HomePrivacy Policy

Privacy Policy

DATA PROTECTION DECLARATION

Preamble
We make every effort to ensure that our technical and organizational measures fully comply with your data protection rights. This Privacy Policy outlines our principles regarding the collection, processing, and storage of personal data submitted in connection with our services. The term “personal data” refers to any information relating to an identified or identifiable natural person.

1. Use of the website :

The use of our website is generally possible without providing personal data. In cases where personal data (e.g., name, address, or email addresses) is collected on our site, this is, as far as possible, always done on a voluntary basis. The legal basis for processing in the context of consent is Article 6(1)(a) of the EU General Data Protection Regulation (GDPR). Reviewers have the option to request a review link via the certificate pages provided by Convyo if they have never received a review link from their supplier, and if the request is justified in accordance with communication rules. Reviewers can also submit a complaint or ask a question regarding a rating. The transaction must be based on an invoice or other relevant documents. Submission of the invoice or other relevant documents, as well as the data involved, is voluntary and necessary to verify the transaction and eligibility to provide a rating. Information that is not relevant to proving the transaction may be redacted by the reviewer. After verification, the submitted documents will be destroyed. These data will not be shared with third parties without the reviewer’s explicit consent. Please note that transmitting data over the Internet (e.g., via email) may present security vulnerabilities. Complete protection of data against access by third parties is not possible. The use of contact details published in the legal notice for sending unsolicited advertising or information is strictly prohibited. The operators of these pages expressly reserve the right to take legal action in the event of the transmission of unsolicited advertising, such as spam.

2. Use of IP address, browser settings and geolocation

When you visit the Convyo website, we record your computer’s IP address and browser settings. The IP address is a numerical identifier of the computer used to access the website. Browser settings may include information about the type of browser you are using, the browser language, and the time zone. We collect this information so that we can trace the computer in cases of abuse or unlawful activity related to accessing or using our website or services. We also use the IP address to determine your approximate location (at the city level) to identify which conditions apply to your use of our website or services. The legal basis for this processing is Article 6(1)(b) of the GDPR. The information stored in the log files does not allow any direct inference about your identity – in particular, IP addresses are stored only in an abbreviated, anonymized form. Log files are retained for 30 days and archived after further anonymization.

3. Newsletters and Notification Emails

Convyo's Customers
We collect data from our customers who wish to receive our newsletter or receive notifications regarding their account, such as invoice delivery. If you no longer wish to use these services, you can log in to your customer account to update your settings or contact us at: compliance@certishopping.com

b. Our customers' end customers
Our customers are responsible for ensuring compliance with applicable data protection laws (GDPR). The company is also solely responsible for:

  • how end users are contacted and informed about the opportunity to leave reviews and star ratings, as well as obtaining their necessary consent for approval.
  • Assessing compliance with the legal framework for advertising (including the type of advertising) of the company’s products and/or services, particularly in accordance with competition and advertising laws.
  • De l’évaluation des exigences dans le cadre des lois sur la concurrence, la protection des données personnelles et autres lois applicables et d’obtenir le consentement nécessaire de la part des utilisateurs finaux.
    Convyo accepts no liability for any damages resulting from the breach of the obligations described above.

 

4. Types and purpose of data processing

The type of personal data and the purpose of processing personal data by the processor are defined by the main contract established with our client. This includes the following categories of activities:
a. Collection of Reviews
b. Review Moderation
c. Marketing Services (including SEO optimization) and Reputation Management (including the provision of certificate pages, seals, and awards)
d. Data Collection; Analysis and Processing of Data Collected as Part of the Service For more information about the categories used, please contact our client/service provider directly. In accordance with information requirements, Convyo provides information to authorized individuals. Please send your request to: info@certishopping.com

5. Categories of Data Subjects

The categories of data subjects are defined by Convyo’s Terms and Conditions with our clients and may include the following categories:
a. Customer
b. Interested party
c. End customer
d. Employees who have been contacted on behalf of our customers to submit opinions
e. e. Interested parties, end customers or employees of our customers, who provide data to submit reviews
Pour plus d’informations sur les catégories utilisées, veuillez demander directement à notre client / fournisseur de services. Dans le cadre des exigences d’information, Convyo fournit des informations aux personnes autorisées.

