Data protection
Privacy policy
This policy explains in practical terms what data KYEASY uses, why it uses it, how long it keeps it and how you can exercise your rights.
This English version is provided for convenience. The French version is the reference text if an interpretation differs; data subjects may still exercise their GDPR rights directly.
1. Scope and roles
This policy covers kyeasy.com, business enquiries, customer accounts, subscriptions and billing, support, and software or cloud services supplied directly by KYEASY. The services are for professional users but may contain data about customer employees, till operators, consumers, loyalty members, order recipients or partner contacts.
2. Controller
KYEASY is a French simplified joint-stock company (SAS) with variable capital and €1,000 subscribed capital, whose registered office is at 60 rue Hoche, 4th floor right, 87100 Limoges, France. It is registered with the Limoges Trade and Companies Register under number 992 394 338 (SIRET 992 394 338 00014; EU VAT number FR50 992394338) and represented by its President, Jinghui YANG.
- Privacy email: admin@kyeasy.com
- Telephone: +33 6 25 82 33 91
- Postal address: KYEASY — Privacy, 60 rue Hoche, 4th floor right, 87100 Limoges, France
3. Data, purposes, legal grounds and retention
Website delivery and security
The server may process the IP address, time, requested URL, response code, browser and operating system, browser language and referring page to deliver the site, select a language, detect abuse, diagnose faults and protect infrastructure.
- Legal ground: KYEASY’s legitimate interest in operating and securing its site.
- Retention: active logs for no more than 12 months, unless evidence, a security incident or law requires longer retention.
Enquiries and business communications
When you email, call or voluntarily use WhatsApp or WeChat, KYEASY processes your identity, contact details, organisation, requested service and message content to respond, prepare a proposal and manage the relationship.
The form shown on the home page is currently a local demonstration: its button does not transmit or retain the fields entered. Use a listed contact channel to send an actual enquiry.
- Legal ground: pre-contract steps requested by you; legitimate interest in relevant professional communications and follow-up.
- Retention: while discussions continue, then three years from the last active contact if no contract is concluded.
Contracts, accounts, subscriptions and billing
KYEASY may process professional contact details, signatory authority, account identifiers, roles, plan and capacity, service history, invoices, payment status and contractual communications to supply the service, administer access, bill and meet accounting and tax duties.
- Legal ground: performance of contract; legal duties; legitimate interest in establishing or defending rights.
- Retention: operational data during the contract, contractual evidence for five years after termination, and invoices and accounting records for ten years.
Support, maintenance and security
A support request may include the requester’s identity and role, device and software details, event times and steps, necessary logs and attachments supplied voluntarily.
- Legal ground: performance of contract and legitimate interest in secure, reliable and traceable support.
- Retention: during the contract and up to five further years where a ticket is contractual evidence; unnecessary attachments are removed sooner.
Relevant B2B information
KYEASY may send information relevant to a recipient’s professional role. Every marketing message provides a simple, free way to object.
- Legal ground: consent where required; otherwise legitimate interest in relevant B2B marketing.
- Retention: until withdrawal or objection and no longer than three years from the last active contact; a suppression record may be kept to honour the choice.
4. Data entrusted by SaaS customers
Depending on enabled modules, a professional customer may entrust transaction, cancellation, correction and refund records; inventory, reports, stores, users and action logs; daily, monthly and annual closures and archives; orders, deliveries, members, points, balances and marketing preferences. The customer is the controller and must inform people, select a legal ground, restrict permissions and set retention. KYEASY uses the data only to deliver, secure and maintain the service under documented instructions.
- An Article 28 GDPR data processing agreement (DPA) must be in place before production use.
- The DPA states the subject, duration, data and people concerned, security measures, subprocessors, assistance, audits, and return or deletion at the end of service.
- Never place a full payment-card number, card security code, password or secret in a free-text field, support ticket or module not expressly designed for it.
5. Sources and required information
Data comes from you, your employer or account administrator, systems your organisation chooses to connect and, for technical security, your device and network. Information marked as required in a quote, contract or interface is needed to set up, supply or bill the service. Without it, KYEASY may be unable to contract or perform. Other information is optional.
6. Recipients and subprocessors
Access is restricted to authorised KYEASY personnel who need it for their duties. Depending on the service actually ordered, hosting, email, backup, support, billing, security or integration providers receive only the data needed for their task.
- The SaaS subprocessors actually used and their locations are listed in the DPA or provided on request.
- Professional advisers, auditors and tax, judicial or administrative authorities receive data only where law permits or requires.
- An integration selected by the customer may disclose data to that provider under its own terms and the customer’s responsibility.
7. Transfers outside the EEA
KYEASY gives preference to processing in the European Economic Area. If a transfer to a country without an adequacy decision is necessary, it uses a GDPR-recognised mechanism such as the European Commission standard contractual clauses, with a transfer assessment and supplementary measures where needed.
WhatsApp and WeChat are optional third-party channels and may involve international processing under their own policies. Email, telephone and post remain available alternatives.
8. Cookies and language selection
At the date of this policy, the public site sets no advertising or audience-measurement cookie and stores no language choice in the browser. Language follows the selected URL and, at the bare site root only, the language preference sent by the browser. External services are contacted only after you activate their links.
If KYEASY later adds a non-essential tracker, it will stay off until valid consent is given, and rejecting or withdrawing will be as easy as accepting.
9. Security and personal data breaches
KYEASY applies measures proportionate to risk, including encrypted communications, restricted access, role separation, logging, updates, backups and incident procedures. No transmission or storage method can guarantee zero risk. As a processor, KYEASY informs the customer controller without undue delay after becoming aware of a personal data breach and supplies information needed for the customer’s duties.
10. Your rights
Subject to the GDPR and French Data Protection Act, you may request access, correction, erasure, restriction and portability; object to legitimate-interest processing or direct marketing; withdraw consent at any time; and give instructions for your data after death.
For data entered into KYEASY by a merchant, contact that merchant first because it is normally the controller; KYEASY assists it as processor. For KYEASY’s own processing, write to admin@kyeasy.com or the postal address above. KYEASY may request only what is necessary to verify identity. It normally responds within one month; a complex or numerous request may add two months, with notice in the first month.
11. Automated decisions and children
For its own purposes, KYEASY makes no decision based solely on automated processing that has legal or similarly significant effects. The professional services are not intended for children. A customer enabling automation remains responsible for its purpose, settings and notices.
12. Policy changes
KYEASY updates this policy as services, providers or law change. The date and version appear above. Where required, a material change affecting existing processing is brought to the attention of affected people by an appropriate means before it takes effect.
13. Official resources
Need an answer for your circumstances?
Tell us your organisation, the service concerned and the outcome you need. Do not include passwords, secrets or payment-card data.
