as necessary for the purposes pursued.

Data categoryRetention period / criterion
Account and authentication dataFor the duration of the contractual relationship, then deletion or anonymization. Session / refresh tokens: per their technical validity period
Contacts and persons dataFor the duration of the relationship, then intermediate archiving if needed to comply with legal obligations
Live editorial content and product dataPer the client's / brand's business need, then deletion. For data processed as a processor, per the controller's instructions
Billing data10 years from the close of the financial year (French accounting obligation)
B2B prospecting contacts3 years from the last contact (CNIL recommendation)
Login, security and technical logsGenerally 6 to 12 months
MCP tool-call audit log (IP, user agent, argument fingerprint)Aligned with technical logs: 6 to 12 months (target; a corresponding automatic purge is being implemented)
Cookie consent evidenceApproximately 6 months (see cookie policy)
Data transmitted to the Anthropic API (Claude)Data not retained by default beyond processing; zero-data-retention option available (limited retention possible for legal or abuse-prevention reasons), under Anthropic's DPA
Data transmitted to the Google API (Gemini)For the paid version: no use for training; logging limited to abuse prevention and legal obligations; zero-data-retention option available

At the end of these periods, data is deleted or anonymized. Intermediate restricted-access archiving may be applied only for applicable statutory limitation periods.


10. Data security

Caast implements appropriate technical and organizational measures to protect data against destruction, loss, alteration, unauthorized disclosure or access, in particular:

  • encryption of communications (TLS / SSL; PostgreSQL database accessible only over SSL);
  • encryption at rest (AES-256-GCM) of files submitted through the secure document deposit portal, whose keys are accessible to super-administrators only;
  • storage of OAuth authorization codes, personal access tokens (PATs) and refresh tokens in hashed form (SHA256), MCP access tokens as short-lived signed JWTs;
  • secret management via a dedicated vault (Doppler), with no secret stored in clear text in the code;
  • role-based access control (admin, sales, success, client, contributor) and token authentication (JWT, magic link, OAuth SSO, PAT); the same authorization check applies to calls made via the MCP server;
  • audit log of MCP tool calls (see sections 3.2, 6.3 and 9);
  • audit copy (BCC) of transactional emails for traceability and deliverability control. This copy is currently directed to an internal Caast address; Caast favors a dedicated functional address (for example audit@caast.tv) over an individual named address, in line with the minimization principle;
  • redaction (masking) of personal data before logging where relevant;
  • continuous database backups (WAL / PITR archiving) externalized to Cloudflare R2;
  • use of subprocessors offering recognized security safeguards.

In the event of a data breach likely to result in a risk to your rights and freedoms, Caast notifies the CNIL and, where applicable, the data subjects, under the conditions set out in Articles 33 and 34 GDPR.


11. Cookies and other trackers

The cookies and trackers used are described in section 11 of this policy, in accordance with the ePrivacy Directive and the CNIL recommendation (consolidated version of 16 January 2026).

Principles applied:

  • no tracker that is not strictly necessary is placed or read without your prior consent, which is free, specific, informed and unambiguous;
  • refusing is as easy as accepting: a "Reject all" button is offered at the same level as "Accept all" from the first screen;
  • trackers strictly necessary for the operation of the Service are exempt from consent;
  • the consent validity period is approximately 6 months; evidence of consent is kept;
  • you can withdraw your consent as easily as you gave it, at any time, via the preference management module.

