Legal

Privacy notice

Our commitment to Data Privacy

Protecting the privacy of individuals who provide us with personal information (“Personal Data”) is a priority. To this end, we are committed to respecting data privacy legislation bearing upon us, namely the General Data Protection Regulation no. 2016/679 (the “Applicable Law”).

General provisions

The Privacy Policy (the “Policy”) describes how Nepsis (“Nepsis”, “we”, or “us”) collects, uses, stores, shares and protects your Personal Data in connection of its services as a data controller including, but not limited to, services provided at or using the domain Nepsis.co (the “Site”) and/or the Nepsis mobile application and platform (together, the “Application”) (collectively, the “Services”).

The Policy applies when you (“you”, the “Client”, the “User”) access, visit or use any portion of the Services.

For the purposes of this Policy:

  • a “Customer” is a legal or natural person using the Application on the basis of the subscription contract;
  • a “Prospect” is a legal or natural person using the Website out of interest for the Services and/or signs up for a demo;
  • a “User” is a person duly authorized access to and use of the Application, in order to benefit from the Services.

Your Privacy at a Glance

Client

Purposes of the ProcessingCategories of Personal Data ProcessedLegitimate BasisRetention Period
Commercial ProspectionIdentification data (name, surname, professional email address, phone number, position in the company), Communication history, Meeting notes.ConsentFor the duration necessary to achieve the purposes described and in any event until consent is withdrawn
Meeting transcriptionIdentity of the participants (name, surname, professional email address, position in the company), voices, transcriptions of the meeting.Performance of a ContractFor the duration of the Commercial Relationship
Contract managementIdentity of the stakeholders (name, surname, professional email address, phone number, position in the company).Performance of a ContractFor the duration of the Commercial Relationship
Management of invoicing and paymentsAccounting contacts (name, surname, professional email address, position in the company), bank account details.Performance of a ContractFor the duration of the Commercial Relationship

Prospect

Purposes of the ProcessingCategories of Personal Data ProcessedLegitimate BasisRetention Period
Contact request and Appointment schedulingIdentification data (name, surname, professional email address, phone number, position in the company).Legitimate interest in addressing your request for information.3 years from the last contact with you.
Commercial ProspectionIdentification data (name, surname, professional email address, phone number, position in the company), communication history, meeting notes.Consent3 years from the last contact with you or until your consent is withdrawn.
Meeting transcriptionIdentity of the participants (name, surname, professional email address, position in the company), voices of the participants, transcription of the meeting.Consent3 years from the last contact with you or until your consent is withdrawn.

Users

Purposes of the ProcessingCategories of Personal Data ProcessedLegitimate BasisRetention Period
Monitoring User’s account of the ApplicationIdentity of the User (name, surname, professional email address, position in the company).Performance of a ContractFor the duration of the Commercial Relationship

Job Applicants

Purposes of the ProcessingCategories of Personal Data ProcessedLegitimate BasisRetention Period
Recruitment processIdentity of the Applicants (name, surname), curriculum vitae, meeting notes.Pre-contractual measures taken at your request in connection with your application for employment.For the duration of the recruiting process

How long will we retain your Personal Data?

Your Personal Data will be handled with this Policy as long as it is needed in order to:

  • perfom the Services for the duration of the duration of the commercial relationship;
  • provide you with personalized Services;
  • comply with the law and namely prevent fraud, collect any fees owed, resolve disputes, troubleshoot problems, assist with any investigation and take other actions permitted by law.

Nepsis will retain your Personal Data for the duration described augmented by any applicable statute of limitation and/or ongoing litigation.

How we share your Personal Data with any Third Parties

In connection with the use of the Services, some of your Personal Data may be processed by third parties, meaning entities outside Nepsis (the “Third Parties”), for the purpose of carrying out some of the processing operations listed out. We can share your personal data with the following Third Parties:

  • our services providers (including their subcontractors) which process Personal Data on our behalf, to help us provide the Services and any information you have requested or which we believe is of interest to you;
  • our partners, including system implementers, value-added resellers, independent software vendors and developers, in order to allow them to provide you with the services you have requested, or they think is of interest to you;
  • credit reference and fraud prevention agencies, government bodies and departments, regulators and any other Third Party necessary to meet our legal obligations and protect our company.

We make sure to work only with companies that safeguard and protect your Personal Data and comply with the Applicable Law in the same way as we do. Therefore, in accordance with Article 28 GDPR, access to your Personal Data by our processors is subject to the signature of an agreement which allows us to monitor and control the way-out processors handle your Personal Data.

Where do we store your Personal Data ?

The Personal Data we process is stored by our hosting Amazon Web Services on servers located within the European Union (the “EU”). The Website is hosted separately by Vercel.

In order to perform the Services, we may transfer some of your Personal Data to Third Party service providers located or using servers outside the EU and the European Economic Area (the “EEA”). In such cases, we can make sure that:

  • they are located in countries considered having an adequate level of protection by the EU in terms of personal data or,
  • if located in the United States or in Israel, they abide by contractual provisions ensuring an equivalent level of protection of your Personal Data (such as Standard Contractual Clauses established by the European Commission).

You may obtain a copy or review the documents containing these safeguards by submitting a request to us for that purpose.

How do we process your Personal Data ?

Here at Nepsis, we care about the security of the Personal Data we process. Therefore, we adopt technical and organizational security measures to guarantee the security of your Personal Data by ensuring a security level adapted to the risks related to the processing and nature of such Personal Data.

You can find further details about the way we protect your Personal Data in our Security Policy.

Your rights

In accordance with the Applicable Law, you have the following rights:

  • Right to access: the right to be informed and to request access to your Personal Data;
  • Right to data portability: the right to request a copy of your Personal Data in a structured and machine-readable format so that you can transmit it to another data controller, in cases where the processing is (i) based on the legal basis of a contract or your consent, and (ii) carried out using automated means.
  • Right to rectification: the right to ask us to modify or update inaccurate or incomplete Personal Data;
  • Right to erasure (right to be forgotten): the right to ask us to permanently delete Personal Data when the data subject considers that we no longer have any reason to do so collect/process;
  • Right to restrict processing: the right to ask us to stop temporarily the processing of all parts of the Personal Data;
  • Right to object: the right to object at any time, for reasons related to the situation of the data subject, to the processing of Personal Data concerning him/her having as its legal basis the pursuit of a legitimate interest. Unless we demonstrate a legitimate and compelling interest justifying such processing, we will only process plus the Personal Data concerned;
  • Right to file a complaint with the supervisory authority or to get compensation from the competent court;
  • Right to decide the fate of your Personal Data after death: the right to impose the fate that you wish to reserve your Personal Data in the event of death.

To exercise your right, please send your request directly to us:

In accordance with the Applicable Law, we will ask you to prove your identity.

Contact the competent Supervising Authority

You also have the right to file a complaint with the French Data Protection Authority (“CNIL”) (Commission Nationale de l’Informatique et des Libertés, 3 Place de Fontenoy – TSA 80715 – 75334 Paris CEDEX 07). You can find more information at www.cnil.fr.

Changes to this Policy

We may amend this Policy from time to time to ensure transparency on all processing operations relating to you and your Personal Data in real-time. We may notify you and any substantial changes to this Policy, before the effective date of the changes, by sending an email or in another conspicuous manner reasonably designed to notify you.

Contact us

If you have any question or request regarding the processing of your Personal Data, please contact us to the following addresses: