Products
Gini

Make smarter location decisions

Born from the combined expertise of Geoblink and MyTraffic, Gini embodies a new kind of intelligence. One that understands places as living systems and transforms territorial complexity into structured, decision-ready insight.

Discover Gini
DataLibrary
The best alternative data for your high-value needs
AudienceLabs
Finally reconcile digital advertising and in-store visits
SmartMonitor
Transform your centre into a thriving hub
Solutions
Retail
Take your business to the next level
Restaurants
Open smarter. Run better. Grow faster.
Franchises
Scale your franchise. Every location, every time.
Commercial Real Estate
Implement a data-driven property strategy
Brokers
Convince top brands, sign more deals
Groceries
Implement a data-driven strategy
Public sector
Make your territory shine
Advertising
Stop guessing. Start knowing.
Charging Point Operators
Deploy your next charging station where it will actually get used with Gini.
FMCG
Take your products portfolio to the next level
PricingClientsCommunity
Resources

Company

About usHow it worksPressJoin us

Contents

Market studiesIndicesBlogEvents
EN
FR
DE
IT
ES
Login
Gini
MyTraffic
Geoblink
Sign up for free

GENERAL TERMS OF SERVICE AND USE (B2B)

Gini: MyTraffic AI Assistant

Version 2.1 – Date: 14/07/2026

1. Legal Notice

MYTRAFFIC SAS

12 rue Vivienne (Lot 3), 75002 Paris, France

SIRET: 814 849 113 00026

Support email: support@mytraffic.fr

2. Preamble: MyTraffic and the Service

MyTraffic develops analysis and mapping solutions for professionals, providing access to indicators and analyses relating in particular to footfall, commercial environments, area dynamics, and decision support for location strategy.

Gini is a conversational AI service integrated into the MyTraffic ecosystem. Authorized Users submit Prompts and receive Outputs (responses, recommendations, summaries, tables).

The Outputs are intended as decision-support tools only and do not constitute professional advice nor a guarantee of performance.

3. Definitions

For the purposes of these General Terms of Service and Use (“GTSU”), terms beginning with a capital letter have the following meanings:

“Authorized User”: any person authorized by the Client to access the Service via an account.

“Account”: an account enabling access to the Service, created for the Client and/or its Authorized Users.

“Billing Period”: a monthly or annual period depending on the subscribed offer, as indicated at the time of subscription via the Service Interface and/or the Order Form / Quotation.

“Client” or “Customer”: any legal or natural person acting in a professional capacity who has subscribed to the Service.

“Client Documents”: any files, documents, or data uploaded by the Client or an Authorized User into Gini (including PDFs, spreadsheets, or similar documents), where applicable.

“Client Content”: all Prompts, Client Documents, and content provided by the Client in connection with the Service.

"Credits": a unit of consumption of the Service, constituting a Quota within the meaning of these terms. Credits apply solely to offers expressly designated as usage-capped, as specified 

in the applicable pricing plan and/or Service Interface. Unlimited plans do not operate on a Credit-based consumption model.

"Country Scope": the list and number of countries in respect of which the Client is authorised to use the Service, as specified in the Order Form / Quotation or, for self-serve offers, as selected by the Client at the time of subscription via the Service Interface. Country Scope constitutes a contractual parameter of the subscribed offer.  MyTraffic does not technically restrict access to countries beyond the contracted Country Scope at the platform level; compliance with the contracted Country Scope is the Client's sole responsibility and may be verified by MyTraffic at renewal

“DPA”: the Data Processing Agreement entered into between the Parties where applicable (Article 28 GDPR).

“MyTraffic Data”: datasets, analytics, indicators, methodologies, models, content, and elements provided by MyTraffic independently of Client Content.

“Organization”: the contractual “Client” entity attached to an Account, within which Authorized Users, Seats, and Quotas are managed.

“Output / Result”: any content generated by Gini in response to a Prompt and/or based on a Client Document (including recommendations, summaries, tables, analyses).

“Order Form / Quotation”: any contractual document or equivalent medium (including online subscription, pricing plan, administration interface, or specific terms accepted electronically) specifying, depending on the applicable offer, the scope of the Service, duration, features, usage quotas, price, and, where applicable, API access conditions.

"Package Restructuring": any modification by MyTraffic of the allocation of features, modules, or options across the available pricing plans, tiers, or packages, including without limitation the reallocation of a feature from one tier to a higher tier, the conversion of an included feature into a paid option, or the bundling or unbundling of features across offers. Package Restructuring does not include changes to Quotas (usage volumes), which are governed by the Credits and Quotas provisions herein.

“Prompt / Input”: any instruction, question, or request submitted to Gini by an Authorized User.

"Quotas": usage limits applicable to the Service depending on the subscribed offer (for example number of requests, processing volume, credits, documents, Authorized Users, number of countries, or any other usage metric specified in the Order Form / Quotation, pricing plan, and/or Service Interface).

“Service”: the MyTraffic web application accessible via a browser; API access is available only if expressly provided for in the Order Form / Quotation.

“Service Interface”: the application interface (including dashboards and management screens) enabling the Client to view or manage, depending on the subscribed offer, the Service’s features, quotas, Authorized Users, and settings.

“Seat”: a named access right allowing one (1) natural person, an Authorized User, to access the Service on behalf of the Client.

"Third-Party AI Providers" or "LLM Providers": third-party service providers involved in the operation of all or part of the Service, acting as sub-processors within the meaning of Article 28 GDPR. These include: (i) aggregation or routing layer providers (including AWS Bedrock (Amazon Web Services), which aggregates access to downstream model providers via the eu-west-1 region (Ireland)); and (ii) downstream model providers whose models are accessed via such aggregation layer (for example Anthropic, OpenAI, Google, and any other provider listed in the applicable Trust Center documentation). The list of active sub-processors may evolve and is made available to the Client via the Trust Center or equivalent documentation.

“Trust Center Summary”: an informational summary of security, privacy, and organizational measures set out in Appendix 5, provided for transparency purposes.

4. Contractual Documents – Order of Priority

The contractual documents governing the Service are, in descending order of priority:

  1. the Order Form / Quotation and, where applicable, any specific terms accepted by the Parties;
  2. the DPA and any amendment relating to the processing of personal data, where applicable;
  3. the Evaluation / Trial Conditions, where applicable;
  4. these GTSU and their appendices (including the AUP (Acceptable Use Policy set out in Appendix 2), the Security Incident Exhibit (Appendix 3), and the AI Safety Exhibit (Appendix 4));
  5. the pricing plan, the Service Interface, and any documentation or reference information made available by MyTraffic.

Note : Data Processing Agreement. Where MyTraffic processes Personal Data on behalf of the Customer, the Data Processing Agreement ("DPA") available on our website is hereby incorporated into these Terms by reference and forms an integral part of the Agreement. By executing an Order Form, accepting these Terms, or using the Services, Customer agrees to the DPA. In the event of any conflict between the DPA and these Terms regarding personal data processing, the DPA shall prevail.

5. Purpose: Scope of the Service

  1. These GTSU define the conditions for access to and use of Gini, as well as the rights and obligations of the Parties, including with respect to data, security, compliance, and liability.
  2. The functional scope, activated modules, quotas, number of Authorized Users, and, where applicable, API access are defined in the Order Form, or failing that, in the applicable pricing plan and/or Service Interface. The features, modules, and options available to the Client at any given time are those included in the subscribed offer as defined in the then-current pricing plan, Service Interface, and/or Order Form / Quotation. The Client acknowledges that the functional scope of each pricing plan may evolve over time, including through Package Restructuring as defined in the Definitions section, in accordance with the conditions set out in the Package Restructuring section herein. Unless expressly agreed in writing by MyTraffic, no feature not included in the subscribed offer (including "Enterprise" features) may be made available to the Client, whether free of charge or on a promotional basis.

The Client acknowledges that the operation of the Service involves the transmission of Prompts, conversation history, and, where applicable, Client Documents to Third-Party AI Providers acting as sub-processors, including via an AI model aggregation layer. Such transmissions may involve providers located outside the European Economic Area, in which case appropriate transfer mechanisms (including Standard Contractual Clauses) apply. MyTraffic implements technical measures to minimise the personal data exposed in such transmissions, including Zero Data Retention (ZDR) configurations where available and applicable.

  1. Online offers, trial, and variable usage (Trial / Freemium / Usage-based). When the Client subscribes to the Service through an online offer, trial, free (“freemium”), or usage-based offer, the available features, Quotas, technical limits, and any applicable restrictions (including rate limits, volumes, number of documents, and/or prioritization) are those (i) of the subscribed pricing plan and/or (ii) displayed in the Service Interface at the time of use.
    1. In the event of Quota overruns or abnormal usage (including unusually high volumes of processed data or generated LLM tokens), MyTraffic may apply limitations, temporarily suspend certain features, or invite the Client to upgrade its offer.
    2. Quotas and usage metrics may be reasonably adjusted in order to:
      1. prevent abuse;
      2. protect the security, performance, or integrity of the Service;
      3. account for technical or regulatory developments; or
      4. reflect substantial cost changes related to third-party providers essential to the operation of the Service, including AI model providers.
    3. MyTraffic may make such Quota adjustments. Such adjustments shall not result in a substantial reduction of the Client’s usage volumes under an ongoing Order Form; if such adjustment occurs, MyTraffic shall implement reasonable alternative measures (such as a pricing adjustment, model change, or modification of the usage scope). For the avoidance of doubt, the allocation of features and modules across pricing plans is governed exclusively by the Package Restructuring section herein and is not subject to the limitations set out in this section.
    4. Country Scope: self-serve offers. For self-serve offers, the Client selects at the time of subscription the country in respect of which it intends to use the Service ("Country Scope"), as displayed in the Service Interface. The Country Scope constitutes a contractual parameter of the subscribed offer. MyTraffic does not technically restrict access to countries beyond the contracted Country Scope at the platform level; compliance with the contracted Country Scope is the Client's sole responsibility and may be verified by MyTraffic at renewal.

5.3.3 Credits

Volumes. For capped-usage plans, the Service includes a fixed number of Credits per Billing Period, as specified in the applicable pricing plan and/or Service Interface. One (1) Credit is consumed per conversation or workflow initiated. Additional Credits may be consumed where the data volume processed within a single conversation exceeds the threshold defined in the Service Interface. Unused Credits at the end of a Billing Period are not carried over and are reset upon renewal.

Monthly offers. Certain monthly offers may be limited to a specific number of Seats and specific Quotas, as displayed in the Service Interface at the time of subscription. These offers may not allow the purchase of additional Seats or options, unless the Client upgrades to an eligible offer.

Reasonable use. In order to prevent abuse and protect the performance of the Service, a reasonable use limit is applied at the Organization level, including in particular: (i) an average cap of two million (2,000,000) LLM tokens generated per conversation; and (ii) a global threshold for the number of conversations and/or workflows initiated over a given period. The foregoing reasonable use limits apply to all plans, including unlimited plans, as anti-abuse measures and not as Quota restrictions

Beyond these safeguards, MyTraffic reserves the right to temporarily limit the Service, temporarily block the Account, suspend access, or invite the Client to upgrade its offer, in accordance with these GTSU.

No standalone purchase of Credits. Unless otherwise specified in the Order Form / Quotation, the Client may not purchase Credits (or a quota of conversations/workflows) on a standalone basis. Any additional usage needs requires an upgrade of the offer (change of package and/or addition of Seats) under the conditions available in the Service Interface and/or through MyTraffic’s sales teams.

5.4 Client Content May Include Business-Sensitive Information

The Client acknowledges and agrees that, depending on its use, Client Content provided to the Service (Inputs, uploaded documents, text, tables) may contain: (i) confidential information and/or trade secrets of the Client or third parties; and/or (ii) personal data.

The Client remains solely responsible for the selection of the information it transmits through the Service, in accordance with these GTSU, the AUP (Appendix 2), and, where applicable, the DPA.

5.5 File Uploads

The Service allows the Client and its Authorized Users to upload files and documents (including PDFs, spreadsheets, or similar documents) in order to enable their analysis, summarization, or processing by Gini as part of the Service’s functionalities.

  1. Data Retention within the Service. The following retention periods apply to data processed within the Service:
    1. Prompts and conversation history: retained for the duration of the active session and for a period not exceeding twelve (12) months thereafter, subject to automatic purge currently in implementation; as indicated in the Service Interface and/or the applicable DPA;
    2. Uploaded Documents (Client Documents): retained for the duration of the processing session only; immediate deletion following processing is implemented where technically feasible;
    3. Technical metadata (timestamps, model identifiers, token counts): retained for a period not exceeding ninety (90) days for security and traceability purposes.‍
    4. ‍Data transmitted to Third-Party AI Providers: MyTraffic implements contractual safeguards with each provider receiving Customer Content, including Data Processing Agreements incorporating Standard Contractual Clauses (SCCs 2021 Module 2) pursuant to Article 28 GDPR. Zero Data Retention (ZDR) configuration is implemented where available and applicable as a supplementary technical measure. MyTraffic does not represent that ZDR is activated for all providers at all times; contractual safeguards constitute the primary compliance mechanism.

The Client may request accelerated deletion of its data by contacting MyTraffic at support@mytraffic.fr, subject to applicable legal hold requirements.

5.6 Package Restructuring

  1. Right to Restructure. MyTraffic reserves the right to modify, at any time, the allocation of features, modules, and options across its pricing plans, tiers, and packages ("Package Restructuring"), including by: (i) reallocating a feature from one pricing plan to a higher-tier plan; (ii) converting an included feature into a separately priced option or add-on; (iii) bundling or unbundling features across offers; or (iv) creating new feature tiers or categories or (v) modifying the countries available within a given pricing tier or plan, including the addition or removal of countries from a Geo Package.
  1. Application to Existing Clients. Package Restructuring shall apply as follows: (a) for subscriptions governed by an Order Form with a fixed commitment period: at the end of the current commitment period, upon renewal; (b) for month-to-month subscriptions or subscriptions without an Order Form: upon the next Billing Period following the expiry of the notice period set out in the Financial Conditions section herein; (c) for new subscriptions: immediately.
  2. Impact on Access. In the event that a feature previously included in the Client's subscribed offer is reallocated to a higher-tier plan or converted into a paid option as a result of a Package Restructuring, the Client's access to such feature shall be maintained until the end of the applicable Billing Period or commitment period. Thereafter, continued access to the reallocated feature shall require the Client to upgrade to the applicable plan or subscribe to the relevant option at the then-current pricing.
  3. No Acquired Right. The Client acknowledges that the inclusion of a feature in a given pricing plan at the time of subscription does not create an acquired right (droit acquis) to the perpetual inclusion of such feature in such plan. The allocation of features across plans is determined by MyTraffic at its reasonable discretion, subject to the notification and transition mechanisms set out herein.
  4. Good Faith. MyTraffic undertakes to exercise its Package Restructuring rights in good faith and shall not use Package Restructuring solely or primarily for the purpose of circumventing its obligations under an ongoing Order Form.

5.7 Package Restructuring — Notification and Acceptance

  1. Notification. In the event of a Package Restructuring, MyTraffic shall notify the Client at least thirty (30) days prior to the effective date of such change. Notification shall be provided via the Service Interface and/or by email to the contractual contact designated by the Client.
  1. Content of Notification. The notification shall include: (i) a description of the features affected by the Package Restructuring; (ii) the effective date of the change; (iii) the upgrade path or option required to maintain access to the affected features; and (iv) the applicable pricing for such upgrade or option.
  2. Deemed Acceptance. If the Client does not object in writing within fifteen (15) calendar days of the notification, the Package Restructuring shall be deemed accepted by the Client. The Client's continued use of the Service after the effective date of the Package Restructuring shall constitute acceptance of the new feature allocation.
  3. Objection and Termination Right. If the Client objects in writing within the fifteen (15) day period and no agreement is reached between the Parties within a further fifteen (15) calendar days, the Client may terminate the affected subscription at the end of the current Billing Period or commitment period, without penalty and without early termination fees. Such termination right constitutes the Client's sole and exclusive remedy with respect to the Package Restructuring.
  4. Transition Period. During the period between the notification and the effective date of the Package Restructuring, the Client shall retain access to the affected features under the existing terms of its subscription. No access shall be removed prior to the expiry of the applicable Billing Period or commitment period.

6. Access to the Service; Accounts and Credentials

  1. The Service is accessible via a personal username and password (or any other authentication mechanism offered). The Client is responsible for managing access rights and maintaining the confidentiality of credentials.
  • large-scale data extraction, scraping, or abusive automation;
  • reverse engineering, circumvention of Quotas or security measures;
  • attempts at prompt injection, jailbreak, or data exfiltration;
  • uploading unlawful content or content infringing third-party rights;
  • collection or processing of unauthorized sensitive data and uploading confidential information of third parties (including trade secrets) without authorization or in breach of a confidentiality obligation. MyTraffic may suspend or limit access to the Service in the event of abuse, security risk, or non-compliance with these GTSU and/or the AUP.
  • submitting Prompts or uploading Client Documents that contain special categories of personal data within the meaning of Article 9 GDPR (including health data, political opinions, religious beliefs, sexual orientation, or biometric data), unless the Client has obtained the express consent of the data subjects concerned and has notified MyTraffic in advance in writing.

Any unauthorized use must be reported to MyTraffic without delay.

6.2 Seats (Authorized Users)

Usage limits, Quotas, and features applicable to the Service may be defined or specified in the Order Form, the subscribed pricing plan, and/or the Service Interface. In the event of exceeding such limits, MyTraffic may apply limitations, temporary suspensions, or propose an upgrade of the offer.

The number of Seats included in the offer corresponds to the maximum number of Authorized Users who may access the Service simultaneously or actively within the Organization.

The applicable number of Seats, prices, billing terms, Quotas, and usage limits (including Seats and Credits) are those indicated in the pricing plan, the Service Interface, and/or the Order Form / Quotation.

6.3 Financial Conditions:

Credential sharing between multiple individuals is prohibited. In the event the number of Seats is exceeded, MyTraffic may limit access, suspend certain features, and/or invite the Client to upgrade its offer.

Access to the Service is subject to payment of the plan or offer selected by the Client.

Prices, billing terms, applicable Quotas, and usage limits are those indicated, depending on the offer, in the Order Form / Quotation, the pricing plan, and/or the Service Interface at the time of subscription or use.

Unless otherwise stated, prices are expressed exclusive of taxes, which shall be invoiced in addition in accordance with applicable regulations.

Access to the Service is conditional upon payment of all amounts due. In the event of non- payment, MyTraffic reserves the right to limit or suspend access to the Service until payment is made.

Any changes to prices or Quotas shall not affect the conditions applicable during the term of an ongoing Order Form. For offers without an Order Form, changes shall apply prospectively and shall be communicated to the Client via the Service Interface or any other appropriate means.

Promotions and discounts. Promotions, discounts, or pricing benefits may be offered for a limited duration and subject to eligibility conditions communicated at the time of the offer (event, early adopters, end-of-period campaigns, etc.). Unless expressly stated otherwise, promotions are not cumulative and apply only for the indicated period; upon expiry, the then-current standard pricing shall apply.

