Privacy policy
In vigore dal 17 agosto 2026 · versione 3
Privacy policy
In force from 17 agosto 2026.
This document describes what Lacima does with personal data, and in particular with the data of the person we call. It is written to be read by a family, not only by a lawyer.
1. Who is responsible
Lacima SAS (informations provisoires) (SAS), registered under number 000 000 000 R.C.S. Paris, with its registered office at 1 rue de l'Exemple, 75001 Paris, FR, is the data controller.
For any question about your data, or to exercise the rights in section 8: dpo@lacima.net-innovation.com. For a service question: support@lacima.net-innovation.com.
2. What Lacima is not
Three points that determine the nature of the data we handle:
- Lacima is not a medical device and produces no diagnosis.
- Lacima is not an emergency service. We never contact emergency services automatically. When
a concern is detected we alert the designated relatives, and that is all.
- Lacima is not a monitoring system. There is no continuous listening: data exists only during
and after an identified call.
3. Whose data
Two categories, in different positions:
- The member — the person who opens the account and pays. They give us their own data.
- The person we call — their data is given to us by the member, and the content of their
conversations is produced during the call.
That asymmetry is the reason for section 5: the person being called must be informed and willing, and that is not for the member alone to decide.
4. What we process, and why
Account and billing — email address, name, language, timezone, subscription data. Lawful basis: performance of the contract.
Profile of the person called — first name, phone number, spoken language, timezone, age if provided, notes the family writes about them, preferred call times. Lawful basis: performance of the contract, and the consent of the person called for the calls themselves.
Conversation content — the transcript, a summary for the family, and short "memories" the assistant keeps so the next call makes sense. This may reveal a person's health, mood or family situation, so it falls under Article 9 GDPR and we process it on the basis of their explicit consent.
Audio recording — the person's own voice, when recording is enabled. It has its own separate consent: agreeing to be phoned is not agreeing to be recorded. The purpose is the wellbeing check-ins the household has asked for, and it is announced out loud at the start of every recorded call, in the language of that call. Withdrawing this consent stops new recordings and immediately closes access to those already made.
Safety alerts — the category of concern, its severity, and a short excerpt of what the person said. Lawful basis: the legitimate interest of relatives in being told, within the consent given to the calls.
Technical logs — timestamps, call identifiers, error codes, IP address for rate limiting and abuse prevention. We log no secrets, no audio and no conversation content.
5. Consent of the person called
We call nobody without a recorded consent. It is stored with the name of the person attesting to it, the date, and the version of this document then in force.
Consent is split so that it can be withdrawn in part: the calls, keeping the transcript, and the audio recording are three separate agreements. Someone can withdraw recording and still accept the calls.
A withdrawal takes effect immediately going forward. It does not retroactively erase what was lawfully processed before, but you may request erasure under section 8.
6. Retention
| Data | Kept for | | ------------------- | ---------------------------------------------------------------- | | Call transcript | 30 days, then deleted automatically | | Audio recording | 60 days, then deleted automatically | | Family summary | as long as the account exists | | Assistant memories | as long as the account exists; editable and deletable | | Safety alerts | as long as the account exists | | Account and billing | the term of the contract, then as accounting obligations require | | Technical logs | 30 days |
Transcript and recording deletion is performed by an automated task and does not depend on anyone remembering to do it.
7. Who can read a conversation
This is where we are strictest, and it deserves stating precisely.
A transcript leaves our systems by two routes only:
- A platform administrator at the highest level, on a call's own page. Every such read **writes a
named audit entry. An ordinary support administrator sees the same page without** the conversation.
- An
OWNERorADMINmember of the household concerned, and only if the corresponding platform
option is enabled. A plain member never has access.
The audio recording, when one exists, leaves our systems by two routes of its own, on the same pattern:
- A platform administrator at the highest level, whose every listen writes a named audit entry.
- An
OWNERorADMINmember of the household concerned — never a plain member — and only if all of
the following are true: recording is enabled on the platform, family listening is enabled on the platform, and the recorded person's own consent has not been withdrawn.
In every case, when the answer is no, the data is not filtered out after being read — it is not retrieved from the database at all.
8. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw a consent at any time.
These rights belong to the person called as well — and above all — including when a relative opened the account. A request from the person called themselves takes precedence over the member's wishes.
Write to dpo@lacima.net-innovation.com. We answer within one month. You may also complain to the data protection authority of your country of residence.
9. Processors
Running a conversational phone call requires technical providers. Each one accesses only what it needs, under a processing agreement:
| Provider | Role | Data involved | | ----------------- | ---------------------------------------------- | --------------------------------------- | | Twilio | telephony | number, call metadata, audio in transit | | OpenAI | voice conversation and transcription | call audio and transcript | | ElevenLabs | voice conversation, depending on configuration | call audio and transcript | | OpenRouter | post-call analysis and summaries | call transcript | | Resend | email delivery | recipient address, message content | | Contabo GmbH | hosting | all data, at rest |
The current list is the one in this document. We update it when it changes.
10. Transfers outside the European Union
We should be plain about this. The voice conversation is currently handled by providers whose infrastructure is not guaranteed to be European, which means a transfer outside the EU governed by the European Commission's standard contractual clauses.
We are working towards a European processing configuration for the conversation. Until that is in place, this page says so.
Account data, billing data and the database itself are hosted in the European Union.
11. What we do not do
- No voice cloning, of anyone, under any circumstances.
- No sale, rental or exchange of data for advertising.
- No automated decision with legal effect: the severity of an alert is set by written, testable
rules, and the action that follows belongs to the family.
- No profiling for commercial purposes.
12. Security
Encryption in transit, encryption of provider credentials at rest, administrative access separated by role, an audit log on sensitive reads, and automatic deletion at the deadlines in section 6.
13. Changes
Every version of this document is dated and archived. Where a change affects the nature of the processing, we inform members and, where necessary, collect fresh consent.
This document is published by Lacima SAS (informations provisoires) and is available at https://lacima.net-innovation.com.
