Legal
Privacy Policy
This policy explains what personal data Vatlas processes, why, and the rights you have over it under the GDPR.
Last updated 27 August 2026.
1. Data controller
JULIEN MAULNY EURL, 9 Rue des Colonnes, 75002 Paris, France — julien.maulny@tuta.io.
Having assessed the criteria in Article 37 of the GDPR, JULIEN MAULNY EURL considers that no mandatory designation of a data protection officer currently applies to its processing, and has not appointed one. Any question about data protection can be sent to the address above, which is the contact point for exercising your rights.
2. What we collect
An account email address, and optionally a company name and billing address; API call logs (timestamp, endpoint, status code, the VAT number looked up) needed to enforce the monthly quota and produce your usage history; technical connection logs (IP address, user agent, timestamp) for security and abuse prevention; a Stripe customer identifier and associated billing data. Card details are entered directly into Stripe's own payment interfaces and are not stored by JULIEN MAULNY EURL.
Your access credentials are kept in two distinct forms, for two different purposes:
- a non-reversible fingerprint (one-way hash) of your session token and of every API key: this is the only form used to authenticate a request, and it cannot be used to reconstruct the original value;
- for API keys only, a separate encrypted, reversible copy, whose sole function is to let you redisplay an active key from the console. It is never read when authenticating a call. The decryption key is held in the server's runtime environment rather than in the database, so a copy of the database alone cannot open these values. As soon as a key is revoked, it is never redisplayed again: only its masked form remains visible.
Your email address is required to create and manage your account: without it, we cannot create an account or provide the service.
3. Why we process it, and on what basis
| Processing | Data involved | Purpose | Legal basis |
|---|---|---|---|
| Account creation | Email, company name | Create and manage the account | Performance of the contract |
| Authentication | Session, API key (hashed) | Secure access to the account and the API | Performance of the contract |
| Quota and usage | API call logs | Enforce the subscribed plan, produce usage history | Performance of the contract |
| Payment | Stripe identifier, payment method | Charge the amount due for the Basic plan | Performance of the contract |
| Billing and accounting | Invoices, billing data | Issue compliant invoices, keep accounting records | Legal obligation |
| Security | IP address, user agent, technical logs | Prevent fraud and abuse, secure the service | Legitimate interest |
| Support (account-related request) | Email, request content | Answer a request related to performing the service | Performance of the contract |
| Support (other request) | Email, request content | Answer a general question, before or outside any contract | Legitimate interest |
Where we rely on legitimate interest, it rests on a genuine need — securing the service and preventing abuse — balanced against your rights and freedoms.
4. Who receives it
The data above may be shared with the following categories of recipients:
- authorised JULIEN MAULNY EURL personnel, limited to what their role requires;
- OVH SAS, our hosting provider, which runs the servers this data lives on — as our processor, acting on our instructions alone;
- Stripe, for collecting payment of the Basic plan. Its role varies with the processing and the service involved: it acts as our processor when carrying out a payment operation on our behalf and on our instructions, and as a controller for what it does for its own purposes — fraud prevention, regulatory and prudential compliance, security of its network. Neither role covers the whole of what it does (see section 6);
- public or judicial authorities, where a legal obligation requires it — recipients imposed on us, not chosen by us.
Transactional emails (login links, invoices) are sent from our own mail server; we use no third-party email provider. We use no advertising network and no third-party analytics.
5. Cookies and trackers
| Name | Set by | Purpose | Duration | Nature |
|---|---|---|---|---|
vatlas_session |
Console (console.vatlas.dev) | Keep you signed in | 30 days | Strictly necessary |
vatlas-locale |
Console (console.vatlas.dev) | Remember your chosen language | 1 year | Functional — exempt from consent |
vatlas-theme (local storage) |
Site (vatlas.dev) | Remember your light/dark theme choice | Until you clear it | Functional — exempt from consent |
| Stripe cookies | Stripe, on its own Checkout / Customer Portal pages | Payment, fraud detection | Per Stripe's policy | Third-party, outside our control |
The vatlas.dev site sets no cookie. It does use your browser's local storage
(localStorage) to remember your theme choice: that technology falls under the same
regime as cookies, so it appears in the table above. The value stays in your browser and is never
sent to us.
The three trackers we use — vatlas_session, vatlas-locale and
vatlas-theme — are all exempt from consent: the first because it is strictly
necessary for authentication, the other two because they merely remember an interface preference
— language and presentation — that you explicitly asked for, which is an intrinsic and expected
part of the service. None is used for anything else. We use no analytics or advertising tracker.
