Contents
- 1Introduction and scope
- 2Roles: controller and processor
- 3Categories of data collected and data subjects
- 4Purposes and legal bases of processing
- 5Use of generative artificial intelligence
- 6Connecting a third-party AI assistant to Faast's MCP server
- 7Hosting, data location and subprocessors
- 8International transfers outside the European Union
- 9Retention periods
- 10Data security
- 11Cookies and other trackers
- 12Data subjects' rights
- 13Automated decision-making and profiling
- 14California residents' rights (CCPA / CPRA)
- 15Minors
- 16Changes to this policy
- 17Contact and complaints
1. Introduction and scope
1.1 Who we are
This privacy policy describes how Caast (hereinafter "Caast", "we", "our" or "the Publisher") collects, uses, shares and protects personal data in connection with the operation of the Faast platform, an online (SaaS) service that assists with organizing AI-assisted live commerce events (hereinafter "Faast" or "the Service").
Controller contact details:
- Name: Caast
- Legal form: simplified joint-stock company (SAS) with share capital of EUR 101,830
- Business registration: 528 509 060 RCS Lille Metropole ; SIRET of the registered office: 528 509 060 00026
- VAT: FR15 528 509 060
- APE/NAF code: 58.29A (software publishing)
- Registered office: 165 avenue de Bretagne, 59000 Lille, France
- Legal representative: Caast is represented by its president, BLAAST (sole-shareholder company, registration No. 912 291 671), itself represented by Mr Antoine Leclercq.
- Website: https://caast.tv
- Contact for any data protection question: privacy@caast.tv
Data Protection Officer (DPO):
Caast has not appointed a Data Protection Officer (DPO). For any question regarding the protection of your personal data or to exercise your rights, contact Caast at privacy@caast.tv.
1.2 Scope of application
This policy applies to:
- Caast's internal users (sales, customer success, administration teams);
- users on the client brand side who have a Faast account (approvers, invited collaborators);
- individuals whose data appears in the Service (professional contacts, live participants, hosts and presenters, team members);
- individuals invited by magic link or by invitation.
This policy is separate from the Service's general terms of use and sale, and from the cookie policy (see section 11).
1.3 Two-layer information
In line with CNIL recommendations, information is structured in two layers: a short summary at the start of each section, followed by full detail. The numbered table of contents above provides direct access to each processing activity.
2. Roles: controller and processor
Caast acts in two distinct capacities depending on the processing concerned.
2.1 Caast as controller
Caast acts as controller within the meaning of Article 4(7) GDPR for the processing it carries out for its own purposes, in particular:
- managing user accounts and authentication;
- billing and managing the B2B contractual relationship;
- Service security, fraud prevention and technical logging;
- managing its own prospecting and business contacts.
2.2 Caast as processor
For data processed on behalf of client brands in the course of using the Service (live editorial content, product data, brand contacts, collaboration data), Caast acts as processor within the meaning of Article 28 GDPR. In that case, the client brand is the controller and determines the purposes and means of the processing.
Such processing is governed by a data processing agreement (DPA) concluded between Caast and the client brand. Caast's use of sub-processors (notably the AI providers described in section 5) for such data takes place on the controller's instructions and authorization, within the framework of the DPA. Where a data subject exercises their rights over data processed by Caast as a processor, Caast directs or assists the controller (the client brand) in handling the request (see section 12).
3. Categories of data collected and data subjects
3.1 Data subjects
- Caast team members who are internal Faast users (administrators, sales, customer success, super-administrators);
- client brand users with an account (client / contributor roles): approvers, invited collaborators;
- hosts, presenters and live participants (hosts, chat moderators, product presenters), named in project roles and scripts;
- contacts of client companies (sales, marketing contacts, sometimes imported from Notion);
- individuals invited by magic link or invitation, identified by their email address;
- team members who have shared their Google calendar with the Faast service account.
