General terms and conditions of sale and use
Version dated 2 October 2026
This translation is provided for information only. Only the French version of this document is legally binding.
Article 1. Purpose and acceptance
1.1. These general terms and conditions of sale and use (the “Terms”) govern the subscription to and use of the Tacite-IA service provided by Simplymy, a SASU (French simplified joint-stock company with a single shareholder) with share capital of €1,000, registered with the Nanterre Trade and Companies Register (RCS) under number 909 119 018, EU VAT number FR15 909 119 018 (the “Provider”), by any organisation that creates a Tacite-IA workspace (the “Client”).
1.2. The Service is intended for organisations (companies, associations, public bodies) and their members acting for professional purposes. The Client declares that it is acting in that capacity. The provisions of the French Consumer Code do not apply, subject to the mandatory provisions applicable to non-professionals, in particular associations.
1.3. The online subscription, concluded when the payment form is validated, constitutes the Client’s unreserved acceptance of the Terms, the Client being represented by the person who creates the workspace and who declares that they have the authority to bind it.
Article 2. Definitions
- “Service”: the Tacite-IA solution, comprising the Tacite-IA program installed on computers, the browser extension, the modules for coding assistants, the licensing and update service, and the administration area.
- “Administration”: the online area reserved for the Administrator, accessible at admin.tacite-ia.com.
- “Administrator”: the person appointed by the Client to manage the Service. There is one Administrator per Client.
- “Subscription”: the contract under which the Client accesses the Service, for a number of Devices and a monthly or annual period.
- “Organisation Key”: the confidential identifier used to activate the Service on the Client’s Devices.
- “Device”: a computer, or a user session, on which the Service is activated with the Organisation Key.
- “User”: any natural person authorised by the Client to use the Service on a Device.
Article 3. Description of the Service
3.1. The Service analyses, exclusively on the Devices, messages, copied and pasted content, files, commands and actions of coding assistants at the time they are sent to artificial intelligence assistants, flags any sensitive data detected and offers to anonymise it or to block the action. No analysed content is transmitted to the Provider.
3.2. The licensing service sends the Devices the detection rules, the policy defined by the Administrator and program updates. It receives from the Devices only the information described in Article 9 (protection events, without values or content).
3.3. Nature of the Service. The Service is an aid to preventing data leaks. Detection is rule-based and cannot be exhaustive: some sensitive data may not be detected and some alerts may be raised in error. Certain tools do not technically allow any control (in particular certain chat applications installed on the computer); the list of tools covered is available on the website and in the documentation. The Service does not replace the Client’s data protection obligations, its security policy or the vigilance of Users. Where a User chooses to send data despite an alert, that decision is the sole responsibility of the Client.
3.4. The Provider may develop the Service, in particular its detection rules and the tools covered, in order to improve it.
3.5. Installation and updates. The Tacite-IA program writes into the configuration of the browsers and coding assistants present on the Devices only the settings required for it to operate, without deleting existing settings; uninstalling it removes those settings. The Client authorises the installation of updates according to the mode chosen in the Administration (automatic, deferred or manual). It is the Client’s responsibility to test the Service on a limited number of Devices before a general rollout and to keep its own backups.
Article 4. Trial, subscription, prices and payment
4.1. The workspace is created online on the tacite-ia.com website, after confirmation of the Administrator’s email address and registration of a valid payment method (bank card or SEPA Direct Debit mandate) with the payment provider Stripe. The Client guarantees the accuracy of the information provided, in particular the name of the organisation and the Administrator’s email address.
4.2. Free trial. The Subscription begins with a free trial of three (3) months from the creation of the workspace. No amount is charged during the trial. The Client may cancel at any time during the trial from the Administration, free of charge. Only one trial is granted per organisation.
4.3. At the end of the trial, the Subscription automatically continues on a paid basis, for the number of Devices chosen by the Client, and the first period is invoiced, unless it is cancelled before the end of the trial. In the absence of a valid payment method, the Subscription ends and the Service stops operating on the Devices.
