GDPR Statement

For the purposes of this document SERVICE means Icypeas. WE means the company providing the SERVICE as per point 12.

Icypeas's core application infrastructure and databases are hosted within the European Economic Area (EEA), including with OVHcloud and Scaleway in France.

Certain personal data may also be processed by third-party service providers located outside the EEA or belonging to international groups.

Where personal data is transferred outside the EEA, Icypeas relies on appropriate transfer mechanisms in accordance with Chapter V of the GDPR. These may include adequacy decisions adopted by the European Commission, including the EU-US Data Privacy Framework for eligible and certified US recipients, and, where applicable, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with additional safeguards where required.

Sub-processors: We use a number of sub-processors which have confirmed their GDPR compliance.

  • Sub-processor: Scaleway  |  Location: France  |  Purpose: Hosting Provider | No third-country transfer for EEA-hosted data
  • Sub-processor: OVH  |  Location: France  |  Purpose: Hosting Provider | No third-country transfer for EEA-hosted data
  • Sub-processor: Freshdesk  |  Location: EU  |  Purpose: Support Platform | EU-US DPF; EU SCCs where applicable
  • Sub-processor: SendGrid  |  Location: USA  |  Purpose: Email Notification | EU-US DPF; EU SCCs where applicable
  • Sub-processor: Google Cloud  |  Location: USA  |  Purpose: Internal Emailing | EU-US DPF; EU SCCs where applicable
  • Sub-processor: Customer.io  |  Location: USA  |  Purpose: Marketing Emailing | EU-US DPF; EU SCCs where applicable

1. Awareness

Our employees, responsible for infrastructure, software development and support are fully aware of the concepts and principles of GDPR.

2. Information we hold

2.1 Customer Data

  • Email address, phone number, full name, company name
  • IP address, user agent
  • Payment and invoicing details

2.2 Prospect Data

  • Email address, phone number, full name, company name, firmographics, technographics. We produce this contact data by collecting it from open sources. Employee profiles and company profiles come from an external data provider: Avanteer.

3. Communicating privacy information

Our privacy and terms are clearly communicated in our Privacy Policy and our Terms of Service.

4. Individuals’ rights

  • The right to be informed; we clearly inform our customers how we use their data via our clear Privacy Policy.
  • The right of access; our customers can access all of their data through our web application.
  • The right to rectification; our customers may Contact Us with any rectification queries.
  • The right to erasure; our customers may Contact Us with any erasure queries.
  • The right to restrict processing; our customers have the right, under certain circumstances, to restrict the processing of their data. In this case, we will not process their data for any purpose other than storing it.
  • The right to data portability; our customers may Contact Us to request a copy of their data in a common format.
  • The right to object; our customers may Contact Us with any objections.
  • The right not to be subject to automated decision-making including profiling; we do not and have no plans to do this.

5. Subject access requests

  • We reply to all access requests within 4 weeks (the legal limit from GDPR is 1 month).
  • All access requests are free of charge.

6. Lawful basis for processing personal data

2.1 Customer Data

User Content is the lawful basis for any processing.

2.2 Prospect Data

Legitimate interest is the lawful basis for any processing.

Processing of Prospect Data is necessary for the performance of our contractual obligations towards you and providing you with our services, to protect our legitimate interests and to comply with our legal obligations. Processing of Public Data is done in accordance with our legitimate interest, as long as such interest does not override your fundamental rights and freedom.

7. Consent

Consent is provided by our customers when signing up for the service and logged by us.

8. Children

This service is not available to Children (under the age of 13). Our product is strictly B2B (business-to-business).

9. Data breaches

Upon request, we will provide you with a detailed description of our security policy. We will notify customers and the relevant supervisory authority within 72 hours of a breach.

10. Data Protection by Design and Data Protection Impact Assessments

Security and Data Privacy always comes first when implementing new features. Our Data Protection Officer is involved at every stage of development.

11. Data Protection Officer

For the purposes of Icypeas and related services, our Data Protection Officer is:

12. International

We operate and are established in Paris, France. Our supervisory authority is the CNIL (Commission nationale de l'informatique et des libertés) based in Paris, France.

  • Legal Address: 31 rue Victor Massé, Paris 75009, France
  • Main office: 31 rue Victor Massé, Paris 75009, France
  • Company No: 919561266 (registered in France)

Companies using the Service and handling European user data (people living in the EU) may need to sign a Data Processing Agreement (DPA), as part of GDPR requirements. You can find your DPA upon request (admin users only) at support@icypeas.com, including instructions on how to sign and return it.