3.2 Categories of data
| Category | Data concerned |
|---|---|
| Account identifiers | Email address, username, role (admin / sales / success / client / contributor), notification preferences |
| Contact details of individuals and contacts | First name, last name, primary and secondary email, phone, photo, job title, LinkedIn URL, postal address, gender, notes, associated company |
| Authentication and session data | Refresh tokens, last login date, JWT claims, Google OAuth tokens (Drive / Calendar) stored for users who have connected these services, personal access tokens (PATs) and OAuth authorization codes for connecting a third-party AI assistant (see section 6) |
| Avatars and profile photos | Avatar URL, photo URL |
| AI-generated live editorial content | Scripts, named speaking parts ("Name:" format), SMS, debrief emails, contests, polls, marketing content |
| Client brand product data | Name, price, image, URL, reference (SKU), description, including data extracted by scraping merchant sites |
| Client brand and company data | Name, contact email, associated Caast app, live billing data (quotes, purchase orders, invoices, payments, reminders) |
| Comments and collaboration | Comments on lives and media, mentions, video timecodes, collaboration activity, task assignments |
| Outgoing email queue | Recipients and content pending validation |
| Live and calendar data | Titles, dates, participants, teams (hosting, client, Caast), team members' calendar availability |
| Technical, error and audit logs | External API call logs, 5xx / panic alerts sent by email, audit log of tool calls via the MCP server (user identifier, tool name, argument fingerprint, decision, IP address, user agent) |
| Imported Google metadata | Drive files and metadata (read-only), Calendar events and busy time ranges, for connected users only |
Messaging (Gmail) feature not deployed. The Service includes a technical foundation for email synchronization (sender, recipients, copies, subjects, bodies, participants, thread identifiers) that is neither enabled nor configured in production to date. No third-party email is synchronized, ingested or processed. Google (Gmail) is therefore not an active subprocessor and does not appear in the register in section 7.2. This data category would only become relevant after the integration is actually enabled, which would be reflected in an update to this policy.
3.3 Sources of data (indirect collection, Art. 14 GDPR)
Some data is not collected directly from the data subject. In accordance with Article 14 GDPR, the main sources are:
- Client brands: user accounts, contacts and live data are often entered or imported by the client brand or by Caast teams.
- Notion: certain contacts and live billing data are imported from Caast's Notion databases (CLPM).
- Merchant sites: product data (name, price, image, description) is extracted by scraping the client brands' merchant sites.
- Caast platform: the identity of the logged-in user is obtained via OAuth SSO (Caast Admin), and live, product and statistics data are synced from the Caast platform.
- Google (Drive / Calendar): when a user connects these services, the corresponding metadata and availability are imported.
4. Purposes and legal bases of processing
In accordance with Article 6 GDPR, each processing activity relies on an identified legal basis.
| Purpose | Data concerned | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and managing accounts, authentication (including magic link and Caast OAuth SSO) | Account identifiers, authentication and session data | Performance of a contract (Art. 6(1)(b)) with the professional user or client brand |
| Providing Service features (live preparation, collaboration, content generation) | Editorial content, product data, live data, comments | Performance of a contract (Art. 6(1)(b)); for data processed on behalf of brands, performance of the contract between the brand and its own users (Caast acting as processor) |
| AI generation of content, visuals and conversational chat, extraction from PDF | Briefs, product names, editorial content, participant names present in briefs and scripts, reference images, messages entered in chat | Performance of a contract (Art. 6(1)(b)) at the user's request. For data processed on behalf of brands, use of AI and recourse to sub-processors (Anthropic / Google) takes place on the controller's instructions and authorization, within the DPA |
| Synchronization with the Caast platform (products, contests, polls, campaigns, statistics) | Logged-in user identity, product and live data | Performance of a contract (Art. 6(1)(b)) |
| Calendar synchronization and reading team availability (Google Calendar) | Live events, busy time ranges of shared calendars | Legitimate interest (Art. 6(1)(f)): operational team coordination, or consent of the user connecting their calendar |
| Importing assets from Google Drive | Drive files and metadata (read-only) | User consent (Art. 6(1)(a)), evidenced by OAuth authorization |
| Connecting a third-party AI assistant to Faast's MCP server (see section 6) | Faast data accessible to the user, read and written by the assistant on the user's behalf | Consent of the user connecting the assistant (Art. 6(1)(a)), evidenced by OAuth authorization |
| Sending transactional emails (login, invitations, notifications, reminders, debriefs) and internal audit copy (BCC) | Recipient email, name, email content | Performance of a contract (Art. 6(1)(b)) for sending; legitimate interest (Art. 6(1)(f)) for the audit copy: traceability and deliverability control |
| Billing and managing the contractual relationship | Live billing data, contact details | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)): accounting obligations |
| Security, logging, fraud prevention, technical monitoring, MCP tool-call auditing | Technical logs, session data, error alerts, MCP audit log (IP, user agent) | Legitimate interest (Art. 6(1)(f)): ensuring the security and proper functioning of the Service |
| B2B prospecting and managing Caast's business contacts | Contact details | Legitimate interest (Art. 6(1)(f)): developing B2B business, with a right to object |
Legitimate interests pursued: where processing relies on Article 6(1)(f), Caast's legitimate interest is, as the case may be, the security and continuity of the Service, the operational coordination of teams involved in lives, the traceability of communications, and the development of its B2B business. A balancing test between this interest and the rights and freedoms of data subjects has been carried out; you have a right to object (see section 12).
