BellumAI

Legal documentation

Privacy and personal data protection policy

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR"), and with French Law No. 78-17 of 6 January 1978 as amended, relating to information technology, data files and civil liberties.

Last updated : May 25, 2026

01

Preamble

The protection of your personal data is a priority for BELLUM. This policy describes the way in which we collect, process and protect your personal data in connection with the use of the website www.bellum-ai.com and the BellumAI platform (together referred to hereinafter as the "Site").

This policy may be supplemented by additional information specified in all or part of a service provided. We may modify, supplement or update this policy at any time, in particular in order to comply with any legal, regulatory or technical development. Any modification shall take effect from the date on which the amended policy is published online.

02

Data controller

The controller of the processing of personal data is BELLUM, a SASU with a share capital of 1,000.00 euros, registered under number 931 750 681 R.C.S. Paris, whose registered office is located at 90, rue des Archives, 75003 Paris.

For any question relating to the protection of your personal data, please contact us at the following details: dpo@bellum-it.com, or by post for the attention of the Data Protection Officer, BELLUM, 90 rue des Archives, 75003 Paris.

03

Data collected

2.1. Data provided directly by the user

When you create your account and use the platform, the following data is collected: surname and first name; professional email address; name of the employing company; information relating to the user's commercial profile as provided during the registration questionnaire (business sectors, service offerings, geographic area, team size, commercial positioning); notes, comments and annotations entered by the user in the platform.

With regard to payment data, this is processed exclusively by our PCI-DSS certified payment provider. BELLUM does not store, collect or have access to any banking data (card number, security code, expiry date).

2.2. Data collected automatically

When you browse the Site and use the platform, the following data may be collected automatically: IP address; browser type and version; operating system; pages viewed and viewing duration; connection data (dates, times, session identifiers); actions performed in the platform (analyses launched, messages copied, contacts enriched).

2.3. Data obtained from other sources

We may also obtain information from other sources, such as: publicly accessible sources (legal registers, professional directories, official publications, information published by the data subjects themselves on public professional networks); the proprietary database of BELLUM, built and enriched in compliance with the applicable legal framework.

2.4. Data relating to third parties (professional contacts)

As part of its business intelligence features, the BellumAI platform references data relating to third-party professional contacts. This data is built exclusively from publicly accessible sources and from the proprietary database of BELLUM. It may include: surnames and first names of professional contacts; roles and job titles; professional contact details (professional email address, professional telephone number); attachment to a legal entity; information published publicly by the data subject in a professional context.

This data is strictly professional in nature. No data relating to private life, no sensitive data within the meaning of Article 9 of the GDPR, and no data relating to minors is collected or processed.

04

Purposes and legal bases of the processing

We collect or process your personal data in compliance with the GDPR, for the following purposes and on the following legal bases:

  • Creation and management of the user account: legal basis of the performance of the contract (Article 6.1.b of the GDPR).
  • Provision of the platform's services, including company analyses, contact identification, the generation of strategic recommendations and personalised messages: legal basis of the performance of the contract (Article 6.1.b of the GDPR).
  • Personalisation of the user experience according to the declared commercial profile: legal basis of legitimate interest (Article 6.1.f of the GDPR).
  • Billing, management of subscriptions and credits: legal basis of the performance of the contract (Article 6.1.b) and of legal obligation (Article 6.1.c of the GDPR).
  • Building and enriching the database of professional contacts from publicly accessible sources, in order to enable users to identify relevant interlocutors in a business-to-business (B2B) commercial prospecting context: legal basis of legitimate interest (Article 6.1.f of the GDPR). BELLUM has carried out a balancing test between this legitimate interest and the rights and freedoms of the data subjects, in accordance with the CNIL's recommendations. The data processed is strictly professional, publicly accessible, and its processing falls within the reasonable expectations of persons holding decision-making roles within companies.
  • Improvement of services, development of new features and production of anonymised usage statistics: legal basis of legitimate interest (Article 6.1.f of the GDPR).
  • Commercial communication relating to BELLUM services: legal basis of consent (Article 6.1.a of the GDPR), or of legitimate interest for existing customers under the conditions provided for by Article L. 34-5 of the French Postal and Electronic Communications Code.
  • Compliance with legal and regulatory obligations: legal basis of legal obligation (Article 6.1.c of the GDPR).
  • Fraud prevention and platform security: legal basis of legitimate interest (Article 6.1.f of the GDPR).
05

Data retention period

  • User account data is retained for the entire duration of the contract, then for a period of three years from the deletion of the account or the last active contact with the user.
  • Billing data is retained for a period of ten years, in accordance with the accounting and tax obligations provided for by Article L. 123-22 of the French Commercial Code.
  • Connection data and access logs are retained for a period of one year from their collection, in accordance with the provisions of the law for confidence in the digital economy (LCEN).
  • Analysis data generated by the platform (company profiles, identified contacts, action plans, messages) is retained for the entire duration of the contract and deleted within thirty days after the termination of the subscription.
  • Third-party professional contact data is retained for a period of three years from collection or from the last update, in accordance with the CNIL's recommendations on commercial prospecting.
  • Cookies and trackers are retained for a maximum period of thirteen months.

