Privacy Policy
The data the Balt service processes, why it processes it, who else sees it, and for how long.
This Privacy Policy describes how SKILLFORGE APP, a French simplified joint stock company (société par actions simplifiée) with a share capital of EUR 1,000, identified under SIREN 993 554 203, with registered office at 2 Rue des Commères, 78310 Coignières, France (the « Provider », « Balt », « we », « us »), processes personal data in connection with the Balt service, its website, and its communications.
It forms an integral part of the Agreement and applies together with the Data Processing Agreement, which governs the processing we carry out on Customer’s behalf as a processor. In the event of conflict between this policy and the DPA with respect to such processing, the DPA prevails. Capitalized terms have the meanings given in the Definitions.
This document describes how the Service actually works, including what Balt reads, which is not always what one would assume from watching it work. Section 4 says so before anything else, because a customer who learns it from a support conversation has been told too late.
1. Scope
This policy covers:
- (a) the Service, meaning the Balt Application and the agent that takes part in conversations in connected Slack and Microsoft Teams workspaces;
- (b) the administration console, where Customer manages its organization, users, integrations, and billing;
- (c) the hire-balt.com website and the forms it offers;
- (d) the communications we send to Authorized Users and to prospects.
It does not cover the processing carried out by the Connected Platforms themselves. Where Customer connects Slack, Microsoft Teams, Google Workspace, or another Connected Platform, that platform remains the controller of the processing it performs on its own behalf, under its own privacy policy.
2. Our two roles
The same service gives rise to two distinct capacities, and the distinction determines which rights each person may exercise and with whom.
2.1 Processor, for data processed through the Service
Conversation content, documents, Outputs, content retrieved from Connected Platforms, and Customer Data generally are processed on Customer’s behalf and on its instructions. Customer is the controller: it determines the purposes and means, ensures it has a legal basis, and informs data subjects. We act as a processor within the meaning of Article 28 GDPR, under the Data Processing Agreement.
A data subject wishing to exercise rights over such data addresses Customer. If they contact us directly, we forward the request to Customer rather than responding ourselves, within the timeframes set out in Section 9 of the DPA.
2.2 Controller, for our own processing
We are the controller for the processing we determine ourselves: account and customer relationship management, billing, security and abuse prevention, audience measurement on our website and console, our commercial communications, and improvement of the Service from Aggregated Data within the meaning of Section 2.3 of the General Terms.
Sections 5, 12, and 14 describe that processing, its legal bases, and the rights exercised directly with us.
3. The data we process
3.1 Account and identity data
The name, business email address, sign-in identifier, and role of Authorized Users, and the organization they belong to. Sign-in to the console goes through our identity provider: we store no password and no third-party identity provider subject, and we mint no session of our own.
3.2 Workspace data
The identifier and name of the connected Slack or Microsoft Teams workspace, the list of conversations Balt has been added to, and the platform identifier, display name, and where applicable the email address of the people taking part in them.
3.3 Conversation content
The text of the messages in the conversations Balt belongs to, their author, their timestamp, and the thread they belong to, together with the files and documents submitted to Balt. Section 4 sets out the exact extent of that reading.
3.4 What Balt has learned
Balt keeps a workspace memory and skill documents, reformulated by Balt rather than quoted, and one private note per person, which no run started by another person can read. This content is derived from conversations and carries no attribution: nothing in it records which sentence came from whom. That property determines how it is deleted, as described in Section 10.
3.5 Integration credentials
The OAuth tokens and other credentials Customer provides to connect a Connected Platform. They are sealed with envelope encryption: the master key never leaves our hosting provider’s key management service, and our systems obtain only the right to ask it to unwrap a data key.
3.6 Technical logs and telemetry
The log of events received from the platforms, access and execution logs, model execution traces, performance metrics, and incidents. The event log retains the body of the received event, which is what makes replay and audit possible; the traces and metrics sent to our observability providers carry metadata and timings only.
3.7 Billing data
The corporate name, billing address, VAT number, subscribed plan, Credit consumption, and invoice history. Bank details and payment card data are handled by our payment provider and do not pass through our systems.
