Data protection is important to us. We at eFront are committed to respecting and protecting your privacy in the relationship of common trust we have established with you.

In accordance with the EU General Data Protection Regulation (“GDPR”), this privacy policy (the “Privacy Policy”) describes how and why we collect and process your personal data.

1. When does this Privacy Policy apply to you?

This Privacy Policy applies to you as client or prospect if you are located in the European Economic Area (“EEA”) when eFront SAS and its affiliates (hereafter altogether “eFront”, “we” or “us”) collect and process your personal data (and the personal data of your contacts located in the EEA) in the context of the supply and promotion of our software and services.

2. How is your personal data collected?

If you are a prospect, we collect personal data you have shared with us in the following situations:

  • when you sign-up to receive marketing information from us;
  • when you attend an event organized by us; and/or
  • when we communicate with you by email of other communication channels.

If you are a client, we collect personal data you have shared with us in the context of:

  • the provision of professional services, support and maintenance services to you;
  • our business relationship, including for invoicing purposes;
  • your signing-up to receive marketing information from us; and/or
  • your attendance to an event organized by us.

Your personal data may also be collected by eFront indirectly from other sources, including social media, your company, or publicly available websites, for the purposes of finding new prospects and completing information on your profile when we already are in touch with you. In such cases, we typically collect the following categories of data: first name, last name, personal or professional email address, personal or professional phone number, name of your employer, job title, country and city of residency.

3. Who collects and processes your personal data?

If you are a prospect, the eFront affiliate with whom you are in contact collects and processes your personal data as the data controller. If no eFront affiliate has been expressly identified as being the data controller, the data controller is deemed to be eFront SAS, a French simplified joint stock company with a share capital of € 477,277.65 €, registered with the Paris Commercial Registry under number 403 913 700, having its registered offices located at 2-4 rue Louis David, 75116 Paris, France.

If you are a client, the eFront affiliate with whom your company has an agreement in place collects and processes your personal data as the data controller.

Notwithstanding the above, eFront SAS is the data controller when your personal data is collected through your use of our website.

Note that your data is not shared with or sold to any third party for marketing or promotional purposes.

4. Why does eFront collect and process your personal data?

If you are a prospect, we collect and process your personal data, in compliance with applicable law, for marketing and promotional purposes and to inform you about our business, our products and services. In addition, we do so to further develop our relationship with you, in line with our legitimate business interest as the data controller.

If you are a client, we collect your personal data as necessary to perform our contractual obligations (including but not limited to invoicing, customer relationship management, marketing activities and promotional solicitations) and to grant you access to the eFront software and/or services, in accordance with the agreement executed with your company.

If you are signing-up on this website to receive marketing information from us, you have consented to the collection and processing of your personal data by eFront for marketing and promotional purposes.

5. Is your personal data transferred outside EEA?

Your personal data may be transferred to our affiliates and service providers located outside the EEA in order to provide you with maintenance and support services, applications and infrastructures, to provide you professional services, to manage our contractual relationship (CRM) and to send you emails and newsletters.

In accordance with the GDPR, eFront has implemented appropriate safeguards to secure these transfers, such as through the execution of standard contractual clauses or a European Commission adequacy decision. A copy of the documents evidencing the security of the transfers of your personal data is available upon request to our Data Protection Officer.

6. Who has access to your personal data?

Only authorized employees at eFront may access your personal data on a need-to-know basis. Our employees are informed of the personal nature of this data, have received appropriate training regarding its processing and protection and have committed to strict confidentiality terms.

Your personal data is also shared with our service providers, such as maintenance and support service providers, consulting services providers, CRM providers or hosting service providers, e.g. AWS or Microsoft. Relevant contractual safeguards, such as data processing agreements, are implemented to secure the confidentiality of your personal data by such third parties.

Your personal data may also be shared with our professional advisors (i.e. our legal and tax advisers, accountants and auditors) and with our Data Protection Officer.

We may also be required to disclose your personal data upon request by administrative or judicial authorities, or to assert our rights.

7. How long do we keep your personal data?

Depending on whether you are a prospect or a client, the retention period applicable to your personal data may vary pursuant to applicable law.

If you are a prospect, we will keep your personal data in accordance with the applicable law of your country of residency.

If you are a client, eFront will keep your personal data as long as eFront provides your company with eFront software or services.

Information collected through cookies on this website, such as your email address and IP address, will be kept for no longer than thirteen (13) months from collection.

Upon expiry of these retention periods, your personal data will be deleted unless we are legally required or entitled to retain it. In such case, your personal data will be kept in accordance with statutory retention periods.

You can at any time unsubscribe from our emailing and newsletter lists. If you would no longer wish to receive communications from eFront and its affiliates, please click here.

8. What are your rights?

You have the right to access your personal data and request for your personal data to be rectified.

You are also entitled to restrict or object to the processing of your personal data and request erasure of your personal data.

If applicable and depending on the type of personal data concerned, you also have a right to obtain a copy of your personal data in a machine-readable format to transmit your personal data to another third-party service provider (“right to portability”).

Finally, when you have consented to receiving marketing information from us, you have the right to withdraw your consent at any time.

You can exercise your rights by writing to dpo@efront.com.

9. Contacting us

You can directly contact the eFront affiliate which has executed an agreement with your company (if you are a client) or with whom you are in touch (if you are a prospect).

For any information or question relating to the protection of your personal data, you can also contact our Data Protection Officer at dpo@efront.com.

In the event of a dispute with eFront concerning the collection and processing of your personal data, and after having previously asserted your rights internally, you have the option to file a complaint with the French supervisory authority (“Commission Nationale Informatique et Libertés” or CNIL) or with the appropriate supervisory authority in your country of residency.