BESNARD CONSULTING SAS
Privacy Policy
Effective date: 19 September 2026
How BESNARD CONSULTING SAS collects, uses, stores, shares and deletes personal data and Google user data in the BoilerTech website and the BT Plate application.
1. Who we are
This privacy policy is published by BESNARD CONSULTING SAS, a French simplified joint-stock company registered in Angers under SIREN 882 670 615, with its registered office at 9 Route des Gaillards, 49250 La Ménitré, France ("BoilerTech", "we", "us"). BoilerTech is the trade name under which BESNARD CONSULTING SAS operates.
It applies to the BoilerTech website (boilertech.io and www.boilertech.io), to the BT Plate application, also presented to Google as "BoilerTech App" (the "Application"), and to every related API and integration we operate. It also covers the data we receive from Google when you connect a Google account to the Application.
You can reach our data protection contact at contact@boilertech.io or by post at the address above.
2. Data we collect
Account data: name, email address, hashed password, multi-factor authentication settings, single sign-on identifiers, workspace memberships and roles.
Customer content: the accounting records, spreadsheets, documents, emails and reports that you or your organisation load into the Application so that it can build financial reporting on your behalf. For this content, your organisation is the data controller and BoilerTech acts as a data processor under its instructions.
Technical data: IP address, browser type, request timestamps, request performance metrics and error logs, used to operate and secure the service.
Google user data: the data listed in section 3 when you choose to connect a Google account.
The BoilerTech website itself does not use advertising cookies or third-party tracking. The Application stores authentication tokens in your browser's local storage so that you stay signed in.
3. Google user data we access
The Application only requests access to Google user data after you explicitly authorise it through Google's consent screen. Each authorisation is limited to the scopes listed below, and every scope is used only for the feature described next to it.
- Basic profile (openid, userinfo.email, userinfo.profile): your Google email address, display name and profile picture, used to identify the connected Google account in the Application and to show you which account is in use.
- Gmail read-only (gmail.readonly): the Application searches your mailbox with the filters you configure (date range, search query, labels) and stores the message headers of matching emails: sender, recipients, subject, date, snippet, thread and label identifiers. The full body and attachments of an email are fetched from Gmail only when you open that email or attachment in the Application, and are not stored unless you explicitly save an attachment into a workspace. The Application never sends, modifies, labels or deletes emails.
- Google Drive (drive): the Application lists the files in the Drive folders you configure, downloads those files as inputs to the data pipelines you set up, and writes the report files you ask it to produce into the folders you choose. To let its background jobs reach those folders, the Application shares the folders you configure with its own service account. It does not browse, read or modify any other file of your Drive.
- Google Sheets (spreadsheets): the Application reads the spreadsheets whose URL you provide as pipeline inputs and writes pipeline results into the spreadsheets you designate as outputs. No other spreadsheet is accessed.
4. How we use data
We use account data to create and secure your account, to authenticate you, to enforce workspace permissions and to send you service emails such as password resets, security alerts and notifications you configure.
We use customer content and Google user data solely to provide and improve the user-facing features you request: synchronising and searching emails, scanning folders, loading spreadsheets, running the data pipelines you configure, and producing the reports, dashboards and exports you ask for.
We use technical data to monitor availability, diagnose incidents, prevent abuse and meet our security obligations.
We do not use Google user data or customer content for advertising, profiling, credit scoring, resale, or to build databases unrelated to your workspace. We do not use Google user data to develop, improve or train generalised, non-personalised artificial intelligence or machine learning models. When you choose to run an AI-assisted feature on your own content, the processing is limited to your request and its result is delivered to you only.
5. Google API Services User Data Policy and Limited Use
BoilerTech App's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we only use Google user data to provide or improve user-facing features that are prominent in the Application, we do not transfer Google user data to third parties except as needed to provide those features, to comply with the law or as part of a merger or acquisition with prior notice to you, we do not use it for advertising, and humans at BoilerTech do not read Google user data unless you have given your explicit consent for a support request, it is necessary for security purposes such as investigating abuse, it is required to comply with the law, or the data has been aggregated and anonymised for internal operations.
6. Who we share data with
We do not sell personal data or Google user data, and we do not share them with data brokers, advertisers or information resellers.
Members of your workspace see the data you load into that workspace and the reports produced from it, according to the permissions you and your organisation administrators configure.
We rely on the following processors to operate the service, each bound by a data processing agreement: Amazon Web Services (hosting, storage, databases, secrets management and backups in the European Union, Frankfurt region, with a US-based parent company), Cloudflare (DNS and network delivery for parts of the website), Google (the Google APIs you authorise), and the email delivery provider used for service emails. Third-party accounting, banking and payment platforms that you connect to the Application receive only the requests needed to synchronise your data with them.
We may disclose data when required by law, by a court order or by a competent authority, or to protect our rights, our users or the public. Where a transfer leaves the European Economic Area, it is covered by the European Commission's standard contractual clauses or an adequacy decision.
7. How we protect data
All traffic between your browser, the Application and third-party APIs is encrypted in transit with TLS. Databases, file storage and backups hosted on Amazon Web Services are encrypted at rest.
Google OAuth tokens are stored server-side, are never exposed to other users, and are only used by the Application's backend to perform the operations described in section 3. Access to production systems is restricted to authorised personnel with multi-factor authentication, and administrative actions are logged.
Passwords are stored as salted hashes. Multi-factor authentication and single sign-on are available to every account, and workspace permissions restrict which members can see or change each dataset.
8. Retention and deletion
Google user data is kept only as long as the corresponding Google connection is active in the Application. When you disconnect a Google account, delete a Gmail, Drive or Sheets connection, or revoke the Application's access from your Google account permissions page (https://myaccount.google.com/permissions), the stored OAuth tokens are removed and the synchronised message headers, file listings and connection settings are deleted from active systems within 30 days.
Account data and customer content are kept for the duration of your subscription and deleted within 30 days after your workspace is closed, unless a longer retention period is required by law, in particular for accounting and tax records. Technical logs are kept for at most 12 months.
Backups are rotated automatically and are only restored for disaster recovery; data deleted from active systems disappears from backups when the corresponding backup expires.
You can request the deletion of your account or of any data we hold about you at any time by writing to contact@boilertech.io.
9. Your rights
Under the General Data Protection Regulation and French data protection law, you have the right to access, rectify, erase and port your personal data, to restrict or object to its processing, and to withdraw your consent at any time. To exercise these rights, write to contact@boilertech.io; we answer within one month. You can also lodge a complaint with the French supervisory authority, the Commission Nationale de l'Informatique et des Libertés (CNIL).
If your data was loaded into the Application by your employer or by another organisation, that organisation is the data controller and we will forward your request to it.
10. Changes to this policy
We may update this policy when our practices or the law change. The effective date at the top of the page shows the latest version. If a change materially affects how we use Google user data or your personal data, we notify signed-in users in the Application and by email before it takes effect.
11. Contact
BESNARD CONSULTING SAS, 9 Route des Gaillards, 49250 La Ménitré, France. Director of publication: Rémi Besnard. Email: contact@boilertech.io.