Skip to content

Privacy policy

Last update: 3 September 2026.

This policy describes how Antoine LE BORGNE, entrepreneur individuel, trading as Orvel (“we”), processes personal data when you use the EU Verify API and MCP service at https://verify.orvel.dev.

Contact: le.borgne.antoine.pro@gmail.com — 10 rue Casabianca, 56600 Lanester, France.

What we process

Data Why Legal basis (GDPR)
Account e-mail, name, billing address, VAT number if you provide one Create the customer account, send receipts, comply with accounting rules Contract; legal obligation
Payment data Taken by Stripe. We never see full card numbers Contract; Stripe as processor / independent controller for the payment
API key and monthly usage counters Authenticate calls and enforce the plan quota Contract
The identifiers you submit (VAT, SIREN/SIRET, IBAN, address, phone, email, EORI) Query the relevant public register and answer you Contract
Technical logs (time, route, tool, resulting status, duration, IP) Security, debugging, abuse Legitimate interest
Docs site cookies Remember language / theme if the browser allows it Legitimate interest (strictly necessary)

Where your inputs go

Verifying an identifier means sending it to the register that holds it. By calling a tool you instruct us to transmit that value to the corresponding body:

Tool Recipient
check_vat VIES, European Commission (DG TAXUD), EU
check_eori EOS validation, European Commission (DG TAXUD), EU
lookup_siren Recherche d'entreprises, DINUM, France
normalize_address_eu (FR) Base Adresse Nationale, IGN / DINUM, France
check_email (MX) Public DNS
normalize_siret, check_iban, normalize_phone, normalize_address_eu (non-FR) Nobody: computed locally

Answers are cached for at most 24 hours (7 days for addresses) so a repeated check does not hit the register again. Nothing else is kept: the values you submit are not written to logs and not stored after the cache expires.

Hosting and subprocessors

  • Application: Railway Corporation (USA), Europe West region (Amsterdam). Processing stays in the EU; Railway acts as processor under its DPA with EU standard contractual clauses.
  • Payments and customer portal: Stripe (Ireland / EU).
  • Usage counters and cache: Redis hosted on the same Railway project.

Retention

  • Customer and billing data: duration of the contract + 10 years (French accounting).
  • Technical logs: 30 days.
  • Cached register answers: 1 hour to 7 days depending on the tool.
  • API keys: until you cancel or we disable the key.

Your rights

Access, rectification, erasure, restriction, portability, objection: write to the e-mail above. You may complain to the CNIL.

We do not sell data and we do not use it for advertising.

Payments

Card and mandate data are handled by Stripe under their privacy policy. Failed or successful payments produce a Stripe receipt sent to the e-mail you entered at checkout.