Privacy policy
& cookies
This page describes the conditions under which the processing that Cegid and its sister entities (hereinafter included in the reference to Cegid) carries out on the personal data collected from natural persons (customers, prospects, etc.) is carried out.
If you have any questions about this policy, you can send us your request on [email protected]
Privacy Policy
Last updated: April 2026
Privacy policy
1. Introduction
The purpose of this policy is to present the rules relating to the protection of personal data, as data controller and data processor, that Cegid and its subsidiaries (hereinafter “Cegid”) undertake to comply with for all processing of personal data covered by this policy. These rules are in particular in application of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation, hereinafter “GDPR”) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
This document is subject to change, in particular when necessary to meet the obligations of the legislation on the protection of personal data. We therefore encourage you to visit our dedicated page regularly: https://www.cegid.com/fr/politique-de-confidentialite/
The concepts concerning the protection of personal data used in this document have the same meaning as that given by the GDPR.
2. Compliance with the general principles on the protection of personal data
When Cegid acts as a data controller
Cegid guarantees that personal data is:
- processed in a lawful, fair and transparent manner;
- collected for specified, explicit and legitimate purposes, and are not further processed in a manner incompatible with those purposes;
- adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed;
- accurate and, if necessary, kept up to date;
- kept for a period not exceeding that necessary in relation to the purposes for which they are processed;
- processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures appropriate to the risks.
When Cegid acts as a data processor
Cegid guarantees that it complies with the obligations signed in the data processing agreement.
3. Purpose and legal bases for the processing of personal data
For its internal purposes, Cegid collects personal data for the purposes of:
- management of customer and prospect contacts (sending marketing information, information on products or Group news, in-depth and responding to the needs of customers or prospects, producing statistics, etc.);
- management of its commercial contracts (management of orders, invoicing, collection, etc.);
- management of Cegid personnel, recruitment and careers (examining and contacting candidates, etc.);
- create and administer user accounts;
- To carry out and manage the services subscribed to by its customers (e.g. ticket management and recording of support calls).
Depending on these different purposes, Cegid ensures that one of the following conditions is met:
- the consent of the natural person has been collected for one or more specific purposes;
- the processing is necessary for the performance of a contract to which a natural person is a party or for the performance of pre-contractual measures taken at the request of that natural person;
- the processing is necessary for compliance with a legal obligation to which Cegid is subject;
- the processing is necessary for the purposes of the legitimate interests pursued by Cegid, unless the interests or fundamental rights and freedoms of the natural person concerned prevail.
The purposes not detailed in this section are detailed in the dedicated information presented to the data subjects when the personal data is collected.
4. Security and Data Breach Notification
Cegid implements appropriate technical and organisational measures to guarantee a level of security adapted to the risks.
Cegid has certifications (including ISO 27001) for its Information Security Management System for the delivery of a service allowing the hosting of applications containing data provided by customers in a Cloud environment.
Within their respective scopes, these certifications guarantee the implementation of a certified security policy applied to Cegid’s processes and workflows throughout the life of the SaaS service delivered to the customer.
More generally, Cegid’s employees are subject to an IT charter annexed to the internal regulations to ensure an appropriate level of security.
Pursuant to Articles 33 and 34 of the GDPR, any data breach will be notified:
- when Cegid acts as data controller, to the French supervisory authority (CNIL) and, if necessary, to the natural persons affected by the said breach;
- when Cegid acts as a data processor, to its customers affected by such breach of the terms of the contract between Cegid and its customers.
5. Rights of individuals
When Cegid acts as a data controller
Under the conditions of Articles 15 and 22 of the GDPR, natural persons have the right to:
- access the personal data concerning them and processed by Cegid;
- request the rectification, erasure or limitation of the processing of their personal data carried out by Cegid;
- under certain conditions, object to the processing of their personal data;
- request the portability of personal data;
- where consent is the legal basis for processing, withdraw consent;
- define directives relating to the fate of their personal data in the event of death (in application of Law No. 78-17 of 6 January 1978 relating to information technology, files and freedoms).
Requests related to these rights can be made by completing the form available on the following page: https://www.cegid.com/fr/privacy-policy/
Cegid reserves the right to request clarification on any request and to justify the identity of the requester.
An unsubscribe method is also available in our email marketing communications.
In any case, Cegid recommends contacting the CNIL to find out more about the regulations relating to the protection of personal data, the rights of natural persons and the possibility of filing a complaint with this authority: https://www.cnil.fr/
When Cegid acts as a data processor
In the event that Cegid receives a request from a natural person concerned by the processing of his or her personal data in the context of the performance of the contract between Cegid and its client, Cegid will communicate this request to its client as soon as possible from its receipt and, taking into account the nature of the processing and under the conditions established in the contract, will assist its client, by appropriate technical and organisational measures, to the greatest extent possible, to fulfil its obligation to comply with these requests.