Pricing plan changes. Changes to the pricing plan (including pricing, Quota allocations, and feature-to-plan mappings resulting from a Package Restructuring) apply to new subscriptions, renewals requiring a new subscription, and upgrades performed after the effective date of such changes. Ongoing subscriptions remain governed by the pricing conditions applicable at the time of subscription for the duration of the current Billing Period or commitment period. However, the functional scope of each pricing plan (i.e. which features are included in which plan) may evolve in accordance with the Package Restructuring section herein, and the Client acknowledges that no feature lock or perpetual feature entitlement shall apply beyond the current Billing Period or commitment period, unless expressly agreed in writing in the applicable Order Form.

Geo packages. MyTraffic may offer pre-packaged regional pricing bundles ("Geo Packages") corresponding to a predefined set of countries, as communicated at the time of the offer or set out in the Order Form / Quotation. Geo Packages constitute contractual pricing arrangements tied to the contracted Country Scope. Any expansion of the Country Scope beyond the contracted Geo Package shall require a new Order Form or written amendment and shall be subject to the then-current pricing applicable to the expanded scope.

7. Conditions of Use: AUP (Summary)

The Client undertakes to comply with Appendix 2 (Acceptable Use Policy – AUP). In particular, the following uses are prohibited:

  • illegal activities, fraud, or discrimination;
  • large-scale data extraction, scraping, or abusive automation;
  • reverse engineering, circumvention of Quotas or security measures;
  • attempts at prompt injection, jailbreak, or data exfiltration;
  • uploading unlawful content or content infringing third-party rights;
  • collection or processing of unauthorized sensitive data and uploading confidential information of third parties (including trade secrets) without authorization or in breach of a confidentiality obligation. MyTraffic may suspend or limit access to the Service in the event of abuse, security risk, or non-compliance with these GTSU and/or the AUP.
  • submitting Prompts or uploading Client Documents that contain special categories of personal data within the meaning of Article 9 GDPR (including health data, political opinions, religious beliefs, sexual orientation, or biometric data), unless the Client has obtained the express consent of the data subjects concerned and has notified MyTraffic in advance in writing.

8. AI-Specific Provisions (Professional-Grade Approach)

8.1 Transparency

The Client acknowledges that Gini incorporates artificial intelligence functionalities and that Users interact, in whole or in part, with an automated system.

8.1.1 Information and Display Obligation

MyTraffic shall implement reasonable means to ensure that the Service displays, at the latest upon an Authorized User’s first interaction with Gini and in a manner that remains easily accessible during use, a notice indicating that the User is interacting with an artificial intelligence system.

The Client, in turn, undertakes to inform its Authorized Users (in particular through its internal policies and/or applicable terms of use) that they are interacting with an AI system and that Outputs are subject to the limitations described herein.

8.1.2 International Transfers and Sub-processors.

The Client acknowledges that the operation of the Service may involve the transfer of personal data contained in Prompts, conversation history, and Client Documents to Third-Party AI Providers located outside the European Economic Area, in particular in the United States of America. Such transfers are governed by appropriate safeguards, including Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46 GDPR, and, where applicable, Transfer Impact Assessments (TIAs).

8.2 Probabilistic Nature – No Warranty

Outputs are probabilistic and may contain errors, omissions, approximations, or biases. MyTraffic does not warrant the accuracy, completeness, or fitness of Outputs for any specific purpose.

8.3.3 Decision Support – No Professional Advice

Outputs are provided for informational purposes only and constitute decision-support tools. They do not constitute professional advice (legal, financial, real estate, or otherwise).

8.3.1 Non-Deceptive Use and Contextualization of Outputs

The Client shall refrain from: (i) presenting Outputs as human-generated, certified, verified, or as personalized professional advice; (ii) substantially removing or obscuring warnings relating to the limitations of Outputs when communicated to third parties; and (iii) using Outputs as the sole basis for decisions likely to have significant impacts without human review in accordance with the Human Review section herein.

8.4 Human Review

The Client remains solely responsible for its use of Outputs and undertakes to implement a reasonable human review before any decision-making or implementation.

8.5 Sensitive Uses

The Client shall not use Gini to automate decisions producing significant legal effects on individuals without appropriate human supervision and without an adequate legal framework. In particular, the Client shall refrain from including, in any Prompt or Client Document, personal data of third parties that is not strictly necessary for the intended use case, and shall take all reasonable measures to anonymise or pseudonymise such data prior to submission to the Service.

8.5.1 Change of Use Case / Regulatory Requalification

The Client undertakes to notify MyTraffic without delay if it intends to use the Service in a context likely to trigger enhanced regulatory obligations (in particular under European artificial intelligence regulations) or involving high-impact decisions concerning natural persons.

In such case, MyTraffic may, at its reasonable discretion: (i) refuse the proposed use case; (ii) suspend access to the Service for the relevant scope; and/or (iii) propose additional contractual terms and compliance measures prior to any continued use.

User warning. The Client acknowledges that the Service is not intended for permanent document storage and undertakes to avoid uploading unnecessarily sensitive or confidential information, in accordance with the data minimization principle.

9. Data, Intellectual Property, and Licenses

1. MyTraffic Ownership

MyTraffic retains all intellectual property and/or exploitation rights in Gini, the documentation, and the MyTraffic Data. No transfer of ownership is granted.

2. License to Use MyTraffic Data

Subject to payment of all amounts due and compliance with these GTSU, MyTraffic grants the Client a license to access and use the MyTraffic Data that is:

  • strictly limited, non-exclusive, non-assignable, non-transferable, and non-sublicensable;
  • restricted to the Client’s internal use;
  • limited to the scope (modules, areas, Quotas, users) defined in the Order Form;
  • granted for the duration of the contract only.

Unless expressly agreed in writing by MyTraffic, the Client is prohibited from reselling, publishing, distributing, making available, granting access to, or otherwise exploiting the MyTraffic Data for the benefit of any third party (including affiliates, group companies, franchisees, partners, service providers, or advisors).

3. Prohibition on Reuse / Third-Party Tools / Training / Derivatives

Unless expressly agreed in writing by MyTraffic, the Client shall not:

  • integrate, synchronize, or import MyTraffic Data into third-party tools or platforms (including data warehouses/lakes, BI tools, indexing engines, analytics platforms, or AI tools) where such integration enables autonomous reuse of MyTraffic Data outside the Service;
  • train, retrain, fine-tune, evaluate, or improve any model or algorithm (including AI/ML, whether generative or not) using MyTraffic Data;
  • create, derive, commercialize, or make available indicators, scores, databases, products, or services that are substantially derived from MyTraffic Data, including through hybridization with third-party data;
  • reconstruct databases, circumvent Quotas, or perform any systematic extraction (scraping, crawling, abusive automation).

The obligations set out in the License to Use MyTraffic Data and Prohibition on Reuse sections above shall survive termination of the contract.

4. Client Content

The Client retains ownership of its Client Content. The Client authorizes MyTraffic to host, process, reproduce, and analyze Client Content strictly for the purposes of providing the Service, ensuring security and anti-abuse measures, complying with legal obligations, and maintaining the Service.

5. Outputs

Subject to MyTraffic’s rights and third-party rights, the Client may use the Outputs for its internal needs. The Client acknowledges that similar Outputs may be generated for other users without this constituting a breach of confidentiality.

6. Client Content and Uploaded Files

The Client remains solely responsible for the Client Content provided to the Service, including files, documents, and data uploaded or entered via Gini.

The Client represents and warrants that it holds all necessary rights, authorizations, and legal bases to provide such Client Content, including where it contains confidential information, trade secrets, or personal data. The Client undertakes to upload only information strictly necessary for the intended purpose (data minimization principle) and not to use the Service to process special categories of personal data within the meaning of the GDPR (including health, biometric, genetic data, political opinions, or religious beliefs), unless expressly agreed in writing by MyTraffic and subject to appropriate contractual safeguards, including a DPA and enhanced security measures.

MyTraffic processes Client Content exclusively for the purposes of providing the Service, in accordance with these GTSU, the AUP (Appendix 2), and, where applicable, the DPA.

10. Third-Party AI Providers (LLM Providers)

Gini may rely on Third-Party AI Providers to operate all or part of the Service. Client Content may be processed by such providers to the extent necessary for the provision of the Service, in accordance with the applicable confidentiality and security commitments.

An indicative list of subcontractors (LLM and/or cloud providers) is set out in Appendix 1. MyTraffic may update this list; in the event of a material change, MyTraffic shall notify the Client in accordance with the terms set out in the Order Form or, failing that, by any reasonable written means.

11. Trust & Security (Trust Center–Style Summary – MyTraffic)

1. Positioning

MyTraffic’s security measures are described in this section and in Appendix 4 (AI Safety Exhibit). Any security certifications held by MyTraffic, where applicable, are confirmed separately in the applicable contractual documentation or upon request.

However, MyTraffic implements technical and organizational security measures proportionate to the identified risks, as described below.

2. Security Measures (Examples of Controls)

By way of illustration, MyTraffic implements the following measures, depending on the applicable technical scope:

  • data encryption at rest;
  • access controls and authorizations based on the “need-to-know” principle (least privilege / RBAC);
  • enhanced authentication mechanisms (MFA / 2FA) for sensitive access;
  • access logging and periodic access rights reviews;
  • data retention and deletion policies (lifecycle management), and legal hold mechanisms where applicable;
  • anti-abuse measures, including rate limiting, anomaly detection, and application-level security control.

