Légal

Privacy Policy

Last updated: 20 July 2026

1. Who is responsible for your data

The data controller is Company Comm Ltd., Flat/Rm 409 Beverley Commercial Center, 87-105 Chatham Road South, Tsim Sha Tsui, Hong Kong, which publishes and operates the callsyst.com website.

For any question regarding your personal data, please write to us via the “Contact” page.

2. What data we collect

When you write to us through the contact form

Last name, first name, email address and the content of your message.

When you complete the quote questionnaire

This questionnaire is detailed because it is used to prepare a proposal tailored to your project. Depending on your answers, we collect:

  • About you: first name, last name, email address, phone number, country, role.
  • About your company, where applicable: name, registration number, address, postcode, city, country.
  • About your project: project type, industry, launch timeframe, target countries, main language and languages spoken.
  • About your existing activity, where applicable: domain name, monthly traffic, current revenue, platforms used, audience size, number of paying customers, social media accounts.
  • About your needs: desired tools and options, number of agents, communication and payment methods considered, expectations regarding audit and design.
  • About your finances: planned investment, funding method, marketing budget and projected revenue over three years, budget allocated to tools.

Only questions marked with an asterisk are mandatory. You are free not to answer the others: this does not prevent your request from being sent, but it may make our proposal less precise.

When you browse the website

If you accept audience measurement cookies, Google Analytics collects browsing data: pages viewed, time spent, device type, referral source and truncated IP address. If you decline, none of these cookies are set.

Our forms are protected against automated submissions by checks carried out on our own servers: an invisible field that only robots fill in, a minimum completion time and a limit on the number of submissions per connection. They are also protected by Google reCAPTCHA, which analyses your browsing behaviour in order to distinguish a visitor from an automated submission.

We do not collect any special category data within the meaning of Article 9 GDPR: no racial or ethnic origin, no political or religious beliefs, no health data, no biometric data. Please do not include any such information in free-text fields.

3. Why we use it, and on what legal basis

  • To answer your message or quote request and prepare a proposal — steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).
  • To follow up commercially on your request — our legitimate interest in developing our business (Article 6(1)(f)).
  • To protect our forms against automated submissions — our legitimate interest in the security of the service (Article 6(1)(f)).
  • To measure website audience — your consent, which you may withdraw at any time (Article 6(1)(a)).
  • To comply with a legal obligation or a request from a competent authority — legal obligation (Article 6(1)(c)).

We do not send unsolicited marketing, and we neither sell nor rent your data to anyone.

4. How long we keep it

  • Contact and quote requests: 36 months from the last exchange, then automatic deletion.
  • Contractual relationship, if your request leads to one: for the duration of the contract, then retained in accordance with applicable accounting and legal obligations.
  • Audience measurement: 14 months maximum.
  • Access log for our administration tool: 12 months.

Deletion of expired requests is automated.

5. Who has access to it

Your data is accessible to authorised staff of Company Comm Ltd. responsible for handling requests.

We use the following providers, acting as processors and solely on our instructions:

  • Vercel Inc. — website hosting — United States.
  • Supabase — database — European Union (Paris).
  • Resend — sending notification emails — United States.
  • Hostinger International Ltd. — business email — European Union.
  • Google Ireland Ltd. — audience measurement and anti-bot protection — Ireland and United States.
  • Cloudflare, Inc. — content delivery network and security — United States.

As some of these providers are established outside the European Union, your data may be transferred there. Such transfers are governed either by the EU-US Data Privacy Framework, an adequacy decision of the European Commission dated 10 July 2023, or by the standard contractual clauses adopted by the Commission.

We do not share your data with any third party for commercial purposes.

6. Your rights

Under the GDPR, you have the following rights:

  • Access: obtain confirmation that we process your data and receive a copy of it (Article 15).
  • Rectification: correct inaccurate or incomplete data (Article 16).
  • Erasure: request deletion of your data (Article 17).
  • Restriction: request that processing be temporarily suspended (Article 18).
  • Portability: receive your data in a machine-readable format, or have it transmitted to a third party (Article 20).
  • Objection: object to processing based on our legitimate interest (Article 21).
  • Withdrawal of consent: at any time for audience measurement, via the "Manage cookies" link in the footer.
  • Post-mortem instructions: decide what happens to your data after your death (Article 85 of the French Data Protection Act).

To exercise these rights, write to us via the “Contact” page. We reply within one month, extendable by two months for complex requests. Proof of identity may be requested in case of reasonable doubt.

7. How we protect it

We implement appropriate technical and organisational measures:

  • Encryption of all exchanges with the website (HTTPS).
  • Encrypted and authenticated connection to the database.
  • Passwords stored as non-reversible hashes.
  • Administration access restricted, role-based and logged.
  • Rate limiting on forms and anti-bot protection.
  • Retention periods applied automatically.

As no system is infallible, in the event of a breach likely to result in a high risk to your rights, we undertake to inform you as soon as possible and to notify the competent authority within 72 hours.

8. Cookies

Details of the cookies used are set out in our cookie policy, accessible from the footer.

No audience measurement cookie is set without your prior agreement. You may change your choice at any time via the "Manage cookies" link in the footer.

9. Minors

Our services are aimed at professionals. The website is not intended for people under 18 and we do not knowingly collect their data. If you become aware that a minor has provided us with information, please write to us and we will delete it.

10. Changes

This policy may change. Any substantial modification will be indicated on this page with an updated date. We invite you to review it periodically.

11. Contact

For any question about this policy or the processing of your data, write to us via the “Contact” page.