Privacy Policy


Privacy Policy

Last updated: 27 May 2025

Thank you for trusting ZeGuild SAS (“Company,” “we,” “our” or “us”). We operate the software-as-a-service platform available at ideascan.co (the “Service”), which allows customers to submit product or business ideas, automatically research competitive offerings, retrieve community feedback from Reddit, and generate a “frustration score” reflecting unmet market need.

This Privacy Policy explains how we collect, use, disclose, and safeguard Personal Data when you visit our website or use the Service, and describes the rights and choices available to you. Capitalized terms not defined here have the meaning given in our Terms of Service.

If you do not agree with any part of this Privacy Policy, please do not access or use the Service.


1. Scope

This Privacy Policy applies to Personal Data we process as a “controller” or, where applicable, as a “business” under the California Consumer Privacy Act (CCPA/CPRA). It does not apply to content that you choose to make public (e.g., posts you publish on Reddit or other third-party sites).


2. Personal Data We Collect

CategoryExamplesSourcePurpose
Account InformationName, email address, password (hashed)YouCreate & administer your account; security
Idea SubmissionsTextual descriptions, files, attachmentsYouPerform competitive analysis & scoring
Encrypted Idea ContentAES-256 encryption of Idea Submissions prior to persistenceYouConfidential storage; only decrypted in volatile memory for processing
Usage DataIP address, browser type, device ID, activity logs, referring URLs, cookies, analytics identifiersAutomated collectionService provision, diagnostics, analytics, security
Support DataMessages, tickets, call recordingsYouRespond to inquiries; improve support
Marketing PreferencesOpt-in/opt-out statusYouRespect communication choices

We do not knowingly collect data from children under 13, nor do we use sensitive Personal Data (as defined under the CPRA) for inferring characteristics.


3. How We Use Personal Data

We process Personal Data only when we have a valid legal basis:

PurposeLegal Basis (GDPR Art. 6)
Provide, maintain & secure the Service; generate frustration scoresPerformance of contract (Art. 6 (1)(b))
Improve and develop new features; train algorithms on fully anonymised dataLegitimate interests (Art. 6 (1)(f))
Send transactional emails & administrative messagesPerformance of contract
Send marketing communications (newsletters, product updates)Consent (Art. 6 (1)(a))
Comply with legal obligations (tax, fraud prevention, court orders)Legal obligation (Art. 6 (1)(c))

We do not sell or “share” Personal Data for cross-context behavioural advertising within the meaning of the CPRA.


4. Cookies & Similar Technologies

We use strictly necessary cookies for authentication and session management, and optional cookies for analytics (e.g., Google Analytics, Plausible) and customer support chat. Where required, we request your consent via a cookie banner. You can withdraw consent or change preferences at any time through the “Cookie Settings” link in the footer or via your browser settings.


5. Disclosures & Recipients

We disclose Personal Data only:

  1. Service Providers – cloud hosting, database backups, analytics, payment processors, customer support platforms—each bound by confidentiality and data-processing agreements.

  2. Legal & Safety – to courts, regulators, or law enforcement if required or to protect rights, safety, or property.

  3. Corporate Transactions – in connection with a merger, acquisition, or sale of assets, provided the recipient agrees to safeguard the data.

  4. Aggregated / De-identified Data – statistics that cannot reasonably be used to identify you.

We never grant service providers access to your unencrypted Idea Submissions; only encrypted blobs are stored at rest. Decryption occurs transiently within isolated compute environments during processing.


6. International Transfers

We are headquartered in France and may store or process data in jurisdictions that may not provide equivalent data-protection laws. When we transfer Personal Data from the European Economic Area (EEA), Switzerland, or the United Kingdom to a third country, we rely on any of the following:

  • Adequacy decisions of the European Commission;

  • European Commission–approved Standard Contractual Clauses (SCCs) with supplementary safeguards (e.g., encryption, access controls);

  • Your explicit consent (Art. 49 (1)(a)) when other mechanisms are unavailable.


7. Data Retention

Data CategoryRetention Period
Account & Idea DataWhile account is active + 90 days (unless earlier deletion is requested)
Usage Logs180 days (aggregated thereafter)
Marketing ListsUntil you unsubscribe or request erasure
Legal/Financial RecordsSeven (7) years or as required by law

We may retain anonymised or aggregated data indefinitely for statistical or research purposes.


8. Security Measures

  • Encryption – TLS 1.3 in transit; AES-256 at rest; per-record encryption of Idea Submissions.

  • Access Controls – role-based access, MFA, least-privilege principles.

  • Network Security – firewalls, IDS/IPS, zero-trust architecture.

  • Application Security – automated dependency scanning, penetration testing, CI/CD code reviews.

  • Incident Response – documented plan including user notification within 72 hours of discovering a notifiable breach (GDPR Art. 33).

No internet transmission or storage system is 100 % secure; however, we follow industry standards to protect your data.


9. Your Rights

Depending on your location, you may have the right to:

RightJurisdictions
Access and obtain a copy of Personal DataGDPR, CCPA
Rectify inaccurate or incomplete dataGDPR
Erase (“right to be forgotten”)GDPR
Restrict or object to processingGDPR
Port data to another controllerGDPR
Opt-out of “sale” or “sharing” of dataCCPA/CPRA
Limit use of sensitive Personal DataCPRA
Lodge a complaint with a supervisory authorityGDPR

To exercise any right, email [email protected] or visit app.ideascan.co. We will respond within 30 days (GDPR) or 45 days (CCPA), subject to verification of identity.


10. Automated Decision-Making & Profiling

Our algorithm analyses publicly available discussions (e.g., Reddit threads) and metadata about competing products to estimate a “Frustration Score.” The score is provided for informational purposes and is not used to make decisions that produce legal or similarly significant effects about a natural person. You may request human review of any automated output by emailing support@[domain].


11. Children’s Privacy

The Service is not intended for persons under 13 (or under 16 in the EEA). We do not knowingly collect Personal Data from children. If we learn that a child has provided us with Personal Data, we will delete it immediately.


12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will:

  • post the updated version with a new “Last updated” date; and

  • where appropriate, provide prominent notice (e.g., email or in-app notification) and request consent if required by law.


13. Contact Us

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact:

ZeGuild SAS
8 rue de penthievres 75008 France
Email: [email protected]