Back to home

Privacy Policy

Last updated: December 15, 2025

At ToDoVoice, we take the protection of your personal data very seriously. This policy explains how we collect, use, store and protect your information in accordance with the General Data Protection Regulation (GDPR).

In Summary

  • We encrypt all your sensitive data
  • We never sell your data to third parties
  • Your data is hosted in Europe (GDPR compliant)
  • You maintain full control of your information

1. Data Controller

The controller of your personal data is:

ToDoVoice
Publisher of ToDoVoice
Email: privacy@todovoice.com
DPO (Data Protection Officer): dpo@todovoice.com

2. Data Collected

2.1 Data Provided Directly

When you sign up, we collect:

  • First and last name
  • Email address
  • Password (encrypted)
  • Phone number (optional)
  • Company and position (for Business and Pro+ plans)

2.2 Data Generated by Usage

When using ToDoVoice, we collect:

  • Created content (tasks, events, notes, voice recordings)
  • Service usage data
  • Preferences and settings
  • Support interaction history

2.3 Technical Data

We automatically collect:

  • IP address
  • Browser type and version
  • Operating system
  • Device type
  • Connection data (timestamp, session duration)
  • Cookies and similar technologies (see Cookies section)

3. Purpose of Processing

We use your data to:

  • Provide the service: Create and manage your account, process voice commands, sync events
  • Improve experience: Personalize interface, optimize AI features
  • Billing: Process payments, issue invoices
  • Customer support: Respond to inquiries, resolve technical issues
  • Security: Detect and prevent fraud, abuse and violations
  • Communication: Send important notifications, newsletters (with your consent)
  • Legal obligations: Comply with accounting and tax obligations

4. Legal Basis for Processing

Our data processing is based on the following legal grounds:

  • Contract execution: Provision of ToDoVoice service
  • Consent: Marketing, newsletters, non-essential cookies
  • Legitimate interest: Service improvement, security, fraud prevention
  • Legal obligation: Retention of billing data, fraud prevention

5. Data Sharing

5.1 Data Recipients

We never sell your data. Your data may only be shared with:

  • Service providers: Cloud hosting (AWS Europe), payment processor (Stripe), email service (with your consent)
  • Your team members: If using Business or Pro+ plan, shared data is visible to authorized members
  • Legal authorities: Upon legal request from competent authorities

5.2 International Transfers

Your data is hosted exclusively in data centers located in the European Union. If a transfer outside the EU is necessary, we use standard contractual clauses approved by the European Commission.

6. Retention Period

  • Active account data: Throughout your subscription
  • Deleted account data: 30 days (then permanent deletion)
  • Billing data: 10 years (legal accounting obligation)
  • Security logs: 12 months
  • Marketing data: 3 years after last contact (or until consent withdrawal)

7. Data Security

We implement technical and organizational measures to protect your data:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest (AES-256)
  • Two-factor authentication (2FA) available for all accounts
  • Strict data access controls
  • Regular security audits
  • Continuous threat monitoring
  • Security incident response plan
  • Ongoing team awareness and training

8. Your Rights (GDPR)

In accordance with GDPR, you have the following rights:

Right of access

Obtain a copy of your personal data

Right to rectification

Correct inaccurate or incomplete data

Right to erasure

Request deletion of your data (subject to legal obligations)

Right to restriction

Limit processing of your data in certain circumstances

Right to portability

Receive your data in a structured, commonly used format

Right to object

Object to processing of your data for legitimate reasons

Right to withdraw consent

Withdraw consent at any time (marketing, cookies)

Right to define post-mortem directives

Define the fate of your data after death

To exercise these rights, contact us at privacy@todovoice.com. We will respond within a maximum of 30 days.

You also have the right to file a complaint with the CNIL (French Data Protection Authority): www.cnil.fr

9. Cookies and Similar Technologies

ToDoVoice uses cookies to improve your experience. You can manage your preferences via your browser settings or our consent banner.

Types of cookies used:

  • Essential cookies: Necessary for service operation (authentication, security)
  • Performance cookies: Anonymous audience measurement (with your consent)
  • Functional cookies: Remember your preferences (language, theme)

10. Policy Changes

We may modify this privacy policy to reflect changes in our practices or legislation. We will notify you of any significant changes by email or via an in-app notification. We encourage you to review this page regularly.

11. Contact

For any questions about this policy or the use of your personal data:

Privacy Policy - ToDoVoice | ToDoVoice