3. AI Traceability (Logs)

For security, support, abuse prevention, and incident investigation purposes, MyTraffic may retain logs associated with Gini interactions, including prompts, outputs, timestamps, Client/account identifiers, IP addresses, user identifiers, model versions, and technical metrics.

Retention periods. Unless otherwise specified in the Order Form or required by law, MyTraffic applies by default a retention period of ninety (90) days from the date of collection for traceability logs relating to the Service.

For certain offers or options, as specified in the applicable Order Form, an extended retention period of up to one (1) year may be agreed. Logs may be subject to a legal hold where required by law or by a request from a competent authority. Upon expiry of the applicable retention periods, logs are deleted or anonymized in accordance with MyTraffic’s retention policy and, where applicable, the DPA.

4. AI Safeguards

The AI protection measures applicable to the Service are set out in Appendix 4 (AI Safety Exhibit), which constitutes the single authoritative reference for these controls. See Appendix 4, Controls section.

5. Incident Management

MyTraffic maintains incident management procedures. In the event of a security incident affecting the Service, MyTraffic shall inform the Client within a reasonable timeframe and shall cooperate in good faith to mitigate impacts.

Where personal data are processed on behalf of the Client (processor role), notification and assistance obligations are detailed in the DPA.

12. GDPR – Personal Data

The Client represents and warrants that it holds all necessary rights, authorizations, and legal bases to upload and process Client Content via Gini.

1. Processor Role

Where MyTraffic acts as a processor within the meaning of the GDPR, the Parties shall enter into a Data Processing Agreement (DPA specifying the instructions, security measures, subprocessors, transfers, retention periods, and deletion mechanisms).

2. DPA Required for Processing on Behalf of the Client

Where the Client uses the Service to process personal data through Client Content, MyTraffic acts as a processor within the meaning of the GDPR, and the Parties agree to implement a DPA (Article 28 GDPR).

Such DPA shall describe in particular the subject matter, duration, nature, and purpose of the processing, the types of personal data and categories of data subjects, the security measures, the list of onward subprocessors, and, where applicable, transfer mechanisms.

In the absence of a required DPA, MyTraffic may suspend the processing of Client Content containing personal data until compliance is achieved.

3. Processing of Personal Data via Uploaded Files

Where the Client uses the Service to upload, analyze, or process files or documents containing personal data, MyTraffic acts as a processor within the meaning of the GDPR.

In such case, the Parties agree to enter into a DPA compliant with Article 28 of the GDPR, prior to or concurrently with such processing.

Failing the implementation of a required DPA, MyTraffic reserves the right to suspend the processing of the relevant Client Content until compliance is restored.

13. Support, Maintenance, Availability

Support. Support is available at support@mytraffic.fr, in accordance with the terms set out in the applicable Order Form. MyTraffic may temporarily interrupt the Service for scheduled or emergency maintenance.

Service Level Agreement (SLA). Any service level commitments apply only if expressly provided for in an Order Form and/or an SLA appendix. Failing such provisions, no specific availability commitment is made.

14. Liability and Limitations

MyTraffic is bound by a best-efforts obligation.

Subject to mandatory statutory provisions, MyTraffic shall not be liable for any indirect, consequential, incidental, or special damages, including loss of profit, loss of data, loss of opportunity, or business interruption.

Liability cap. MyTraffic’s total aggregate liability in connection with the Service shall not exceed the total amount actually paid by the Client for the Service during the twelve (12) months preceding the event giving rise to the claim, except in cases of gross negligence (faute lourde), willful misconduct (dol), or bodily injury.

AI-specific clause : The Client remains solely responsible for verifying Outputs and for all decisions made on the basis thereof.

15. Suspension and Termination

MyTraffic may suspend access to the Service in the event of abuse, security risk, or breach of these GTSU and/or the AUP.

Either Party may terminate the Contract in the event of a material breach by the other Party that remains uncured within a reasonable period following written notice, in accordance with the terms set out in the Order Form or, failing that, within thirty (30) days.

16. Term, End of Contract – Cessation of Use, Deletion/Return, Verification

This Agreement shall remain in force for the initial term specified in the applicable Order Form (the “Initial Term”). Upon expiration of the Initial Term, the Agreement shall be automatically renewed for successive periods of the same duration (each a “Renewal Term”), unless either Party provides written notice of termination at least thirty (30) calendar days prior to the end of the then-current term for monthly offers, and at least two (2) months prior to the end of the then-current term for annual offers or offers governed by an Order Form. The Client shall be notified in advance of each upcoming renewal period in order to ensure full transparency regarding the continuation of the Agreement.

2. Cessation of Use

Upon expiration or termination of the Contract, the Client shall: (i) cease all access to and use of the Service; and (ii) cease any use of the MyTraffic Data, unless otherwise provided for in the Contract (in particular, vested rights relating to expressly identified deliverables).

3. Deletion of MyTraffic Data

Within thirty (30) days following the end of the Contract, the Client shall delete or render unusable all copies of the MyTraffic Data in its possession or under its control, including extracts and exports insofar as they enable substantial reconstruction of the MyTraffic Data or independent use outside the Service.

This article does not require deletion of the Client’s internal documents (reports, presentations, decisions) that contain only aggregated results or Outputs that do not allow substantial reconstruction of the MyTraffic Data.

4. Deletion Certificate

Upon written request from MyTraffic, the Client shall provide a deletion certificate signed by a duly authorized representative within fifteen (15) calendar days.

5. Targeted Verification

In the event of a reasonable suspicion of non-compliance with the obligations set out in this article (in particular unauthorized use or retention of substantial extracts of the MyTraffic Data), MyTraffic may request a targeted verification.

Such verification shall take the form, at MyTraffic’s reasonable discretion, of:

  1. a compliance questionnaire and/or
  2. limited, strictly necessary, and non-intrusive supporting evidence.

An on-site audit or audit by an independent third party may be requested only as a last resort, subject to reasonable prior notice, during business hours, and in compliance with confidentiality obligations.

6. Costs

The cost of any verification or audit shall be borne by MyTraffic, unless such verification or audit reveals a material breach by the Client, in which case the reasonable costs thereof may be invoiced to the Client.

7. Personal Data (Reminder)

Where applicable, deletion or return of personal data contained in Client Content is governed exclusively by the DPA.

17. Governing Law – Jurisdiction

These GTSU are governed by French law.

The competent courts shall be those of Paris, unless otherwise specified in the Order Form.

18. Confidentiality

Definition

“Confidential Information” means any information disclosed by one Party to the other Party, in any form whatsoever, that is identified as confidential or that, by its nature, should reasonably be considered confidential, including without limitation MyTraffic Data, Client Content, specifications, technical data, pricing, roadmaps, code, and Outputs.

Exclusions

Confidential Information does not include information that: (i) is or becomes public other than through a breach of this Contract; (ii) was lawfully known to the receiving Party prior to disclosure; (iii) is lawfully received from a third party without breach of a confidentiality obligation; or (iv) is independently developed by the receiving Party without use of the Confidential Information.

Obligations

The receiving Party undertakes to: (i) not disclose Confidential Information except to its employees, advisors, Affiliates, or subcontractors who have a strict need to know and are bound by confidentiality obligations at least equivalent to those set forth herein; (ii) use Confidential Information solely for the performance of the Contract; and (iii) protect Confidential Information using reasonable safeguards at least equivalent to those it applies to its own confidential information.

Required Disclosure: If the receiving Party is required by law, regulation, or court order to disclose Confidential Information, it shall, to the extent permitted by law, notify the disclosing Party in advance and reasonably cooperate to limit the scope of such disclosure.

Return or Destruction: Upon expiration or termination of the Contract, the receiving Party shall, at the disclosing Party’s option, return or destroy all Confidential Information within thirty (30) days and provide a written certification upon request. Copies required to be retained by law may be kept and shall remain subject to the confidentiality obligations set forth herein.

Term: Confidentiality obligations shall apply for the duration of the Contract and for five (5) years thereafter, except for trade secrets, which shall remain protected for as long as they retain their status as trade secrets.

Injunctive Relief: Any breach of confidentiality obligations may cause irreparable harm. Accordingly, the disclosing Party shall be entitled, in addition to damages, to seek injunctive or equitable relief without the need to post a bond.

Personal Data: Where Confidential Information includes personal data, the provisions of the DPA shall prevail in the event of any conflict.

19. Compliance (Sanctions, Export Controls, AML/CFT, Anti-Corruption)

Each Party undertakes to comply with all applicable laws and regulations, including without limitation those relating to economic sanctions, embargoes, export controls, anti-money laundering and counter-terrorist financing (AML/CFT), and anti-corruption laws (including, where applicable, the U.S. Foreign Corrupt Practices Act and the UK Bribery Act).

Upon reasonable request, the Client shall provide any necessary KYC/AML information and represents that neither it, nor its beneficial owners, nor any relevant Authorized User is listed on any applicable sanctions list.

20. Commercial References

Unless the Client objects in writing in advance, MyTraffic may refer to the Client as a commercial reference and use its name, corporate name and/or logo, as well as a general description of the services provided, in its institutional and commercial communications, provided that such use does not harm the Client’s image or reputation.

APPENDIX 1 — Subprocessors (Indicative List)

Artificial Intelligence Models

AWS Bedrock (Amazon Web Services) — Primary LLM Gateway — access to Anthropic Claude and other models via AWS — region eu-west-1 (Ireland) — AWS Customer Agreement DPA — SCCs 2021 Module 2.

OpenAI Ireland Ltd / OpenAI LLC — RAG and embeddings — direct API call — DPA signed 30/03/2026 — SCCs 2021 Module 2.