Any tracker set during a payment is set by Stripe, on its own Checkout and Customer Portal pages, for its payment and fraud-detection purposes. Those are governed by Stripe and its own policies: see Stripe's privacy policy for their detail and the choices offered to you there.
6. International transfers
Our servers and hosting provider are located in France, and no account data leaves the European Economic Area through any act of ours. Stripe, however, may process some billing data in third countries, including the United States.
There is no single transfer mechanism: which one applies depends on the processing in question, the destination country and the Stripe group entity involved. Stripe states that it relies, as the case may be, on an adequacy decision where the country benefits from one, on the EU-U.S. Data Privacy Framework where the receiving entity is certified under it, and on the European Commission's standard contractual clauses together with supplementary measures otherwise. We do not restate a fixed qualification here that could stop being accurate. Stripe publishes the mechanism in force, together with the group entity that contracts with European customers, in its own data processing terms; you can also write to us and we will tell you which safeguard covers your billing data and obtain a copy of it for you. See Stripe's privacy policy for the safeguards that apply to each processing activity.
7. Retention
Each duration is set by the purpose that justifies it:
- Account data: for as long as the account exists. On deletion, the identifying fields — email address, billing details — are overwritten in the active database immediately, and any residual copy outside it is purged within 30 days. An account left inactive for 3 years — no sign-in and no API call — is deleted automatically, after a warning email a month beforehand;
- Detailed API call logs (the VAT number looked up, timestamp, status code): 90 days. Since the quota is monthly, this covers the current and the previous month, which is what handling a billing dispute over the elapsed period requires. Beyond that, only the aggregate counter is kept;
- Aggregate usage counters (requests per month, without the detail of which numbers were looked up), shown in your usage history on the console: kept for as long as the account exists;
- Technical security logs (IP, user agent): 12 months, the usual period for investigating a security incident or abusive use detected after the fact;
- Support requests: 3 years from the last exchange — long enough to retrieve the context of a recurring incident and to show how a complaint was handled, without exceeding the period during which a contractual dispute can still usefully be discussed;
- Technical backups: a rolling 30 days. Deleted data therefore survives at most 30 days in a backup, from which it disappears by rotation; a backup is never restored in order to bring back deleted data, only following an incident affecting the service as a whole.
Invoices and accounting records. Each accounting document is kept for the legal period that applies to it — ten years from the close of the financial year where that period applies. The personal data they contain (name, billing address) follows that same period, but leaves the active database as soon as the commercial relationship ends: it moves to intermediate archiving, with access restricted to the people responsible for accounting follow-up and any disputes, and is no longer used to operate the service.
A revoked API key or an expired session is purged from active use immediately, though its hash may remain in a log until the periods above expire, for audit and security purposes.
Deleting is not erasing everywhere at once. Deleting your account removes your data from the active database immediately: your email address, billing details and keys stop existing as such, and the service can no longer identify you. Data whose retention remains necessary — logs, within the periods above, and accounting records for their legal period — survives in restricted archive until those periods end, and is then destroyed. Technical backups follow their own rolling 30-day cycle.
8. Automated decision-making
We make no fully automated decision that produces legal effects concerning you or significantly affects you. An API key may be automatically suspended by our abuse-prevention system in case of anomalous use; this is a purely technical, reversible measure that you can contest by contacting us.
9. Your rights
Within the conditions set by the GDPR, you have rights of access, rectification, erasure and restriction over your data — subject to the exceptions those same rules provide, in particular where retention is required by a legal obligation (for example an invoice, for its accounting retention period). The right to portability, under Article 20 of the GDPR, is narrower than the rights above: it covers only data you yourself provided, processed by automated means on the basis of the contract or of consent — separately from which you may ask us at any time for an export of your account and usage data, which we provide as a contractual matter. Erasure is exercisable whether or not a subscription is running: the console's delete button asks you to cancel first, but a request sent to the address below is honoured either way, subject to the exceptions in Article 17(3). The right to object applies to processing based on our legitimate interest (see section 3). Write to julien.maulny@tuta.io to exercise any of these rights: we respond within one month, extendable by a further two months for a complex request, as provided by the GDPR. You may also lodge a complaint with the CNIL, the French data protection authority.
10. Security
Passwords, sessions and API keys are never stored in clear text; traffic is encrypted in transit; access to production data is limited to what is needed to operate the service.
