Privacy and the protection of your data.
The invoices and contracts you upload are encrypted before they are written and kept on a private volume, outside the public web. Only the ENCOM teams authorised to handle the file can read them.
Last updated: 8 September 2026
At a glance
- Purpose
- Handling your telecom audit or call-back request, and sending you its summary.
- Data collected
- Your name and business contact details, the practice, the site address, the invoices and contracts you upload.
- Retention
- Audit request: 3 years (1095 days). Uploaded documents: 1 year (365 days). Email events: 400 days.
- Access
- Only the ENCOM teams authorised to handle the file, on named accounts with mandatory two-factor sign-in.
- Rights
- Access, rectification, erasure, restriction, objection, portability, by writing to audit@encom-conseil.fr.
- Cookies
- Strictly necessary cookies only, the session and the anti-CSRF token. No analytics, no advertising tracker.
Publisher and data controller
This site is published by ENCOM Conseil & Audit, a telecom integrator based at 159, rue Montmartre, 75002 Paris, reachable on 01 73 30 00 00 and at https://encom-conseil.fr. ENCOM Conseil & Audit is the controller of the data collected here. For any question about your data, write to audit@encom-conseil.fr.
Purposes and legal bases
Your data is used only to handle your request, to reply to you and to send you the audit summary. No automated result is ever produced: every file is read by an ENCOM adviser.
- Audit request and call-back request: your consent, given when you submit the form and time-stamped with the request.
- Sending the summary and the follow-up messages about your request: performing the process you started.
- Email prospecting of notary practices: ENCOM's legitimate interest in presenting its services to professionals in that field. Every message carries an unsubscribe link.
Data we collect
We collect only what handling the file requires.
- Your identity and business contact details: name, role, email address, telephone number.
- The notary practice: its trading name and the address of the site to audit.
- The scope you declare: what you ask us to review and any detail you add.
- The telecom invoices and contracts you upload.
- Technical logs: date and time of access, IP address, a fingerprint of each uploaded file, and the actions ENCOM accounts take on the file.
- The cookies strictly necessary to run the site: the session cookie and the anti-CSRF token, without which the form cannot be submitted. No analytics and no advertising tracker is set.
Who receives your data
Your data is never sold, rented or passed on. It is available to the ENCOM teams authorised to handle your file, and to Postmark, our email delivery sub-processor, which sends our messages on our behalf and never has access to the documents you upload.
Transfers outside the European Union
Postmark is a provider established in the United States, so delivering our email involves transferring your address and the content of the message outside the European Union. That transfer is framed by the European Commission's standard contractual clauses. The invoices and contracts you upload, by contrast, stay on our servers and are sent to no delivery provider at all.
How long we keep it
The periods below are applied automatically, every night, by a scheduled purge.
- Audit request and the contact details attached to it: 3 years (1095 days). After that, a closed request is anonymised rather than deleted, so that only the statistics of the operation remain.
- Uploaded invoices and contracts: 1 year (365 days). The record and the encrypted file are then deleted.
- Email events, sends, opens, clicks and bounces: 400 days, then deletion.
- The suppression list: kept with no time limit. That record is the proof an address asked not to be written to, and deleting it would put the address back into our sends.
Security
The application receives documents covered by professional secrecy. The following measures are in place.
- Uploaded documents are written to a private storage volume, outside the public web root, and encrypted with the application key before the write.
- A document can only be downloaded by an authenticated ENCOM account, through a signed link valid for five minutes, after its permissions and the SHA-256 fingerprint recorded at upload have both been checked.
- ENCOM accounts are personal and protected by mandatory two-factor authentication.
- Every sensitive action taken from an ENCOM account is written to an append-only trail that nobody can alter or erase.
- Traffic between your browser and the site is encrypted with HTTPS.
The email we send you
Two categories of message, sent separately.
- The messages about your request, the confirmation, the reminder, the summary and a resent access link, reach you because you submitted a request. They carry no open or click measurement whatsoever.
- The prospecting messages sent to notary practices do measure opens and clicks, so that the number and the content of the sends can be adjusted. Every message carries an unsubscribe link, effective immediately and permanently.
Your rights
You have rights of access, rectification, erasure, restriction, objection and portability over your data. To exercise any of them, write to audit@encom-conseil.fr setting out your request: we answer within one month. If our answer does not satisfy you, you may lodge a complaint with the CNIL, the French data protection authority, at 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at https://www.cnil.fr.
- Right of access: obtain a copy of the data we hold about you.
- Right to rectification: have inaccurate or incomplete data corrected.
- Right to erasure: ask for your data to be deleted, the suppression list excepted.
- Right to restriction: ask for processing to be paused while something is checked.
- Right to object: refuse email prospecting, at any time and without giving a reason.
- Right to portability: receive your data in a machine-readable format.
Changes to this page
This page may be updated to follow a change in the service, in our sub-processors or in the applicable rules. The published version is dated 8 September 2026, shown at the top of the page.