Privacy policy
Last updated: 8/14/2026
1. Controller
The controller for the data collected through the Lou service is:
- COME & H, SASU with share capital of €3,000 (publisher of the "Lou" service)
- Lyon Trade and Companies Register no. 921 125 191 — SIRET: 921 125 191 00012
- Registered office: 12 rue de la Part-Dieu, 69003 Lyon, France
- Telephone: +33 (0)4 65 84 10 97
- Data protection contact: dpo@lou.care
Role of partners
The Publisher's role varies according to the processing concerned:
| Processing | Role |
|---|---|
| Conversation at a partner point of sale: making the assistant available in the establishment, catalogue offered, campaigns displayed, handling of your request by a professional | Joint controllers (Art. 26): the partner and the Publisher |
| Core of the service: conversation outside a point of sale, health reference sources, security, individual account, platform statistics | The Publisher alone as controller |
| Content a professional publishes themselves (product pages, catalogue, brand content) and data they entrust to us | The Publisher as processor (Art. 28) for the professional |
Joint controllership — allocation (Art. 26(1)):
- the Publisher provides the technical supply of the service, security, retention, information of data subjects and the handling of requests to exercise rights;
- the partner decides on making the service available in its establishment, on the catalogue and campaigns, and processes the exchanges transferred to it when one of its professionals takes over.
🚨 Whichever the partner, you may exercise all of your rights with the Publisher, which is your single point of contact within the meaning of Article 26(1): dpo@lou.care. You retain the option of exercising your rights with each of the joint controllers (Art. 26(3)).
2. Who this policy applies to
It covers three uses: the visitor (conversation without an account), the holder of an individual account (history, favourites, profiles) and the professional (access to the professional area). Where relevant, the sections specify the use concerned.
A professional who connects their account to a third-party application (AI assistant connector) is additionally covered by the MCP connector privacy policy, which supplements this one.
3. Data collected
Conversation (all uses)
- Conversation data: content of the messages exchanged with Lou, technical identifiers of the conversation and of the message.
- Session data: technical session identifier (cookie lou_session_id), point of sale scanned, brand or product identified by the QR code.
- Technical data: IP address hashed irreversibly with a secret salt (HMAC-SHA256) for security purposes (anti-abuse, rate limiting) — no raw IP address is retained. User agent, campaign parameters, timestamps.
- Visit context data: approximate location at country, region and city level, derived from the IP address by our host (resolution takes place at the delivery-network level — Lou never receives the raw IP address); device type, operating system and browser inferred from the user agent. IP-based geolocation is of limited accuracy and is indicative only.
- Photographs: where you send a photo (product, question to a professional), it is retained for the time needed to handle your request. Capture metadata (including geolocation) is removed on receipt.
Individual account
- Identification data: display name, email address, authentication credentials (password, passkey, or Google/Apple credentials if you choose that sign-in method).
- Profiles: for you and, if you wish, for your relatives — display name, family relationship, date of birth, declared sensitive populations, declared allergies, skin and hair characteristics, preferences.
- Usage: favourites, conversation history, preferences inferred from your browsing, consents and their history, notification settings.
Professional
- Identification data and attachment to an establishment, sign-in and action logs, billing data.
4. Health data
Some of the information you provide (sensitive populations, allergies, or what you write spontaneously in the conversation) constitutes data concerning health, protected by Article 9 GDPR. It is subject to distinct processing:
- Safety — your declared populations and allergies are used to rule out products that are not suitable for you. This filter is always active and rests on your explicit consent given when the profile is recorded.
- Commercial personalisation — using that same information to offer you personalised offers or recommendations is disabled by default. It requires separate, specific consent, revocable at any time, distinct from use of the service.
- Exchange with a professional — where your request is transferred to a professional at the establishment, they access the conversation thread in order to reply. Those exchanges follow a dedicated retention regime (see Article 6).
Health content is enabled in the service only with partners expressly authorised for it who have signed the corresponding undertakings.
Profiles of relatives
The service allows you to record the profile of a third party (a child, a parent). If you do so, you must inform that person that their data appears in your account and that they have the rights described in Article 9. You may delete a profile at any time; deleting it does not erase the conversation history, which reverts to being attached to your default profile.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provision of the conversational service (product guidance, reproduction of composition, official information) | Performance of the contract (Art. 6(1)(b)) |
| Management of the individual account, history, favourites | Performance of the contract (Art. 6(1)(b)) |
| Safety filter based on declared populations and allergies | Explicit consent (Art. 9(2)(a)) |
| Personalised recommendations and offers based on health data | Separate explicit consent (Art. 9(2)(a)) |
| Recommendations based on browsing preferences (non-health) | Legitimate interest (Art. 6(1)(f)) |
| Handling of a request by a professional at the establishment | Consent (Art. 6(1)(a)) and Art. 9(2)(a) |
| Notifications (email, push notification) | Consent (Art. 6(1)(a)) |
| Publication of product reviews and moderation | Performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Security, fraud prevention, rate limiting | Legitimate interest (Art. 6(1)(f)) |
| Audience measurement and aggregated statistics | Legitimate interest (Art. 6(1)(f)) |
| Billing and management of professional subscriptions | Performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Response to requests to exercise rights | Legal obligation (Art. 6(1)(c)) |
6. Retention periods
| Data | Period |
|---|---|
| Conversation without an account, without human intervention | 13 months after the last message, then irreversible anonymisation (content and identifiers are erased; only non-identifying counters remain) |
| Conversation attached to an account | Retained for as long as the account exists, then erased when it is deleted |
| Exchange handled by a professional (health data) | 3 years after the last activity, then irreversible anonymisation |
| Photographs sent | Erased together with the exchange to which they relate |
| Hashed IP address | 30 days |
| Session cookie lou_session_id | 90 days, rolling (see Article 10) |
| Technical conversation diagnostics | 90 days |
| Raw audience-measurement data | 18 months, after which only aggregated statistics remain |
| Individual account and profiles | Until the account is deleted by its holder |
| Consents and their history | 3 years from their withdrawal, as evidence |
| Requests to exercise rights | 3 years after closure (Art. 30 GDPR) |
| Billing data | 10 years (accounting obligation) |
| Aggregated non-identifying statistics | No limit (non-identifying) |
The anonymisation referred to above is not reversible: the content of messages, the hashed IP address, the user agent, the city, the region and the session identifier are permanently erased.