5. Use of generative artificial intelligence
5.1 Summary
Faast uses generative AI models to produce, at the user's request, the content of a live package (scripts, SMS, contests, marketing content) and marketing visuals, to generate editorial concepts and plans for lives from the public analysis of a brand (observed social media handles, history of operations), to respond in a conversational assistance chat feature, and to extract product information from PDF documents. Two providers process data for this purpose: Anthropic (Claude) and Google (Gemini).
5.2 How it works and data transmitted
Anthropic (Claude) is used to generate the live package, for the conversational assistance chat feature, and to extract products from PDFs (multimodal capability). By default, Faast mainly uses Claude Sonnet 4.6 (via the API) or Claude Opus (via the local Claude Code client, selected first when available); a lighter model (Claude Haiku) may be used for short tasks. The model receives, in each request (prompt), everything sent for the requested task: brand briefs, product names, live editorial content, chat messages, and potentially names of individuals (hosts, contacts) present in briefs or scripts.
Technically, depending on the task, text generation and chat may transit either through a local "Claude Code" client, selected by default when available, or through the Anthropic API (api.anthropic.com). In both cases, data is sent to Anthropic's servers (United States). Multimodal extraction (PDF) goes through the Anthropic API. Responses are also delivered from those servers.
Google (Gemini API, gemini-2.5-flash-image model) is used to generate and edit marketing visuals. It receives the visual creation text prompt and reference images (brand or product visuals) which are downloaded and then transmitted to the Gemini endpoint (generativelanguage.googleapis.com, United States). Depending on their content, these reference images may contain personal data (for example, people, models or faces appearing in a visual).
5.3 On-demand triggering, limited access
AI is never triggered in the background over all your data. It runs only on demand, during a content generation action, a visual generation action, a chat exchange or a PDF extraction. Generative AI has no direct access to the database: it only receives the context specifically assembled for each call.
5.4 Retention and training on the provider side
- Anthropic: Anthropic does not train its models on data sent through its commercial API and provides a Data Processing Addendum (DPA). Data may be processed in the United States; transfers are governed by the European Commission's Standard Contractual Clauses (SCC). By default, content is not retained beyond what is necessary to process the request, and a zero-data-retention option is available; limited retention may apply for legal or abuse-prevention reasons. Anthropic acts as a processor under its DPA.
- Google (Gemini): Google does not use data sent through the paid Gemini API to train its models and acts as a processor under its Cloud Data Processing Addendum. Google LLC is certified under the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses. Logging is limited to abuse prevention and legal obligations; a zero-data-retention option is available. Images generated by Gemini carry a SynthID digital watermark.
5.5 AI transparency (Article 50 of the AI Act)
In accordance with Article 50 of Regulation (EU) 2024/1689 ("AI Act"), whose transparency obligations apply from 2 August 2026, Caast implements the following transparency measures:
- Interaction with AI: for conversational features or agents exposed in Faast's interface, you are or will be informed, by the applicable deadline at the latest, that you are interacting with an AI system. Where the conversational interaction takes place in a third-party AI assistant connected via the MCP server (see section 6), the transparency obligation for that chatbot lies with the assistant's provider.
- Marking of generated content:
- Images: visuals generated by Gemini carry the SynthID watermark applied by Google.
- Text: AI-generated text content (scripts, SMS, emails, marketing content) is identified as AI-generated within the Faast interface. A machine-readable text marking is not implemented to date; Caast monitors the evolution of applicable standards (notably the Code of Practice on marking AI-generated content) and will incorporate it once technical standards are stabilized, ahead of the 2 August 2026 deadline.
