Skip to main content

Trust

Security, compliance and commitments

Our own infrastructure, hosted in France, certified and audited every year, with governance dedicated to data protection.

Our commitments

  • Dedicated governance

    Certified DPO, quarterly security committee with executive management, CISO and CIO, security policy reviewed yearly.

  • CNIL label

    GDPR Governance label issued by the French CNIL in 2018, audited annually since.

  • Protection by design

    Impact assessments, processing register, rights procedures and defined retention periods.

  • Certified infrastructure

    Hosting at Téléhouse 2 in Paris, ISO 27001, 9001 and 14001 governance. No storage outside the European Union.

  • Proven consent

    Timestamped collection, wording retained, traceable and enforceable proof across the chain.

  • 24/7 continuity

    Continuity and recovery plans tested every year, backup site and permanent supervision.

Governance and organisation

  • Documented security policy, reviewed every year
  • IT charter, administrator charter and internal procedures
  • Internal and external audits twice a year
  • Up-to-date risk mapping
  • Quarterly security committee: executive management, CISO, CIO and DPO
  • External DPO provided by a specialised law firm
  • Role-restricted access, reviewed and logged

Infrastructure and hosting

  • Data hosted at Téléhouse 2, Paris
  • Redundant services, hardware and links
  • Continuity and recovery plans tested every year
  • Encryption of data in transit
  • Monthly access review
  • No processing of card data, PCI-DSS SAQ A validated
  • Abnormal behaviour detection

GDPR and AI compliance

  • GDPR Governance label issued by the CNIL in 2018
  • Impact assessments, mapping and processing register
  • Procedures for exercising data subject rights
  • Transfers outside the EU framed by standard contractual clauses
  • No storage or extraction of data outside the European Union
  • Data breach notification within 72 hours
  • Defined retention periods and extraction procedures
  • Internal charter on the use of artificial intelligence

Culture and tooling

  • Training on hiring, then every year
  • Awareness sessions for every new joiner
  • Security referents and DPO appointed in each department
  • GDPR governance and consent certification tooling
  • Specialised provider for card data handling

Were you contacted by eurocrm and want to exercise your rights or check the origin of a call? The transparency page explains how.

Let's discuss your programme.

We frame a first scope together, the expected indicators and the engagement model that suits you.