Privacy Policy
Version 1.2 — June 2026
This English text is a courtesy translation. In the event of any discrepancy, the French version available at mcp.silexia.legal/confidentialite prevails.
Silexia SARL — 32 avenue Bosquet, 75007 Paris
SIRET: 894 462 217 00015 — RCS Paris
Publication director: Maxime Lehmann
Contact: bonjour@silexia.fr
Website: https://mcp.silexia.legal
Host: Scalingo SAS — 13 rue Jacques Peirotes, 67000 Strasbourg
1. Who we are
Company name: Silexia SARL
Legal form: French limited liability company (SARL)
Share capital: €1,000
Registered office: 32 avenue Bosquet, 75007 Paris
SIRET: 894 462 217 00015 — RCS Paris
Email: bonjour@silexia.fr
Website: https://mcp.silexia.legal
Silexia SARL acts as data controller within the meaning of Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and French Act No. 78-17 of 6 January 1978, as amended.
2. Data collected
2.1 Data collected directly
- Identification data: last name, first name, professional email address
- Professional data: firm or company name, role, bar membership
- Account data: account credentials, encrypted password (not accessible to Silexia)
- Payment data: processed directly by Stripe. Silexia stores no banking data
2.2 Data collected automatically
- Browsing data: IP address, browser type, pages visited, session duration
- MCP usage metadata: number of requests, timestamp, database queried — collected solely for quota management and billing
- Cookies and trackers: detailed in the Cookie Policy
3. Special case — MCP connector and official databases
3.1 Neutral technical architecture
The Silexia MCP connector is a hosted technical gateway that the user connects to the large language model (LLM) of their choice — Claude by Anthropic, Mistral, ChatGPT by OpenAI, Cursor or any other MCP-compatible agent. The connection is established securely via the OAuth 2.0 protocol and a personal access key. In this context:
- Silexia does not store the content of the requests sent to the connector or of the responses returned by the official databases or by the LLM (except for the legal-watch feature described in § 3.4);
- Silexia keeps only a technical record of each call (metadata, see § 3.2), in order to verify the proper operation of the Service, detect any malfunctions and monitor usage (quota management and billing);
- the user remains solely responsible for the choice of their LLM, its configuration and the data they decide to submit to it;
- Silexia acts as a provider of a technical tool and does not exploit the content of the exchanges for any other purpose.
This architecture has been designed to preserve the confidentiality of professional data, in particular the legal professional privilege of lawyers provided for in Article 66-5 of Act No. 71-1130 of 31 December 1971.
3.2 MCP request metadata
In order to manage usage quotas and bill subscriptions, Silexia collects and retains limited technical metadata associated with each MCP request:
- User account identifier
- Request timestamp
- Official database queried (e.g.: Légifrance, Judilibre, RNE…)
- Request status (success / failure)
This metadata never includes the content of the requests or the responses returned. It is retained for 12 months and then automatically deleted.
3.3 Requests to official databases
When using the Service, real-time requests are sent to the APIs of the following databases:
- Légifrance (consolidated legislative and regulatory texts — api.piste.gouv.fr);
- Judilibre (case law of the Cour de cassation and Conseil d'État — api.piste.gouv.fr);
- National Business Register – RNE (company and director data — data.inpi.fr);
- INPI Trademarks (registered trademarks — French, European Union and international: search, details, logos and BOPI publications — data.inpi.fr);
- NATINF (national classification of criminal offences — data.gouv.fr);
- Collective bargaining agreements (search by SIRET and content — api.piste.gouv.fr);
- Service-public.fr / Taxes (administrative and tax procedures — api.service-public.fr);
- CNIL (DPO register and data breaches — donnees.cnil.fr);
- Géoplateforme urban planning IGN / BDNB / DVF (land registry, local urban plans, energy-performance diagnostics, real-estate transactions — api.gouv.fr, data.ademe.fr, api.carto.gouv.fr);
- EUR-Lex / CJEU (European Union law and EU case law — eur-lex.europa.eu);
- European Parliament (legislative procedures, votes, MEPs and documents — data.europarl.europa.eu);
- Parliamentary questions (written questions and ministerial answers from the National Assembly and the Senate — data.assemblee-nationale.fr, senat.fr);
- Juriveille (legal-watch database published by Silexia, read-only access).
These requests transit through Silexia's servers without their content being stored; only the technical record of the call is retained (see § 3.1 and § 3.2). Each official database is subject to its own terms of use, in particular the Etalab v2.0 open licence for French public data. Silexia cannot be held liable for the unavailability or modification of these databases. The availability levels (SLAs) of the official databases are those published by their respective providers.
3.4 Legal watch and email notifications
Silexia offers an optional legal-watch feature allowing the user to set up automated monitoring of legal sources and to distribute the results by email (newsletters). Unlike the passthrough described in § 3.1, this feature requires the storage of the data strictly necessary for its operation:
- the watch configuration (title, search terms, monitored sources, sending frequency);
- the recipient email addresses entered by the user;
- the sending history (subject, newsletter content, recipients, date and status), for traceability and proper operation of the Service.
