Privacy Policy — Deep Talk SAS (MARCO)
1. Who we are and how to contact us
Deep Talk SAS (“Deep Talk”, “we”, “us”) is the controller of the personal data described in this policy, within the meaning of Regulation (EU) 2016/679 (the “GDPR”) and the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978, “Informatique et Libertés”).
| Legal name | Deep Talk SAS |
|---|---|
| Registered office | 149 Avenue du Maine, 75014 Paris, Île-de-France, France |
| SIRET | 920 440 922 00010 |
| Legal representative | Juan Jose Soto, President |
| Privacy contact | privacy@deep-talk.ai |
| Data Protection Officer (DPO) | Marcelo Drago |
| Contact form | www.info.marco.care/contact |
2. Scope of this policy
This policy explains how we process personal data when you:
- create and use an account on MARCO, our AI-agent service that supports healthcare professionals with scientific information and evidence-based medicine;
- interact with MARCO through any supported channel (web application, WhatsApp, messaging channel, API);
- visit our website www.marco.care;
- contact us for support, sales or any other reason.
It does not apply to third-party websites or services that we may link to, which have their own privacy policies.
MARCO is an information-support tool. It is not a medical device, it does not provide a diagnosis or a treatment prescription, and it does not replace the clinical judgement of the treating professional. See section 10 on automated processing.
3. What personal data we collect
3.1 Data you provide
| Category | Examples |
|---|---|
| Identification and contact data | First and last name, professional email address, mobile telephone number |
| Professional data | Country of practice, medical specialty |
| Account data | Username, authentication credentials, language and content preferences |
| Content of your interactions | The questions, prompts, documents and files you submit to MARCO, and the responses generated — see section 4 |
| Support and commercial correspondence | The content of your messages, incident tickets and, where applicable, billing data |
3.2 Data we collect automatically
| Category | Examples |
|---|---|
| Usage data | Dates and times of your interactions with MARCO, features used, volume and frequency of queries, feedback given on responses |
| Technical data | IP address, device and browser type, operating system, language settings, unique identifiers, connection logs |
| Cookies and similar technologies | See section 12 |
Providing the data marked as mandatory in our forms is necessary for us to create your account and provide the service; without it we cannot make MARCO available to you. All other data is optional.
4. Special category data and the content of your queries
MARCO is designed for use by healthcare professionals and processes scientific and clinical literature, not patient records.
- Do not enter data that identifies a patient. You must not submit names, initials combined with other identifiers, national health or insurance numbers, addresses, dates of birth, full-face images, or any other information that allows a patient to be identified, directly or indirectly. Please pseudonymise or aggregate clinical details before submitting them.
- Data concerning you. Your medical specialty and areas of professional interest are processed as professional data, not as health data about you.
- If your organisation uses MARCO to process patient data under a specific agreement, your organisation acts as controller and Deep Talk acts as processor on its behalf, under a data processing agreement concluded pursuant to Article 28 GDPR. In that case, your organisation’s own privacy notice governs that processing, and this policy applies only to the data we process as controller (accounts, billing, security, service operation).
- Where we do process data revealing health information covered by Article 9 GDPR outside such an agreement, we do so only on the basis of your explicit consent (Article 9(2)(a) GDPR), which you may withdraw at any time.
5. Why we process your data and on what legal basis
| Purpose | Legal basis (Article 6 GDPR) | Retention |
|---|---|---|
| Creating and administering your account; providing MARCO and its features; user support | Performance of a contract — Art. 6(1)(b) | Duration of the account + 3 years from last activity |
| Processing and responding to your queries within the service | Performance of a contract — Art. 6(1)(b) | 24 months, or until you delete the conversation |
| Sending you updates about MARCO and scientific information relevant to your specialty | Your consent — Art. 6(1)(a); or our legitimate interest in informing healthcare professionals about products relevant to their profession — Art. 6(1)(f) | Until you object or withdraw consent, and in any event max. 3 years from your last interaction with us |
| Tailoring the scientific content we send or surface to your specialty and preferences (profiling) | Your consent — Art. 6(1)(a) [or legitimate interest, Art. 6(1)(f), where permitted] | While your account is active |
| Measuring audience, diagnosing faults, and improving the quality and safety of the service | Legitimate interest in improving our service — Art. 6(1)(f); consent for non-essential cookies | 24 months for analytics data |
| Ensuring security, preventing abuse and fraud, keeping logs | Legitimate interest in the security of our systems — Art. 6(1)(f); legal obligation — Art. 6(1)(c) | 12 months for security logs |
| Managing billing and meeting accounting, tax and pharmacovigilance-related obligations, and handling requests from authorities | Legal obligation — Art. 6(1)(c) | 10 years for accounting records (Art. L. 123-22 French Commercial Code) |
| Establishing, exercising or defending legal claims | Legitimate interest — Art. 6(1)(f) | Until the end of the applicable limitation period |
Where we rely on legitimate interests, we have carried out a balancing assessment; you may request a summary of it and you may object at any time (see section 11).
6. Who we share your data with
We do not sell or rent your personal data, and we do not share it with third parties for their own marketing purposes.
