Privacy Policy
Last updated: December 15, 2025
At ToDoVoice, we take the protection of your personal data very seriously. This policy explains how we collect, use, store and protect your information in accordance with the General Data Protection Regulation (GDPR).
In Summary
- We encrypt all your sensitive data
- We never sell your data to third parties
- Your data is hosted in Europe (GDPR compliant)
- You maintain full control of your information
1. Data Controller
The controller of your personal data is:
ToDoVoice
Publisher of ToDoVoice
Email: privacy@todovoice.com
DPO (Data Protection Officer): dpo@todovoice.com
2. Data Collected
2.1 Data Provided Directly
When you sign up, we collect:
- First and last name
- Email address
- Password (encrypted)
- Phone number (optional)
- Company and position (for Business and Pro+ plans)
2.2 Data Generated by Usage
When using ToDoVoice, we collect:
- Created content (tasks, events, notes, voice recordings)
- Service usage data
- Preferences and settings
- Support interaction history
2.3 Technical Data
We automatically collect:
- IP address
- Browser type and version
- Operating system
- Device type
- Connection data (timestamp, session duration)
- Cookies and similar technologies (see Cookies section)
3. Purpose of Processing
We use your data to:
- Provide the service: Create and manage your account, process voice commands, sync events
- Improve experience: Personalize interface, optimize AI features
- Billing: Process payments, issue invoices
- Customer support: Respond to inquiries, resolve technical issues
- Security: Detect and prevent fraud, abuse and violations
- Communication: Send important notifications, newsletters (with your consent)
- Legal obligations: Comply with accounting and tax obligations
4. Legal Basis for Processing
Our data processing is based on the following legal grounds:
- Contract execution: Provision of ToDoVoice service
- Consent: Marketing, newsletters, non-essential cookies
- Legitimate interest: Service improvement, security, fraud prevention
- Legal obligation: Retention of billing data, fraud prevention
5. Data Sharing
5.1 Data Recipients
We never sell your data. Your data may only be shared with:
- Service providers: Cloud hosting (AWS Europe), payment processor (Stripe), email service (with your consent)
- Your team members: If using Business or Pro+ plan, shared data is visible to authorized members
- Legal authorities: Upon legal request from competent authorities
5.2 International Transfers
Your data is hosted exclusively in data centers located in the European Union. If a transfer outside the EU is necessary, we use standard contractual clauses approved by the European Commission.
6. Retention Period
- Active account data: Throughout your subscription
- Deleted account data: 30 days (then permanent deletion)
- Billing data: 10 years (legal accounting obligation)
- Security logs: 12 months
- Marketing data: 3 years after last contact (or until consent withdrawal)
7. Data Security
We implement technical and organizational measures to protect your data:
- Encryption of data in transit (HTTPS/TLS)
- Encryption of data at rest (AES-256)
- Two-factor authentication (2FA) available for all accounts
- Strict data access controls
- Regular security audits
- Continuous threat monitoring
- Security incident response plan
- Ongoing team awareness and training
8. Your Rights (GDPR)
In accordance with GDPR, you have the following rights:
Right of access
Obtain a copy of your personal data
Right to rectification
Correct inaccurate or incomplete data
Right to erasure
Request deletion of your data (subject to legal obligations)
Right to restriction
Limit processing of your data in certain circumstances
Right to portability
Receive your data in a structured, commonly used format
Right to object
Object to processing of your data for legitimate reasons
Right to withdraw consent
Withdraw consent at any time (marketing, cookies)
Right to define post-mortem directives
Define the fate of your data after death
To exercise these rights, contact us at privacy@todovoice.com. We will respond within a maximum of 30 days.
You also have the right to file a complaint with the CNIL (French Data Protection Authority): www.cnil.fr
9. Cookies and Similar Technologies
ToDoVoice uses cookies to improve your experience. You can manage your preferences via your browser settings or our consent banner.
Types of cookies used:
- Essential cookies: Necessary for service operation (authentication, security)
- Performance cookies: Anonymous audience measurement (with your consent)
- Functional cookies: Remember your preferences (language, theme)
10. Policy Changes
We may modify this privacy policy to reflect changes in our practices or legislation. We will notify you of any significant changes by email or via an in-app notification. We encourage you to review this page regularly.
11. Contact
For any questions about this policy or the use of your personal data:
- Email: privacy@todovoice.com
- DPO: dpo@todovoice.com
- Support: support@todovoice.com