Privacy policy

Last updated: August 7, 2026

This page is a courtesy translation. Only the French version is authoritative.

This policy describes how JUNGA processes personal data on its junga.ai website and on its platform. It applies to website visitors, prospects and platform users (the staff of the wealth-management firms that are Junga's customers).

Who we are

JUNGA, a French simplified joint-stock company (SAS) registered with the Lyon Trade and Companies Register under number 106 948 045, whose registered office is located at Bureau 3, 30 avenue Maréchal Foch, 69006 Lyon, France (hereinafter "Junga"), publishes the junga.ai website and the Junga software platform for independent French wealth advisers (CGP).

Junga is the data controller for the data described in this policy. For the end-client data that firms manage in the platform, Junga acts as a processor on behalf of the firm: see the section "Junga as a processor for firms".

Data Protection Officer

Junga has appointed a Data Protection Officer (DPO): Nicolas Molins, who can be reached at dpo@junga.ai or by post at the registered office address. The DPO is your contact point for any question about your personal data.

The data we process and why

Website visitors and demo requests

When you browse junga.ai, we process technical logs (IP address, pages viewed) necessary for the operation and security of the website (legitimate interest). When you fill in the demo request form, we process the information provided (name, business email address, firm) to answer your request and arrange a call (pre-contractual measures). These requests are tracked in our internal management tool.

Platform users

For the staff of subscribing firms, we process account data (identity, business email address, role within the firm), authentication data (sessions, second factor, passkeys) and activity logs, in order to provide the service subscribed to by your firm (performance of the contract concluded with it, and legitimate interest in providing the service to its staff), to ensure the regulatory traceability of actions (legal obligation and legitimate interest) and to secure the platform.

An approximate location (city level) is derived from the IP address at sign-in, for security purposes (detection of unusual sign-ins). This derivation is performed locally on our servers, without your IP address being sent to any third party.

Calendar sync (Google Calendar and Microsoft Outlook)

If you choose to connect your Google or Microsoft calendar, Junga accesses the list of your calendars and syncs the events of the calendars you select: title, times, location, description, attendees and organiser, response, availability and visibility statuses, as well as the email address of the connected account. This data is used exclusively to display your calendar in Junga and to schedule your tasks in your available slots (performance of the contract). The requested access covers both read and write: write access will be used to create and update your appointments from Junga (feature in preparation, no write is performed today). Synced events are kept as a minimal copy on our servers hosted in the European Union, together with the necessary access tokens, for as long as the integration is active. You can disconnect the integration at any time from the settings: the synced copy is then deleted. You can also revoke Junga's access from the security settings of your Google account (myaccount.google.com/permissions) or Microsoft account.

Junga's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Junga does not use Google Calendar data for advertising purposes, does not sell it, does not transfer it to third parties beyond what is necessary to provide the calendar sync feature, and does not use it to train generalized artificial-intelligence models. We do not allow humans to read this data, except with your explicit consent, for security purposes, to comply with a legal obligation, or on aggregated and anonymised data.

When connecting a Microsoft account, the application also requests permissions to read and send emails: they will serve the email sync feature, currently in preparation. Today, only your calendar is synced; no email is read or sent. This policy will be updated before that feature is activated.

If you are an attendee of a synced calendar event: Junga may hold your name, email address and response status, obtained from the Google or Microsoft calendar connected by a platform user (source of the data). This information is used solely to display the event in that user's calendar (legitimate interest) and is deleted when they disconnect their integration. You have the rights described in the "Your rights" section of this policy, by writing to dpo@junga.ai.

Product communications

As a professional user of the platform, you receive communications about product developments (legitimate interest: keeping you informed about the service your firm uses). You can object at any time via the unsubscribe link in every email or by writing to dpo@junga.ai.

Billing

For subscribing firms, we process the billing and payment data necessary to manage the subscription (performance of the contract and accounting obligations). Payments are handled by our provider Stripe; Junga does not store card numbers.

Account data is necessary to provide the service subscribed to by your firm: without it, the account cannot be created. The demo request form information is necessary to get back to you. Other data, such as connecting a calendar, is optional.

Junga as a processor for firms

End-client data (KYC files, wealth data, MIF2 suitability questionnaires, AML-CFT checks, documents) is processed by Junga on behalf of the firm that manages it, on its documented instructions, under a data processing agreement compliant with Article 28 GDPR. For this data, the firm is the controller: if you are a client of a firm using Junga, address your data-rights requests to your adviser. Junga assists firms in handling these requests. The client area (portal) made available to you by your firm is covered by the information provided by the firm: for the portal, your firm is the controller and Junga acts as its processor.

Recipients and processors

Data is accessible only to authorised Junga staff and to our processors, to the extent necessary for their tasks:

Junga does not sell or rent your personal data. The up-to-date list of processors, their location and the applicable safeguard mechanism are maintained in our vendor register.

Transfers outside the European Union

Data is hosted in the European Union (AWS Paris region). Some processors are located outside the European Economic Area (notably Anthropic and Groq in the United States, Hookdeck in Canada). These transfers are governed by the European Commission's standard contractual clauses, supplemented where appropriate by additional measures. You can obtain a copy of the applicable safeguards by writing to dpo@junga.ai.

Retention periods

Your rights

Under the GDPR, you have the rights of access, rectification, erasure, restriction of processing and portability. You may in particular object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest, and withdraw your consent where processing relies on it. You may also set directives on the retention, erasure and disclosure of your data after your death (Article 85 of the French Data Protection Act). To exercise these rights, write to dpo@junga.ai. We reply within one month, extendable by two months for complex requests. Some data cannot be deleted before a statutory retention obligation expires (for example AML-CFT records, kept for five years after the end of the business relationship): in that case, we tell you the legal basis and the scheduled deletion date.

You can lodge a complaint with the CNIL (www.cnil.fr).

Security

Junga implements technical and organisational measures appropriate to the risk: encryption of data in transit and at rest, strict partitioning of data between firms, role-based access control, action logging and continuous monitoring. The details of our security posture are presented at junga.ai/securite.

Cookies

The junga.ai website does not use any advertising tracker. The platform uses cookies strictly necessary for the operation of the service (authentication, security), exempt from consent, as well as a usage-analytics tool (PostHog, hosted in the European Union) used exclusively to produce usage statistics and improve the product. For any question about these trackers, write to dpo@junga.ai.

Changes to this policy

This policy may change, in particular when a new processor or a new feature is introduced. The last update date is shown at the top of this document. In the event of a substantial change, platform users are informed. Previous versions are archived and available on request from dpo@junga.ai.