Google AI Studio (Google LLC) — Lightweight auxiliary tasks (titles, geocoding) — DPA confirmation in progress.

Authentication

Supabase Inc. — User authentication (email, phone) — DPA signature in progress.

Twilio Inc. / Twilio Ireland Ltd — OTP phone validation — DPA signature in progress.

Observability

LangChain Inc. (LangSmith) — Tracing and debugging of LLM interactions — DPA signed 27/03/2026 — SCCs 2021 Module 2 — 15-day retention.

AI monitoring and traceability: LangSmith / LangChain (USA) — Function: tracing, debugging, and internal service improvement for Gini interactions. LangSmith receives full prompt and output content. DPA signed 27/03/2026. SCCs 2021 Module 2 included. Governing law: Ireland. Retention: 15 days on LangSmith platform; internal extract retained up to 12 months for service improvement, access restricted to authorised Engineering personnel.

Depending on technical configurations and availability, certain processing operations may be carried out within the European Union and/or outside the European Economic Area (EEA). Where transfers outside the EEA are required, they are governed by appropriate transfer mechanisms (including, where applicable, Standard Contractual Clauses and supplementary measures), in accordance with the DPA where applicable.

MyTraffic maintains an up-to-date list of subprocessors and shall inform the Client of any material changes in accordance with these GTSU and/or the DPA.

Upon the Client’s written request, MyTraffic shall provide the available information relating to the primary processing location per provider and the applicable transfer mechanisms.

APPENDIX 2 — Acceptable Use Policy (AUP)

Prohibited Uses

The following uses are strictly prohibited:

  • illegal activities, fraud, impersonation, discrimination, or harassment;
  • large-scale extraction, scraping, crawling, abusive automation, or circumvention of Quotas (including multiple accounts or scripts);
  • uploading, entering, or processing content that infringes third-party rights (including copyright or trademarks) or discloses third-party confidential information without authorization;
  • reverse engineering, attempts to access system prompts, or exfiltration of secrets or data;
  • prompt injection or jailbreak attempts intended to bypass safeguards or obtain internal information;
  • uploading unauthorized sensitive data;
  • automation of sensitive decisions without appropriate human supervision;
  • generation, dissemination, or facilitation of malware, phishing, spam, or any activity intended to compromise systems or accounts;
  • uploading sensitive data or special categories of personal data within the meaning of the GDPR (e.g., health, biometric, political opinions), unless expressly authorized in writing and governed by a DPA and appropriate security measures;
  • use intended to generate abnormally high volumes of LLM tokens or to artificially multiply conversations or workflows in order to circumvent Quotas.

Sanctions

In the event of a violation, MyTraffic may apply limitations, suspend access, or terminate the Contract.

Immediate measures may be taken where there is a security, compliance, or third-party rights risk.

MyTraffic may suspend access immediately in the event of a security, compliance, or third-party rights risk and shall notify the Client as soon as reasonably practicable of the general reasons for such action. Access may be restored if the violation is remedied, unless a continuing risk or legal obligation prevents reinstatement.

APPENDIX 3 — Security Incident Exhibit

1. Notification

MyTraffic shall notify the Client without undue delay after reasonable confirmation of a security incident impacting the Service.

Where the incident involves personal data processed on behalf of the Client, notification and assistance obligations shall be governed by the DPA (GDPR).

Notification shall occur once the incident is reasonably confirmed by MyTraffic and presents a significant impact on the confidentiality, integrity, or availability of the Service or the affected data.

2. Minimum Content of Notification

To the extent reasonably available at the time and permitted by legal, contractual, and security requirements, the notification shall include:

  • a description of the incident (nature, date, scope);
  • the types of data potentially affected;
  • the likely impact;
  • measures already taken;
  • recommendations for the Client;
  • next steps.

3. Communication Channel

Notification shall be sent by email to the security contact designated in the Order Form or, failing that, to the contractual contact.

MyTraffic contact: support@mytraffic.fr

Email subject: “Security Incident – Gini”

4. Update Frequency

MyTraffic shall provide reasonable updates proportionate to the severity of the incident (e.g., daily for critical incidents, weekly for major incidents).

A closing report may be provided upon reasonable request.

5. Cooperation

The Client shall reasonably cooperate with MyTraffic.

MyTraffic may implement protective measures as necessary, including credential resets, token revocation, or temporary suspension of access.

6. No Admission of Liability

Any notification or communication made pursuant to this Appendix shall not constitute an acknowledgment of fault, liability, or breach by MyTraffic.

APPENDIX 4 — AI Safety Exhibit

Authorized Use Cases

  • business decision support (including area analysis, document summarization, and generation of tables and insights)

Prohibited / Restricted Use Cases

  • automated sensitive decisions without appropriate human supervision;
  • data exfiltration;
  • any use in violation of the Acceptable Use Policy (AUP).

Controls

MyTraffic implements reasonable technical and organizational controls, including in particular:

  • rate limiting;
  • anomaly detection;
  • prompt-injection and jailbreak prevention;
  • output filtering;
  • measures aimed at reducing risks related to personal data (PII) exposure;
  • traceability and logging.

The controls and measures described above constitute reasonable technical and organizational measures intended to reduce the risks associated with use of the Service. They do not guarantee the complete absence of errors, bias, interruptions, or abusive use, nor do they guarantee any specific result.

Processes

  • limited red teaming exercises;
  • quality review procedures;
  • rollback and/or kill switch mechanisms in the event of a significant risk.

Change Management

Model and/or dataset versioning is implemented where reasonably possible. Material changes are notified through release notes or equivalent communications.

Regulatory Qualification

The Service is designed and provided as a limited-risk artificial intelligence system within the meaning of applicable European regulations, subject to the Client’s compliance with the authorized use cases and the restrictions set forth herein and in the AUP.

Feedback

A support channel is available to report problematic Outputs or abusive use cases.

APPENDIX 5 — Trust Center Summary

This Appendix 5 constitutes an informational summary (“Trust Center Summary”) provided for transparency purposes only. In the event of any inconsistency, the GTSU, the applicable Order Form, and/or the DPA shall prevail. The measures described herein may evolve in accordance with the Contract.

Security

  • encryption at rest where applicable, depending on components and offers;
  • role-based access control (RBAC) and least-privilege principles;
  • multi-factor authentication (MFA / 2FA) for sensitive and/or administrative access;
  • access logging and periodic access reviews;
  • anti-abuse measures.

Retention

  • Gini logs retained for 90 days (standard);
  • automatic deletion;
  • legal hold where applicable;
  • accelerated deletion available as an option and/or upon request, subject to legal obligations and legal hold requirements.

Subprocessors

  • AWS (primary hosting region as contractually agreed, where applicable);
  • LLM Providers and monitoring (depending on Service architecture): AWS Bedrock (Amazon Web Services, eu-west-1, primary gateway), OpenAI Ireland Ltd / OpenAI LLC (RAG and embeddings), Google AI Studio (auxiliary tasks), LangSmith/LangChain (USA, monitoring — DPA signed 27/03/2026), Supabase Inc. (authentication — DPA in progress), Twilio Inc. / Twilio Ireland Ltd (OTP phone validation — DPA in progress).

Where transfers outside the EEA are required, appropriate transfer mechanisms apply (including Standard Contractual Clauses). Material changes to subprocessors are notified in accordance with the Contract and/or the DPA.

Incidents

  • notification without undue delay;
  • minimum information content;
  • proportionate updates;
  • cooperation with the Client.

Artificial Intelligence

  • transparency regarding AI use and limitations;
  • human review requirements;
  • AI safeguards;
  • prohibition of sensitive uses without appropriate supervision.

Privacy

  • DPA available (Article 28 GDPR);
  • data minimization;
  • deletion in accordance with the DPA and/or the Contract.

Contact

Support and security reporting: support@mytraffic.fr

APPENDIX 6 — Evaluation / Trial Conditions

1. Purpose

Where MyTraffic grants the Client access to the Service on a trial, evaluation, demonstration, or free basis (“Trial”), the Client may use the Service within the limits set out below and as displayed in the Service Interface.

2. Duration

The Trial is granted for a fixed period of fourteen (14) calendar days, unless expressly stated otherwise at the time of activation (via the website and/or the Service Interface). The Trial start date and end date are displayed in the Service Interface.

Unless expressly agreed otherwise by MyTraffic, the Client may benefit from a Trial and/or a free (“freemium”) offer only once every six (6) months following the end of the previous Trial or freemium period.

3. Access and Activation (Self-Service)

The Trial may be activated on a self-service basis via the MyTraffic website, without mandatory prior qualification. MyTraffic reserves the right to limit, suspend, or refuse access to the Trial in the event of abuse, fraud, or non-compliance with these GTSU and/or the AUP.

4. Scope / Quotas / Support

The features available during the Trial, as well as applicable Quotas and technical limits, are those displayed in the Service Interface at the time of use.

The Trial is provided “as is”, without warranty, without any service level commitment (SLA), and with limited support.

5. Continuity from Trial to Paid Offer (Account, Data, Configuration)

If the Client subscribes to a paid offer at the end of the Trial, the Client shall retain the same Account, as well as the settings, configurations, and data created during the Trial, subject to compliance with these GTSU and payment of the amounts due.

Such continuity is guaranteed provided that subscription to a paid offer occurs no later than seven (7) calendar days following the end of the Trial.

6. Pre-Expiration Notifications

Prior to the expiration of the Trial, the Client may receive informational notifications (by email and/or in-app) regarding the upcoming end of the Trial and subscription options.

7. End of Trial / Upgrade / Payment

At the end of the Trial, if the Client has not subscribed to a paid offer, access to Trial features shall be blocked and the Client shall be invited to subscribe to a paid offer.

