Otiggo.com

Privacy policy

Last updated: 5 May 2026

1. Introduction

This policy explains how Otiggo, published by Alvexa (“we”, “us” or “Otiggo”), collects, uses, stores and protects personal data in connection with its services.

Otiggo provides Otiggo Enterprise, a SaaS platform for subcontracted delivery businesses, and Otiggo Driver, a mobile application for drivers with AI-assisted manifest and label scanning, address extraction and route optimisation. Together they are the “Service”.

We process personal data in accordance with Regulation (EU) 2016/679 (the GDPR) and the amended French Data Protection Act of 6 January 1978.

2. Controller and processor roles

2.1 Data controller

For Service administration, accounts, billing, support, security, sales management and communications, the controller is:

2.2 Data processed for business customers

When Otiggo Enterprise processes data about a customer's drivers, staff, routes, parcels, manifests, leave, vehicles, operational invoices or internal business activity, the business customer remains the controller and Alvexa acts as processor under Article 28 GDPR.

Alvexa processes that data only on the customer's documented instructions, to provide the Service and under the applicable contract.

3. Personal data we collect

3.1 Identification and account data

  • name, email address and, where applicable, telephone number;
  • hashed password, user identifier and sign-in information;
  • company name and the user's function or role.

3.2 Delivery business data

We may process parcel and manifest numbers, delivery addresses and statuses, routes, zones, delivery points, carriers, principals, customers, recipients, depots and the history of actions carried out in the Service.

This may include information associated with carriers or principals such as DHL, FedEx, Cogepart, Ciblex, France Express or any partner entered by a business customer.

3.3 Location data

Navigation, tracking and route-optimisation features may process location data to optimise routes, display directions, monitor route execution and, where necessary and permitted, provide or verify evidence of delivery.

Processing depends on application and device settings and on the configuration selected by the business customer.

3.4 AI and OCR data

When a user scans a manifest, label or document, the captured image may be processed automatically to extract delivery addresses, parcel numbers and other information required to create or optimise a route.

Images or scanned content may be sent to Anthropic's Claude API solely to provide the requested extraction. Otiggo deletes images once processing is complete, unless temporary technical storage, a legal obligation or an expressly selected setting requires otherwise.

Anthropic retention depends on the service and contractual settings used, including any Zero Data Retention option. Extracted data may be retained in the user or customer account. These features do not by themselves make decisions producing legal or similarly significant effects within Article 22 GDPR.

3.5 Financial, billing, fleet and HR data

Depending on enabled modules, we may process carrier rates, remuneration and billing rules, pre-invoices, invoices, revenue, expenses, cash-flow data, accounting history, vehicle registration and condition, maintenance, incidents, administrative deadlines, driver assignments, leave requests, absence dates and planning information.

HR, leave and operational employee data is mainly processed for the business customer, which remains the controller.

3.6 Payment data

Payment-card data, authentication information, payment history, payment status and billing information are collected and processed directly by our secure payment provider. We never store complete payment-card details on our servers.

3.7 Technical data, cookies and trackers

We may collect IP address, browser, operating system, device type, pages visited, visit duration, referrer, connection logs and security data to operate, secure, maintain and improve the Service.

Analytics or marketing cookies will be introduced only after prior information and, where required, consent.

4. Required and optional data

Some data is required to create an account, access and provide requested Service features, manage subscriptions and billing, or comply with legal obligations. Without it, some or all of the Service may be unavailable.

Optional data is identified when collected or results from the user's voluntary activation of a module or feature.

5. Purposes and legal bases

  • Accounts and Service delivery: performance of a contract or pre-contractual steps, Article 6(1)(b) GDPR.
  • AI/OCR extraction: performance of the contract, or the business customer's instructions where Alvexa is a processor.
  • Location and route optimisation: performance of a contract or the business customer's legitimate interests in a professional context, subject to individual rights.
  • Payments and billing: performance of a contract.
  • Support and service communications: legitimate interests or performance of the contract.
  • Improvement, maintenance, abuse prevention and security: legitimate interests, Article 6(1)(f) GDPR.
  • Marketing: consent, or legitimate interests where applicable law permits; users may object at any time.
  • Legal, tax and accounting duties: compliance with a legal obligation, Article 6(1)(c) GDPR.

