Personal data protection policy

Updated: 26 September 2025

This English translation is provided for convenience only. In case of discrepancy, the French version prevails.

The protection of the personal data of the Site's Users is essential and is based on transparency, in accordance with applicable legislation (the French Data Protection Act and the GDPR).

This policy details:

  • The categories of data collected
  • Their use and purpose
  • The recipients
  • Your rights

1. Data controller

The data is processed by TRIPTIC SAS, R.C.S. Nanterre no. 889 274 510, 57 rue Raspail, 92300 Levallois-Perret, acting as data controller. Data may be collected directly or via third parties, and only the data necessary for the stated purposes is collected.

2. Data collected

TRIPTIC processes the following categories of data:

  • Identification data: gender, title, last name, first name
  • Contact data: email, phone number
  • Connection data: IP address, usage logs
  • Content of messages sent by the user
  • Indirect data via cookies and trackers: browsing, internal analytics, Site improvement

Mandatory fields are necessary to use the services. Failure to provide them prevents access to these services.

3. Purposes of processing

a) Performance of a contract

  • Account management
  • Sending digital greeting cards
  • Technical and commercial support
  • Management of individuals' rights
  • Provision and operation of the Site's services

b) TRIPTIC's legitimate interests

  • Development and enrichment of the client/prospect database
  • Personalized recommendations based on usage analysis
  • Commercial prospecting: emailing, SMS, referrals
  • Responding to Users' questions
  • Responses to requests to exercise rights
  • Management of the GDPR rights-exercise list

4. Data recipients

The data may be accessed by:

  • Authorized personnel: marketing, sales, customer relations, administrative, logistics, IT
  • Audit services: statutory auditor, internal procedures
  • Partner BREVO for sending digital cards
  • Partner OVH for server hosting
  • The Data Protection Officer (DPO)

Confidentiality: data is not disclosed to third parties without authorization.

Transfers outside the EU: carried out in compliance with the GDPR with appropriate safeguards.

5. Data subjects

Information is collected from:

  • Users of the Site
  • Recipients of digital cards
  • Visitors and readers

Account holders must regularly verify the accuracy of their data.

6. Retention period

  • Browsing data: for as long as necessary for the stated purposes
  • Client employees: for the duration of the business relationship
  • Prospects: 3 years after collection or last contact
  • Digital card recipients: from early December until the following 31 March
  • GDPR rights: an additional 3 years

7. Data security

Measures in place:

  • Encryption
  • Access rights management
  • Secure data flows
  • Compliance by employees and service providers

8. Cookies and trackers

Cookies may be stored while browsing. See our cookie policy.

9. Users' rights

You have the following rights:

  • Access and rectification
  • Objection to or restriction of processing
  • Erasure under certain conditions
  • Right to data portability
  • Withdrawal of consent at any time
  • Lodging a complaint with the CNIL (the French data protection authority)

To exercise your rights: https://www.evercard.digital/contact Response within 1 month.

In case of disagreement: CNIL 3 place de Fontenoy TSA 80715 75334 Paris cedex 07 France

Copyright © Evercard - Todos los derechos reservados