The customer remains responsible for the response to be given to the natural person concerned.
6. Information for natural persons
When Cegid acts as a data controller
Cegid undertakes to provide the natural persons concerned with at least the following information, as far as possible and regardless of the processing carried out:
- the contact details of the data controller and its Data Protection Officer;
- the purposes of the processing and its legal basis;
- the recipients;
- transfers outside the EU if applicable;
- the retention period;
- the possibility of requesting the exercise of the rights that may be exercised under the applicable regulations;
- the right to lodge a complaint with the supervisory authority (in particular the CNIL).
When Cegid acts as a data processor
The responsibility for informing natural persons lies with the data controller.
Under the conditions set out in the contract, Cegid provides its customers acting as data controller with all useful information to enable it to comply with this obligation.
7. Transfers outside the European Union
The data collected may be processed outside the European Union. Thus, in accordance with data protection legislation, Cegid is prohibited from transferring Personal Data, without putting in place the appropriate tools to supervise these transfers pursuant to Article 46 of the GDPR, except:
- of the European Union, or
- of the European Economic Area, or
- countries recognised as having an adequate level of security by the European Commission.
In particular, Cegid can call on its subsidiary Cegid Atlas in Morocco for processing related to:
– Recoveries,
– the technical means to ensure the support of its solutions,
– Feature development.
In the context of commercial relations, data transfers may also be made between Cegid France and its subsidiaries in Canada, the United States and China.
These transfers are based on the European Commission’s Standard Contractual Clauses.
8. The recipients of the data
Cegid may share personal data with third parties only under the conditions set out in this document and/or the applicable contract.
Service Provider
- Cegid may share personal data with third parties providing a service, in particular in the following cases:
- on behalf of Cegid in the context of the performance of the customer contract (hosting, consulting, sub processor, etc.) under the conditions set out therein;
- to support Cegid in the execution of the financial and administrative conditions of the contract (collection, invoicing, etc.);
- for the production of marketing communications on behalf of Cegid;
- for support in the development of new products or services
Distribution and/or sales partners
Cegid has developed a network of partners (distributors, publishers, etc.) for several of its offers to help it supply and develop its products.
Depending on the offer that interests the contact or is likely to be of interest to him, Cegid may be required to share the contact details of this contact with a relevant partner.
Cegid subsidiaries and stakeholders
Cegid may share personal data with the companies of the Cegid Group or its shareholders for the purposes mentioned in this policy.
Public authorities
In some cases, Cegid may be compelled to share personal data in the context of a request from a public authority, a subpoena or any legal request pursuant to applicable laws. In this case, Cegid will provide the data necessary to respond to this request, in particular when Cegid believes in good faith that such sharing is necessary to protect your rights, ensure your safety or that of others, investigate cases of fraud or meet a legal requirement.
To learn more about the recipients, contact us at [email protected].
9. Cegid’s cooperation with its customers and the supervisory authority
In accordance with Article 28 of the GDPR and in compliance with its contractual commitments, Cegid is committed to cooperating with its customers in order to help them meet their obligations.
In general, Cegid undertakes to cooperate with the French supervisory authority (CNIL) when necessary and to take into account its recommendations.
10. Privacy by design in products and services
When Cegid plans to develop a new service or a new offer, Cegid, in its capacity as publisher, introduces the principles of personal data protection (“privacy by design”) from the beginning of this project and thus helps Cegid’s customers to comply with the requirements of the applicable regulations through specific functionalities and means.
11. Raising awareness among Cegid staff
All new employees at Cegid must follow an awareness of the protection of personal data.
More generally, Cegid makes every effort to offer all its employees regular awareness of the challenges of personal data protection.
More specific awareness-raising or training can be carried out for employees who are required to handle personal data on a regular basis.
12. Governance of the protection of personal data
In order to manage the protection of personal data, Cegid has set up a dedicated governance system.
A Data Protection Officer, or Data Protection Officer (DPO) has been appointed to the CNIL. The latter manages this governance.
13. Processing records
Pursuant to Article 30 of the GDPR, Cegid maintains two registers of personal data processing:
- a register describing the processing carried out in its capacity as data controller;
- a register describing the processing carried out on behalf of and on the instructions of its customers responsible for processing.
These registers are made available to the CNIL on request.
14. Contractual Policy
Cegid has taken into account the new mandatory contractual obligations pursuant to Article 28 of the GDPR in all the contracts impacted. Thus, contractual clauses specific to data protection and in accordance with the applicable regulations have been introduced in:
- customer contracts (T&Cs/T&Cs);
- contracts between Cegid and its own processors.
