This policy describes the personal data collected by FerrLabs (Bryan Ferrando, sole proprietor, SIREN 104 243 951) acting as data controller for the FerrFleet service, in accordance with the GDPR.
Data collected
- Account: email address, password (hashed with Argon2id), display name, timezone, locale.
- Organization: name, slug, team size, country.
- Audit: IP address, user-agent, timestamps of sensitive actions.
- Cookies:
fl_session(httpOnly, SameSite=Lax, 7-day lifetime) — strictly necessary for authentication. - Server logs: 30-day retention.
- Agent runs: invocation parameters, full transcript (prompts, tool calls, model responses), token counts, USD cost, exit code, started_at, finished_at, attributing user. Persisted in the
agent_runstable for replay and billing reconciliation. - Agent catalog: agent name, prompt template, working directory, default sub-agents, owner, attached MCP skills (server URLs, scope, optional auth headers encrypted at rest).
When an agent runs, your prompts and outputs may be transmitted to Anthropic as a sub-processor for the execution of Claude Code. This data is subject to Anthropic's privacy policy. No training is performed on your prompts (standard API mode under Anthropic's commercial terms). Session IDs returned by Claude Code are stored to enable resume, continue, and replay flows.
Purposes
- Authentication and access to the service.
- Operation and security of the platform.
- Execution of agent runs (dispatch, observability, replay).
- Billing of paid subscriptions and usage-based run charges.
- Compliance with legal obligations.
Legal bases (GDPR art. 6)
- Performance of the contract (6.1.b) for accounts, subscriptions, and run execution.
- Legitimate interest (6.1.f) for security, audit logs, and abuse prevention.
- Legal obligation (6.1.c) for accounting and tax data.
Sub-processors
- OVH SAS — hosting (France).
- Anthropic PBC — Claude API for agent execution (United States, certified under the Data Privacy Framework). Active on every agent run; receives the prompt and any tool outputs forwarded by the agent.
- Stripe Inc. — payments (United States, certified under the Data Privacy Framework) — active when a paid subscription is activated.
- Resend — transactional emails (European Union) — active when transactional emails are sent.
Retention period
| Data | Retention |
|---|---|
| Active account | For the lifetime of the account |
| Deleted account | 90 days, then permanent purge |
| Server logs | 30 days |
| Agent run transcripts | For the lifetime of the workspace; deleted on workspace deletion |
| Cost ledger | 13 months for billing reconciliation |
| Audit log | 90 days after the action |
| Billing data | 10 years (art. L.123-22 of the French Commercial Code) |
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, portability, objection, and restriction of processing. FerrFleet-specific exports (agents catalog + run transcripts) are available through the in-app Data export screen.
To exercise your rights: contact@ferrlabs.com.
You may also lodge a complaint with the CNIL (cnil.fr).
Data Protection Officer (DPO)
FerrLabs has not appointed a DPO. This is not required for a sole proprietorship that does not carry out large-scale processing of sensitive data (GDPR art. 37).
Transfers outside the European Union
Transfers to Anthropic PBC and Stripe Inc. (United States) occur under the Data Privacy Framework adequacy decision. No transfer is made to a country without adequate safeguards.
Changes
This policy may be updated. The date of the last revision is shown at the top of this page.
French version: Politique de confidentialité.