Beyond the periods indicated above, data is deleted or irreversibly anonymised. In the event of litigation proceedings, the relevant data may be retained for the entire duration of the proceedings and until all avenues of appeal have been exhausted.

06

Recipients of the data

The personal data collected may be communicated to the following recipients: authorised staff of BELLUM, strictly within the limits of their duties; technical subcontractors involved in the hosting, maintenance and operation of the platform, bound by contractual clauses compliant with Article 28 of the GDPR; the payment provider, solely for the processing of financial transactions; the judicial or administrative authorities, where the law so requires.

BELLUM does not carry out any transfer, rental or provision of personal data to third parties for commercial purposes. It does not sell its users' data.

The commitments that BELLUM undertakes under this policy are reflected in the commitments it has entered into with its subcontractors, BELLUM remaining solely responsible towards the user for the performance of its obligations.

07

Transfers of data outside the European Union

Some of BELLUM's technical subcontractors may be established outside the European Union. Where applicable, these transfers are governed by the safeguards provided for by the GDPR: an adequacy decision of the European Commission (in particular the EU-United States Data Privacy Framework, adopted on 10 July 2023), standard contractual clauses adopted by the European Commission, or any other adequate safeguard within the meaning of Articles 46 and 49 of the GDPR.

You may obtain a copy of the safeguards put in place by writing to dpo@bellum-it.com.

08

Data security

BELLUM implements appropriate technical and organisational measures in order to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR, and in particular: the encryption of data in transit (TLS 1.2 protocol at a minimum) and at rest; secure authentication mechanisms with session management; the partitioning of data between users through row-level access control policies at the database level; the logging of accesses and actions; regular backups and tested restoration procedures; the restriction of access to authorised persons only.

Access to the platform is carried out by means of personal credentials (email address and password) and through a secure connection using the HTTPS protocol. The user is responsible for the confidentiality of their credentials and must protect access to them.

BELLUM regards as strictly confidential any information and any document of which it may become aware in connection with the performance of its services, and refrains from disclosing it except in cases where the disclosed elements are in the public domain at the date of disclosure or obtained from third parties by legitimate means.

09

Notification of data breaches

In the event of a personal data breach within the meaning of Article 4(12) of the GDPR, BELLUM undertakes to notify the Commission nationale de l'informatique et des libertés (CNIL) within seventy-two hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of the data subjects. Where the breach is likely to result in a high risk, the data subjects will also be informed as soon as possible.

10

Rights of data subjects

In accordance with Articles 15 to 22 of the GDPR and the French Data Protection Act, you have the following rights over your personal data:

  • The right of access: you may obtain confirmation as to whether or not data concerning you is being processed and, where applicable, access said data as well as a certain amount of additional information (purposes, categories of data, recipients, retention period).
  • The right to rectification: you may obtain the rectification of inaccurate or incomplete data concerning you.
  • The right to erasure (right to be forgotten): under the conditions provided for by Article 17 of the GDPR, you may obtain the erasure of your personal data, except where the processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
  • The right to restriction of processing: in the cases defined in Article 18 of the GDPR, you may obtain the restriction of the processing of your data.
  • The right to object: you may object to the processing of your personal data where the processing is based on legitimate interest, including profiling. BELLUM may however maintain the processing for compelling legitimate grounds that override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
  • The right to portability: you may receive your personal data in a structured, commonly used and machine-readable format, and transmit it to another controller.
  • The right to withdraw consent: where the processing is based on consent, you may withdraw your consent at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
  • The right to set out directives relating to the fate of your data after your death, in accordance with French law.

To exercise these rights, send your request together with a valid proof of identity: by email to dpo@bellum-it.com ; or by post to BELLUM, 90 rue des Archives, 75003 Paris, for the attention of the GDPR Department. BELLUM undertakes to respond within one month of receipt of the request. This period may be extended by a further two months in the event of complexity or a high number of requests.

11

Rights of third-party professional contacts

In accordance with Article 14 of the GDPR relating to the information to be provided where the data has not been collected from the data subject, BELLUM informs the professional contacts whose data is referenced in its database that they have the same rights as those described above, and in particular the right to object at any time to the processing of their data.

Any request to object or to delete will be processed within thirty days. The data subject's data will then be permanently deleted from BELLUM's database and will no longer be accessible to the platform's users. The data subject's email address will be entered on a permanent objection list in order to prevent any subsequent collection.

The sources of the data are: the French legal registers, publicly accessible company directories, information published by the persons themselves in a professional context, and the proprietary database of BELLUM.

12

Complaint to the CNIL

If you consider that the processing of your personal data constitutes a breach of the GDPR, you have the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), the French supervisory authority. CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07. Website: www.cnil.fr.

BELLUM also informs the user of the existence of the Bloctel telephone marketing opposition list, on which they may register (https://conso.bloctel.fr/).