- Publication of content of public interest: if AI-generated text is published to inform the public on matters of public interest, its AI origin is disclosed, except where there is substantial human editorial review.
5.6 AI-generated content may be inaccurate
Content produced by AI (scripts, SMS, product descriptions, visuals, chat responses, PDF extractions) may contain errors, inaccuracies or incorrect elements. It is provided as a production aid and must undergo human review before any use or distribution. Caast does not guarantee the accuracy of generated content.
5.7 AI-specific right to object
In accordance with the CNIL recommendations on the development of AI systems (19 June 2025), you have a right to object enabling you to request that certain of your data not be reused in the AI context. Any request may be sent to privacy@caast.tv (see section 12).
6. Connecting a third-party AI assistant to Faast's MCP server
6.1 Principle (actual direction of the flow)
Faast exposes its own remote MCP (Model Context Protocol) server, accessible over HTTP (Streamable HTTP). This server lets a third-party AI assistant that you choose to connect (for example OpenAI's ChatGPT or Anthropic's Claude) call Faast's API on your behalf.
The flow does not consist of Faast "pushing" data to a third-party assistant. It is the reverse: once you have authorized it, the third-party assistant connects to Faast and reads and writes data in Faast at your request.
To authorize this connection, Faast acts as its own OAuth 2.1 authorization server (Dynamic Client Registration RFC 7591, Authorization Code flow with PKCE S256). You authenticate to Faast and explicitly approve the connection. A connection using a personal access token (PAT) that you paste into your assistant's connector is also possible.
6.2 Data flow, scope of access and consequences
Once the connection is authorized, the third-party AI assistant can access, with exactly the same rights as your account, all the data and features you have access to in Faast, both for reading and writing: products, scripts, contacts and persons, billing, comments and collaboration, etc. The MCP server exposes a function per API endpoint as well as a generic gateway allowing any /api/... endpoint to be called with your permissions. Access is not limited to reduced per-task "scopes": the authorizable scope corresponds to everything you can do yourself in Faast.
When the assistant reads Faast data, that data is ingested into the processing context of the assistant's provider (for example OpenAI or Anthropic, in the United States), which processes it under its own terms of use and privacy policy, and not under this policy. This flow sends personal data (contacts, named scripts, billing data, etc.) out to a system you have chosen to connect.
In this case, the third-party assistant's provider is not a subprocessor of Caast: it is a third-party recipient that you choose to connect and for whose use you (or the client brand) are responsible. We encourage you to read that assistant's privacy policy and to only authorize trusted assistants, given the scope of access granted.
6.3 Security, logging, control and revocation
- Authorization is per user: each connection is tied to your identity and your rights, with no shared organizational token.
- The access token issued to the assistant is a short-lived signed Faast session JWT; a refresh token (with rotation) may also be issued to it to extend access until revocation. Authorization codes, personal access tokens (PATs) and refresh tokens are stored in hashed form (SHA256), never in clear text.
- Every tool call via the MCP server is logged (user identifier, tool name, argument fingerprint, decision, IP address, user agent) for traceability and security (see retention in section 9).
- Revocation: you can revoke a personal access token (PAT) from Faast's settings. For a standard OAuth connection, revoke access from your third-party assistant and/or by disconnecting your Faast sessions (token rotation). A dedicated screen for managing connected OAuth clients within Faast is not available to date.
Caast is not responsible for processing carried out by the third-party assistant's provider once data is read at your request.
7. Hosting, data location and subprocessors
7.1 Primary hosting (European Union)
Faast's production is hosted by OVHcloud (a French company), on a single-node Kubernetes cluster. All application data at rest is hosted in this cluster: PostgreSQL database (CloudNativePG, SSL required), backend, frontend, WebSocket server, collaboration sidecar and scraper, all self-hosted.
OVHcloud, a French company whose main datacenters are located in France (Gravelines, Roubaix, Strasbourg). The application is hosted within the European Union. No transfer outside the EU for application hosting.