3.8 Meeting recording and transcription
Where Customer has Balt join an online meeting, the audio or video recording, the transcript, and the meeting metadata. This feature is a High-Risk Action within the meaning of Section 3.3 of the Product Terms: it always requires explicit human approval and can never be pre-authorized. The obligations to inform participants and obtain their consent lie with Customer, under Section 2 of the Acceptable Use Policy.
3.9 Website and communications
The data submitted through the website’s forms, the audience measurement described in Section 14, and the open and deliverability data for our transactional emails.
4. What Balt reads in a conversation
Balt reads every message in the conversations it belongs to, not only the ones that mention it.
That is a consequence of how chat platforms deliver events, not a choice made after the fact: Slack delivers every message in a channel to an app that is a member of it, and the equivalent consents on Microsoft Teams are read permissions on channel and chat messages. The scope is not narrowed because it is what allows Balt to answer from what was actually said rather than by querying the platform’s history on every question.
What Balt acts on is much narrower than what it reads. A message that is not addressed to it is written down and starts nothing: no model run, no reply. That decision is taken before anything durable happens.
Nothing is filtered at ingestion. A message is stored as it was written. It follows that Customer remains responsible for what is submitted to the Service, in particular for compliance with Section 3 of the Acceptable Use Policy, which lists the prohibited data categories.
4.1 How far back Balt can see
From the moment it joined a conversation, and up to ninety (90) days before that. When Balt is added to a conversation it reads that conversation’s recent history once, and never again. The boundary is stable and Balt is expected to state it rather than answer a question it cannot see far enough back to answer. That history backfill may be turned off on a deployment, in which case the boundary is simply the day Balt joined.
5. Purposes and legal bases
For the processing for which we are the controller within the meaning of Section 2.2:
- Providing and operating the Service, managing accounts, access, and support: performance of the contract with Customer, and legitimate interest as regards Authorized Users who are not parties to it;
- Billing and collecting amounts due, and keeping accounts: performance of the contract and compliance with legal and tax obligations;
- Securing the Service, detecting and preventing fraud, abuse, and incidents: legitimate interest in protecting the Service, its customers, and their data;
- Improving the Service from aggregated, de-identified, or anonymized data: legitimate interest, it being specified that such data identifies neither Customer nor any individual;
- Measuring audience on the website and console: consent, under Section 14;
- Sending communications about the Service: performance of the contract for service communications, consent or legitimate interest for prospecting, with a right to object exercisable at any time;
- Responding to requests from authorities and asserting our rights in legal proceedings: compliance with legal obligations and legitimate interest.
For processing carried out on Customer’s behalf, the purpose is the provision of the Service as described in Annex I to the DPA, and the legal basis is the one Customer has determined as controller.
6. Artificial intelligence and model training
We do not train any model, ours or a third party’s, on Customer Data. The contractual arrangements we have in place with each AI Subprocessor prohibit the use of Customer Data to train general-purpose AI models or for advertising purposes.
The content of a conversation is sent to the model provider at the moment Balt answers it, and for that purpose alone. The model used is the one named in Section 7.1, whose identity changes when we change it and is updated here when we do. The provider does not use that content to train its models; it may retain it for a limited period, at most thirty (30) days, solely to detect abuse, and then deletes it.
AI Subprocessors may modify their terms unilaterally. If we become aware that such a modification would materially reduce the level of protection applicable to Customer Data, we will inform Customer through the subprocessor change notification process set out in Section 8 of the DPA.
6.1 Data received from the Google APIs
Balt’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- that information is used only to provide and improve user-facing features prominent in the requesting Authorized User’s experience, such as answering a question about an email or placing an appointment in a calendar;
- it is neither used nor transferred to train, improve, or feed any generalized artificial intelligence model, nor for advertising purposes;
- it is transferred only to the subprocessors strictly necessary for those features, listed in Section 7, including the model provider that produces the requested answer;
- no individual at Balt reads it, except with Customer’s express prior agreement as to the specific items concerned, where necessary for security purposes, where required by law, or where the data is aggregated and anonymized for internal operations;
- Customer may revoke access at any time from the Service settings or from its Google account, which deletes the associated tokens under Section 5.4 of the Product Terms.