15. Contact
If you have any questions about this policy or contact our Data Protection Officer, you can send your request to the following email address: [email protected]
Personal Data Collected in Connection with Your Commercial Relationship with Cegid
To provide the service you subscribe to and manage your commercial relationship, Cegid SAS, the data controller located at 52 Quai Paul Sedallian, 69009 Lyon (France), collects and processes the following personal data: name, first name, email address, telephone number, job title, organisation, and training undertaken.
This data is processed to manage your commercial relationship, deliver the service or product you subscribe to, and administer training programmes (including those delivered by Cegid Academy). We may also use this data to send surveys, conduct satisfaction studies, or compile statistics.
For these purposes, Cegid may receive data collected by other companies within the Cegid group.
Unless otherwise required by law, personal data collected for these purposes is retained for a maximum of five years following the end of your commercial relationship. Satisfaction survey responses are retained for a maximum of four rolling years.
Cegid may share certain of your data with Cegid group companies, third-party organisations, or partners to:
- Conduct data collection operationsVerify the quality of contact information provided
- Assess the effectiveness of social media campaigns (LinkedIn)
- Conduct solvency checks and fulfil due diligence obligations
- Execute commercial communications
- Facilitate contact and commercial follow-up
- For details on these partners, contact [email protected] .
Cegid or our partners may also send you commercial communications. These are sent based on legitimate business interests to share communications relevant to your professional role, or with your consent where required. You may opt out at any time by clicking the unsubscribe link included in all communications.
Personal data collected for commercial communications is retained for a maximum of three years following the end of your commercial relationship or your last communication with us.
You may exercise your data rights by completing the “Individual Rights Request” form below, in accordance with this privacy policy.
Personal Data Collected Through Cegid.com Forms or Obtained from Third-Party Sources
Cegid SAS, the data controller located at 52 Quai Paul Sedallian, 69009 Lyon (France), may collect the following personal data: name, first name, email address, telephone number, job title, and organisation. This data may be collected through online forms or from third-party sources to respond to your enquiry, manage our customer and prospect database, deliver commercial communications, and compile statistics. These purposes are pursued based on Cegid’s legitimate business interests or your consent where required by applicable law.
You may opt out or withdraw your consent to commercial communications at any time by clicking the unsubscribe link included in all communications.
Personal data collected for these purposes will be deleted after three years if you no longer express interest in Cegid’s products or services, including if you do not respond to emails received.
Cegid SAS subsidiaries and our partners may receive the same personal data for the purposes described above. Partners may include distributors of Cegid offerings relevant to your business.
Cegid SAS, its subsidiaries, and its partners will only transfer this data to countries outside the European Economic Area where necessary to fulfil these purposes. In all cases, Cegid implements appropriate safeguards to oversee these transfers.
You may exercise your data rights by completing the “Individual Rights Request” form below, in accordance with this privacy policy.
Personal Data Processed When Using Guest Network (Guest Wi-Fi)
By connecting to the guest network at Cegid facilities, you consent to Cegid SAS processing your information to provide internet access. To this end, Cegid may collect connection information such as your IP address or device identity (for further information, see article R10-13 of the CPCE).
The legal bases for processing are as follows:
- For service delivery: your consent
- For traffic data retention: legal obligation under article 34-1 of the CPCE
Your data may be shared with Cegid group entities and external service providers responsible for processing implementation, or with third parties as required by competent authorities.
Your personal data is retained for a maximum of one year from the date of collection.
You may exercise your data rights by completing the “Individual Rights Request” form below, in accordance with this privacy policy.
Personal Data Collected in Connection with Cegid SaaS Offerings and Customer Portals
To deliver the service you subscribe to, Cegid SAS, the data controller located at 52 Quai Paul Sedallian, 69009 Lyon (France), collects and processes the following personal data: name, first name, email address, telephone number, job title, organisation, usage data relating to solution utilisation (activity logs), and data you enter into the system.
Unless expressly excluded by your service agreement, this personal data may be processed in Cegid’s legitimate business interest for the following purposes:
- Maintain traceability of actions on the SaaS platform and data
- Compile statistics
- Analyse individual or aggregated data to better understand product usage and propose custom features or product improvements
- Secure the SaaS platform and your data
- Manage your contractual relationship
- Administer user accounts
- Send communications regarding Cegid offerings
Your data is not retained beyond the duration of service use. However, activity logs are retained for a maximum of one year from the date of collection.
You may exercise your data rights by completing the “Individual Rights Request” form below, in accordance with this privacy policy.
If you subscribe to a third-party product through a Cegid offering, the relevant business partners may process the same data. In such cases, data processing terms are defined by that partner.
Data processing practices related to Cegid Account are detailed on the service portal.