7.2 Subprocessor register
Caast uses the following subprocessors, which process personal data for the purposes described. We do not use any browser-side analytics or error-tracking tools (no Google Analytics, Sentry, PostHog, Datadog or equivalent). The WebSocket server and collaboration sidecar are self-hosted in the OVHcloud cluster and involve no third party. As the Gmail messaging integration is not active in production, Google (Gmail) does not appear as an active subprocessor (see section 3.2). The third-party AI assistant providers you connect via the MCP server (for example OpenAI / ChatGPT, Anthropic / Claude) are not subprocessors of Caast but third-party recipients (see sections 6 and 8).
| Subprocessor | Purpose | Data concerned | Location | Transfer safeguard |
|---|---|---|---|---|
| Anthropic (Claude) | AI generation of the live package (script, SMS, contests, marketing); conversational assistance chat; product extraction from PDF | Prompts: brand briefs, product names, editorial content, chat messages, names of individuals in briefs / scripts | United States | SCC 2021 + TIA (Anthropic DPA). DPF status to be verified (see section 8) |
| Google (Gemini API) | Generation and editing of marketing visuals | Visual creation prompt, reference images (brand / product visuals, possibly containing people) | United States | SCC 2021 + TIA; EU-US DPF status to be verified (see section 8) |
| Amazon Web Services (SES) | Sending transactional emails (magic link, invitations, notifications, reminders, debriefs, alerts) | Recipient emails, names, email content; internal Caast audit BCC | European Union (eu-west-3 region, Paris) | Processing in the EU (eu-west-3, Paris), no transfer outside the EU |
| Cloudflare R2 | Storage of uploaded media files and documents (served via CDN); target for PostgreSQL WAL / PITR backups | Media files and documents (may contain personal data); full database backups | Cloudflare, Inc. (United States); public media URL clpm-media.caast.fr | Transfers governed by the EU-US Data Privacy Framework (Cloudflare self-certified) and Standard Contractual Clauses, under the Cloudflare DPA |
| Caast (live shopping platform) | Live synchronization (apps, sellers, stats, products, contests, polls, promo codes, campaigns); OAuth SSO; short-link generation | Logged-in user identity (OAuth), product data (name, price, image, URL, SKU), contests, polls, campaigns | Caast infrastructure (api-k8s.caast.tv, admin.caast.tv); European Union | Intra-group processing: Caast, a French company, is the publisher of Faast and controls this infrastructure (European Union) |
| Notion | Live synchronization (CLPM), billing import, reading contacts and companies | Live data, contacts (Notion identifier on persons), billing data | Notion Labs, Inc. (United States) | Certified under the EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses and a DPA |
| Google Calendar API (service account) | Live calendar synchronization; reading free/busy availability of team members who shared their calendar | Live events (titles, dates, participants); busy ranges of shared calendars | United States (calendar hosted on Caast Google Workspace) | SCC 2021 + TIA; EU-US DPF status to be verified (see section 8) |
| Google Drive API (OAuth, read-only) | Read-only access to files and metadata to preview / import assets, upon user connection | Drive files and metadata authorized by the user (drive.readonly + drive.metadata.readonly scopes) | United States | SCC 2021 + TIA; EU-US DPF status to be verified (see section 8) |
| Bright Data | Scraping proxy / unlocker for client merchant product pages | URLs of product pages to scrape. No personal data of Faast users is transmitted; outbound traffic routed via proxies | Residential proxies (exit may be geolocated) | Infrastructure subprocessor (proxy), no user personal data |
| OVHcloud | Kubernetes hosting of all production (backend, frontend, WS, PostgreSQL database, scraper) | All application data at rest and in processing | France (European Union) | Processing in the EU |
| Doppler | Storage and injection of infrastructure secrets (API keys, credentials) | Technical secrets only; no end-user personal data | Doppler (United States), secrets and configuration management | Transfers governed by Standard Contractual Clauses and a DPA (no DPF certification) |
Caast keeps this register up to date and undertakes to conclude an Article 28 GDPR-compliant agreement with each subprocessor.
8. International transfers outside the European Union
8.1 Principle
The core of the data (database, files) is hosted in the European Union (OVHcloud, France) and at AWS in the eu-west-3 region (Paris) for email sending: these processing activities do not involve any transfer outside the EU.
Some subprocessors are, however, located in the United States: Anthropic, Google, Cloudflare, Notion and Doppler. Transfers to these subprocessors are framed in accordance with Chapter V GDPR.