7. Recipients and providers
Your data is accessible only to authorised persons at the Publisher, to partners under the conditions of Article 1 (exchange handled by a professional, aggregated statistics), and to the following technical providers:
| Provider | Role | Processing location |
|---|---|---|
| Vercel Inc. | hosting of the interface and server functions, tracker-free audience measurement | European Union (Paris) |
| Google Cloud | managed database | European Union (Paris) |
| Google Cloud (Vertex AI) | language model and embedding model | European Union |
| Amazon Web Services (Bedrock) | fallback model, used only when the primary model is unavailable | European Union (Frankfurt) |
| Cloudflare | protection against bots and abuse | European Union |
| Ably | real-time transmission of exchanges with a professional | European Union |
| Scaleway | sending of the service's emails | France (Paris) |
| Stripe | payment and management of professional subscriptions | European Union |
| Sentry | collection of application errors | European Union |
| Better Stack | availability monitoring | European Union |
| Google, Apple | sign-in via a third-party account, if you choose that method | European Union |
The language model providers used by Lou process data solely in order to produce the requested response; reuse for training purposes is disabled.
No data is transferred, rented or sold to third parties for commercial purposes.
8. Transfers outside the European Union
Data is processed and stored within the European Union. Several of the providers listed above are nevertheless established in the United States or may access data from there for technical support purposes. Those accesses are framed by the standard contractual clauses adopted by the European Commission, supplemented where applicable by the provider's certification under the EU–US Data Privacy Framework, together with additional technical measures (encryption in transit and at rest, minimisation of the data transmitted).
You may obtain a copy of the applicable safeguards by writing to dpo@lou.care.
9. Profiling and automated decisions
The service analyses your browsing and your interactions in order to suggest products likely to suit you. That processing constitutes profiling within the meaning of Article 4(4) GDPR.
- It produces no automated decision producing legal effects or similarly significantly affecting you within the meaning of Article 22.
- Health data is used for it only with your separate explicit consent (see Article 4).
- You may object at any time from your account settings or by writing to dpo@lou.care. The safety filter, for its part, remains active: it protects you, it does not target you.
10. Cookies and trackers
Details of the cookies placed, their purpose and their duration are set out in the cookie policy.
Lou places a technical session cookie (lou_session_id, HttpOnly, Secure, SameSite=Lax) lasting 90 days, rolling. It ensures the continuity of your conversation and allows you to retrieve your exchanges when you return.
This cookie is strictly necessary for the provision of the service expressly requested by the user: without it, a conversation cannot continue from one message to the next. On that basis, it is not subject to prior consent.
No advertising cookie is placed. Audience measurement is carried out without any tracker placed on your device and without following your browsing on other sites; the corresponding data is used for statistical and security purposes only.
If an account is created, an authentication cookie is placed to keep your session open.
11. Rights of data subjects
In accordance with the GDPR and the French Data Protection Act, you have the following rights:
- Right of access — to obtain confirmation that data concerning you is being processed and to receive a copy of it;
- Right to rectification — to have inaccurate or incomplete data corrected;
- Right to erasure ("right to be forgotten") — to obtain the erasure of your data in the cases provided for in Art. 17;
- Right to portability — to receive the data you have provided in a structured, commonly used format;
- Right to object — to object, on grounds relating to your particular situation, to processing based on legitimate interest;
- Right to restriction of processing;
- Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand;
- Right to give directives concerning the fate of your data after your death.
These rights are exercised free of charge through our dedicated form or by email to dpo@lou.care. We reply within one month of receipt of the request, extendable by two months where the request is complex or where there is a high number of requests — you are then informed within the initial period (Art. 12(3) GDPR).
In the event of a persistent disagreement, you may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), the French data protection authority, www.cnil.fr.
12. Security
Lou implements technical and organisational measures appropriate to the risk: TLS encryption in transit, encryption at rest, hashing of sensitive technical identifiers, strict partitioning of data between partners, role-based access control, audited logging of access to health data, separation of environments, mandatory code reviews and continuous monitoring.
In the event of a data breach likely to result in a risk to your rights and freedoms, the Publisher informs the CNIL within 72 hours and, where the risk is high, the data subjects as soon as possible (Art. 33 and 34 GDPR).
13. Changes to the policy
This policy may be updated to reflect a change in the service or in the legal framework. The date of the last update is shown at the top of the page. Any substantial change is brought to the attention of account holders by appropriate means.