Confidentiality Policy
This Privacy Policy (hereinafter “Policy”) is intended to inform you about how the company Utelys (hereafter “us” or “our Society”) collects, uses and protects personal data when you use the site https://www.trigger-flow.com And the solution Trigger Flow.
1. Identification of the data controller
Social name : Utelys (SAS with a capital of 28,000€)
S.C.R : 842 608 671 Toulouse
Head office : 13 Saint Ursule Street, 31000 Toulouse, France
Legal representative : Mr. Mounir LAKHFIF
Contact (DPO/Data Protection Manager) : privacy@utelys.fr
2. Personal data collected
2.1 Data collected via the Trigger Flow solution
Enrollment Information : name of the client company, last name, first name (if applicable), professional email address, telephone number.
Payment information : processed via our payment provider Stripe (bank card information, billing information). We do not store credit card data directly on our servers; this data is managed securely by Stripe.
2.2 Usage and navigation data (website)
Audience statistics : via Google Analytics (IP addresses, pages viewed, length of visit, etc.), in order to measure site traffic and improve our services.
Facebook Pixel : used for audience measurement and advertising retargeting on Facebook/Instagram.
No personal data (name, email) is collected directly via a form on our site https://www.trigger-flow.com, except those relating to creating an account on the Trigger Flow platform (see above).
3. Purposes of the treatment
The data collected is used to:
1- Manage customer accounts (registration, authentication, configuration of the customer area).
2- Provide customer support and answer any questions or technical incidents.
3- Insure billing and payment processing via Stripe.
4- Analyzing the audience of the site (Google Analytics, Facebook Pixel) and create statistics to improve our services.
5- Comply with legal obligations and regulatory (accounting, dispute management, etc.).
4. Legal basis for processing
We process personal data on the following legal bases:
- Execution of the contract : registering for the Trigger Flow platform and using its functionalities (creating an account, orders, billing).
- Legitimate interest : for audience analysis (Google Analytics, Facebook Pixel) and the improvement of our services.
- Compliance with legal obligations : accounting and fiscal obligations, in particular the preservation of certain invoices or proof of payment.
5. Data recipients
5.1 Subcontractors and service providers
- Accommodation : Your data is hosted on our servers at Digital Ocean, located in the EU.
- Sending emails : We use Mailgun for the automatic sending of emails (notifications, campaigns).
- Sending SMS : We use a service provider Geteway API for SMS delivery.
- Payment : Transactions are managed via Stripe, which acts as a subcontractor for payment data.
- Audience analysis : Google Analytics (Google Ireland Limited) and Facebook Pixel.
These service providers are contractually committed to respecting the confidentiality and security of the personal data they process on our behalf.
5.2 Transfers outside the EU
Data may be transferred outside the European Union, especially if our service providers (e.g. Mailgun) host their servers outside the EU. In this case, we make sure to put in place appropriate guarantees (European Commission Standard Contractual Clauses or equivalent).
6. Shelf life
We keep personal data for the period strictly necessary for the purposes mentioned above, namely:
- Customer account data : as long as your account is active and up to 3 years after the last activity, for monitoring and prospecting purposes. Beyond that, deletion or secure archiving.
- Billing data : 10 years (in accordance with legal and accounting obligations).
- Logs and analytics : Duration in accordance with Google Analytics settings (generally 14 months for IP anonymization).
Once the deadlines have expired, we proceed with the deletion or anonymization of the data concerned.
7. User rights
In accordance with Regulation (EU) 2016/679 (RGPD) and French legislation, you have the following rights:
1- Right of access : obtain confirmation that data concerning you is being processed and receive a copy.
2- Right to rectification : to have inaccurate or incomplete data corrected.
3- Right to erasure (or “right to be forgotten”): request the deletion of your data, subject to our legal obligations.
4- Right to limitation treatment: in certain cases provided for by the regulations.
5- Right to object : oppose the processing of your data at any time, for reasons relating to your particular situation.
6- Right to portability : receive your data in a structured, commonly used and machine-readable format, when the processing is based on your consent or on a contract.
7- Withdrawal of consent : when the processing is based on your consent (e.g. newsletter), you can withdraw it at any time.
To exercise these rights, you can contact us:
- By email: privacy@utelys.fr
- Or by post: Utelys — 13 rue Saint Ursule, 31000 Toulouse, France
We will make every effort to respond to your request in a timely manner Of one (1) month, which can be extended by two months if necessary.
In the event of a dispute, you also have the option of seizing thesupervisory authority of your country (in France, the CNIL : https://www.cnil.fr).
8. Data security
We are setting up technical and organizational measures appropriate to guarantee a level of security adapted to the risk:
- Use of the HTTPS protocol to secure exchanges,
- Access control strict and protected passwords (hashed and salted),
- Limitation of rights access to only authorized collaborators and subcontractors,
- Regular backups and encryption if required.
Despite these precautions, no system is infallible. In the event of a data breach, we will inform you as soon as possible, in accordance with current regulations.
9. Cookies and other trackers
We use cookies or similar technologies for:
- Ensure proper functioning of the site (session cookies, possibly).
- Measuring the audience (Google Analytics): analyze traffic, optimize navigation.
- Advertising and retargeting (Facebook Pixel).
During your first visit, a consent banner allows you to accept or refuse certain non-essential cookies. You can also set your browser to block or delete cookies.
For more information, refer to our Cookies Policy (if it exists in detail) or contact us at privacy@utelys.fr.
10. Services for professionals (B2B)/Minors
Our site and our services (Trigger Flow) are mainly intended for a professional audience (hotels, restaurants). We do not intentionally target minors. If you believe that a minor child has provided us with personal data without the consent of their legal representative, please contact us so that we can take appropriate action.
11. Privacy Policy Updates
We reserve the right to update this Policy at any time in order to reflect the evolution of our practices or to comply with any new legal obligations. The “Last Updated” date at the top of this page indicates the last revision in effect. We invite you to consult this page regularly to find out about any changes.
12. Contact us
For any questions regarding this Privacy Policy or the processing of your personal data, you can write to us at the following address: privacy@utelys.fr
Or send us a letter by post to:
Utelys
13 rue Saint Ursule, 31000 Toulouse, France