No payment information is required to activate the Trial. Payment details are requested only at the time of subscription to a paid offer.

8. Subscription to a Paid Offer

Subscription to a paid offer may be completed: on a self-service basis via the Service Interface (in particular for self-serve offers); or through MyTraffic’s sales teams, depending on the selected package and the agreed commercial terms.

GINI – Privacy & Data Use Notice

MyTraffic SAS
‍
Version 2.2 | July 2026

This Notice is published to GINI users in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). It replaces Draft v1.0 of January 2026 in its entirety. In the event of any conflict with MyTraffic's general Privacy Policy, this Notice prevails with respect to GINI.

1. Purpose and Scope

This Privacy & Data Use Notice (the "GINI Privacy Notice") provides clear, precise and transparent information regarding the processing of personal data carried out in connection with the use of GINI, MyTraffic's AI-powered conversational assistant, in accordance with Articles 13 and 14 GDPR.

This GINI Privacy Notice must be read in conjunction with:

  • the MyTraffic Global Privacy Policy (Politique de Gestion des Données Personnelles);
  • the GINI Terms of Service;
  • where applicable, the Data Processing Agreement (DPA) entered into with professional customers.

In the event of inconsistency, the GINI Terms of Service and the applicable DPA prevail for matters relating to GINI. This Notice applies solely to GINI and does not replace MyTraffic's general privacy documentation applicable to other products and services.

2. Data Controller and Contact

MyTraffic SAS, a French société par actions simplifiée, having its registered office at 12 rue Vivienne (Lot 3), 75002 Paris, France, registered under number 814 849 113 RCS Paris, acts:

  • as data controller for technical and security-related processing operations related to GINI (notably logs, access management, abuse prevention, and compliance obligations);
  • as data processor within the meaning of Article 28 GDPR when processing personal data contained in Customer Content on behalf of its professional customers.

For any question relating to data protection:

Data Controller Table
Field Details
Data Controller MyTraffic SAS — 12 rue Vivienne, 75002 Paris, France
Privacy contact privacy@mytraffic.fr
DPO Yaël COHEN-HADRIA — Yael.Cohen.Hadria@ey-avocats.com

3. Description of the GINI Service

GINI is a web-based AI conversational service that enables authorised users to:

  • submit questions or instructions in natural language ("Prompts");
  • upload documents or datasets ("Customer Documents");
  • receive AI-generated responses, analyses or recommendations ("Outputs").

GINI operates under human supervision. Users remain solely responsible for verifying Outputs before using them in any professional or decision-making context.

GINI does not perform autonomous or automated decision-making within the meaning of Article 22 GDPR. Outputs are probabilistic by nature and do not constitute professional, legal, financial or strategic advice.

4. Categories of Personal Data Processed

4.1 Customer Content

Depending on how GINI is used, MyTraffic may process the following categories of data on behalf of customers:

  • text-based prompts submitted by users;
  • documents, files or datasets uploaded by users;
  • contextual information included by users in the course of their interaction with GINI.

Customer Content may, at the sole initiative and responsibility of the customer or its authorised users, contain personal data.

4.2 Technical and Usage Data

In connection with the use of GINI, MyTraffic processes certain technical data including:

  • user identifiers and account references (pseudonymised);
  • timestamps of interactions;
  • identifiers of the AI model and service version used;
  • technical logs strictly for traceability, security and compliance purposes.

4.3 Excluded Data — Special Categories

GINI is not intended to process special categories of personal data within the meaning of Article 9 GDPR (health data, political opinions, religious beliefs, etc.). Users are expressly instructed not to submit sensitive personal data through GINI. An Acceptable Use Policy (AUP) governs permitted use.

4.4 Inference Data

In the course of generating Outputs, temporary intermediate data (inference data), which may include elements derived from Customer Content, is processed transiently by the AI model. This data is not stored, not used to train or improve AI models, and is automatically discarded once the Output has been generated. MyTraffic does not make any representation that such intermediate data is free of personal data, as its content depends on what is included in the original prompt or uploaded documents.

5. Purposes of Processing

Personal data processed in connection with GINI are processed exclusively for the following purposes:

  • provision and operation of the GINI service;
  • generation of AI-based outputs at the request of users;
  • security, monitoring, abuse prevention and fraud detection;
  • compliance with legal and regulatory obligations, including the EU Artificial Intelligence Act;
  • incident management, troubleshooting and internal service improvement, including the use of anonymised or pseudonymised conversation examples to improve GINI's prompt engineering and response quality (without training external AI models on Customer Content);
  • AI system supervision and audit trail maintenance in accordance with CNIL recommendations.

6. Legal Bases for Processing

The following table sets out the legal basis applicable to each processing operation carried out by MyTraffic as data controller:

Legal Basis Table
Processing Operation Legal Basis Justification
Transmission of prompts to AI models to generate Outputs Art. 6(1)(b) Contract Processing is necessary for the performance of the GINI service contract with the Customer.
Security logs, access management, abuse prevention Art. 6(1)(f) Legitimate interests MyTraffic's legitimate interest in ensuring the security and integrity of the service. Interests do not override users' fundamental rights given the technical and pseudonymised nature of the data.
Usage analytics and product improvement (Mixpanel, Segment) Art. 6(1)(f) Legitimate interests MyTraffic's legitimate interest in improving service quality. Data is pseudonymised and limited to technical usage events.
AI monitoring and traceability (LangSmith) Art. 6(1)(f) Legitimate interests MyTraffic's legitimate interest in debugging, ensuring AI system reliability, and improving GINI's internal response quality.
LangSmith receives full prompt and output content for tracing and debugging purposes. Conversation examples may also be used internally (without external transmission) to improve GINI's prompt engineering. This constitutes a transfer of personal data to the United States. The Data Processing Agreement was signed on 27/03/2026.

Retention: 14 days (base traces) on LangSmith. An internal extract may be retained for up to 12 months for service improvement purposes, accessible only to authorised Engineering personnel. Deletion of this internal extract mechanism is still pending implementation on MyTraffic's side.
Compliance with legal obligations (GDPR, AI Act, CNIL) Art. 6(1)(c) Legal obligation Processing necessary to comply with applicable legal and regulatory obligations.
Phone validation for account security (Twilio) Art. 6(1)(b) Contract Processing is necessary to provide the account authentication feature requested by the user.

Where MyTraffic acts as a data processor, the legal basis for processing is determined by the Customer as data controller, as set out in the applicable DPA.

7. Use of AI Models and Third-Party Sub-Processors

GINI relies on AI models and APIs provided by third-party sub-processors acting as data processors within the meaning of Article 28 GDPR. These providers process personal data solely on documented instructions from MyTraffic, strictly to the extent necessary to generate Outputs, and are contractually prohibited from processing such data for any other purpose. Prompts, conversation history and, where applicable, uploaded documents are transmitted to these providers strictly to the extent necessary to generate Outputs.

The main sub-processors acting as data processors on MyTraffic's documented instructions in GINI's AI processing chain include:

  • Anthropic (Claude) — primary LLM model provider, accessed via AWS Bedrock (EU region, eu-west-1) rather than direct API — zero data retention (ZDR) and zero operator access (ZOA) — Amazon Bedrock does not store model inputs or outputs by default, and no operator of the service can access model input or output — Anthropic acts as a sub-processor of AWS, with no direct contractual relationship with MyTraffic for this data flow — AWS Data Processing Addendum applies, incorporating Standard Contractual Clauses (SCCs 2021 Module 2)
  • OpenAI (Ireland Ltd / OpenAI LLC) — LLM model provider for RAG operations and knowledge base embeddings, accessed via direct API (USA, with OpenAI Ireland Ltd as EEA contracting entity) — 30-day retention for abuse monitoring logs (per OpenAI's public API policy) — DPA signed 30/03/2026, SCCs included
  • Google Gemini API — LLM model provider for lightweight auxiliary tasks accessed directly via MyTraffic's Google Cloud Platform (GCP) account — Google AI Studio is not used — region and DPA status to be confirmed with Engineering
  • LangSmith / LangChain Inc. — AI monitoring and traceability, receives full prompt and output content (USA) — 14-day retention on the LangSmith platform — DPA signed 27/03/2026, SCCs 2021 Module 2 included, Irish law applicable
  • AWS Ireland (eu-west-1) — cloud hosting infrastructure (EU)
  • Supabase Inc. — authentication and login management (email address and phone number) — logs retained 7 days, session retained 3 days — DPA status under confirmation
  • Twilio Inc. / Twilio Ireland Ltd — phone number validation via one-time password (OTP/SMS) — phone numbers retained in pseudonymised form for 13 months on Twilio's side; validation response retained by MyTraffic for 24 hours only — DPA status under confirmation

The complete and up-to-date list of sub-processors is made available via MyTraffic's Trust Center. Customers are notified of any material changes to this list in accordance with Article 28 GDPR.

Technical safeguard: MyTraffic routes its primary LLM model calls (Anthropic Claude) through AWS Bedrock, configured on the EU region (eu-west-1), which consolidates data processing safeguards under a single AWS Data Processing Addendum. MyTraffic no longer relies on a third-party AI routing layer. For providers called directly (OpenAI, Google Gemini API via MyTraffic's GCP account, LangSmith), MyTraffic implements contractual safeguards including Data Processing Agreements with Standard Contractual Clauses. All transmissions are encrypted in transit (TLS 1.2 minimum). Customer Content is not used to train or improve external AI models.

