Trust
The documents a purchasing, IT security or data protection team asks for before signing. We publish them so that your review starts from the text, not from a questionnaire.
What we touch on your side
| Access to your vendor or seller account | None. Never requested, never needed. |
|---|---|
| Data about your buyers, orders, addresses, identities | None. |
| Payment data of your end customers | None. |
| Connection to your internal systems | None. No connector, no inbound API, no agent to install. |
| Personal data we process on your behalf | The accounts of your users: name, professional email, role. |
| Browser extension | Optional. It reads the product references shown on the page you visit, nothing else. |
Market data comes from the public product pages, under a written commercial license from a market data provider established in the European Union. Details in Data and methodology.
Documents
Contract documents are in French, which is the language of the contract. The information notice for sellers exists in five languages.
- Legal noticePublisher, hosting and storage providers, applicable law.
- Terms of serviceThe contract: free trial (article 1.5), rights of use, service levels, reversibility, liability.
- Price scheduleThe price list that the order form refers to. Per market, unlimited users.
- Data processing annexArticle 28 agreement, security annex and the list of sub-processors.
- Privacy policyEvery processing of personal data, and the trackers we use. One document.
- Information notice for sellersFor sellers observed on the marketplaces: source, retention, rights, how to object. Also in: ENDEESIT
- Security and data protectionWhat we touch on your side, hosting, measures in place and measures still due, reversibility.
- Data and methodologyWhere the data comes from, how we rebuild the Buy Box history, what is a fact and what is an estimate, the limits we publish.
Hosting and sub-processors
| Component | Provider | Location |
|---|---|---|
| Database, authentication, storage | Supabase Pte. Ltd. (Amazon Web Services infrastructure) | France, region eu-west-3 (Paris) |
| Collection jobs | Hostinger International Ltd. | France (Paris), EU |
| Service messages, alerts and trial onboarding emails | Resend | Irlande, Union européenne (région eu-west-1) |
| Professional email (exchanges, support, trial onboarding) | Google Cloud France SARL (Google Workspace) | Google data centers, no choice of region: transfers outside the EU possible, under the Google Cloud Data Processing Addendum (EU standard contractual clauses; Google LLC certified under the EU-US Data Privacy Framework) |
| AI assistant Ask WhoHeld, on pseudonymised data and the question as typed | Anthropic Ireland, Limited (processing by its parent, Anthropic, PBC) | Ireland; processed in the United States, EU standard contractual clauses |
| Web application | Vercel Inc. | Germany (Frankfurt, region fra1), global delivery network; US company, EU standard contractual clauses |
Any addition or replacement is notified thirty days in advance, with a right to object and to terminate without penalty (data processing annex, article C.1). Data is hosted in the European Union. Sub-processors established outside it, and Google Workspace (email), whose data centers may be outside the EU, work under the EU standard contractual clauses (data processing annex, article C.2).
Retention of seller data
| Seller name and country | 24 months after the last observation |
|---|---|
| Seller marketplace identifier | 36 months, rolling |
| Buy Box events and shares, at seller level | 36 months, rolling |
| Price history linked to a seller | 36 months, rolling |
| Seller profile indicators | 12 months, replaced at each refresh |
| Series linked only to a product, without seller identifier | Not personal data |
At the end of these periods, data is deleted or aggregated so that no seller can be identified. Observed sellers have a free right to object, applied at every collection: information notice.
Security
Client data is isolated at the database level, on every application table. Secrets stay out of the source code. Backups run daily. Automated tests run on every change, and an automated check of database access rights runs after every change to the schema or permissions. What is in place and what is still due, with its deadline, are listed separately, on purpose: Security and data protection.
On request
The following documents are handed over under a confidentiality agreement. Write to contact@whoheld.com.
- Order form template.
- Data supplier due diligence sheet, with the signed attestation of our license.
- Procurement and data protection response file (pre-filled vendor questionnaire).
- Summary of the data protection impact assessment.
- Incident procedure.
- Insurance certificate and tax and social contribution certificates, once a year.
Contacts
Data protection: privacy@whoheld.com
Procurement and everything else: contact@whoheld.com
Every document shows its version. Our prices change at most once every twelve months, with sixty days' notice, taking effect at your next renewal and capped at the Syntec index or 5%, whichever is higher (except the data cost case of article 9.4 of the terms).