For transparency, the main cookies actually placed by the Service are:

CookieDurationPurposeNature
__Secure-faast-known2 years, readable in JavaScriptMarker indicating an already-known connection on the device, used to adapt the home page call to actionConvenience cookie whose strictly-necessary nature is under review; its duration may be reduced
questionnaire_session30 days, HttpOnlyQuestionnaire sessionStrictly necessary for the operation of the relevant feature
oauth_*5 minutes, HttpOnlySecuring the SSO / OAuth flowStrictly necessary

12. Data subjects' rights

12.1 Your rights

In accordance with Articles 15 to 22 GDPR, you have the following rights:

  • Right of access: to obtain confirmation that your data is processed and to obtain a copy of it;
  • Right to rectification: to have inaccurate or incomplete data corrected;
  • Right to erasure ("right to be forgotten"): to have your data deleted in the cases provided for by the GDPR;
  • Right to restriction of processing;
  • Right to data portability: to receive your data in a structured, commonly used and machine-readable format, or to have it transmitted to another controller;
  • Right to object: to object to processing based on legitimate interest, and at any time to commercial prospecting;
  • Right to withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of processing carried out before withdrawal);
  • Right not to be subject to a solely automated decision producing legal effects or significantly affecting you (Art. 22, see section 13);
  • Right to issue directives regarding the fate of your data after your death.

For AI-related processing, you also have the specific right to object described in section 5.7.

12.2 How to exercise your rights

You can exercise your rights free of charge by writing to privacy@caast.tv. A proportionate identity check may be requested. Caast responds within one month of receiving the request, extendable by two months in the event of complexity or a high number of requests (you will be informed).

Data processed as a processor: if your request concerns data processed by Caast on behalf of a client brand (the controller), Caast will forward your request to that brand or assist in handling it, and may redirect you to it.

12.3 Complaint to the CNIL

If you believe your rights are not respected, you can lodge a complaint with the French Data Protection Authority (CNIL):

  • CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Website: https://www.cnil.fr

13. Automated decision-making and profiling

Faast does not carry out any decision producing legal effects or significantly affecting data subjects solely on the basis of automated processing within the meaning of Article 22 GDPR.

The generative AI described in section 5 produces content (scripts, SMS, marketing, visuals, chat responses, extractions) at the user's request; these outputs are intended for human review and do not constitute automated decisions within the meaning of Article 22. No behavioral profiling of data subjects is carried out for decision-making purposes.


14. California residents' rights (CCPA / CPRA)

This section applies only if you are a California resident and the applicability thresholds of California law (CCPA as amended by the CPRA) are met. Since the expiry of the B2B exemption, professional contacts are also covered.

Subject to eligibility, you have the following rights:

  • Right to know which categories of personal data are collected, used and shared;
  • Right to delete your personal data;
  • Right to correct inaccurate data;
  • Right to opt out of the "sale" or "sharing" of your personal data ("Do Not Sell or Share My Personal Information"): Caast does not sell your personal data. We honor the Global Privacy Control (GPC) signal;
  • Right to limit the use of your sensitive personal data;
  • Right to non-discrimination for exercising these rights.

Regarding automated decision-making technologies (ADMT) introduced by the amended California regulations (effective 1 January 2026, with ADMT compliance for significant decisions from 1 January 2027), Faast does not carry out such significant automated decisions (see section 13).

To exercise these rights, write to privacy@caast.tv.


15. Minors

Faast is a professional (B2B) service, not intended for minors. The Service does not target minors, is not offered to them and does not knowingly collect data concerning them. If you believe a minor has provided us with personal data, contact privacy@caast.tv so that we can delete it.


16. Changes to this policy

Caast may amend this policy, in particular to reflect legal, regulatory or technical changes or the addition of subprocessors. The version in force is the one published on the Service, identified by its version number and update date at the top of the document.

In the event of a substantial change, Caast informs users by appropriate means (in-Service notification or by email). Changes relating to subprocessors are subject to prior information in accordance with the applicable contractual commitments, opening, where applicable, a right to object.


17. Contact and complaints

  • Data protection questions / exercising rights: privacy@caast.tv
  • Data Protection Officer (DPO): Caast has not appointed a DPO; requests are handled via privacy@caast.tv
  • Controller: Caast, 165 avenue de Bretagne, 59000 Lille, France
  • Supervisory authority: French Data Protection Authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, https://www.cnil.fr

This policy reflects information verified as of the last-updated date shown above. It may evolve; any substantial change will be communicated.