EnDroit EnDroit
Features Pricing Blog About Contact
Sign in Get started
Features Pricing Blog About Contact Get started
Legal

Privacy Policy

Last updated: 13 May 2026 · GDPR-aligned

EnDroit takes your privacy seriously. This policy explains what personal data we collect when you use our content management platform, how we use it, who we share it with, and the rights you have under the General Data Protection Regulation ("GDPR") and other applicable data-protection laws.

1. Data controller

The data controller is Gillian Masse, operating under the brand "EnDroit", headquartered in Toulon, France. You can reach our data-protection contact at gillian83.masse@gmail.com.

2. What we collect

We collect three categories of personal data:

2.1 Account data. When you create an account or apply for beta access, we collect your name, email address, and any other information you choose to provide (channel handle, country, content niche, etc.).

2.2 Content data. Scripts you write, videos you render, captions, hashtag lists, and the metadata of the videos you publish through us (titles, descriptions, schedule times).

2.3 Usage data. Technical information about your use of the platform, including IP address, browser type, pages visited, timestamps, and the connected social-media accounts you authorise.

3. Legal basis for processing

We process your data under the following GDPR legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — to deliver the service you signed up for, including account management, publishing on your behalf, and customer support.
  • Legitimate interest (Art. 6(1)(f) GDPR) — to improve the platform, prevent fraud, ensure security, and run analytics on aggregate usage.
  • Consent (Art. 6(1)(a) GDPR) — for optional marketing emails, product newsletters, and the use of non-essential cookies.
  • Legal obligation (Art. 6(1)(c) GDPR) — to comply with accounting, tax and fraud-prevention obligations.

4. Why we use your data

We use the data we collect for the following purposes:

  • To provide and operate the platform (rendering videos, publishing on your behalf to connected accounts);
  • To bill you and process payments (via Stripe);
  • To send you transactional emails (welcome, account changes, security alerts, billing receipts);
  • To respond to your support requests;
  • To improve the product (in-aggregate analytics, error monitoring);
  • To detect, prevent and address fraud, abuse and security incidents;
  • To comply with our legal obligations (accounting, tax, lawful requests from authorities).

5. Who we share data with

We share personal data with the following categories of recipients, only as strictly necessary to deliver the service:

  • Subprocessors — Stripe (payments), Anthropic (AI-assisted suggestions), ElevenLabs (voice synthesis), Pexels (stock footage). Each is bound by a data-processing agreement.
  • Hosting providers — for storage of platform data within the European Union.
  • Social-media platforms — TikTok, Instagram (Meta), YouTube (Google). We send only the content and metadata you instruct us to publish, plus the authentication tokens you have provided.
  • Legal authorities — when required by law, court order, or to defend our rights, with the minimum necessary data.

We do not sell your personal data, ever.

6. International transfers

Some of our subprocessors are located outside the European Union (notably in the United States). Where this is the case, transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–US Data Privacy Framework.

7. Retention periods

We retain your personal data for the following periods:

  • Account data — for the lifetime of your account, plus 30 days after deletion to allow you to recover data;
  • Content data — for the lifetime of your account, plus 30 days after deletion;
  • Billing data — 10 years (legal requirement in France for accounting records);
  • Usage logs — 12 months, then anonymised;
  • Marketing data — until you withdraw consent, then deleted within 30 days.

8. Your rights (GDPR)

Under the GDPR, you have the following rights regarding your personal data, which you can exercise at any time:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you;
  • Right to rectification (Art. 16) — correct any inaccurate or incomplete data;
  • Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten");
  • Right to restriction of processing (Art. 18);
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format;
  • Right to object (Art. 21) — to processing based on legitimate interest or for direct marketing;
  • Right to withdraw consent at any time, where processing is based on consent;
  • Right to lodge a complaint with a supervisory authority (in France: the CNIL, www.cnil.fr).

To exercise any of these rights, email gillian83.masse@gmail.com. We respond within one month, with a possible extension of two months for complex requests.

9. Security

We take security seriously. Personal data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access to your account requires authentication. API tokens to connected platforms are encrypted with a per-user key. We follow industry best practices for credential storage, access logging, and incident response.

If a personal-data breach occurs, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

10. Cookies

The website uses a minimal set of essential cookies for authentication and security. We do not use third-party advertising or tracking cookies. We use a privacy-friendly analytics service (Plausible) that does not set cookies and does not collect personally identifiable information.

11. Children

EnDroit is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced by email and on the website at least 30 days before they take effect. The "Last updated" date at the top of this page always reflects the current version.

13. Contact

For privacy-related questions, requests or complaints, reach our data-protection contact at gillian83.masse@gmail.com or via the contact page.

EnDroit EnDroit

Content management platform for legal education creators on short-form video platforms.

Made in France 🇫🇷

Product

Features Pricing Sign up Contact sales

Resources

Blog About us Support Email

Legal

Terms of Service Privacy Policy Cookies
© 2026 EnDroit · All rights reserved. v1.0 · Beta