Third-party recipients at your initiative (not subprocessors). When you connect your own third-party AI assistant to Faast's MCP server (see section 6), personal data is transmitted to that assistant's provider, notably OpenAI / ChatGPT and Anthropic / Claude, located in the United States. These providers are not subprocessors of Caast: they are third-party recipients you choose to connect and that process the data under their own privacy policy. You (or the client brand) are responsible for this use. The EU-US DPF status of each of these providers must be verified on the official list before being relied upon.
8.2 Transfer mechanisms
Transfers outside the EU rely, depending on the subprocessor, on one or more of the following mechanisms:
- Standard Contractual Clauses (SCC 2021) of the European Commission, supplemented by a Transfer Impact Assessment, used as the primary safeguard or as an additional safeguard. Anthropic's DPA incorporates SCCs (EU) and a UK IDTA; the exact version binding on Caast remains to be confirmed (see section 5.4).
- EU-US Data Privacy Framework (DPF) adequacy decision: European Commission adequacy decision of 10 July 2023, confirmed by the General Court of the European Union on 3 September 2025 (Latombe case, T-553/23). This safeguard only applies to subprocessors actually certified and active on the official list (dataprivacyframework.gov/list). The DPF status of each US subprocessor must be individually verified on this list before being invoked; Caast does not presume such status.
Caast maintains Standard Contractual Clauses as a primary or additional safeguard, including for subprocessors otherwise DPF-certified, given the persistent legal uncertainty (Latombe appeal pending before the Court of Justice of the European Union, case C-703/25 P).
8.3 Information and access to safeguards
You can obtain a copy or details of the safeguards applicable to a transfer by writing to privacy@caast.tv. The active DPF status of each subprocessor can be checked at dataprivacyframework.gov/list.
9. Retention periods
In accordance with Article 5(1)(e) GDPR, data is kept only for as long as necessary for the purposes pursued.
| Data category | Retention period / criterion |
|---|---|
| Account and authentication data | For the duration of the contractual relationship, then deletion or anonymization. Session / refresh tokens: per their technical validity period |
| Contacts and persons data | For the duration of the relationship, then intermediate archiving if needed to comply with legal obligations |
| Live editorial content and product data | Per the client's / brand's business need, then deletion. For data processed as a processor, per the controller's instructions |
| Billing data | 10 years from the close of the financial year (French accounting obligation) |
| B2B prospecting contacts | 3 years from the last contact (CNIL recommendation) |
| Login, security and technical logs | Generally 6 to 12 months |
| MCP tool-call audit log (IP, user agent, argument fingerprint) | Aligned with technical logs: 6 to 12 months (target; a corresponding automatic purge is being implemented) |
| Cookie consent evidence | Approximately 6 months (see cookie policy) |
| Data transmitted to the Anthropic API (Claude) | Data not retained by default beyond processing; zero-data-retention option available (limited retention possible for legal or abuse-prevention reasons), under Anthropic's DPA |
| Data transmitted to the Google API (Gemini) | For the paid version: no use for training; logging limited to abuse prevention and legal obligations; zero-data-retention option available |
At the end of these periods, data is deleted or anonymized. Intermediate restricted-access archiving may be applied only for applicable statutory limitation periods.
10. Data security
Caast implements appropriate technical and organizational measures to protect data against destruction, loss, alteration, unauthorized disclosure or access, in particular:
- encryption of communications (TLS / SSL; PostgreSQL database accessible only over SSL);
- encryption at rest (AES-256-GCM) of files submitted through the secure document deposit portal, whose keys are accessible to super-administrators only;
- storage of OAuth authorization codes, personal access tokens (PATs) and refresh tokens in hashed form (SHA256), MCP access tokens as short-lived signed JWTs;
- secret management via a dedicated vault (Doppler), with no secret stored in clear text in the code;
- role-based access control (admin, sales, success, client, contributor) and token authentication (JWT, magic link, OAuth SSO, PAT); the same authorization check applies to calls made via the MCP server;
- audit log of MCP tool calls (see sections 3.2, 6.3 and 9);
- audit copy (BCC) of transactional emails for traceability and deliverability control. This copy is currently directed to an internal Caast address; Caast favors a dedicated functional address (for example audit@caast.tv) over an individual named address, in line with the minimization principle;
- redaction (masking) of personal data before logging where relevant;
- continuous database backups (WAL / PITR archiving) externalized to Cloudflare R2;
- use of subprocessors offering recognized security safeguards.