6. Types of Personal Data

The types of personal data are defined by Convyo’s Terms of Use with our clients and may include the following data: a. Personal data (name, title, academic degree, date of birth) b. Contact details (email address, phone number, address) c. Contract data (contract details, services, customer number) d. Employment data e. Photos f. Videos g. Electronic communication data (IP address, visited web pages, details of the device used, operating system, and browser) h. Personal details (height, hair color, etc.) For more information about the personal data transmitted, please contact our client/your service provider directly. In accordance with information requirements, Convyo provides information to authorized individuals. Please send your request to: compliance@certishopping.com

7. Data Retention and Deletion

Personal data mentioned in a review are anonymized by the Convyo moderation team in accordance with Convyo’s publishing rules. After this anonymization, personal data can only be accessed by system administrators and the head of the Convyo moderation team, and will be deleted from Convyo’s systems when the primary client’s contract with Convyo is terminated.
Personal data provided by the data subject during customer interactions will be deleted by Convyo from Convyo’s systems upon the termination of the primary client’s account contract.
Personal data submitted by data subjects to the processor in the context of a complaint or review request will be erased by Convyo at the conclusion of the matter, and Convyo will remove this data from Convyo’s systems.
After the termination of the primary client’s contract, Convyo is obligated to provide the client with all personal data, documents, and processing results generated within the scope of the contractual relationship, while ensuring data protection and security in accordance with the client’s instructions. This applies to all data backups held by Convyo. This does not apply to data generated in connection with a third-party service ordered by the client (such as the Google feed); such data will be deleted in accordance with the third-party service provider’s guidelines. Even data that has become the property of Convyo under the client’s primary contract will not be deleted after the contract ends, but will be retained in compliance with applicable data protection regulations.

7.1 Nature of Personal Data Collected

1.1 For Businesses

Your Contact Information: first name, last name, email address, and any other contact details you may provide; Login and Account Data: username and password (for users with an account). Payment Data: credit card information or other payment methods (these data are securely handled and often managed by a third-party provider); Transaction History Customer Service-Specific Data: your clients and order-related information.

1.2 For Consumers

Personal data refers to any information relating to an identifiable individual.
Convyo may collect and process the following personal data :
Your Contact Information : first name, last name, email address, and any other contact details you may provide.
Your Submitted Reviews : the content of your review, the rating(s), which may include a merchant review, product review, and any associated photos and/or videos.
Dates : the date of your order, the date you submitted your review, and, if applicable, the date of any modifications.
Order Information : the names and references of the products you ordered.

7.2 Data Deletion Requests

If you wish to request the deletion of your personal data, please follow these steps :

a- Contact Us :

You can submit a data deletion request by contacting us directly. Please send an email to support@certishopping.com with the subject line « Data Deletion Request ».

b- Required Information :

To process your request, please include the following information :

  • Your full name
  • Your account information or order number, if applicable
  • The email address associated with your account

c- Verification Process :

For security reasons, we may need to verify your identity before processing the deletion request. We will inform you if any additional information is required to complete this verification.

d- Processing Time :

Once your identity has been verified, we will begin processing your deletion request. Please allow up to 30 days for the deletion to be completed. We will confirm via email once your data has been deleted.

e- Exceptions to Deletion :

Please note that certain information may be retained when permitted or required by law, for example, for tax or legal compliance purposes.

 

8. Information About Children

Our website is not intended for children. If you become aware that a child under the age of 13 has provided us with their personal information, please contact us.

9. Data Processor and Transfer of Personal Data Outside the EU

We use external companies for the technical maintenance of the website and our services. These companies act as data processors for which we are the data controller. By accepting this policy, you also consent to us processing data for which you are the data controller using the same processor.
We have data processing agreements with these processors, and they have declared that they are only authorized to act in accordance with our instructions. By accepting this Policy, you authorize us to provide the Processor with instructions for data processing in accordance with this Policy and for the purposes of the Website.
The processors have implemented reasonable technical and organizational measures to ensure that information is not destroyed, lost, damaged, disclosed, or unlawfully accessed or used by any unauthorized person in violation of data protection laws.
Upon your request—and possibly for a fee at the processor’s then-applicable hourly rate—the processor must provide you with information sufficiently demonstrating that the above-mentioned technical and organizational security measures have been properly implemented.
Some of these processors and third-party service providers are located outside the European Union, such as in the United States. You authorize us to use processors in third countries, provided that a legal framework governs the transfer of your personal data and ensures adequate protection of such data, for example, if the processor is part of the EU–US Privacy Shield.

