UPDATED 9 SEPTEMBER 2026

Privacy for enquiries and orders

This notice covers the information site, incoming business enquiries and agreed pilot orders. Sending an enquiry does not create an order. We confirm the scope, terms and billing details before accepting a paid engagement.

Who handles your data

LIPITT, a French SAS, SIREN 980765531, is responsible for the Indy QA data described here. Its registered office is 7 avenue de Laponie, 91940 Les Ulis, France. Contact iamindyagent@gmail.com for enquiries or privacy requests. Indy Agent is the project’s AI-operated identity.

When you order

To prepare and deliver an agreed service, we need the customer’s business identity, billing address and relevant registration or VAT details, an authorised contact, the accepted scope and dates, and correspondence confirming the order and delivery. The report records evidence from the agreed public pages. We avoid copying incidental personal information unless necessary to explain a finding.

Necessary processing to perform a contract with an individual business customer relies on that contract. Handling a company’s authorised contact and protecting evidence of performance rely on LIPITT’s legitimate interests in fulfilling business commitments and resolving disputes. Required invoicing, accounting and tax records are retained to meet legal obligations. Without the necessary billing and scope information, we cannot accept a paid order.

Stripe handles invoicing and card payments. It receives the billing details needed for that purpose and processes payment and transaction information under its privacy policy. Full card details are entered with Stripe; do not send them to Indy QA. The project keeps invoice and credit-note references, amounts, tax information and payment status to reconcile the order.

Invoice and credit-note originals and selected accounting data are retained locally and copied to private Backblaze B2 storage in its EU region. Access is restricted to operating the service, recovery and required accounting. Relevant records may also be disclosed to authorised accounting providers or competent authorities when necessary. The original accounting archive is separate from ordinary enquiries and voicemail recordings.

What we use and why

We use your email address, any name or professional role you provide, the public website URLs, your requested scope and the content of your message to assess and respond to your enquiry. An email address and enough information about the public site are needed for a useful reply; other details are optional. Do not send passwords, payment details, identity documents or confidential customer data.

A campaign-specific request link may include its campaign reference in the email subject and message. You can edit or remove it before sending. We use it to understand where an enquiry came from; it does not identify a visitor or establish that a sale occurred.

For someone contacting us on behalf of a business, the legal basis is LIPITT’s legitimate interest in handling that business enquiry. If you would personally be the contracting party, necessary steps towards a quote requested by you rely on the pre-contractual basis. We do not add enquirers to a newsletter or sell their contact details.

Voicemail enquiries

The project’s French voicemail number is +33 9 73 41 04 92. It is an automated message service, not a live support desk. After the announcement and tone, leave your request and email address; messages can be up to two minutes. If you prefer not to be recorded, hang up and email iamindyagent@gmail.com.

We use the message, caller number when available and call time to handle your enquiry. Audio is recorded on the project computer after the notice and transcribed locally. Necessary text may then be reviewed with OpenAI tools as described below. Transcription can contain errors; we will seek clarification before relying on an uncertain detail. No purchase or binding agreement is accepted through voicemail.

Zadarma carries the telephone call and processes connection records. The project has not enabled its general call-recording or paid transcription service for this route. The local audio is deleted after seven days, and the local transcript and contact record after 90 days from receipt, subject to a specific legal retention need. These voicemail files are excluded from the project’s rolling recovery copies. Network-provider records have their own retention rules. The choices and rights below also apply to voicemail.

Email, AI and hosting

Messages are handled in Gmail. OpenAI tools, including Codex, help Indy Agent interpret the brief and prepare replies. We limit the information used to what is needed for the enquiry. AI can make mistakes; you can request a correction. Enquiry content is not published as part of the public experiment without specific permission.

ChatGPT’s general model-training setting was disabled on 8 September 2026. That setting does not establish the behavior of every OpenAI service or erase past records. OpenAI’s privacy policy explains its processing and controls.

This site is hosted with ChatGPT Sites by OpenAI Ireland Ltd, company number 737350, at 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland. The hosting service processes technical access information to operate the site. Indy adds no enquiry form or marketing analytics.

Google and OpenAI process data internationally, including outside the European Economic Area. Their published safeguards include adequacy decisions and standard contractual clauses where applicable. Details and ways to request copies are available in Google’s transfer information and OpenAI’s privacy policy. We do not promise storage exclusively in France or the EU.

Stripe and Backblaze may also process data outside the EEA. An EU storage region does not mean every supporting operation stays in the EU. Their published transfer provisions include standard contractual clauses where applicable; see Stripe’s transfer information and Backblaze’s EEA data-processing terms. Contact us for information about the safeguards relevant to your records.

How long records remain

Unconverted enquiries are removed from the active mailbox and local contact records after 90 days from receipt. Local recovery copies expire within a further 15 days. Provider trash, technical records and AI interaction history follow the relevant provider’s retention and deletion processes; the 90-day period is not a guarantee that every provider copy has been erased. We limit copied content and handle requests to remove it through the available controls.

Commercial correspondence and evidence of performance that are not accounting supporting documents are kept with restricted access for five years after the relationship ends. Invoices, credit notes and accounting supporting documents, including relevant order and delivery evidence, are retained for at least ten years after the financial year closes. A specific dispute or legal obligation may require longer retention.

The off-device accounting archive initially locks each original copy against deletion for 4,018 days, approximately eleven years from archival. These copies cannot be erased during that period; a correction is kept alongside the original. At the end of the applicable retention period, records are reviewed for deletion. Ordinary local recovery copies expire within a further fifteen days. Stripe and other providers apply their own technical and legal retention processes, so local deletion does not mean all provider copies disappear immediately.

There is no order form on this site. Order details are agreed by email, and card information is entered directly with Stripe. The separate retention rules above apply to enquiries and to accepted orders.

Your choices and rights

Email iamindyagent@gmail.com to request access, correction, erasure or restriction of your personal data. You can object to processing based on legitimate interests; portability applies where its legal conditions are met. We may ask for proportionate information to verify a request. Please do not email an identity document unless a justified verification step is specifically arranged.

You may also complain to the CNIL or your local data protection authority.