4.4. Prices. The price is set per Device (referred to as a “user” on the website and in the Administration), for a monthly or annual period, according to the rate in force on the date of subscription, as displayed on the website. Prices are expressed in euros excluding taxes; applicable VAT is added. A Client established in another Member State of the European Union with a valid VAT number is invoiced excluding taxes, under the reverse-charge mechanism. Above two hundred and fifty (250) Devices, or for additional services (deployment assistance, training), the terms are set out in a quotation accepted in writing.
4.5. Invoicing and payment. The Subscription is payable in advance, at the start of each period, by bank card or SEPA Direct Debit, through Stripe. It is tacitly renewed for successive periods of the same length. Invoices are made available in the Administration. The Provider never has access to bank card numbers.
4.6. Number of Devices. The Client adjusts the number of Devices from the Administration, including during the trial, which then continues without any charge. After the trial, added Devices are invoiced immediately, pro rata to the current period; a reduction in Devices gives rise to a credit note applied to subsequent invoices. A margin of twenty per cent (20%) above the number of Devices subscribed is tolerated; beyond that, the activation of new Devices is refused until the Subscription has been adjusted.
4.7. Late payment. In accordance with Article L. 441-10 of the French Commercial Code, any sum not paid by its due date automatically bears interest at three times the statutory interest rate and gives rise to a fixed indemnity for recovery costs of forty (40) euros, without prejudice to additional compensation upon presentation of supporting evidence. The Service remains available for fourteen (14) days from the unpaid due date; thereafter, the Provider may suspend it without further formality until payment is made in full.
4.8. Price changes. The Provider may change its rates. Any change is notified to the Administrator at least thirty (30) days before it takes effect and applies from the following period. A Client that refuses the change may cancel the Subscription before that date.
4.9. The Provider may refuse or close a workspace in the event of abuse, in particular the creation of multiple workspaces in order to obtain repeated trials, manifestly false information or use contrary to Article 5.
Article 5. Licence to use
5.1. The Provider grants the Client, for the term of the Subscription, a personal, non-exclusive, non-assignable and non-transferable right to use the Service for its internal needs, within the limit of the number of Devices subscribed.
5.2. The Client and Users are prohibited in particular from: disclosing the Organisation Key to third parties; reproducing, modifying, decompiling or disassembling the Service, except within the limits provided for by law; circumventing or attempting to circumvent the licensing, protection or Device-counting mechanisms; extracting, copying or reusing the detection rules; making the Service available to third parties or using it to provide a competing service.
5.3. Any breach of Article 5.2 entitles the Provider to revoke the Organisation Key and the Devices concerned and, where applicable, to terminate the Subscription under the conditions of Article 12.3, without prejudice to any damages.
Article 6. Client’s obligations
6.1. The Client is responsible for deploying the Service on its Devices, for choosing its detection policy and for configuring its computers, browsers and tools.
6.2. The Client keeps the Organisation Key and the Administrator’s credentials (password and authenticator app) confidential. It informs the Provider without delay of any loss or disclosure and renews the Organisation Key from the Administration.
6.3. The Client informs its Users in advance of the introduction of the Service and, if it enables User identification, complies with its obligations under data protection and employment law (individual information, consultation of employee representatives where applicable, impact assessment where necessary).
6.4. The Client uses the Service in accordance with its intended purpose, these Terms and applicable regulations.
6.5. The Client indemnifies the Provider against any claim, action or judgment by third parties, in particular Users, their representatives or an authority, resulting from the Client’s failure to comply with Articles 6.1 to 6.4.
Article 7. Availability and support
7.1. The Provider uses reasonable means to ensure the availability of the licensing service and the Administration, without any service level commitment. Devices continue to protect Users without a connection to the licensing service for the validity period of the rules received (seven days).
