Privacy policy¶
Last update: 3 September 2026.
This policy describes how Antoine LE BORGNE, entrepreneur individuel, trading as Orvel (“we”), processes
personal data when you use the EU Verify API and MCP service at https://verify.orvel.dev.
Contact: le.borgne.antoine.pro@gmail.com — 10 rue Casabianca, 56600 Lanester, France.
What we process¶
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Account e-mail, name, billing address, VAT number if you provide one | Create the customer account, send receipts, comply with accounting rules | Contract; legal obligation |
| Payment data | Taken by Stripe. We never see full card numbers | Contract; Stripe as processor / independent controller for the payment |
| API key and monthly usage counters | Authenticate calls and enforce the plan quota | Contract |
| The identifiers you submit (VAT, SIREN/SIRET, IBAN, address, phone, email, EORI) | Query the relevant public register and answer you | Contract |
| Technical logs (time, route, tool, resulting status, duration, IP) | Security, debugging, abuse | Legitimate interest |
| Docs site cookies | Remember language / theme if the browser allows it | Legitimate interest (strictly necessary) |
Where your inputs go¶
Verifying an identifier means sending it to the register that holds it. By calling a tool you instruct us to transmit that value to the corresponding body:
| Tool | Recipient |
|---|---|
check_vat |
VIES, European Commission (DG TAXUD), EU |
check_eori |
EOS validation, European Commission (DG TAXUD), EU |
lookup_siren |
Recherche d'entreprises, DINUM, France |
normalize_address_eu (FR) |
Base Adresse Nationale, IGN / DINUM, France |
check_email (MX) |
Public DNS |
normalize_siret, check_iban, normalize_phone, normalize_address_eu (non-FR) |
Nobody: computed locally |
Answers are cached for at most 24 hours (7 days for addresses) so a repeated check does not hit the register again. Nothing else is kept: the values you submit are not written to logs and not stored after the cache expires.
Hosting and subprocessors¶
- Application: Railway Corporation (USA), Europe West region (Amsterdam). Processing stays in the EU; Railway acts as processor under its DPA with EU standard contractual clauses.
- Payments and customer portal: Stripe (Ireland / EU).
- Usage counters and cache: Redis hosted on the same Railway project.
Retention¶
- Customer and billing data: duration of the contract + 10 years (French accounting).
- Technical logs: 30 days.
- Cached register answers: 1 hour to 7 days depending on the tool.
- API keys: until you cancel or we disable the key.
Your rights¶
Access, rectification, erasure, restriction, portability, objection: write to the e-mail above. You may complain to the CNIL.
We do not sell data and we do not use it for advertising.
Payments¶
Card and mandate data are handled by Stripe under their privacy policy. Failed or successful payments produce a Stripe receipt sent to the e-mail you entered at checkout.