Unless otherwise agreed in writing and in compliance with GDPR:

  • Customer Content is not used to train or improve the AI models of MyTraffic's sub-processors (Anthropic, OpenAI, or any other external LLM provider); MyTraffic may however use anonymised or pseudonymised conversation examples internally to improve GINI's own prompt engineering and response quality, without transmitting such data to any external model provider;
  • Customer Content is processed solely for the purpose of providing the GINI service.

8. International Data Transfers

GINI’s primary hosting infrastructure, and its primary LLM inference (Anthropic Claude via AWS Bedrock), are located within the European Economic Area (AWS Ireland), with no cross-region transfer for this flow. However, the operation of GINI involves transmissions of data to providers located outside the EEA, in particular in the United States. The following providers receive personal data outside the EEA: OpenAI Ireland Ltd / OpenAI LLC (USA — direct API for RAG and embeddings, 30-day abuse monitoring retention, DPA signed 30/03/2026), Google Gemini API accessed via MyTraffic's GCP account (USA — lightweight auxiliary tasks such as title generation and geocoding; region and DPA status to be confirmed with Engineering), LangSmith / LangChain Inc. (USA — full prompt and output content, 14 days retention on platform, DPA signed 27/03/2026), Supabase Inc. (authentication — email and phone number, DPA status under confirmation), and Twilio Inc. / Twilio Ireland Ltd (phone number validation via OTP, 13-month retention on Twilio’s side in pseudonymised form, DPA status under confirmation). GCP and AWS infrastructure used for primary hosting and primary LLM inference is located within the EU (eu-west-1 / EU region) and does not involve transfers outside the EEA.

For all transfers outside the EEA, MyTraffic ensures that appropriate safeguards are in place in accordance with Articles 44 to 49 GDPR, including:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021 (Decision 2021/914), Module 2 (controller to processor);
  • Transfer Impact Assessments (TIAs) carried out or in progress for each US-based provider receiving personal data, with priority given to sub-processors that receive full prompt and output content (OpenAI, LangSmith);
  • technical supplementary measures including encryption in transit (TLS 1.2 minimum). The primary LLM inference flow via AWS Bedrock (eu-west-1) operates under Bedrock's zero data retention (ZDR) and zero operator access (ZOA) model, under which model inputs and outputs are not stored by default and no service operator can access them. For providers called directly (OpenAI, Google Gemini API), MyTraffic is assessing the feasibility of equivalent zero-retention configurations and will update this Notice accordingly.

9. Data Recipients

Personal data processed through GINI may be accessed, on a strictly need-to-know basis, by:

  • authorised MyTraffic personnel involved in service operation, security, and compliance;
  • third-party sub-processors providing hosting, infrastructure, AI model APIs, monitoring and authentication services strictly required to deliver GINI functionalities;
  • competent public authorities, where required by applicable law.

MyTraffic ensures that all recipients are bound by confidentiality obligations and appropriate data protection agreements.

10. Data Retention Periods

Personal data processed in connection with GINI are retained only for the period necessary to achieve the purposes described in this Notice. The applicable retention periods are as follows:

Data Retention Table
Data Category Retention Period Deletion Mechanism
Conversation history
(prompts & outputs)
12 monthsafter last activity Automatic deletion 12 months after the last message in a conversation (last-activity basis), in accordance with the data minimisation principle (Art. 5.1.c GDPR).
Technical logs
(security, access, errors)
15 – 90 days Automatic rotation and deletion by logging infrastructure.
Usage and analytics data 24 months Aggregated after 24 months — individual identifiers deleted.
Account and authentication data Duration of contract+ legal retention obligations Deleted or returned upon contract termination per applicable DPA.
AI monitoring traces
(LangSmith)
14 dayson LangSmith Up to 12 monthsinternal extract Automatic deletion by LangSmith after 14 days.
Internal extract deletion mechanism not yet implemented on MyTraffic's side (pending). Access restricted to authorised Engineering personnel in the meantime.
Uploaded documents
(Customer Documents)
Session durationor as specified in DPA Conversation history deleted at session end.
File storage in S3: deletion mechanism pending confirmation with Engineering.

11. Rights of Data Subjects

Where personal data are processed, data subjects may exercise the following rights under the GDPR:

  • Right of access (Article 15) — obtain confirmation and a copy of personal data processed;
  • Right to rectification (Article 16) — request correction of inaccurate data;
  • Right to erasure (Article 17) — request deletion of personal data, subject to legal retention obligations;
  • Right to restriction of processing (Article 18) — request temporary suspension of processing;
  • Right to data portability (Article 20) — receive personal data in a structured, commonly used format;
  • Right to object (Article 21) — object to processing based on legitimate interests.

To exercise any of the above rights, please send a written request to: privacy@mytraffic.fr

MyTraffic will respond within one (1) month of receipt of the request, in accordance with Article 12 GDPR.

Where MyTraffic acts as data processor on behalf of a Customer, requests from data subjects will be forwarded to the relevant Customer acting as data controller, who remains responsible for responding.

12. Right to Lodge a Complaint with a Supervisory Authority

In accordance with Article 13(2)(d) GDPR, data subjects have the right to lodge a complaint with a competent supervisory authority if they consider that the processing of their personal data infringes applicable data protection law.

The competent supervisory authority for MyTraffic SAS is:

Supervisory Authority Table
Field Details
Authority Commission Nationale de l'Informatique et des Libertés (CNIL)
Address 3 Place de Fontenoy, 75007 Paris, France
Website www.cnil.fr

13. Security Measures

MyTraffic implements appropriate technical and organisational measures to ensure a level of security appropriate to the risks, in accordance with Article 32 GDPR, including:

  • access controls and multi-factor authentication (2FA) for all systems processing personal data;
  • encryption of data at rest and in transit (TLS 1.2 minimum);
  • secure hosting within the European Union (AWS Ireland, eu-west-1);
  • Consolidation of primary LLM model access through AWS Bedrock (EU region), reducing the number of direct sub-processor relationships and centralising data protection safeguards under a single AWS Data Processing Addendum;
  • logging and monitoring of access to the service;
  • internal governance procedures and staff confidentiality obligations;
  • regular security reviews and incident response procedures.

14. AI-Specific Transparency — EU Artificial Intelligence Act

In accordance with Article 50 of the EU Artificial Intelligence Act and CNIL recommendations on generative AI systems, users of GINI are informed that:

  • they are interacting with an AI system;
  • Outputs are generated automatically by a large language model and may contain inaccuracies, hallucinations or biases;
  • Outputs must be reviewed and validated by a human before being used for any professional, legal, financial or strategic decision;
  • GINI does not generate decisions with legal or similarly significant effects within the meaning of Article 22 GDPR.

MyTraffic does not use Customer Content to train, fine-tune or improve the AI models of third-party providers, whether Anthropic, OpenAI, or any other external model provider. MyTraffic may however use anonymised or pseudonymised conversation examples internally to improve GINI's own response quality and prompt engineering, without sharing such data externally.

15. Updates to this Notice

This GINI Privacy Notice may be updated from time to time to reflect changes in the service, applicable legal requirements or regulatory guidance. The version number and date of last update are indicated at the top of this document.

The applicable version is the one published within the GINI interface and on MyTraffic's website at the time of use. In the event of a material update, MyTraffic will inform users through appropriate means (in-product notification or email).

16. Contact

For any question regarding this GINI Privacy Notice or the processing of personal data in connection with GINI:

MyTraffic Contact Table
Field Details
MyTraffic SAS MyTraffic SAS — 12 rue Vivienne (Lot 3), 75002 Paris, France
Privacy email privacy@mytraffic.fr
DPO Yaël COHEN-HADRIA — Yael.Cohen.Hadria@ey-avocats.com

DATA PROCESSING AGREEMENT

Pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR)

This Data Processing Agreement (the "DPA") is entered into between:

  • [CONTROLLER LEGAL NAME], [address] (the "Controller"); and
  • MyTraffic SAS, a French simplified joint-stock company, 12 rue Vivienne (Lot 3), 75002 Paris, France, SIRET 814 849 113 00026 (the "Processor").

Each a "Party" and together the "Parties".

This DPA forms part of, and is incorporated by reference into, the General Terms of Service and Use (B2B) – Gini: MyTraffic AI Assistant, Version 2.0, dated 15/06/2026 (the "Main Agreement"). Where the Processor processes personal data on behalf of the Controller in connection with the GINI service (the "Services"), this DPA governs that processing. In the event of any conflict between this DPA and the Main Agreement regarding the processing of personal data, this DPA prevails.

1. Definitions

1.1 Terms such as "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in the GDPR.

1.2 "Sub-processor" means any processor engaged by the Processor to carry out processing activities on behalf of the Controller. "SCCs" means the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), Module Two (controller-to-processor). "Client Content" means all Prompts, uploaded documents and content provided by the Controller in connection with the Services. "Data Protection Law" means the GDPR and any applicable national implementing legislation.

2. Subject matter and details of processing

2.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I.

2.2 The Processor processes personal data only for the duration of the Main Agreement and for any period during which it continues to hold personal data on the Controller's behalf, subject to Clause 3.8.

3. Obligations of the Processor

3.1 Documented instructions.

The Processor processes personal data only on the Controller's documented instructions, including with regard to international transfers, unless required by Union or Member State law. The Main Agreement, this DPA and the Controller's use of the Services constitute the Controller's complete and documented instructions. The Processor informs the Controller if, in its opinion, an instruction infringes Data Protection Law.

3.2 Confidentiality.

The Processor ensures that persons authorised to process personal data are bound by an obligation of confidentiality (contractual or statutory).

3.3 Security.

Taking account of the state of the art, costs and the nature, scope, context and purposes of processing, the Processor implements appropriate technical and organisational measures under Article 32 GDPR, as described in Annex II.