6.2 Data received from Slack and Microsoft Teams
Data obtained through the Slack and Microsoft Teams APIs is not used to develop, train, or improve any generalized machine learning model, nor for advertising or targeted advertising purposes. It is used solely to operate Balt in the workspace that installed it, and is disclosed neither to other customers nor to third parties other than the subprocessors listed in Section 7.
7. Subprocessors
The list below is the list of authorized subprocessors within the meaning of Section 8 of the DPA. It is kept here and nowhere else: the DPA and the Product Terms point to it rather than holding a copy of it.
Four of them process message content, and the rest do not. They are named first, because a list that flattened the two categories into one would be accurate and useless. Distinct from both, the infrastructure providers store that content at rest without processing it, and are marked as such below.
7.1 Subprocessors that process message content
- The model provider (OpenAI and Microsoft Azure AI Foundry): receives the content of the conversation Balt is answering, as the prompt sent to the model. Balt is an agent, and the model is what answers.
- Modal: receives message content whenever Balt writes and runs code about it. Code the agent writes runs in an isolated sandbox rather than on our machines.
- Recall.ai: takes the meeting bot into an online meeting, records it and transcribes it. Receives the audio, the video, the transcript and the list of participants.
- ElevenLabs: speech transcription. Receives the audio excerpts concerned and produces the corresponding text.
7.2 Other subprocessors
- Slack Technologies and Microsoft: already hold every conversation. The conversation is theirs, and Balt is a participant in it.
- Neon (Frankfurt, Germany): the Service’s database, where content is stored at rest and encrypted. Does not process it and does not access it on its own account.
- Scaleway (France): compute infrastructure and the encryption key management service, whose master key never leaves it.
- Restate: durable orchestration of runs. Queue messages and signals carry workspace, conversation, and event identifiers only; message bodies stay in the database and never reach the orchestrator.
- Nango: holds the OAuth integration credentials for Connected Platforms, and no messages.
- Clerk: console sign-in identity, and no messages.
- Langfuse and Superlog: model execution tracing and platform telemetry. Metadata and timings only, content deliberately never reaching them.
- Resend: delivery of transactional emails, including invitations.
- PostHog (European ingest): audience measurement on the website and the console.
- Autumn and Stripe: subscriptions, payments, and invoicing.
- Vercel: hosting of the public website.
We impose on each subprocessor, by contract, data protection obligations at least equivalent to those incumbent on us. Customer may object to the addition of a new subprocessor on the terms and within the period set out in Section 8 of the DPA.
We do not sell personal data and do not disclose it to third parties for targeted advertising purposes. We may disclose data where required by law or ordered by a competent authority, and in connection with a merger, acquisition, or asset sale, in which case this policy continues to apply until Customer is informed of any change.
8. Transfers outside the European Union
The Service’s primary data is hosted in France and in the European Union. Some of the subprocessors listed in Section 7 are established outside the European Union, principally in the United States.
Those transfers are framed by the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 and, where applicable, by the recipient’s certification under the EU-US Data Privacy Framework. They are subject to a transfer impact assessment and to supplementary measures where those are necessary. The detail is set out in Section 11 of the DPA.
9. Retention periods
A workspace’s data is kept while that workspace is connected, and deleted when it is not, or on request.
Nothing is deleted for being old. That is deliberate: a record pruned by age would give a moving boundary, and Balt could no longer answer consistently how far back it can see.
- Conversation content, memory, and derived documents: until the workspace is disconnected, the Agreement is terminated, or deletion is requested;
- Uninstallation of the app from Slack or Microsoft Teams: all data associated with that workspace is deleted within fourteen (14) business days, with no request needed;
- Event log: the same period as conversation content, which it makes it possible to rebuild;
- Integration credentials: until the relevant Connected Platform is disconnected, it being specified that disconnection does not by itself delete Customer Data already collected;
- Account data: for the Subscription Term, then thirty (30) days;
- Accounting records and invoices: ten (10) years, under article L. 123-22 of the French Commercial Code;
- Technical logs and telemetry: twelve (12) months at most;
- Meeting recordings and transcripts: until deleted by Customer, and at the latest as set out in the first bullet above;
- Prospects and business contacts: three (3) years from the last contact.
