1. Who is the controller
The controller for the processing of the data described below is MURMUR, a French simplified joint-stock company (société par actions simplifiée), 8 B rue Abel, 75012 Paris, France, registered with the Paris Trade and Companies Register (RCS) under number 108 784 521 (“murmur”).
murmur processes two very different populations of data, and this policy distinguishes between them throughout: on the one hand, the data of visitors to the murmur.ad website and of clients of the service; on the other hand, the data of the business contacts of the companies to which clients address messages — people who are not our clients and have entrusted nothing to us directly.
2. Visitors and clients on one side, prospected contacts on the other
For website visitors and clients of the service, murmur is the controller: it alone determines why and how this data is processed (providing the service, invoicing, securing, responding).
For prospected contacts, two operations coexist. Building the company database — collecting public business data, on our own initiative and for our own purposes — is carried out by murmur as controller; it is the subject of dedicated information, under Article 14 of the GDPR, accessible from every message sent. Running a campaign for a client — the choice of targeted companies, the approved content, the sending — is carried out on behalf of that client, who determines its purpose; murmur acts there on the client’s instructions and within the limits published on the website.
3. Data of visitors and clients
Data processed: account information (company identity, name and email address of the representative, billing address, EU VAT number); billing data (payment card data is processed exclusively by the payment provider, murmur never has access to it); the settings and content of the campaigns created by the client; exchanges with support; the technical connection data strictly necessary for security (IP address, timestamp, log of account actions); and, if the client connects an inbox to collect replies, the messages received at that address.
Purposes and legal bases: providing the service and managing the account (performance of the contract); invoicing and keeping accounts (legal obligation); securing the service, preventing fraud and abuse (murmur’s legitimate interest); responding to requests submitted through the website (pre-contractual measures or legitimate interest).
Retention periods: account data is kept for the duration of the contractual relationship, then for the applicable limitation periods; invoices and accounting records, ten years from the close of the financial year (article L123-22 of the French Commercial Code); technical campaign logs, 90 days; the text of messages sent, 180 days; the content of replies received in a connected inbox, 365 days. These are the periods the system applies automatically.
A request submitted through the website contact form is kept for the time needed to handle it, then for the duration of any commercial relationship that may result from it.
4. Data of prospected business contacts
Categories of data: exclusively public business data — company identification (name, legal form, public register identifiers), published business contact details (address, telephone, contact form or email address published on the company’s website), firmographic data (sector, headcount, location), online presence (website and its public content).
Sources: public company registers (for example SIRENE in France and the equivalent national registers), the company’s public website, public map directories. murmur collects nothing from the individuals themselves and never reconstructs a personal email address.
Recipients: the client on whose behalf a message is sent receives the business contact details needed for that contact and, if they have connected an inbox, the replies addressed to them. The technical providers listed in section 5 process this data on behalf of murmur.
Full information under Article 14 of the GDPR (controller, sources, purposes, rights) is made available to data subjects from every message sent and kept for three years together with proof of its origin (1,095 days).
Retention period: the data of a prospected business contact is kept for three years from the last contact with the company concerned, then deleted. An objection, however, is kept for as long as necessary to be honoured: that is the only way to guarantee that a person who no longer wishes to be contacted will not be.
5. Providers and processors
murmur uses the following providers, which process data on its behalf under processing agreements:
- Hetzner Online GmbH (Germany) — hosting of the servers, the database and the website.
- Brevo (Sendinblue SAS, France) — delivery of transactional emails (confirmations, invoices, notifications).
- Zoho — hosting of the inboxes in which the replies of contacted companies are collected.
- Stripe — payment processing; only Stripe holds payment card data.
- DeepSeek — language model used for assisted drafting of messages and targeting filtering; it receives the public content of the target company’s website and the client’s instructions, never the client’s account data.
- OpenAI — text embedding model used for semantic search in the company database (public activity descriptions) and, for campaigns configured that way, language model for assisted drafting, under the same conditions as DeepSeek.
- CapSolver — service for solving the anti-bot protections encountered when submitting a form; it receives the image of the protection displayed by the third-party site, and nothing else.
- Google — authentication (OAuth) when the client chooses to connect a Gmail inbox; murmur accesses only the permissions strictly necessary to collect replies.
- Webshare — provision of exit addresses (proxies) through which traffic to the websites of prospected companies is routed.
6. Data location and transfers outside the European Union
The data of the website, the client area and the company database is hosted in the European Union, at Hetzner (Germany); transactional emails are delivered by Brevo (France).
Two providers established outside the European Union receive data as part of the service — exclusively public business data relating to prospected companies (public content of their website, activity description) and the client’s targeting instructions; no client account, billing or connected-inbox data is transmitted to them. This policy is updated upon the conclusion of these agreements; for the other providers in section 5, murmur is cataloguing the location of processing and the applicable safeguards and supplements this policy as it goes:
- DeepSeek (China) — assisted drafting of messages and targeting filtering. The contractual framework for this transfer is in progress.
- OpenAI (United States) — semantic search in the company database and, depending on the campaign configuration, assisted drafting. The data processing agreement is being signed.
7. Your rights and how to exercise them
Everyone has the rights of access, rectification, erasure, restriction, objection and, where the processing is based on the contract or on consent, portability. Every access request receives the exact provenance — source and date — of each item of data held.
To object to any prospecting message, without an account or justification: the page stop being contacted. The objection is recorded after confirmation by email, applies to all of murmur’s clients and is permanent.
For any other request: write to contact@murmur.ad, providing proof of your identity. murmur responds within the one-month period provided for by Article 12 of the GDPR.
Everyone may also lodge a complaint with the competent supervisory authority — in France, the CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
8. Cookies and trackers
The murmur.ad website and the client area set no audience-measurement, advertising or tracking cookie, and use no third-party analytics tool. There is therefore no consent banner: there is nothing to consent to.
Only information strictly necessary to operate the service is kept in your browser: the language preference, the theme choice, and — after signing in to the client area — a session token indispensable for authentication.
murmur may put in place an audience-measurement tool. If so, this policy will be updated to name it; if that tool sets cookies or trackers that are not strictly necessary, your consent will be requested before any are set.
9. Security
Data is hosted in the European Union, at Hetzner (Germany). Exchanges with the website and the client area are encrypted (HTTPS). Access to data is limited to the people and the processing operations that need it; sensitive actions are logged.
10. Contact
For any question relating to this policy or to the exercise of your rights: contact@murmur.ad, or by post to MURMUR, 8 B rue Abel, 75012 Paris, France.
murmur has not appointed a data protection officer (DPO); requests are handled directly by the company.
11. Changes to this policy
This policy may be updated to reflect a change in the service, its providers or the regulations. The date at the top of the page indicates the version in force; a substantial change is notified to clients by email.