Accord de traitement des données
Un accord de traitement des données que vous pouvez télécharger, signer et archiver.
Ces politiques sont publiées en anglais. Le texte anglais fait foi ; les traductions sont fournies à titre indicatif.
Dernière mise à jour: 2026-08-01
Les informations d'immatriculation de la société exploitant ce service ne sont pas encore publiées. Elles apparaîtront ici et dans le pied de page dès leur confirmation.
This is the template we sign. Download it, fill in your organisation's details, and return it to legal@shelftap.com. We counter-sign and return a copy.
1. Roles
For the personal data a customer submits or generates through the Service, the customer is the controller and [LEGAL ENTITY NAME — TO BE SUPPLIED] is the processor. For the account, billing and public-source directory data described in the Politique de confidentialité, [LEGAL ENTITY NAME — TO BE SUPPLIED] is an independent controller and this agreement does not apply.
2. Subject matter and duration
Processing lasts for the term of the subscription plus the retention windows published on the Conservation des données page. The subject matter is the operation of a B2B company-discovery service.
3. Nature and purpose
Storage, retrieval, structuring, analysis and export of company records and search results; delivery of transactional email; and processing of payment metadata.
4. Categories of data subject and data
Data subjects: the customer's own users, and individuals named in publicly published company contact information. Data: name, business email, business telephone, business address, job title where published, and the source URL of each fact. No special-category data is processed.
5. Processor obligations
- Process personal data only on the controller's documented instructions, including for transfers.
- Ensure that personnel with access are bound by confidentiality.
- Apply the technical and organisational measures published on the Aperçu de la sécurité page.
- Engage only the sub-processors listed on the Sous-traitants ultérieurs page, and give notice before adding another.
- Assist the controller with data-subject requests, security, breach notification and impact assessments.
- Delete or return personal data at the end of the term, at the controller's choice.
- Make available the information needed to demonstrate compliance and allow audits, subject to reasonable notice and confidentiality.
6. Breach notification
We notify the controller without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting their data. Details are on the Réponse aux incidents page.
7. Transfers
Where a listed sub-processor is outside the EEA, the United Kingdom or Türkiye, transfers are made under that provider's standard contractual clauses or an equivalent mechanism.
8. Signature block
Processor: [LEGAL ENTITY NAME — TO BE SUPPLIED], [REGISTERED ADDRESS — TO BE SUPPLIED], registration number [REGISTRATION NUMBER — TO BE SUPPLIED]. Controller: to be completed by the customer.