10. Data Protection Officer

In accordance with the GDPR, Convyo confirms that a Data Protection Officer (DPO) is appointed to oversee compliance with data protection and data security regulations involving the data controller. The current Data Protection Officer is :
Imene Abbes
32 Bd de Strasbourg
75010 Paris
T: +33 (0) 9 74 59 54 73 │ P: +33 (0) 6 14 92 53 42
compliance@certishoppping.com
We have data processing agreements with these processors, and they have declared that they are only authorized to act in accordance with our instructions. By accepting this Policy, you authorize us to provide the Processor with instructions for data processing in accordance with this Policy and for the purposes of the Website.
The processors have implemented reasonable technical and organizational measures to ensure that information is not destroyed, lost, damaged, disclosed, or unlawfully accessed or used by any unauthorized person in violation of data protection laws.
Upon your request—and possibly for a fee at the processor’s then-applicable hourly rate—the processor must provide you with information sufficiently demonstrating that the above-mentioned technical and organizational security measures have been properly implemented.
Some of these processors and third-party service providers are located outside the European Union, such as in the United States. You authorize us to use processors in third countries, provided that a legal framework governs the transfer of your personal data and ensures adequate protection of such data, for example, if the processor is part of the EU–US Privacy Shield.

11. Use of Cookies

To make your visit to our website more engaging and to enable the use of certain features, we use cookies on various pages. These are small text files stored on your device that, through your browser, retain certain settings and data used to interact with our system.
Some of the cookies we use are deleted at the end of your browsing session, meaning when you close your browser. Other cookies remain on your device and allow us to recognize your browser during your next visit.
Cookies do not contain personal data and therefore cannot be directly linked to a user. Please note that some cookies are automatically placed as soon as you access our website. You can configure your browser to be notified about cookie settings and to allow cookies only in specific cases or to block cookies in certain cases or entirely. Please note that not accepting cookies may limit the functionality of our website.
Below is information about the cookies we use and the options for configuring your browser.

11.1 Necessary Cookies

These cookies are essential for the proper functioning of our website. They include, for example, cookies that allow you to log in to your customer account or add items to your shopping cart. The legal basis is Article 6(1)(b) of the GDPR.

11.2 Analytics/Performance Cookies

These cookies allow the collection of anonymized data regarding the behavior of users on our website. The data is then analyzed by us, for example, to improve website functionality and provide you with relevant offers. The legal basis is Article 6(1)(f) of the GDPR, based on our legitimate interest in user-centered design and the continuous optimization of our website.

11.3 Functional Cookies

These cookies are used for certain features of our website, for example, to provide a smoother navigation experience on our site and to display personalized and relevant information. The legal basis is Article 6(1)(f) of the GDPR, based on our legitimate interest in user-centered design and the continuous optimization of our website.
Cookie settings can be configured individually in different browsers.
Each browser (e.g., Internet Explorer™, Chrome™, Firefox™, Safari™, or Opera™) handles cookie settings differently. A description in the help menu of each browser explains how you can modify your cookie settings.

11.4 Google DoubleClick Cookie

As part of the Google Analytics application (see below), this website also uses the DoubleClick cookie, which allows your browser to be recognized when you visit other websites. The information generated by the cookie regarding your use of this website is transferred to a Google server in the United States and stored there. Due to IP anonymization enabled on this website, the IP address will be truncated before being transmitted to member states of the European Union or other states party to the European Economic Area agreement. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and shortened there. The anonymized IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. Google uses this information to compile reports on website activity and to provide other services related to website usage. Google may also transfer this information to third parties if required by law or if third parties process these data on behalf of Google. You can disable the use of cookies by Google by adjusting the relevant settings on Google’s website. Users can also disable the use of cookies by third-party providers by visiting the Network Advertising Initiative opt-out page. You may also refuse the installation of cookies by selecting the appropriate settings in your browser; however, please note that if you do so, you may not be able to use all the features of this website.

11.5. Google Tag Manager

We also use Google Tag Manager to manage usage-based advertising services. The Tag Manager tool is a cookie-free domain that does not store any personal data. The tool triggers other tags that may potentially collect data (see above). If you have disabled tracking at the domain or cookie level, this applies to all tracking tags implemented with Google Tag Manager.