7.2. Support is provided by email at support@simplymy.fr, as far as possible, with no guaranteed response time.
7.3. The Provider may temporarily suspend all or part of the licensing service or the Administration for maintenance or updates, or in the event of a threat to the security of the Service or its clients, limiting the duration of the suspension as far as possible.
Article 8. Intellectual property
8.1. The Service, its components, its detection rules, its documentation, its trade marks and its logos are and remain the exclusive property of the Provider or its licensors. No right other than that provided for in Article 5 is granted to the Client.
8.2. The Client remains the owner of its data. It authorises the Provider to use, on an aggregated and anonymous basis, usage statistics of the Service that do not allow the Client to be identified, in order to improve the Service.
Article 9. Personal data
9.1. Analysed content. Content is analysed exclusively on the Devices: the Provider has no access to any content, detected value, text or file name.
9.2. Data processed on behalf of the Client. In order to provide the Service, the Provider processes, as the Client’s processor, the technical identifiers of the Devices, protection events (date, event type, decision, tool concerned, data types and counts) and, if the Client enables it, the User’s session name on the computer; as well as the Administrator’s account data required for the Administration. This processing is governed by the data processing agreement set out in the annex, which forms an integral part of the Terms.
9.3. Data processed on behalf of the Provider. The Provider processes, as controller, the data of its clients required for account management, in accordance with its privacy policy available at tacite-ia.com/confidentialite.
Article 10. Liability
10.1. The Provider is bound by an obligation of means (best endeavours).
10.2. The Provider shall not be held liable for: data transmitted by a User despite an alert, or not detected given the nature of the Service described in Article 3.3; any configuration, deployment or use of the Service that does not comply with the Terms or the documentation; the operation of artificial intelligence assistants, browsers, operating systems and third-party tools.
10.3. Under no circumstances shall the Provider be liable for indirect damage, such as loss of turnover, customers, data or image, or damage to reputation.
10.4. The Provider’s total liability, for all causes combined, is limited to the amount excluding taxes actually paid by the Client for the Service during the twelve (12) months preceding the event giving rise to liability, and to one hundred (100) euros during the trial. This limitation does not apply in the event of gross negligence or wilful misconduct, or to personal injury.
Article 11. Confidentiality
Each party keeps confidential the information of the other party of which it becomes aware in the course of performing the Terms, in particular the Organisation Key, throughout the term of the Subscription and for five (5) years after it ends.
Article 12. Term and termination
12.1. The Subscription takes effect when the workspace is created, for the duration of the trial and then of the period chosen, and is tacitly renewed under the conditions of Article 4.5.
12.2. The Client may cancel the Subscription at any time from the Administration (Subscription page) or by email to support@simplymy.fr. Cancellation takes effect at the end of the trial or of the current period; sums paid for the current period remain due to the Provider.
12.3. The Provider may terminate the Subscription at the end of the current period by giving three (3) months’ notice. In the event of a serious breach by either party that is not remedied within thirty (30) days of formal notice, the other party may terminate the Subscription automatically, without prejudice to any damages. This period is reduced to eight (8) days in the event of a breach of Article 5.2.
12.4. At the end of the Subscription, the Service stops operating on the Devices. The Client may export protection events from the Administration until that date. The Client’s data is deleted within thirty (30) days.
12.5. The Provider may permanently discontinue the Service for all of its clients by giving ninety (90) days’ notice to the Administrator. Sums paid in advance for the unused period are then refunded.
Article 13. References
Unless the Client objects in writing, the Provider may mention the Client’s name and logo as a reference.
Article 14. Force majeure
Neither party is liable for a failure resulting from an event of force majeure within the meaning of Article 1218 of the French Civil Code. If the impediment lasts more than thirty (30) days, either party may terminate the Subscription in writing.
Article 15. Changes to the Terms
The Provider may amend the Terms. Amendments are notified to the Administrator at least thirty (30) days before they come into force. A Client that refuses them may cancel the Subscription before that date; failing this, they apply from the following period.
