Skip to main content

These terms are pending review by legal counsel.

Publisher details are accurate and up to date. The contractual wording itself has not yet been reviewed by a legal professional and may still change. Contact us at adrien@checkeasy.co with any question about these terms.

Privacy Policy

Last updated: 26/08/2026

This policy describes how CHECK EASY (hereinafter the "Publisher") processes personal data in connection with the provision of its B2B prospecting service (hereinafter the "Service"), in compliance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (Loi Informatique et Libertes).

1. Two categories of processing

Two situations with different roles must be distinguished:

  • Data of the Service's users (accounts, billing, support): the Publisher acts as data controller.
  • Prospecting data imported and processed by the Client (prospects, contacts, exchanges): the Client is the data controller and the Publisher acts as data processor on behalf of the Client. This processing is governed by the data processing agreement (DPA).

2. Data processed by the Publisher as controller

  • Account data: name, email address, password (in hashed form), organization, role.
  • Subscription and billing data: plan, payment history (processed by Stripe).
  • Usage data and technical logs: logins, actions, IP addresses, security events.
  • Support data: content of requests sent to the team.

3. Purposes and legal bases

  • Provision and administration of the Service: performance of the contract.
  • Billing and subscription management: performance of the contract and legal obligations.
  • Security, abuse prevention, and logging: legitimate interest.
  • Improvement of the Service and aggregated statistics: legitimate interest.
  • Communications relating to the Service: performance of the contract or legitimate interest.

4. Artificial intelligence processing (BYOK model)

The Service operates on a "BYOK" (Bring Your Own Key) model. Artificial intelligence processing is performed using the Client's own API key (Anthropic, OpenAI, or another provider configured by the Client). As a result, the data submitted to the AI (for example, the content of a message to be drafted or analyzed) passes through the Client's account with its AI provider and is subject to that provider's terms and privacy policy. The Client chooses its provider, accepts its terms, and remains responsible for the data it decides to submit to the AI. The Publisher does not retain a separate copy of the exchanges for the purpose of training its own models.

5. Campaign pages and online advertising

The Service allows the Client to publish campaign pages (URLs of the form/c/<slug>) and to run advertising campaigns on Google Ads and Meta. On these pages, and in the native lead forms hosted by Meta, the visitor voluntarily provides the data requested by the form (in all cases an email address, and where applicable a name, company, telephone number and answers to free-form questions).

  • Roles. The Client is the data controller for these submissions; the Publisher acts as data processor under the DPA. The Client is responsible for the lawfulness of its campaigns and for the consent wording displayed on its pages.
  • Consent. Each submission records the exact consent text shown and its timestamp. No submission is accepted without it.
  • Attribution data. Advertising click identifiers (gclid, fbclid), UTM parameters, the referrer and a hashed user agent are stored in order to attribute the contact to the campaign that generated it.
  • Conversion signals sent back to the ad networks. When a lead becomes a booked meeting or a signed deal, that event may be sent back to Google Ads or Meta so that the campaigns optimize on real outcomes rather than on clicks. Any identifier used for matching (email address, telephone number) is normalized then hashed with SHA-256 before transmission: the networks never receive it in clear text. The legal basis is the Client's legitimate interest in measuring the effectiveness of its advertising spend.
  • Indexing. Campaign pages are served with noindex and are not intended to be listed by search engines.

Google and Meta act as independent controllers for the data they process on their own platforms. Their respective policies apply in addition to this one.

6. Recipients and processors

The data is accessible to the Publisher's authorized personnel and to technical service providers acting as processors (hosting, transactional emails, payment, AI). The detailed list, purposes, locations, and associated safeguards are set out in the register of subprocessors.

7. Transfers outside the European Union

Some providers may process data outside the European Union. In that case, transfers are governed by appropriate safeguards, in particular the standard contractual clauses of the European Commission (SCCs) and, where applicable, supplementary measures. Details are set out in the register of subprocessors.

8. Retention periods

  • Account and workspace data: for the duration of the contractual relationship.
  • After deletion of the workspace: erasure or anonymization within a reasonable period, subject to technical backups with limited rotation.
  • Billing data: retained for as long as required by statutory accounting and tax obligations.
  • Security logs: retained for a limited period proportionate to the security purpose.
  • Email tracking (opens, clicks): the IP address and browser are erased after 90 days, the event itself after 13 months. A daily automated purge enforces these periods.
  • Technical logs (AI usage, external API calls, webhook deliveries): 13 months.

For prospecting data processed on behalf of the Client, retention periods are defined by the Client, who is the controller of that data; the Publisher erases or returns it in accordance with the DPA.

9. Your rights

In accordance with the GDPR, you have the rights of access, rectification, erasure, restriction, objection, and portability, as well as the right to set directives regarding the fate of your data after your death. You may exercise these rights by contacting adrien@checkeasy.co. Some actions are directly available in the application, in particular the deletion of the workspace, which triggers the erasure of the associated data. Where the data concerned relates to prospecting managed by a Client (data controller), the request is forwarded or directed to that Client. You may lodge a complaint with the CNIL (www.cnil.fr).

10. Security

The Publisher implements appropriate technical and organizational measures, including:

  • encryption of sensitive secrets at rest (API keys, access tokens, credentials);
  • encryption of communications in transit (TLS);
  • password hashing;
  • workspace isolation (multi-tenant architecture, access segregation);
  • access control, logging, and backups.

11. Cookies

The Service uses cookies and similar technologies that are strictly necessary for its operation (authentication, security, language preference). These do not require your consent.

NON-essential trackers, namely audience measurement and the support widget, are only set after you accept them through the banner shown on your first visit. If you decline, neither is loaded: no script, no cookie, no request to the provider. Your choice is kept for one year, after which you are asked again. To change it sooner, clear the site cookies in your browser and the banner will reappear.

12. Contact

For any question regarding this policy or the exercise of your rights, contact the data protection officer at adrien@checkeasy.co, or by mail at 6 rue Albert Difusco, 13007 Marseille, France.