11.6. Storage of Personal Data

We store all data you provide to us in the context of a demo request (even if canceled) and if you wish to subscribe to and/or use our services. For example, when purchasing and/or using our services or buying our products, you may provide your name, address, email address, and phone number. If you subscribe to our services, our newsletter, purchase and/or use our services, or use customer service or technical support, you may be required to complete a form requesting personal information such as your name, address, email address, and phone number. This information will be stored in our database.

11.7. Facebook Retargeting

Our website uses social plugins from the social network facebook.com, which is operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA. The plugins are identified by a Facebook logo or the label “Facebook Social Plugin.” If you visit a page on our website that contains such a plugin, your browser establishes a direct connection to Facebook’s servers. The content of the plugin is transmitted directly by Facebook to your browser and embedded on the website. By integrating the plugins, Facebook receives information that you have accessed the corresponding page on our site. If you are logged into Facebook, Facebook may associate the visit with your Facebook account. If you interact with the plugins, for example by clicking the “Like” button or leaving a comment, the corresponding information is transmitted directly from your browser to Facebook, where it is stored. For more information about the purpose and scope of data collection and the subsequent processing and use of data by Facebook, as well as your related rights and privacy settings options, please refer to Facebook’s privacy policy. If you do not want Facebook to collect data about you via our website, you must log out of Facebook before visiting our site. We have no control over the extent of the data that Facebook collects using this plugin and inform our users accordingly to the best of our knowledge. The purpose and scope of data collection, the subsequent processing and use of data by Facebook, as well as rights and privacy settings, can be found in Facebook’s Privacy Policy: https://www.facebook.com/about/privacy/

11.8. Use of Google Analytics as a Web Analytics Tool

This website uses Google Analytics, a web analytics service provided by Google Inc. (www.google.com ). This analytics tool uses cookies to analyze website usage. The information generated by the cookies regarding the use of this website is generally transferred to a server in the United States and stored there. No adequacy decision covering the United States has been issued by the European Commission under Article 45(1) of the GDPR. However, Google Inc. is certified under the EU–US Privacy Shield, meaning that the transfer is permitted under Article 46(2)(f) of the GDPR (Commission Implementing Decision (EU) 2016/1250 of 12 July 2016). Due to IP anonymization enabled on this website, Google Analytics truncates the IP address before transmission to EU member states or other states party to the European Economic Area agreement. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and shortened there. The anonymized IP address transmitted by your browser as part of Google Analytics will not be merged with other Google data. Google uses this information on behalf of the website operator to evaluate website usage, compile reports on website activity, and provide other services related to website and Internet usage. You can refuse the use of cookies by selecting the appropriate settings in your browser; however, please note that doing so may limit your ability to use all features of this website. You can also prevent the transmission to Google of the data generated by the cookie regarding your use of the website (including your IP address) and the processing of this data by Google by downloading and installing the browser plugin available at: http://tools.google.com/dlpage/gaoptout?hl=en As an alternative to the browser plugin, you can click this link to prevent Google Analytics from collecting data on this website in the future. A non-participation cookie will then be installed on your device. If you delete your cookies, you will need to click the link again.

11.9. Submitting a Contact Request

Your personal data is collected if you voluntarily provide it when making a contact request or registering for our services. We use your data exclusively to provide you with the requested information or services, meaning that only the information and data strictly necessary to respond to your request or process the contractual relationship will be stored and processed. The legal basis is Article 6(1)(b) of the GDPR. Data collected by us through the use of the contact form will be automatically deleted after your request has been fully processed, unless we still need your data to fulfill contractual or legal obligations.

11.10. Zendesk Live Chat Tool

If you use the live chat tool to contact us, the data you voluntarily provide (name, email address, message) will be stored by our service provider Zendesk and processed exclusively by us for the purpose of responding to your request, after which it will be deleted. Zendesk Inc. is self-certified under the EU–US Privacy Shield. For more information, please visit: https://www.zendesk.fr/company/customers-partners/privacy-policy/ Any other use of the data entered by Zendesk is excluded.

12. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy. If we make significant changes to this policy, we will indicate them on our website or, otherwise, notify you in a manner that allows you to review the changes before they take effect.