Article 16. General provisions
16.1. Evidence. The records of the licensing service and the Administration (dates, events, action log) are binding between the parties, unless proven otherwise.
16.2. The Terms and their annex constitute the entire agreement between the parties with respect to their subject matter. If any of their provisions is declared void, the others remain in full force and effect. A party’s failure to invoke a breach does not constitute a waiver of its right to invoke it subsequently.
16.3. The Provider may assign the Terms to any company that takes over the Service; the Client will be informed.
Article 17. Governing law and disputes
17.1. The Terms are governed by French law.
17.2. The parties will seek an amicable solution to any dispute. Failing agreement within thirty (30) days, any dispute relating to the formation, performance or interpretation of the Terms falls within the exclusive jurisdiction of the Tribunal des activités économiques (Economic Activities Court) of Nanterre, including in the event of multiple defendants or third-party claims.
17.3. The Terms are drawn up in French. Translations may be made available for information purposes; in the event of any discrepancy, only the French version is authoritative.
Annex. Data processing agreement (Article 28 of the GDPR)
1. Purpose. This agreement sets out the conditions under which the Provider (the “Processor”) processes personal data on behalf of the Client (the “Controller”) in connection with the Service, in accordance with Article 28 of the GDPR.
2. Description of the processing.
| Purpose | Provision of the Service: management of licences and Devices, the Administrator’s dashboard and reports. |
|---|---|
| Nature | Collection, recording, consultation, aggregation, export and deletion. |
| Data subjects | Users of the Devices; the Administrator. |
| Categories of data | Technical identifiers of the Devices (random identifier, type, version); protection events (date, event type, decision, tool concerned, data types and counts); the User’s session name on the computer if the Controller enables identification; the Administrator’s account (email address, password hash, encrypted two-factor authentication secret, log of their actions). No analysed content and no detected values. |
| Duration | For as long as the Service is used; events retained for the period chosen by the Controller (180 days by default, from 30 days to 3 years); Administrator’s log: 3 years. |
| Location | Database subject to the jurisdiction of the European Union (Cloudflare D1, EU jurisdiction). |
3. Processor’s obligations. The Processor undertakes to: process the data only for the purpose described and on the documented instructions of the Controller, these Terms and the settings of the Administration constituting such instructions; guarantee the confidentiality of the data and ensure that persons authorised to process it are bound by a duty of confidentiality; implement the security measures described in point 5; assist the Controller in responding to requests from data subjects to exercise their rights, in particular through the export and deletion functions of the Administration; assist it in ensuring compliance with its obligations relating to security, breach notification and impact assessments; inform it immediately if, in its opinion, an instruction infringes the regulations.
4. Sub-processors. The Controller authorises the use of the following sub-processor: Cloudflare, Inc. (hosting of the licensing service, the Administration and the database). The Processor informs the Controller of any addition or replacement at least thirty (30) days in advance; the Controller may object on legitimate grounds and, failing agreement, stop using the Service. Any transfers outside the European Union are governed by the European Commission’s standard contractual clauses and, where applicable, by the EU-US Data Privacy Framework.
5. Security. Content analysed exclusively on the Devices (data minimisation); encryption of communications (HTTPS, HSTS); database not exposed to the internet; signed detection rules and licences; passwords protected by key derivation and a server secret; mandatory two-factor authentication for the Administrator; lockout after failed attempts; time-limited sessions; log of the Administrator’s actions; strict segregation between clients; automatic purging according to retention periods.
6. Data breach. The Processor notifies the Controller of any personal data breach without undue delay and no later than forty-eight (48) hours after becoming aware of it, with the information available.
7. Audit. The Processor makes available to the Controller the information necessary to demonstrate compliance with this agreement. The Controller may carry out an audit, at its own expense, once a year, subject to thirty (30) days’ notice, by an auditor bound by professional secrecy who is not a competitor of the Processor.
8. End of processing. When the workspace is closed, the Processor deletes the data within thirty (30) days, after having enabled its export via the Administration.