Where Alvexa processes data for a business customer, that customer determines the applicable legal basis and is responsible for informing its staff, drivers and contractors, particularly about professional location tracking.

6. Retention periods

  • Account data: while the Service is used and for up to three years after the account's last activity, unless a legal duty or valid deletion request applies.
  • Business data: for the subscription period or the period configured by the customer, followed by limited archiving where required for evidence, compliance or legal duties.
  • Invoices and accounting records: up to ten years under French law.
  • AI-scanned images: deleted by Otiggo as soon as automated processing ends, subject to the exceptions described above; extracted information may remain in the account.
  • Location data: only as long as needed for the route and feature. A customer-enabled history should in principle not exceed two months unless a specific permitted need applies.
  • Technical logs and audience data: only as long as needed for security, maintenance and improvement; audience data for no more than 13 months where applicable.
  • Cookies: no more than 13 months from placement, unless a shorter period or renewed consent applies.

After the relevant period, data is deleted, anonymised or archived where required by law or to establish, exercise or defend legal claims.

7. Recipients and processors

We never sell personal data. Access is restricted to authorised team members and recipients strictly needed for support, maintenance, security, billing, Service administration, contractual management or legal compliance.

  • Vercel Inc., United States: web-platform hosting and related technical services.
  • Stripe, Inc., United States: secure transactions, subscriptions and payments.
  • Anthropic PBC — Claude API, United States: image recognition, OCR and extraction from scanned documents.
  • Analytics providers: audience measurement where used; non-essential cookies require prior consent.
  • Authorities: where disclosure is legally required or needed to defend our rights.

Processors are contractually required to protect confidentiality, security and personal data under the GDPR. Claude API use is contractually framed in relation to confidentiality, security, retention and, where applicable, non-use of submitted data for model training.

8. Transfers outside the European Union

Providers including Vercel, Stripe and Anthropic may be established in the United States. Where data is transferred outside the EU, we use appropriate GDPR safeguards, which may include an adequacy decision, the EU–US Data Privacy Framework, European Commission Standard Contractual Clauses or another recognised safeguard.

For information about applicable safeguards, contact florian.jolie@otiggo.com.

9. Cookies and trackers

Cookies are small files stored on a device when a website or online service is used.

  • Strictly necessary cookies support authentication, security, sessions, required preferences and technical operation and do not require consent.
  • Analytics cookies measure audience and improve features; consent is obtained unless a legal exemption applies.
  • Marketing cookies may measure campaigns or personalise content and are placed only with prior consent.

Preferences may be managed through the consent banner, where available, or browser settings. Consent may be withdrawn at any time without affecting earlier lawful processing.

10. Your rights

Subject to the applicable conditions, you have rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and the right under French law to give instructions concerning your data after death.

Portability applies to automated processing based on consent or a contract and may cover eligible account, parcel, route or billing data. You may object at any time to direct marketing and, on grounds relating to your situation, to processing based on legitimate interests.

To exercise a right, email florian.jolie@otiggo.com. We may request information needed to verify identity. We respond within one month, extendable by two months for complex or numerous requests as permitted by the GDPR.

You may complain to the CNIL at https://www.cnil.fr.

11. Data security

We use appropriate technical and organisational measures against destruction, loss, alteration, unauthorised disclosure and unauthorised access. These include HTTPS/TLS encryption in transit, protection at rest where applicable, hashed passwords, restricted access, technical logging, rapid deletion of scanned images, system updates, infrastructure backup and monitoring, and staff awareness.

No system can guarantee absolute security. If a personal-data breach is likely to create a risk to individuals, we take the measures required by the GDPR.

12. Children

The Service is not intended for anyone under 16. We do not knowingly collect data about children under 16 and will promptly delete such data if it was collected without an appropriate legal basis.

13. Business customer obligations

Customers using Otiggo Enterprise to process data about staff, drivers, contractors, customers, recipients or partners remain responsible for their GDPR duties. They must inform individuals, determine legal bases, ensure necessity and proportionality, comply with workplace-location rules, handle rights requests within their responsibility and configure the Service lawfully.

Alvexa assists customers where possible and as provided by the applicable contract.

14. Changes to this policy

We may update this policy to reflect changes to the Service, features, providers or law. Material changes will be communicated by email, an in-Service notice or another appropriate method. The latest update date appears at the top of the policy.

15. Contact

© 2026 Alvexa — All rights reserved