Personal Data Collected and Processed for Customer Support Purposes
When you interact with Cegid Customer Care, Cegid SAS, the data controller located at 52 Quai Paul Sedallian, 69009 Lyon (France), collects and processes the following personal data: name, first name, email address, telephone number, job title, organisation, and content of your interactions. Cegid may also listen to and/or record calls between you and our support operator.
This data is processed for the following purposes:
- Manage and resolve support tickets
- Evaluate customer satisfaction
- Assess the quality of telephone interactions between you and our operator. Recordings are retained for a maximum of 6 months; analysis reports may be retained for one year
- Preserve evidence in case of dispute. Data is retained for 5 years in such cases
If we listen to and/or record your call, you will be informed in advance.
You may exercise your data rights in accordance with this privacy policy, specifically:
- If you wish to object to the listening to and/or recording of your call, you may inform the operator during the call. To exercise this right after the call ends, you may complete the “Individual Rights Request” form below
- For other rights, including the right of access, you may submit a request by completing the “Individual Rights Request” form below
In Cegid’s legitimate business interest, a satisfaction survey may be sent to you after your support request is resolved to evaluate the service provided.
When an AI-assisted solution is used to process support requests, your data may be processed by a Cegid partner specialising in artificial intelligence.
Cegid SAS and its subsidiaries will only transfer your data to countries outside the European Economic Area where necessary to fulfil these purposes. Data transfers outside the European Union, including to Cegid Atlas in Morocco, are governed by the European Commission’s standard contractual clauses.
You may exercise your data rights by completing the “Individual Rights Request” form below, in accordance with this privacy policy.
Personal Data Processed in Connection with Invoice & Financing Services and Related Services
Cegid SAS processes personal data in connection with:
- Execution and management of financing agreements
- Solvency analysis of individuals using these services
The categories of personal data processed are:
- Identification data
- Financial data
This information may be obtained from professional data providers.
Your data may be shared with Cegid SAS and its subsidiaries, as well as external service providers responsible for processing implementation, or with third parties as required by competent authorities.
Your personal data is retained for the following periods:
- Data required for financing agreement management: 10 years from the definitive closure of the agreement
- Data necessary for solvency analysis: 10 rolling years from the definitive closure of the agreement
Your personal data may be transferred to countries outside the European Union for the purposes described above. These transfers are subject to a specific legal framework to ensure your data receives adequate protection.
Product Enhancement and Artificial Intelligence
Cegid, as the data controller, and in accordance with its legal and contractual obligations, may use data generated through use of its products, websites, and/or services to improve its offerings or create new features, including those related to artificial intelligence technologies.
This processing is carried out based on Cegid’s legitimate business interests as a service provider. The data processed is limited to what is available within the relevant product or service, in accordance with data minimisation principles. Data is not shared with third parties outside Cegid group subsidiaries, stakeholders, or service providers.
Data retention periods are determined on a case-by-case basis in accordance with data retention limitation principles. Unless otherwise specified, queries may be retained for a maximum of three months. If retained longer, they are anonymised. For specific questions about retention periods, contact Cegid’s Data Protection Officer through the rights exercise form.
Regarding artificial intelligence technologies, Cegid uses leading market models and/or proprietary models. When using market models, Cegid ensures implementation respects individual rights.
You have the right to access, rectify, erase, restrict, and object to processing of your data. Cegid may request additional information to identify you where the system does not collect directly identifying data.
For further information and to exercise your rights, contact Cegid’s Data Protection Officer at [email protected]
Personal Data Processed by Cegid in Connection with Intra-Group Relations with EBP
Cegid SAS and its subsidiary EBP process data as joint controllers, including for purposes of workforce management, customer relations, user account administration, and development of new products or services.
A joint processing agreement has been executed between these two entities to define their respective roles and their relationships with data subjects.
For any enquiries concerning the principal terms of this agreement or to exercise your rights, contact Cegid’s Data Protection Officer at [email protected].
Cookie Management
Trackers are placed when you visit cegid.com.
When you arrive at the site for the first time, a banner offers you the option to accept, decline, or configure (or “customise your preferences for”) cookies placed on your browser according to their category.
You may modify your preferences by clicking the “Cookies” button in the bottom left corner of your screen.
Information on tracker categories is available by clicking the “Cookie Settings” button in the banner, along with details of relevant third-party providers.
Cookies have a maximum lifespan of 13 months, and data collected by cookies is retained for a maximum of 25 months.
Personal rights
In accordance with Regulation (EU) 2016/679 of 27 April 2016 (‘GDPR’), you have the right of access, rectification, erasure (or ‘right to be forgotten’), data portability and objection in relation to the processing of your personal data carried out by Cegid.
You can submit your request by completing the form below.
You also have the right to lodge a complaint with the CNIL.
Form for Exercising Individual Rights
Pursuant to Regulation (EU) 2016/679 on the protection of personal data (“GDPR”)