Privacy Policy
Last updated: 14 August 2026
DONYME is a service operated by Levered Partners. This policy explains, in plain language, what data may be processed, why, and which controls remain yours.
Data controller
The data controller is Levered Partners, the operator of the DONYME service.
- 296 Avenue Napoléon Bonaparte, 92500 Rueil-Malmaison, France
- 988 788 485 R.C.S. Nanterre
- contact@donyme.com
Data minimisation
DONYME seeks to process only the data required for the features you enable. Connections to third-party services are optional.
- No third-party service is accessed without an action or an authorisation from you.
- Permissions are requested incrementally, when a feature actually requires them.
- A permission planned for the future is never presented as a permission already in use.
Categories of data that may be processed
Account data
- email address;
- technical account identifiers;
- language preferences;
- settings and authorisations.
Conversations and instructions
- text you enter;
- requests addressed to DONYME;
- context required for conversation continuity.
Voice
When the voice feature is used, audio may be sent to the DONYME backend and then to a speech recognition provider acting to deliver the transcription. The purpose is the transcription and understanding of your command.
Documents and images
Where you choose to submit them:
- documents;
- images;
- necessary metadata;
- content extracted in order to perform the requested task.
Connected services
Only if you enable a connection, and according to the permissions actually requested. DONYME may in particular integrate Google Workspace services for user-facing features: Gmail, Google Calendar, Google Contacts and Google Drive. The access actually enabled remains aligned with the service’s real OAuth configuration.
Technical and security data
- technical logs;
- security events;
- request identifiers;
- information required for abuse prevention, auditing and diagnostics.
Purposes
- providing the requested features;
- performing actions expressly requested or confirmed;
- maintaining the personal context required by the service;
- securing accounts and connections;
- preventing abuse, errors and unauthorised access;
- providing user support;
- complying with legal obligations.
DONYME does not engage in behavioural advertising, data resale, advertising profiling or data brokerage.
Legal bases
- performance of the service / contract, or pre-contractual measures;
- consent where legally required;
- legitimate interest for certain security and fraud-prevention measures;
- legal obligation where necessary.
An OAuth authorisation granted to a third-party service enables technical access; it does not automatically amount to consent within the meaning of the GDPR for all processing activities.
Use of Google API user data
- DONYME accesses a user’s Google data only when that user connects their account and enables a feature requiring such access.
- Data obtained through Google APIs is used solely to provide or improve user-facing features requested by that user.
- DONYME does not sell Google user data.
- DONYME does not use Google user data for advertising, ad targeting or data brokerage.
- DONYME does not use Google user data to train or improve generalised artificial intelligence models.
- Human access to Google user data is limited to necessary and permitted situations: specific support with the user’s agreement, security, legal obligations, or aggregated / anonymised processing where permitted.
- Any transfer to providers occurs only where necessary for the requested feature, for security, or for a legal obligation, with the applicable safeguards.
DONYME’s use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Artificial intelligence and technical providers
Some requests require data to be processed by technical providers or artificial intelligence models acting to deliver the requested feature. The data transmitted is limited to what is necessary for the task.
User data originating from Google Workspace is not used to train generalised models.
Storage and security
- encryption of data in transit;
- access protections for systems and data;
- separation of authentication secrets from application data;
- permissions revocable at any time;
- security logging where necessary.
Retention periods
Data is retained for as long as necessary for the purposes described, then deleted or anonymised. Minimal data may be retained where a legal obligation applies, or where it is necessary to establish, exercise or defend legal claims.
- Account: kept while the account is active, then deleted or anonymised.
- Conversations: kept for as long as needed for service continuity, then deleted or anonymised.
- Documents and images: kept for as long as needed for the requested task and its follow-up.
- Audio: kept for as long as needed for transcription and any related diagnostics.
- Technical logs: kept for a limited period, for security and diagnostic purposes.
- Audit evidence: kept for as long as needed to evidence an executed action and to meet legal obligations.
Recipients and processors
The categories of recipients that may be involved are:
- hosting and infrastructure;
- AI providers required by the service;
- speech recognition, where the feature is enabled;
- connected services chosen by the user;
- strictly necessary security and observability providers.
International transfers
Some providers may process data outside the European Economic Area. Where a transfer is subject to the GDPR, appropriate legal mechanisms are used.
Your rights
- access;
- rectification;
- erasure;
- restriction;
- objection where applicable;
- portability where applicable;
- withdrawal of consent where processing is based on it;
- lodging a complaint with a supervisory authority, including the French CNIL, or with the authority of your country of residence.
To exercise your rights: contact@donyme.com
Deletion and revocation
You can request deletion of your data and find out how to revoke a connected service on the Manage or Delete My Data page. Access can also be revoked directly with the provider concerned.
Changes
This policy may change as the service evolves. The last update date is shown at the top of this page.
In case of discrepancy between the French and English versions, the French version shall prevail to the extent permitted by applicable law.