Emails are sent by our processor Resend Inc. (DPA in force). The legal basis for this processing is the performance of the contract (Art. 6.1.b GDPR).
The user is solely responsible for the addresses they register as recipients and ensures they have the right to send them these communications. Each email includes a one-click unsubscribe link (Art. 21 GDPR; RFC 8058).
Retention periods: the watch configuration is kept for the duration of the contractual relationship; the sending history is limited to the 10 most recent sends per watch, kept for a maximum of 12 months, after which they are deleted.
4. Purposes and legal bases for processing
- Performance of the contract (Art. 6.1.b GDPR): creation and management of your account, provision of subscribed plans, request-quota management, billing
- Legitimate interest (Art. 6.1.f GDPR): improvement of the Service, platform security, fraud prevention, aggregated and anonymised usage statistics
- Consent (Art. 6.1.a GDPR): sending of marketing communications, placement of non-essential cookies — consent may be withdrawn at any time
- Legal obligation (Art. 6.1.c GDPR): retention of billing data in accordance with accounting and tax obligations (Art. L. 123-22 French Commercial Code — 10 years)
5. Retention periods
- Account data: duration of the contractual relationship + 2 years after termination
- Billing data: 10 years (legal obligation — Art. L. 123-22 French Commercial Code)
- MCP request metadata: 12 months
- Connection logs: 12 months
- Prospecting data: 2 years from the last contact
- Audience-measurement cookies: 13 months maximum (CNIL recommendation)
- Watch data: configuration kept for the duration of the contractual relationship; sending history limited to the 10 most recent sends per watch (12 months maximum)
6. Data recipients
Your data may be shared with the following processors, strictly within the limits of the purposes described above, with whom Silexia has concluded a data processing agreement (DPA) compliant with the GDPR:
- Scalingo SAS — hosting of the gateway and of account/billing/watch data, France (EU)
- Replit, Inc. — hosting of the connection servers ("MCP") that relay requests to some of the official databases, United States (Google Cloud infrastructure). Transfer framed by safeguards (see § 8)
- Stripe — online payment solution
- Resend Inc. — sending of transactional emails and watch newsletters (Resend DPA in force)
- Sentry — application monitoring
Silexia never sells your data to third parties for commercial purposes.
7. Your rights
In accordance with the GDPR and the amended French Data Protection Act, you have the following rights:
- Right of access (Art. 15 GDPR): obtain a copy of your personal data
- Right to rectification (Art. 16 GDPR): correct inaccurate or incomplete data
- Right to erasure (Art. 17 GDPR): request the deletion of your data, subject to legal conditions
- Right to restriction (Art. 18 GDPR): temporarily restrict a processing operation
- Right to data portability (Art. 20 GDPR): receive your data in a structured, machine-readable format
- Right to object (Art. 21 GDPR): object to processing based on legitimate interest or for prospecting purposes
- Right to withdraw consent: at any time, without retroactive effect
To exercise your rights, contact us at: bonjour@silexia.fr. We undertake to respond within one month. If you encounter difficulties, you may lodge a complaint with the CNIL (the French data protection authority), 3 place de Fontenoy, 75007 Paris — www.cnil.fr.
8. Transfers outside the European Union
Account, billing and watch data are hosted in France by Scalingo SAS and are not subject to any transfer outside the EU.
However, for some of the official databases, the technical relay between the gateway and the official API is handled by connection servers ("MCP") hosted by Replit, Inc. in the United States (Google Cloud infrastructure). When a request is made to one of these databases, the content of the request transits through these US servers — transiently, encrypted (TLS) and without storage — before reaching the official API. Only the technical record of the call (metadata, see § 3.2) is retained, in France.
This transfer is framed by the European Commission's Standard Contractual Clauses (SCCs) (Decision 2021/914, Modules 2 and 3), as incorporated into Replit, Inc.'s Data Processing Agreement, supplemented by technical measures (TLS encryption in transit, no storage of content).
Location of connection servers by database:
| Hosting | Databases concerned |
|---|---|
| United States (Replit / GCP) | Judilibre, Collective bargaining agreements, RNE, INPI Trademarks, Urban planning, Service-public.fr, CNIL, NATINF, Juriveille |
| France (Scalingo) | Légifrance, EUR-Lex, European Parliament, Parliamentary questions |
9. Security
Silexia implements appropriate technical and organisational measures to protect your data, in accordance with Article 32 of the GDPR, including:
- Encryption of data in transit (TLS 1.2 minimum) and at rest
- Strong authentication on administration interfaces
- Data access limited to authorised personnel, on a least-privilege basis
- Logging of access to sensitive data
10. Cookies
Our site uses cookies and trackers. To learn more and set your preferences, see our Cookie Policy.
11. Changes
Silexia reserves the right to amend this policy at any time, in particular to reflect legal and regulatory developments. In the event of a substantial change, you will be informed by notification on the site or via your client area at least 30 days before the new provisions take effect.
12. Contact
Email: bonjour@silexia.fr
Mail: Silexia SARL — 32 avenue Bosquet, 75007 Paris
Last updated: 15 June 2026 — Version 1.2