Personal data protection policy

Updated: 7 September 2026

This English translation is provided for convenience only. In case of discrepancy, the French version prevails.

The protection of the personal data of people who use the site www.evercard.digital (the "Site") and the Evercard greeting card platforms (the "Platform") is based on transparency, in accordance with the French Data Protection Act and the General Data Protection Regulation (GDPR).

This policy sets out:

  • EVERSIDE's role depending on the data concerned;
  • the categories of data collected;
  • their use and purposes;
  • their recipients;
  • their retention period;
  • your rights.

1. EVERSIDE's roles

EVERSIDE SAS, Nanterre Trade Register no. 523 916 104, 57 rue Raspail, 92300 Levallois-Perret, France, publishes the Site and the Platform. It acts in two capacities.

a) Data controller

EVERSIDE is the data controller for:

  • visitors of the Site;
  • people who fill in a form on the Site: contact, demo request, trial request, quote request, partner or ambassador programme;
  • employees of client companies who hold an account on the Platform, for the data of that account and its use.

b) Data processor

For the recipients of greeting cards and for all data that client companies import or enter on their Platform (contacts, messages, replies), the client company is the data controller. EVERSIDE acts as a processor, under the Terms of Sale and the data processing agreement concluded with the client. Requests to exercise rights over this data must be addressed to the client company; EVERSIDE forwards those it receives.

2. Data collected

On the Site

  • Contact data: company, first name, last name, phone, email address, message, entered in the forms;
  • Connection data: IP address, technical logs.

On the Platform, for employees

  • Identification data: title, first name, last name, work email address, profile picture if you add one;
  • Organisation data: company, entity, role (employee or administrator);
  • Connection data: IP address, browser, technical logs, sign-in method (email link, Google account or corporate directory);
  • Content produced: card subjects and messages, published greeting pages;
  • Messages sent to support through the built-in chat, with the IP address and browser used at the time, which help understand an issue.

On the Platform, for card recipients (client companies' data)

  • Identification and contact data: email address, first and last name when provided;
  • Sending data: status of each sending (delivered, opened, clicked, bounced), reported by our email provider;
  • Replies: the content of replies sent to the employee from the card or from a greeting page, with the name and email address the recipient chooses to give;
  • Greeting page views: number of views and the network the link came from, without identifying the person.

Google and Microsoft 365 address books: when an employee imports recipients from their Google or Microsoft contacts, EVERSIDE reads the address book at import time, displays the contacts for them to choose from, and only stores the recipients selected for the sending. The address book itself is never kept.

Mandatory fields are required to use the services. Not answering prevents access to those services.

3. Purposes of processing

a) Performance of a contract or pre-contractual measures

  • Answering requests made from the Site;
  • Managing employees' accounts;
  • Preparing, sending and tracking greeting cards;
  • Publishing greeting pages;
  • Technical and commercial support;
  • Providing and operating the services.

b) EVERSIDE's legitimate interests

  • Security of the Platform and prevention of abuse;
  • Managing the commercial relationship with client companies and prospects;
  • Commercial prospecting of professionals, by email;
  • Improving the service.
  • Answering requests to exercise rights;
  • Keeping accounting records.

4. Public greeting pages

An employee may publish a greeting page accessible by a link, which they share on social networks or by email. This page shows the employee's name, their profile picture if they added one, the name of their company or entity, and the message they wrote. It is visible to anyone who has the link, as long as the employee keeps it online. They can take it offline or delete it at any time.

5. Data recipients and processors

The data may be accessed by EVERSIDE's authorised staff (customer relations, support, administration, IT) and, where applicable, by its audit services.

EVERSIDE uses the following processors:

ProcessorRoleData location
OVHServer hosting, storage of card images and videos, backupsFrance
BrevoEmail sending and delivery status reportingEuropean Union
CloudflareProtection and routing of traffic to the PlatformEuropean Union, with possible transfers outside the EU governed by standard contractual clauses
GoogleGoogle account sign-in and Google contacts reading, only if the employee chooses these services; font loadingUnited States, transfer governed by the EU-US Data Privacy Framework and standard contractual clauses
MicrosoftMicrosoft 365 contacts reading, only if the employee chooses this serviceUnited States, transfer governed by the EU-US Data Privacy Framework and standard contractual clauses

Data is not disclosed to other third parties without your authorisation or a legal obligation.

6. Data subjects

Information is collected from:

  • visitors of the Site and people who fill in a form there;
  • employees of client companies;
  • greeting card recipients, through client companies.

Account holders are invited to check the accuracy of their data regularly.

7. Retention period

  • Browsing data and technical logs: as long as needed for the security of the service, one year at most;
  • Requests made from the Site and prospects: three years after collection or last contact;
  • Employee accounts: until deleted by the client company, or at the employee's request;
  • Card recipients and sending data: until the end-of-season purge, carried out after the client company's greeting season closes, or earlier at its request;
  • Recipients' replies: same period as recipients;
  • Messages sent to support: two years after the request is closed;
  • Records relating to the exercise of rights: three additional years;
  • Accounting records: ten years.

8. Data security

Measures in place:

  • encryption of exchanges and backups;
  • access rights management and logging;
  • secured flows with processors;
  • confidentiality commitments of employees and providers.

9. Cookies and trackers

Strictly necessary cookies may be saved while browsing. See our cookie policy.

10. Your rights

You have the following rights:

  • access and rectification;
  • objection to or restriction of processing;
  • erasure, under conditions;
  • portability;
  • withdrawal of consent at any time, where processing relies on it;
  • setting directives regarding the fate of your data after your death.

To exercise them with EVERSIDE: https://www.evercard.digital/contact. A copy of an identity document may be requested. Reply within one month.

For data processed on behalf of a client company (greeting card recipients), contact that company first; EVERSIDE forwards any request it receives.

In case of disagreement, you may contact the CNIL: 3 place de Fontenoy, TSA 80715, 75334 Paris cedex 07, France.