11. Data about the companies looked up through the API
The sections above describe data relating to your account. This section describes data about the companies looked up, which is not provided to us by the data subjects themselves — the information required by Article 14 of the GDPR is therefore given here.
Who is concerned. The vast majority of records returned concern legal persons, which fall outside the GDPR. But a VAT number can also identify a sole trader (a sole proprietorship, micro-entrepreneur, self-employed professional, and their equivalents in other member states). In that case the legal name may be the person's first and last name, and the registered address may be their home address: such records are then personal data.
Categories of data concerned. Intra-community VAT number, national identifier (SIREN, Business ID, registrikood…), legal name — which may be a natural person's name — legal form, activity status, and establishment address — which may be a home address. No special category of data within the meaning of Article 9 of the GDPR is processed.
Source. Exclusively official public registers, whose publication and reuse are provided for by the applicable regulations in each member state: national trade and company registers that we import (SIRENE for France, PRH, RIK, the Latvian register…), official APIs of certain tax administrations queried on demand, and VIES, the European Commission's verification service. We collect this data from no other source, enrich it with no privately sourced data, and carry out no profiling.
Purpose and legal basis. This data is processed only to answer a verification request issued by a business customer, on the basis of our legitimate interest and that of our business customers in verifying the identity and VAT status of a trading partner, subject to that interest being balanced against the interests, rights and freedoms of the people concerned. That balancing has been carried out and is documented internally. It is never used for prospecting, advertising or resale, and is not disclosed to any recipient other than the customer who issued the request.
Retention. Records from a register import are refreshed at each import and kept for as long as they appear in the source register, up to a limit of 24 months from the last import in which they appeared: a record that has vanished from its source and has not been seen for two years is purged. That period is what remains useful to the verification purpose: a recently struck-off company must still be verifiable by a customer checking an invoice or a contract from the previous financial year, which 24 months covers across the current and closed accounting periods; beyond that, the verification has no object and the record is not kept. Responses obtained from VIES are cached for at most 24 hours. The number looked up also appears in our call logs, under the conditions and durations described in section 7.
How you are informed. Article 14 of the GDPR requires that someone whose data was not collected from them be informed within a reasonable period, and allows an exception where that information would involve a disproportionate effort. That exception is never automatic: it calls for an assessment, which we have carried out, keep current, and can put before the supervisory authority.
That assessment finds that we import several million records from public registers; that those registers publish no contact details and that we would have no legitimate reason to collect any for the sole purpose of writing to each person; and that the data is used neither to contact you, nor to profile you, nor to ground a decision about you. We conclude that informing each person individually would involve a disproportionate effort within the meaning of Article 14(5)(b) — on the understanding that this conclusion covers the reuse described here, and would have to be revisited if the use of this data changed.
The same provision then requires appropriate measures to protect your rights. Ours are these: this information is public, permanent, reachable without signing in from the footer of every page on this site, published in English and French, and indexed by search engines; the exact sources we use are listed above and the current list is published by the API itself; and we answer individually anyone who contacts us. If these measures seem insufficient in your situation, write to us and we will reconsider them.
Your rights, if you are a data subject. You have the rights described in section 9 — access, rectification, erasure, restriction — and, since this processing rests on our legitimate interest, a right to object under Article 21 of the GDPR, which you may exercise at any time on grounds relating to your particular situation. Write to us at julien.maulny@tuta.io.
Every request is examined individually, against the conditions and exceptions the GDPR provides. The official origin of a record neither removes nor limits your rights: it carries only a practical consequence, which we would rather tell you up front. If we correct or erase a record in our database without the source register being changed, a later import may restore the version that register publishes. A correction at the source — with INSEE or the competent registry for France — is therefore often the more durable route, and we will point you to the right contact. That does not relieve us of handling your request on our side, and we do handle it.
12. How roles are allocated with our customers
The roles of data controller and processor are not assigned by contract alone: they depend on the processing actually carried out. For building and operating our database sourced from public registers, described in section 11, we act as data controller. Where a customer sends us personal data that belongs to their own processing and asks us to process it on their behalf, they may act as controller and Vatlas as processor for that operation — see section 5 of the Terms of Service and Sale. The Data protection (DPA) sets out, processing by processing, which qualification applies and what follows from it.
13. Where this data comes from
Depending on the data, it comes from:
- you directly, when you create an account or contact us;
- your use of the service, for call and connection logs;
- Stripe, for your customer identifier and payment status;
- official national registers and VIES, for the company data returned by the API — see section 11.
14. Changes to this policy
We may update this policy from time to time; the date above reflects the latest revision.