3.4 Sub-processors.

The Controller grants a general written authorisation for the engagement of the sub-processors listed in Annex III. The Processor shall inform the Controller of any intended addition or replacement of a sub-processor with reasonable prior notice, giving the Controller the opportunity to object on reasonable data-protection grounds. The Processor shall ensure that each sub-processor is bound, by way of a written agreement, by data-protection obligations providing a level of protection equivalent to that set out in this DPA. The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.

3.5 Data subject rights.

Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller's obligation to respond to data-subject requests under Chapter III GDPR. Where the Processor receives such a request directly, it forwards it to the Controller and does not respond substantively unless instructed.

3.6 Assistance.

The Processor assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, personal data breach notification, data protection impact assessment and prior consultation), taking into account the nature of processing and the information available to the Processor.

3.7 Breach notification.

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data, providing the information reasonably necessary for the Controller to meet its obligations under Articles 33 and 34 GDPR. Notification and cooperation are further detailed in the Security Incident Exhibit (Appendix 3 to the Main Agreement).

3.8 Return or deletion.

At the Controller's choice, the Processor deletes or returns all personal data at the end of the provision of the Services and deletes existing copies, unless retention is required by Union or Member State law. Applicable retention defaults are set out in Annex I. Deletion or return of personal data contained in Client Content is governed exclusively by this DPA.

3.9 Audits and information.

The Processor makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. Documentation-based review is the default; an on-site audit or third-party audit may be requested as a last resort, subject to reasonable prior notice, during business hours and in compliance with confidentiality obligations.

4. International transfers

4.1 The Processor does not transfer personal data outside the EEA except where an appropriate safeguard under Chapter V GDPR applies — an adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified) or the SCCs — supported by a Transfer Impact Assessment per recipient. The safeguard and current agreement status for each sub-processor are set out in Annex III.

4.2 Transfer Impact Assessment documentation and, where applicable, executed SCCs can be made available to the Controller on request.

5. Obligations of the Controller

5.1 The Controller warrants that it has a valid lawful basis for the processing it instructs, that its instructions comply with Data Protection Law, and that it is responsible for the personal data it or its Authorized Users include in Client Content, in accordance with the data-minimisation principle.

5.2 The Controller shall not include special categories of personal data (Article 9 GDPR) in Prompts or uploaded documents unless it has obtained the explicit consent of the data subjects concerned and has notified the Processor in advance in writing, or as otherwise expressly agreed in writing with the Processor and subject to appropriate additional safeguards. This reflects the Acceptable Use Policy (Appendix 2 to the Main Agreement).

6. Liability

6.1 Each Party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Main Agreement.

7. Term and termination

7.1 This DPA takes effect on the effective date of the Main Agreement and remains in force for as long as the Processor processes personal data on the Controller's behalf.

8. Governing law

8.1 This DPA is governed by French law. The competent courts shall be those of Paris, unless otherwise specified in the Order Form.

ANNEX I — DETAILS OF PROCESSING

Subject matter Provision of the GINI AI-powered location-intelligence assistant (SaaS) to the Controller.
Duration For the term of the Main Agreement and any period during which the Processor retains personal data on the Controller's behalf.
Nature and purpose Hosting; processing of Prompts and uploaded documents; generation of AI Outputs (analyses, summaries, tables, recommendations); user authentication; security, anti-abuse and traceability; legal compliance; and Service maintenance. No automated decision-making within the meaning of Art. 22 GDPR.
Types of personal data Account data of the Controller's Authorized Users (name, business email; phone number where OTP validation is used). Pseudonymised technical/usage data (identifiers, timestamps, model versions, token counts). Authentication data. Client Content (Prompts, uploaded documents) may contain personal data at the Controller's discretion. Special categories (Art. 9) are prohibited save under the conditions in Clause 5.2.
Categories of data subjects The Controller's Authorized Users and any individuals referenced in Client Content at the Controller's discretion.
Frequency Continuous, for the duration of the Services.
Retention defaults Prompts, conversation history and uploaded documents: for the active session and a period not exceeding 12 months thereafter (automatic purge currently in implementation). Technical metadata / AI traceability logs: up to 90 days by default (up to 1 year for certain offers, as specified in the Order Form). AI monitoring (LangSmith): 15 days on the LangSmith platform; internal extract retained up to 12 months for service improvement, with access restricted to authorised Engineering personnel. Accelerated deletion on request (support@mytraffic.fr), subject to legal-hold requirements.

ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES (Art. 32 GDPR)

The Processor implements technical and organisational security measures proportionate to the identified risks, including, depending on the applicable technical scope:

1. Encryption

  • Encryption at rest where applicable, depending on components and offers.

2. Access control

  • Role-based access control (RBAC) and least-privilege / need-to-know principles.
  • Enhanced authentication (MFA / 2FA) for sensitive and administrative access.
  • Access logging and periodic access-rights reviews.

3. Data lifecycle

  • Data retention and deletion policies (lifecycle management), with legal-hold mechanisms where applicable, and data minimisation.

4. Anti-abuse and monitoring

  • Rate limiting, anomaly detection and application-level security controls.
  • Traceability and logging of Service interactions.

5. AI safeguards (AI Safety Exhibit — Appendix 4)

  • Prompt-injection and jailbreak prevention; output filtering; measures to reduce risks related to personal-data (PII) exposure.
  • Limited red-teaming exercises; quality-review procedures; rollback and/or kill-switch mechanisms in the event of significant risk.
  • Model and/or dataset versioning where reasonably possible; material changes notified via release notes or equivalent.

6. Incident management

  • Documented incident-management procedures; notification to the Controller without undue delay; personal-data breach obligations as set out in this DPA and the Security Incident Exhibit (Appendix 3).

7. Organisational measures

  • Staff bound by confidentiality commitments; sub-processors engaged under Data Processing Agreements; per-provider Transfer Impact Assessments; documented internal policies.

The measures described above constitute reasonable technical and organisational measures intended to reduce the risks associated with use of the Service. They do not guarantee the complete absence of errors, bias, interruptions or misuse, nor any specific result.

ANNEX III — SUB-PROCESSORS

Your data is primarily hosted and processed in the European Union. A small number of specialised sub-processors support specific features, each engaged (or being engaged) under a Data Processing Agreement. Transfers outside the EU are protected by EU Standard Contractual Clauses and assessed through Transfer Impact Assessments; the current agreement status for each is shown below.

Provider Purpose / role in the service Data involved Transfer protection / agreement status
Amazon Web Services (AWS) Secure cloud hosting and primary AI inference (Anthropic Claude via AWS Bedrock, EU inference profile), region eu-west-1 (Ireland) All service data, processed within the EU Processed in the EU — no international transfer. AWS DPA; SCCs (2021, Module 2) as backstop.
OpenAI Ireland Ltd / OpenAI LLC Semantic search: RAG and embeddings (direct API) Query content used for retrieval DPA signed 30/03/2026; SCCs (2021, Module 2).
Google AI Studio (Google LLC) Lightweight auxiliary tasks (titles, geocoding) Limited prompt-derived content DPA confirmation in progress; SCCs (2021, Module 2) to apply on execution.
Supabase Inc. User authentication (email, phone) Authentication data DPA signature in progress; SCCs (2021, Module 2) to apply on execution.
Twilio Inc. / Twilio Ireland Ltd OTP phone validation Phone number and OTP delivery data DPA signature in progress; SCCs (2021, Module 2) to apply on execution.
LangChain Inc. (LangSmith) Tracing and debugging of LLM interactions Prompt and output content, timestamps (15-day platform retention) DPA signed 27/03/2026; SCCs (2021, Module 2). Governing law: Ireland.
Stripe (Stripe Payments Europe Ltd / Stripe Inc.) Billing and payment processing (PCI-DSS Level 1). No card data reaches MyTraffic. Billing / transaction data US. DPA signature in progress; SCCs (2021, Module 2) to apply on execution.
Datadog Inc. System log management and observability Technical logs with user/organisation context (pseudonymised) US. DPA signature in progress; SCCs (2021, Module 2) to apply on execution.

How Anthropic Claude is used: GINI's main AI model, Anthropic Claude, is accessed through AWS Bedrock in Europe (EU inference profile), so prompts and responses are processed and stored within the EU. There is no separate transfer of your data to the United States for this core AI inference.

Key points

  • Primary hosting and primary AI inference take place within the EU (AWS, Ireland).
  • Providers outside the EU support only limited, specific tasks (authentication, OTP validation, embeddings, auxiliary features, monitoring, billing, log management).
  • Each provider is engaged under a Data Processing Agreement; transfers outside the EU rely on EU Standard Contractual Clauses (2021, Module 2) and/or the EU–US Data Privacy Framework, supported by Transfer Impact Assessments.
  • Where a provider agreement is still being finalised, this is indicated in the table; the Standard Contractual Clauses apply upon execution.
  • Client Content is processed only to provide, secure, maintain and improve the Service. Transfers to sub-processors are governed by DPAs and SCCs; Zero Data Retention is applied where available and applicable (not guaranteed for all providers at all times — contractual safeguards are the primary mechanism).

Get all the latest news about MyTraffic

Follow us on

Discover our monthly newsletter

Products
Gini
DataLibrary
AudienceLabs
SmartMonitor
Solutions
Retail
Restaurants
Franchises
Commercial Real Estate
Brokers
Groceries
Public sector
Advertising
Charging Point Operators
FMCG
Content
Market studiesBlogClientsEventsAlternatives
Company
About usPress & Media kitHow it worksJoin usContact

MyTraffic ©2026 - All rights reserved.

Terms and conditionsPrivacy Policy