Security and data protection
Client facing document, handed over on request. Version of September 30, 2026. It summarizes our procurement and DPO response file; the full file is available under a confidentiality agreement. What is in place and what is still due are stated separately, on purpose.
1. What we touch on your side
| Access to your vendor or seller account | None. Never requested, never needed |
| Data about your buyers, orders, addresses, identities | None |
| Payment data of your end customers | None |
| Connection to your internal systems | None. No connector, no inbound API, no agent to install |
| Personal data we process on your behalf | The accounts of your users: name, professional email, role |
| Browser extension | Optional. It reads the product references shown on the page you visit and nothing else |
The risk surface on your own systems, accounts and internal data is limited to the accounts of your users.
2. Who is responsible for what
- Market and third party seller data, as shown publicly by the marketplaces: WhoHeld is the data controller, on its own account. We document the observation, the balancing test and the handling of seller requests. You receive an analysis result.
- Your user accounts: you are the controller, we are the processor. A data processing agreement is signed with the order form.
- Security, logging and usage measurement for billing: WhoHeld is a separate controller.
3. Where the data is hosted
Database, authentication and storage run on Supabase, on Amazon Web Services infrastructure, in France (region eu-west-3). The collection jobs run on a server in the European Union. Our market data provider is established in Germany. Some sub-processors are established outside the European Union (Singapore, United States) and may access data from there, and our email (Google Workspace) may be processed in Google data centers outside the European Union, all under the EU standard contractual clauses; the AI assistant Ask WhoHeld, where it is made available, sends pseudonymised data and the question exactly as the user typed it to Anthropic (Anthropic Ireland, Limited, which has it processed in the United States by its parent company). A question can name a seller: it is sent as typed. The list of sub-processors is published; any addition is notified thirty days in advance, with a right to object and to terminate without penalty.
4. Security measures
In place. Data isolation between clients at the database level, through row level security on every application table, not only in the application code. TLS 1.2 minimum in transit, encryption at rest by the hosting infrastructure. Secrets kept out of the source code. Named accounts, least privilege, no shared account. Automatic daily backups by the database host, restorable over the depth of the subscribed tier (stated on request), deleted within a rotation cycle of at most ninety days. Automated tests run on every change. An automated check of database access rights after every change to the schema or permissions. Monitoring by absence of signal: if the system goes quiet, an alert fires. A written incident procedure and a breach register exist.
Due, as obligations. WhoHeld must put the following in place at the latest on the effective date of the first order form: multi factor authentication on administration consoles (already in place on business e-mail), separation of development and production environments, and a dated restore test. These points are part of the security annex of the contract. Their dated evidence is sent with our supplier file.
Not held. No SOC 2 or ISO 27001 certification to date. We answer vendor security questionnaires in full instead, and a penetration test is performed when the order form provides for it.
5. Data protection
Market data is processed under our own responsibility, on the basis of legitimate interest, with a documented balancing test. Retention periods are published: 36 months for Buy Box events and price history linked to a seller; for seller identity, the name and country are kept 24 months after the last observation and the marketplace identifier 36 months, rolling; 12 months for seller profile indicators. Data is deleted or aggregated at the end of these periods, with a rule that prevents any single seller from being identified in an aggregate. Observed sellers have an information notice written in five languages and a free right to object, applied at every collection.
The impact assessment was adopted on September 29, 2026. No data protection officer is appointed: the legal threshold is not met, according to a written and dated analysis that we provide on request.
6. Reversibility and continuity
- During the contract, you export your results free of charge, from every screen that offers it (CSV).
- At the end of the contract, you keep thirty days of read and export access, and we deliver a full export within fifteen working days on request. The only condition is the payment of undisputed amounts due.
- You keep, for free and without time limit, the internal use of the results about your catalog that you exported.
- If WhoHeld ceased its activity, read and export access is maintained for ninety days. The full export is delivered on request within fifteen working days: we recommend asking for one and keeping a copy.
- If our data supplier changed its terms or ended the service, you are informed within five working days and may terminate without penalty. The history already collected stays with us and remains exportable.
- If WhoHeld were acquired by a competitor of yours or by a marketplace, you are informed within fifteen days and may terminate without penalty.
7. Your data and other clients
The data you entrust to us stays your property. Our license on it ends with the contract. We train no model on your data for the benefit of another client. No published statistic is built from fewer than five clients or five brands, or where one of them would represent 85 percent or more of the total, and nothing is published about a category where you are active without your written consent. We serve other clients, including competitors, without any exclusivity of sector or territory, and we write it rather than let an exclusivity be assumed.
Contact for data protection: privacy@whoheld.com. Contact for procurement: contact@whoheld.com.