In the event of a data breach likely to result in a risk to your rights and freedoms, Caast notifies the CNIL and, where applicable, the data subjects, under the conditions set out in Articles 33 and 34 GDPR.
12. Data subjects' rights
12.1 Your rights
In accordance with Articles 15 to 22 GDPR, you have the following rights:
- Right of access: to obtain confirmation that your data is processed and to obtain a copy of it;
- Right to rectification: to have inaccurate or incomplete data corrected;
- Right to erasure ("right to be forgotten"): to have your data deleted in the cases provided for by the GDPR;
- Right to restriction of processing;
- Right to data portability: to receive your data in a structured, commonly used and machine-readable format, or to have it transmitted to another controller;
- Right to object: to object to processing based on legitimate interest, and at any time to commercial prospecting;
- Right to withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of processing carried out before withdrawal);
- Right not to be subject to a solely automated decision producing legal effects or significantly affecting you (Art. 22, see section 13);
- Right to issue directives regarding the fate of your data after your death.
For AI-related processing, you also have the specific right to object described in section 5.7.
12.2 How to exercise your rights
You can exercise your rights free of charge by writing to privacy@caast.tv. A proportionate identity check may be requested. Caast responds within one month of receiving the request, extendable by two months in the event of complexity or a high number of requests (you will be informed).
Data processed as a processor: if your request concerns data processed by Caast on behalf of a client brand (the controller), Caast will forward your request to that brand or assist in handling it, and may redirect you to it.
12.3 Complaint to the CNIL
If you believe your rights are not respected, you can lodge a complaint with the French Data Protection Authority (CNIL):
- CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Website: https://www.cnil.fr
13. Automated decision-making and profiling
Faast does not carry out any decision producing legal effects or significantly affecting data subjects solely on the basis of automated processing within the meaning of Article 22 GDPR.
The generative AI described in section 5 produces content (scripts, SMS, marketing, visuals, chat responses, extractions) at the user's request; these outputs are intended for human review and do not constitute automated decisions within the meaning of Article 22. No behavioral profiling of data subjects is carried out for decision-making purposes.
14. California residents' rights (CCPA / CPRA)
This section applies only if you are a California resident and the applicability thresholds of California law (CCPA as amended by the CPRA) are met. Since the expiry of the B2B exemption, professional contacts are also covered.
Subject to eligibility, you have the following rights:
- Right to know which categories of personal data are collected, used and shared;
- Right to delete your personal data;
- Right to correct inaccurate data;
- Right to opt out of the "sale" or "sharing" of your personal data ("Do Not Sell or Share My Personal Information"): Caast does not sell your personal data. We honor the Global Privacy Control (GPC) signal;
- Right to limit the use of your sensitive personal data;
- Right to non-discrimination for exercising these rights.
Regarding automated decision-making technologies (ADMT) introduced by the amended California regulations (effective 1 January 2026, with ADMT compliance for significant decisions from 1 January 2027), Faast does not carry out such significant automated decisions (see section 13).
To exercise these rights, write to privacy@caast.tv.
15. Minors
Faast is a professional (B2B) service, not intended for minors. The Service does not target minors, is not offered to them and does not knowingly collect data concerning them. If you believe a minor has provided us with personal data, contact privacy@caast.tv so that we can delete it.
16. Changes to this policy
Caast may amend this policy, in particular to reflect legal, regulatory or technical changes or the addition of subprocessors. The version in force is the one published on the Service, identified by its version number and update date at the top of the document.
In the event of a substantial change, Caast informs users by appropriate means (in-Service notification or by email). Changes relating to subprocessors are subject to prior information in accordance with the applicable contractual commitments, opening, where applicable, a right to object.
17. Contact and complaints
- Data protection questions / exercising rights: privacy@caast.tv
- Data Protection Officer (DPO): Caast has not appointed a DPO; requests are handled via privacy@caast.tv
- Controller: Caast, 165 avenue de Bretagne, 59000 Lille, France
- Supervisory authority: French Data Protection Authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, https://www.cnil.fr
This policy reflects information verified as of the last-updated date shown above. It may evolve; any substantial change will be communicated.