Empi is built in the EU and privacy-first. This notice summarises your rights under the General Data Protection Regulation (GDPR) and how to exercise them. It complements our full Privacy Policy, which describes the data we process in detail.
1. Controller and contact
The data controller is Empi, France. For any data protection request, contact [email protected].
2. Your rights
- Access: get confirmation of whether we process your data and a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure: have your data deleted, including via a GDPR crypto-shred that destroys your tenant key so encrypted content cannot be recovered, backups included.
- Restriction: limit how we process your data in certain cases.
- Portability: receive the data you provided in a structured, machine-readable format, and have it sent to another controller where technically feasible.
- Objection: object to processing based on our legitimate interests, including profiling.
- No solely automated decisions: we do not make decisions with legal or similarly significant effects about you based solely on automated processing. Empi's scheduling suggestions are decision-support, not binding decisions.
- Withdraw consent: where we rely on consent, you can withdraw it at any time, without affecting prior processing.
3. How to exercise them
Email [email protected]. We respond within one month, as the GDPR allows, and may ask you to confirm your identity. You can also export and delete much of your data directly from your account settings.
4. Lawful bases
We process personal data on these bases: performance of our contract with you (running the Service and billing), our legitimate interests (security, abuse prevention, and aggregated analytics, balanced against your rights), legal obligations (such as keeping invoices), and your consent (non-essential analytics, optional communications). See the Privacy Policy for the mapping of purposes to bases.
5. Sub-processors
We use a small set of vetted sub-processors under data-processing agreements, including Scaleway (EU hosting and key management), Google and Microsoft (calendar integrations), Clerk (authentication), PostHog (analytics), and Sentry (error monitoring). The current list and regions are in the Privacy Policy.
6. Data location and transfers
Your data is hosted in the European Union. Where a sub-processor is outside the EU/EEA, transfers rely on an adequacy decision or the European Commission's Standard Contractual Clauses, with supplementary safeguards where appropriate.
7. Encryption and crypto-shred
Task and note content is encrypted at rest with a per-tenant key wrapped by a master key in our key management service. A crypto-shred destroys the tenant key, so the corresponding ciphertext is permanently unrecoverable, backups included. This is how we deliver a delete that truly deletes.
8. Right to complain
If you believe we have mishandled your data, you can lodge a complaint with your local supervisory authority. In France, that is the CNIL (cnil.fr). We would appreciate the chance to address your concern first.
9. Business customers (DPA)
If you use Empi on behalf of an organisation and need a Data Processing Agreement, request one at [email protected] and we will provide our standard DPA, including the sub-processor list and SCCs.