On expiry of the Agreement, deletion of Customer Data is governed by Section 13 of the DPA. Customer Data that does not constitute personal data is retained for thirty (30) days following termination and is then deleted or anonymized, under Section 11.8 of the General Terms.
10. Deletion and the right to erasure
Deletion rests on two guarantees, and the ordering between them matters more than either alone.
10.1 By person
Everything a person said goes, from the event log and from the message record together, because the record can be rebuilt from the log and deleting only one of them would put the messages back the next time anything rebuilds. The conversation stays coherent for everybody else: erasure is by person, never by room.
10.2 By block, for what Balt derived
The workspace memory and the skill documents are reformulated and carry no attribution. The only honest erasure is therefore to remove them whole and let Balt learn again from what remains. A person’s own private note goes with them, by name.
10.3 Raw first, derived second
Removing a memory while the messages behind it are still there would leave the very next run free to write the same fact back, and it would then be unattributed text nobody could erase a second time. The ordering is therefore enforced.
10.4 What survives an erasure
The integration documents Balt installs from its own source, which are not written from anything anybody said. Removing them would disconnect a workspace’s integrations because one person exercised a right that has nothing to do with them.
11. Security
We maintain an information security program proportionate to the nature of the Service and the risks involved. The technical and organizational measures are described in Section 6 of the Product Terms and detailed in Annex II to the DPA: encryption of data in transit and at rest, envelope encryption of integration credentials, access control and least privilege, hosting in France and in the European Union, logging and continuous monitoring, regular encrypted backups, and staff awareness training.
In the event of a personal data breach affecting Customer Data, we notify Customer without undue delay under Section 10 of the DPA, so that Customer can meet its own obligations. No system being immune, these measures reduce risk without eliminating it.
12. Your rights
Every data subject has, under Articles 15 to 22 GDPR, the rights of access, rectification, erasure, restriction, objection, and portability, together with the right to give directions as to the fate of their data after death and the right to withdraw consent at any time where processing rests on it.
With whom to exercise these rights. For data processed through the Service, the request is addressed to Customer, which is the controller; we forward any request received directly rather than responding to it ourselves, and we assist Customer under Section 9 of the DPA. For processing for which we are the controller, the request is addressed to legal@cobalt-ia.com.
We respond within one (1) month of receiving the request, extendable by two (2) months having regard to its complexity or to the number of requests. Proof of identity may be requested where there is reasonable doubt as to the identity of the requester.
Every data subject may lodge a complaint with the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or with the supervisory authority of their place of residence.
13. Minors
The Service is intended for professional use and is not designed to be used by minors. Customer shall not submit to the Service data relating to persons under fifteen (15) years of age, the age of digital consent in France, under Section 3 of the Acceptable Use Policy. If we learn that such data has been submitted, we delete it without delay.
15. Changes
This policy carries a version number and an effective date, available in the version history. Material changes are notified to Customer’s administrator under Section 16 of the General Terms, before they take effect. We review this policy at least once a year.
16. Contact us
For any question about this policy, about exercising your rights, or about data protection generally: legal@cobalt-ia.com, or by post to SKILLFORGE APP, Legal Department, 2 Rue des Commères, 78310 Coignières, France.
The other documents of the agreement
- Definitions : The defined terms used across the Balt contractual documents.
- General Terms : The core contractual terms governing access to and use of the Balt service.
- Acceptable Use Policy : The rules for acceptable and prohibited use of the Balt service, and prohibited data.
- Product Terms : Service description, AI functionality, autonomous actions, connected platforms and security.
- Usage Terms : How Credits, allocations, top-ups and accounts work.
- License Terms : The license granted to use the Balt service, and its restrictions.
- Data Processing Agreement : The Article 28 GDPR agreement, Standard Contractual Clauses included, counter-signed on request.
- Legal Notice : The website publisher, its publication director and its hosting providers.
For any question about this policy, contact us at: legal@cobalt-ia.com