We disclose personal data only to:
- authorised staff of Deep Talk, on a need-to-know basis and subject to confidentiality obligations;
- processors acting on our instructions under Article 28 GDPR contracts, in the following categories:
- cloud hosting and infrastructure — Azure cloud, hosted in France and Sweden;
- large language model and AI infrastructure providers — Azure cloud (Sweden); Pinecone;
- email delivery and CRM — AWS SES;
- analytics and product telemetry — Google Analytics;
- customer support tooling — Zoho;
- payment processing — FastSpring;
- professional advisers (lawyers, auditors, accountants), bound by professional secrecy;
- public authorities and courts, where we are legally required to disclose;
- an acquirer or successor entity, in the event of a merger, acquisition or transfer of all or part of our business, subject to the protections of this policy.
An up-to-date list of our processors is available on request at privacy@deep-talk.ai.
7. International transfers
We host and process your data within the European Union / European Economic Area wherever possible.
Where a processor or sub-processor is located outside the EEA (in particular certain AI infrastructure providers in the United States), the transfer is protected by at least one of the following:
- an adequacy decision of the European Commission for the country concerned (for example, the EU–US Data Privacy Framework, where the recipient is certified);
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), supplemented by technical and organisational measures identified in a transfer impact assessment;
- another safeguard provided for in Chapter V GDPR.
You may request a copy of the relevant safeguards by writing to privacy@deep-talk.ai.
8. How long we keep your data
Retention periods are set out in the table in section 5. As a general rule, we keep personal data only for as long as is necessary for the purpose for which it was collected, and thereafter for the period required to comply with our legal obligations or to defend legal claims.
At the end of the applicable period, data is deleted or irreversibly anonymised so that no individual can be identified.
9. Security
We implement appropriate technical and organisational measures under Article 32 GDPR, including encryption in transit (TLS) and at rest, role-based access control, multi-factor authentication for administrators, logging and monitoring, regular backups, staff confidentiality undertakings and security training, vendor security assessments, and periodic penetration testing. We also hold ISO 27001 and SOC 2 certifications.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours as required by Article 33 GDPR and, where the risk is high, inform you without undue delay under Article 34 GDPR.
No system is completely secure. You are responsible for keeping your credentials confidential and for notifying us promptly at security@deep-talk.ai if you suspect unauthorised use of your account.
10. Automated decision-making and profiling
- Profiling. We use your declared specialty, preferences and interaction history to select the scientific content we send or surface to you. This has no legal or similarly significant effect on you and you can disable it at any time in [Settings] or by contacting us.
- AI-generated responses. MARCO generates answers automatically from scientific sources. These outputs are informational support for a qualified healthcare professional; they do not constitute a medical decision, and any clinical decision remains yours, taken under your own professional responsibility.
- We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR. Should that change, we will inform you and provide the safeguards required by that Article, including the right to obtain human intervention, to express your point of view and to contest the decision.
11. Your rights
Under the GDPR and the French Data Protection Act, you have the right to:
- access your personal data and obtain a copy (Art. 15);
- obtain rectification of inaccurate or incomplete data (Art. 16);
- obtain erasure of your data in the cases provided by law (Art. 17);
- obtain restriction of processing (Art. 18);
- receive your data in a structured, commonly used, machine-readable format and have it ported to another controller (Art. 20);
- object at any time to processing based on our legitimate interests, and at any time and without justification to direct marketing (Art. 21);
- withdraw your consent at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3));
- not be subject to a decision based solely on automated processing (Art. 22);
- issue directives on the fate of your data after your death (Art. 85 of the French Data Protection Act), general directives being registrable with a certified digital trustee.
How to exercise them. Write to privacy@deep-talk.ai or use the form at www.info.marco.care/contact. Exercising your rights is free of charge. We may ask for additional information to verify your identity where we have reasonable doubts; we will not request a copy of your identity document unless it is strictly necessary and proportionate.
Our response time. We will respond within one month of receiving your request. That period may be extended by up to two further months where the request is complex or where we have received a large number of requests; we will inform you of any extension and the reasons for it within the first month (Art. 12(3) GDPR).
Complaints. If you consider that we have not respected your rights, you may lodge a complaint with the French supervisory authority:
CNIL — Commission Nationale de l’Informatique et des Libertés
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
www.cnil.fr
You may also lodge a complaint with the supervisory authority of the EU/EEA Member State where you live or work, and you have the right to an effective judicial remedy.
12. Cookies and similar technologies
Our websites and application use cookies and similar technologies.
- Strictly necessary cookies (authentication, session, security, load balancing, recording your cookie choices) are placed without consent, as permitted by Article 82 of the French Data Protection Act.
- Analytics, preference and marketing cookies are placed only with your consent, collected through our consent banner. You may accept, refuse or withdraw your consent at any time via [Cookie settings], as easily as you gave it. Your choice is retained for a maximum of 6 months, in line with CNIL recommendations.
Details of the cookies used, their purpose and their lifetime are set out in our [Cookie Policy].
13. Minors
MARCO is intended for healthcare professionals and is not directed at minors. We do not knowingly collect personal data from persons under 18. If you believe a minor has provided us with personal data, please contact privacy@deep-talk.ai so that we can delete it.
14. Accuracy of the data you provide
You are responsible for the accuracy, currency and authenticity of the personal data you enter, and for ensuring that you are entitled to submit any third-party data you provide to us. Please keep your account details up to date, or ask us to correct them.
15. Changes to this policy
We may update this policy to reflect changes in our services or in applicable law. The version in force is always the one published at [URL], with its date of last update. Where a change materially affects how we process your data, we will notify you by email or through the service before it takes effect and, where the change requires it, we will ask for your consent again.
16. Contact
Questions about this policy or about how we handle your data: privacy@deep-talk.ai — Deep Talk SAS, 149 Avenue du Maine, 75014 Paris, France.

