Privacy policy
Last updated: 7 October 2026
This is a translation of the French version, provided for convenience. If the two differ, the French version prevails.
Parla is published by Abdellah Hmache, sole trader (entrepreneur individuel, EI), 23 rue Olympe de Gouges, 92600 Asnières-sur-Seine, France (SIREN 105 820 757). Contact: contact@askparla.com.
Two different roles. For the data of the askparla.com website and of its merchant customers, Parla is the controller. For conversations that take place on a merchant's shop, Parla is a processor: the merchant is the controller, and Parla acts only on their instructions, under the data processing agreement.
1. What Parla processes as controller
Demo requests and prospects
When you fill in the website's form or ask the website's assistant: name, email address, shop address, platform, message, language, and the conversation that led to the request. Legal basis: legitimate interest in answering a request you made. Retention: 12 months after the last exchange, then automatic deletion.
Customer accounts
Company name, email address, password (stored only as a hash), language, email preferences, billing details and VAT number, linked shops, usage and invoices. Legal basis: performance of the contract and accounting obligations. Retention: the length of the contract, then 10 years for accounting records, as the law requires.
Parla sends customers service emails: usage alerts, handovers, end of trial, and a weekly summary on Mondays. The summary and the usage alerts can be turned off in the customer account. Parla does not send marketing to its customers without their consent.
Shopify shops
When the app is installed, Shopify sends Parla the shop's name and address, its contact email and an access token. Parla then reads the shop's catalogue, stock and rules to answer, and reads an order only when a visitor asks about it, after checking its number and email. Parla answers the data and erasure requests Shopify forwards on behalf of the shop's customers, and erases the shop's data 48 hours after uninstall, when Shopify asks it to.
The website itself
No advertising trackers, no social networks, no third-party analytics. Server logs keep IP addresses for security, for less than 30 days.
2. What Parla processes as processor, for merchants
When a visitor uses the chat on a merchant's shop, Parla processes on that merchant's behalf:
- the text of written messages, and the audio during a voice call;
- a random conversation identifier, the page being viewed, the browser language;
- the order number and email entered to check an order, and that order's details;
- the delivery address, when the visitor asks to change it;
- for a handover to the merchant's team: the request, the visitor's email and, where relevant, the order number;
- the email address left to be told when a product is back in stock, or when an item the shop does not sell yet arrives.
Handovers. When the assistant hands over, the request is emailed to the address the merchant chose, with the conversation, and shows in their account for 30 days.
"Let me know" addresses. They are used for that one message only. On WooCommerce, they are stored in the merchant's own database and the shop itself sends the email: Parla does not keep them. On Shopify, where no interface lets an app send an email on the merchant's behalf, Parla keeps the address until the message is sent, writes in the shop's name with its contact address for replies, then erases the address; an address whose message never went out is erased after 120 days. Only one message is sent: there is no mailing list and nothing to unsubscribe from.
Postal addresses are masked before being sent to the AI model. IP addresses are never stored in clear: they are hashed with a server-specific salt to limit abuse. Parla never uses this data to train a model, or for its own purposes.
Retention periods
| Data | Period |
|---|---|
| Conversations (message text, page context) | 24 hours |
| Handovers to the merchant's team (request, email, order number) | 30 days |
| "Let me know" emails: back in stock, item not sold yet | until the message is sent, 120 days at most |
| Transcripts, only if the merchant turns them on | 14 days, last 50 conversations |
| Audio of a voice call | not stored: processed live, during the call |
3. Sub-processors
Parla uses the following providers. Each is bound by a data processing agreement, and transfers outside the European Union rely on the European Commission's standard contractual clauses (SCCs).
| Provider | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Server and backup hosting | Germany |
| Anthropic | AI model that writes the answers | United States (SCCs) |
| Deepgram | Speech recognition, calls only | European Union |
| Cartesia | Speech synthesis, calls only | United States (SCCs) |
| Brevo | Sending service, handover and "let me know" emails | France |
| OVHcloud | Domain name and mailbox | France |
| Stripe | Payment for subscriptions taken on the website; receives no data about shop visitors | Ireland, and United States (SCCs) |
Deepgram and Cartesia are only involved if premium voice is on for the shop. Without a voice call, no audio leaves the visitor's browser. Shopify, for shops that use it, is the merchant's platform, not a sub-processor of Parla.
4. Cookies and local storage
Parla sets no advertising or audience-measurement cookies. The items below are needed for the service to work and do not require consent.
| Name | Where | Purpose | Duration |
|---|---|---|---|
| parla_assist | Shop (cookie) | Random conversation identifier, to link an order to a conversation | 7 days |
| parla_added | Shop (cookie) | Products added to the cart from the chat | 7 days |
| Chat history | Shop (session storage) | Keep the conversation on screen across pages | Until the tab is closed |
| Greeting dismissed | Shop (local storage) | Stop showing the greeting bubble once closed | 7 days |
| parla_ac | Customer account (cookie) | Sign-in session | 12 hours |
| Language and setup list | Website and customer account (local storage) | Remember the chosen language and a hidden setup list | Until the browser clears it |
5. Security
Everything travels over HTTPS. Shop access tokens, conversations and email addresses left by visitors are encrypted at rest (AES-256-GCM); backups are encrypted and kept away from the main server. Access to administration is password-protected and limited to those who need it. Any data breach is notified to the merchants concerned without undue delay, and to the French data protection authority (CNIL) within 72 hours when the law requires it.
6. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability. Write to contact@askparla.com; you will get an answer within one month.
If your request concerns a conversation on a merchant's shop, contact that merchant first: they are the controller. Parla will help them.
You can also complain to the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at cnil.fr, or to the authority of the EU country where you live.
7. Artificial intelligence
Parla is an AI system. Visitors are told so as soon as the chat opens and at the start of a call, in line with article 50 of the EU Artificial Intelligence Act. No decision with legal effects is taken automatically: the assistant answers, suggests and hands over, and a human stays reachable.
8. For merchants: a paragraph to reuse
Merchants must inform their visitors. This paragraph can be copied as is into their own privacy policy:
"Our shop uses Parla, an AI-based conversational assistant, to answer your questions, advise you and track your orders, in writing or by voice. The messages you send it, the order details you give it and, if you ask, your email address are processed by Parla on our behalf, as a processor. Conversations are deleted after 24 hours; a request passed on to our team is kept for 30 days. Details are in Parla's privacy policy: askparla.com/en/privacy."
9. Changes
This policy may change. Merchants are told by email of any substantial change at least 30 days before it takes effect.