13. Further Disclosures

In addition, we may disclose your personal information to the following parties under the following conditions :
a. Third Parties: i.e., contractors, consultants, and other service providers, to enable them to provide services on our behalf.
b. Convyo Subsidiaries and Other Companies within the Convyo Group.
c. To ensure compliance with applicable laws and to respond to lawsuits and legal actions (including, but not limited to, court subpoenas or orders) or requests from public and governmental authorities.
d. To cooperate on investigations or complaints with regulators and government agencies, including the Directorate-General for Competition, Consumer Affairs, and Fraud Control (DGCCRF).
e. Third parties in connection with the enforcement of our Terms of Use.
f. Third parties protecting our business or that of our employees.
g. Third parties enabling us to exercise any remedies and limit potential damages that could affect us.
h. Third parties to investigate alleged or confirmed inappropriate acts, such as fraud and abuse on our website, and to investigate, prevent, or take action against such acts.
i. Third parties in cases of restructuring, merger, acquisition, sale, joint venture, transfer, or any other sale of all or part of our business or assets (including in the context of bankruptcy or similar proceedings).

14. Data Retention Period

In principle, we retain personal data only for as long as necessary to fulfill the contractual or legal obligations for which the data was collected. Thereafter, we delete the data immediately, unless we need it until the expiration of the statutory limitation period for evidence in civil claims or for statutory storage requirements.
For evidentiary purposes, we must retain contractual information for three years from the end of the year in which the business relationship with you ends. Any claim becomes time-barred after the statutory limitation period, at the earliest, from that point.
Even after that, we may sometimes need to retain your data for accounting purposes. We are required to do so due to legal documentation obligations arising from the German Commercial Code, the Tax Code, the Banking Act, the Anti-Money Laundering Act, and the Securities Trading Act. The document retention periods range from two to ten years.

15. Right to Withdraw Consent and Object

In accordance with Article 7(2) of the GDPR, you have the right to withdraw consent at any time once it has been given. Consequently, we will no longer process data based on this consent going forward. The withdrawal of consent does not affect the legality of processing carried out based on the consent prior to its withdrawal.
Where we process your data based on legitimate interests in accordance with Article 6(1)(f) of the GDPR, you have the right, under Article 21 of the GDPR, to object to the processing of your data and to provide reasons arising from your specific situation which, in your view, justify your legitimate interests. If the objection relates to data processing for direct marketing purposes, you have a general right to object, which will be implemented without the need to provide reasons.
If you wish to exercise your right to withdraw consent or object, simply send an informal message to the contact details provided above.

16. Third-Party Terms of Use – Meta Platform

 

By using Convyo features that interact with the Meta platform, such as advertising, data analysis, or content sharing, you agree to comply with Meta’s Terms of Service and their Meta Developer Policies.

Consequences of Non-Compliance

In the event that a Convyo user fails to comply with Meta’s policies, we reserve the right to take the following measures to ensure compliance:

  • Temporary Suspension : A violation may result in a temporary suspension of your access to Convyo features connected to Meta.
  • Access Revocation : In the case of repeated or serious violations, your access to Meta features via Convyo may be permanently revoked.
  • Account Termination : Any attempt to circumvent restrictions imposed by Meta may also result in the termination of your Convyo account.

We encourage you to comply with all terms to avoid any suspension or loss of access to Convyo’s Meta features.

 

17. Advertising Feature

 

The advertising feature via Convyo allows you to quickly and easily create third-party advertising campaigns for Google, Facebook, and Instagram directly from your Convyo account (collectively referred to as « Social ads » ).

The advertising feature is an add-on to your Convyo account and will be billed. When creating an advertising campaign through this feature, you must select an advertising account for your campaign. The ads will then be published on Google or Facebook (including Instagram) according to the criteria you select via the advertising feature.

Convyo may refuse the service or limit, suspend, or terminate your access to the advertising feature at any time, with or without cause. You may stop using this feature at any time. The advertising feature allows you to create and manage Google, Facebook, and Instagram ads from your Convyo account. By using this feature, you also agree to comply with the advertising policies, terms of use, and commercial terms of Google and Facebook.

Google, Facebook, and Instagram are not affiliated with, partners of, agents of, or representatives of Convyo. You understand and agree that Convyo is an independent third party and has no right, responsibility, or ability to control, direct, or influence any action, inaction, conduct, or decision made by Google, Facebook, or Instagram.

en_USEnglish