Legal
GDPR
The point that really matters: when we send review requests to your customers, we do so on your behalf. The allocation of roles is described here.
This English version is provided for convenience; the French version prevails.
Two distinct situations
Depending on the data concerned, we do not hold the same position within the meaning of the General Data Protection Regulation (GDPR).
Data controller
For the data we collect on our own behalf: audit requests, sales contacts, billing, client portal accounts. The purposes and retention periods are described in our privacy policy.
Processor
For the contact details of your own customers that you entrust to us in order to send review requests. You remain the data controller for that data. We act only on your documented instructions, within the scope of the service.
Our commitments as a processor
- Process this data only to send the agreed review requests.
- Never reuse it for our own purposes, nor pass it on to third parties.
- Delete it no later than 90 days after sending, or at your request.
- Notify you without undue delay in the event of a data breach.
- Assist you in handling requests from individuals exercising their rights.
- Engage no sub-processor without informing you.
What you remain responsible for
You must have a legal basis for contacting your customers — most often their consent for SMS, or legitimate interest in the context of an existing business relationship. You must also inform them of how their contact details are used and honour their requests to object.
Every message we send on your behalf includes a simple way to opt out of further contact.
Security measures
- Encryption of communications (HTTPS) and of backups.
- Database not exposed to the public internet.
- Passwords stored as hashes, never in plain text.
- Access restricted to the people who actually need it.
- Logging of access to customer data.
Contact
For any question relating to data protection: bonjour@avislocalpro.fr.