Skip to content

CompanyOS legal

Privacy Policy

How CHAMAN VENTURES processes personal data through CompanyOS, including the strict conditions for any future LinkedIn portability integration.

Effective and last updated: 19 July 2026

1. Scope and operator

This Privacy Policy applies to the CompanyOS public website, authenticated application and workspaces, APIs, previews, support, and connected integrations.

CHAMAN VENTURES, SAS with share capital of €100, registered with RCS Paris under SIREN 989 498 902 (SIRET 989 498 902 00018, VAT FR92 989 498 902), with its registered office at 229 rue Saint-Honoré, 75001 Paris, France, operates CompanyOS.

2. Our roles

CHAMAN VENTURES acts as a controller for account administration, security, service communications, product operation, and its own legitimate business purposes.

Where an organization directs how data is processed inside its workspace, CHAMAN VENTURES may act as its processor. The customer remains responsible for its instructions, notices, and lawful basis.

3. Data we process

  • Account and identity data, including name, professional contact details, authentication identifiers, role, and workspace membership.
  • Workspace and GTM content, such as company briefs, target accounts, evidence, notes, messages, approvals, and uploaded or connected records.
  • Third-party business-contact data and provider-derived business context, such as professional roles, company relationships, and engagement signals, when a customer lawfully uploads that information or enables a corresponding provider.
  • Integration and provider data when a customer enables a supported connection, including authorization state, provider identifiers, and necessary payloads.
  • Support, commercial, security, audit, device, request, and limited usage data needed to operate and protect the service.

4. Purposes and legal bases

We process data to provide and secure the service, authenticate users, administer workspaces, perform customer instructions, support users, maintain audit and approval controls, communicate about the service, comply with law, and improve reliability.

Depending on the context, our legal bases are performance of a contract, legitimate interests in operating and protecting a B2B service, compliance with legal obligations, and consent where required. A customer directing workspace processing must establish its own valid basis.

5. Recipients and service providers

Access is limited to authorized personnel, the relevant customer and workspace members, and service providers needed for the configured service.

Depending on configuration, providers may include Vercel for hosting and analytics, database and authentication infrastructure, Resend for service email, and customer-connected services such as Google, Attio, Reclaim, FullEnrich, or Sillage. A provider is involved only when the corresponding production feature is enabled or connected; package presence or a preview does not by itself mean that provider receives personal data.

We may disclose information to professional advisers, authorities, or counterparties where law or a legitimate corporate transaction requires it.

6. International transfers

Some configured providers may process data outside France or the European Economic Area. Where required, transfers rely on an adequacy decision, appropriate contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. We do not claim EU-only hosting.

7. Retention

Account and workspace data is kept while the account or customer relationship remains active and then for the period reasonably needed to close the service, address disputes, protect security, and meet legal obligations. Support, audit, security, billing, and contractual records may follow different statutory or operational periods.

We delete or anonymize data when it is no longer needed for its purpose, subject to backups, legal holds, and retention required by law. Customer-directed deletion requests are handled according to the applicable role and verified authority.

8. Planned LinkedIn Member Data Portability

The LinkedIn Member Data Portability API integration is planned and pending LinkedIn approval. It is not currently an approved or active CompanyOS capability.

If approved and implemented, it will be available only to consenting members using transparent OAuth authorization and official LinkedIn APIs in the European Union, European Economic Area, or Switzerland. Members will be able to understand the requested access, disconnect or withdraw authorization, and request an export or deletion through privacy@companyos.run.

If approved and implemented, any Member Portability Data will be retained only while a valid legal basis and member authorization remain. We will delete it without undue delay after a valid request, closure of the member's CompanyOS account, or LinkedIn disconnect or withdrawal, except where retention is required by law.

CompanyOS will not collect LinkedIn passwords, scrape LinkedIn, discriminate based on sensitive attributes, or re-identify people from de-identified data. LinkedIn does not sponsor, endorse, or verify CompanyOS.

9. Your GDPR rights

Subject to applicable conditions, you may request access, correction, deletion, restriction, objection, and portability, and withdraw consent at any time without affecting earlier lawful processing. You may also give instructions concerning your data after death where French law permits.

Contact privacy@companyos.run. We may need to verify identity and authority. You may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL) or another competent supervisory authority.

10. Security and governance

We use proportionate technical and organizational safeguards, including access controls, workspace boundaries, audit records, review gates, and provider capability checks. No system is completely secure, and these controls are not a claim of certification or risk-free operation.

11. Analytics

CompanyOS uses Vercel Analytics to obtain limited, aggregated information about website and product usage and performance. We minimize the data sent through application events and do not add legal-page click tracking. Browser or provider behavior may change according to configuration; this policy does not claim a cookie consent center or the absence of all provider-side storage.

12. Changes to this policy

We may update this policy when our service, providers, purposes, or legal obligations materially change. The effective date above identifies the current version. We will provide an appropriate notice where a change materially affects users.

Privacy, deletion, and legal questions can be sent to privacy@companyos.run.

CHAMAN VENTURES
229 rue Saint-Honoré, 75001 Paris, France
RCS Paris · SIREN 989 498 902