Last updated: August 22, 2026
Conclavik is a closed-access analytical tool operated by Altanest SAS, a company registered in France. This policy describes how we collect, use, and protect your personal data when you, as an existing authorised user, use the Conclavik service (conclavik.com and its API).
Under the EU General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:
We do not sell your personal data, and we do not use your submitted questions to train any model of our own. Questions are processed by third-party AI providers under their respective API terms of service. Our four core providers (Anthropic, OpenAI, Google, xAI) are covered by the commercial terms described in section 5a; models reached through an intermediary carry different terms, which section 5a sets out.
Account data is retained as long as your account is active. You have full control over your data:
Deleted data is permanently removed from our servers and cannot be recovered. Server logs (containing IP addresses) are retained for 30 days for security purposes. Cryptographic attestation records, which contain only content hashes, processing parameters, and digital signatures (no question text or analysis content), are retained indefinitely to support compliance verification, even after content deletion.
We share data with the following third-party processors, each bound by data processing agreements:
When you submit a query, Conclavik transmits the question text and routing parameters to the providers whose models are selected for that run. The default panel uses four large language model providers under their paid commercial API tiers: Anthropic, OpenAI, Google, and xAI (all United States). We do not transmit your account email, payment data, or other directly identifying information to these providers. Where your query itself contains personal data, that content is transmitted as part of the prompt; you are responsible for the content you submit.
Anthropic, OpenAI, and Google contractually do not train models on customer API content under their commercial terms. xAI's published Grok API terms do not contain an explicit no-training commitment; we rely on the absence of identifying information in standard query bodies and monitor changes to its terms.
Some models offered in the analysis interface are not called at the vendor directly, but reached through OpenRouter, Inc. (United States), which forwards the request to a host. These models are marked in the model picker, and selecting one shows a notice naming the intermediary and stating where the question goes. They fall into two cases. Some are served from a single fixed host, which we name: at the date above, Meta (United States) for Muse Spark, Z.AI (China) for GLM and Alibaba (China) for Qwen — for these the recipient is known in advance, and for two of them it is in China. The rest are served from a pool that OpenRouter selects from per request; the pool changes over time and includes providers outside the EU and the United States, among them hosts in China. For those we cannot state in advance which host will receive a given question, and the no-training commitments described above do not necessarily apply to the host selected. Because the roster changes, the interface — not this list — is authoritative for any given model at the moment you select it. Using any of them is optional: none is part of the default panel, and reaching them requires enabling the corresponding data jurisdiction.
The Customer is the data controller for any personal data submitted within queries. Conclavik acts as data processor with respect to such input data, processing it solely to execute the requested multi-model analysis. Conclavik acts as data controller for system data (account information, billing records, request logs).
Your account data and analysis results are stored on servers in Germany (EU). Question content is transmitted to AI providers whose servers are located in the United States; these transfers rely on the Standard Contractual Clauses (SCCs) and equivalent safeguards under GDPR Art. 46 incorporated in each provider's commercial terms.
Under the EU General Data Protection Regulation, you have the right to:
To exercise any of these rights, contact us at the address below.
You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), the French data protection authority, at cnil.fr, or with any other competent EU supervisory authority.
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the CNIL within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay (GDPR Art. 34), describing the nature of the breach, its likely consequences, and the measures taken to address it.
Conclavik does not make automated decisions that produce legal effects or similarly significantly affect you (GDPR Art. 22). The AI analysis outputs are informational tools provided for your consideration; they do not constitute binding decisions, and no automated profiling of users is performed.
Authentication is managed by Clerk SSO. All traffic is encrypted via TLS (HTTPS). API keys are generated with cryptographically secure random generators. Sensitive data is encrypted at rest with AES-256. API endpoints are protected by rate limiting to prevent abuse. Access to infrastructure is restricted to authorized personnel only.
Clerk SSO sets a small number of strictly necessary cookies required to maintain your authenticated session; under Article 82 of the French Data Protection Act and CNIL guidance, these are exempt from prior consent. We do not use advertising or third-party tracking cookies. For audience measurement we run a self-hosted Umami instance which does not set cookies, does not fingerprint users, and stores no IP addresses (only a hashed country-level signal).
Conclavik is not directed at children and is intended for users aged 18 and over. We do not knowingly collect personal data from children under 16 (the age of digital consent in France under Article 8 GDPR / Art. 45 LIL). If you believe we have done so, contact contact@conclavik.com for deletion.
Altanest SAS
SIREN: 877 916 916 · TVA: FR67 877 916 916
20 Rue Guillaume Fichet, 74000 Annecy, France
Email: contact@conclavik.com