AGICAP Privacy Policy

Last updated on September 2026

AGICAP is committed to protecting your privacy and to processing your Personal Data lawfully, fairly and transparently.

This Privacy Policy sets out how we handle your Personal Data and the rights available to you.


1. What is the purpose of this Privacy Policy?

This Privacy Policy (the "Privacy Policy") explains how AGICAP collects and processes your Personal Data (as defined under the GDPR) when you visit our website https://agicap.com/en/ (the "Website") or use our application app.agicap.com (the "Application"), the measures we take to protect it, and the rights you have in respect of that processing.

"AGICAP", "we" or "us" means AGICAP SAS, the controller of your Personal Data, as further detailed under section 2.

Depending on your relationship with us, you may be a:

  • "Visitor" when you are browsing our Website as a general internet user before becoming a Prospect or Customer.
  • "Prospect" when you have shown interest in our Services and/or left us your contact details (e.g., to request a demonstration or free trial of our Application and/or through our partnership program);
  • "Customer" when you use the Application under a subscription contract through which we provide our SaaS services via the Application (the "Services").

We refer to Visitors, Prospects and Customers together as "Users" or "you". The purposes, legal bases and retention periods set out below indicate which of these situations each one applies to.

We may update this Privacy Policy at any time to ensure transparency about the processing of your Personal Data, and we encourage you to review it regularly.

This Privacy Policy applies where AGICAP acts as the data controller. When AGICAP processes Personal Data on behalf of its Customers within the Application ("Customer Data"), it acts as a processor on the Customer's instructions, and that processing is governed by the Data Processing Agreement entered into with the relevant Customer, not by this Privacy Policy.


2. Who is the data controller for your Personal Data?

The controller who collects and manages your Personal Data on the Website and Application is AGICAP, an SAS (simplified joint stock company) having its registered office at 57-59 Rue de St Cyr, 69009 Lyon, France, and entered in the Lyon company and trade register under number 823 248 703.

This means that AGICAP is your dedicated point of contact for any questions about your Personal Data's protection within the Website and Application.


3. Which Personal Data do we collect?

When you browse the Site and/or the Application and use the various Services, we may collect and process the Personal Data categories listed below. You are responsible for the accuracy of the Personal Data you provide.

  • Identification information, including civil status, surname and first name, gender, date and place of birth, copy of an identity document if necessary for the management of GDPR requests.
  • Contact data, including e-mail, telephone number and postal/professional address as appropriate.
  • Data relating to your professional situation, including information on the position held.
  • Information required to manage payment for subscription to AGICAP Services and comply with related legal obligations, including bank details (BIN/IBAN).
  • Satisfaction data, including Customer feedback.
  • Browsing data, including IP address, geolocation, Mac address, logs, time stamps, cookies, tracers.
  • Personal data you may decide to include in the free text fields you fill in, or within the documents you send us. We only collect and process this data to the extent necessary to process your request. You should not include third parties' personal data without their prior consent.

When you fill in a form on the Site, the information required is indicated by an asterisk. This information is necessary for us to process your request and identify you. If you choose not to provide it, we will not be able to process your request.


AGICAP may process your Personal Data for the purposes described below.

Purposes

Data concerned

Legal basis  

Duration of retention

Sales prospecting , including prospect acquisition, communication and exchanges with prospects 

Identification, professional and contact data of prospects

AGICAP's legitimate interests in developing and managing its portfolio of prospects and in contacting professionals whose activity is related to prospecting. 

Consent to respond to requests sent via the site's contact forms

3 years from last contact


Receiving and managing customer payments   

Information needed for payment management and compliance with related legal obligations

Contractual performance   

Until receipt of the last payment and for the time necessary to comply with the related legal obligations

Improving Services and the customer experience, in particular by personalizing the experience and analyzing the use of functionalities and customer feedback   

Satisfaction data and browsing data


AGICAP's legitimate interests in improving the functionality of its solution and satisfying customers  

User consent regarding customer feedback

25 months for data from cookies and trackers

 

The time needed to carry out satisfaction analyses

Improving company performance 

Satisfaction data

AGICAP's legitimate interests in growing and improving its performance 

The time needed to carry out satisfaction analyses

Security of AGICAP Services, in particular by analyzing logs and blocking abnormal requests 

browsing data


AGICAP's legitimate interests in ensuring product security and detecting abnormal usage behaviour   

Contractual performance to inform the customer of abnormal behavior   

6 months

Customer support and assistance (incident management) 

Identification data, contact data and data included in free text boxes

Contractual performance 

5 years from the resolution of the incident

Contractual and dispute management, in particular by sending out contracts and quotations and managing customer complaints 

Identification, contact, satisfaction and data included in free text boxes

Execution of pre-contractual and contractual measures  

AGICAP's legitimate interest in managing pre-litigation and commercial disputes.

5 years from the end of the contractual relationship


Respond to requests to exercise the rights of customers, prospects and applicants 

Identification and contact data

Compliance with a legal obligation (GDPR and Data Protection Act) 

5 years from the closing of the request

Corporate financial management 

Information needed for payment management and compliance with related legal obligations

AGICAP's legitimate interests in optimizing and managing the company's finances 

Time needed to manage


5. How does AGICAP use Artificial Intelligence (AI)?

AGICAP uses AI-based tools in the context of its relationship with Visitors, Prospects and Customers, in particular in order to (i) improve, develop and secure its Website, Application and Services; and (ii) improve, assist and speed up its internal tasks and processes (for example customer support, sales operations, content drafting and internal analysis). The AI features used within the Application to process Customer data are governed by the Data Processing Agreement entered into with our Customers and not by this Privacy Policy.

AI is used solely as a means of carrying out the purposes described in this Privacy Policy. The applicable legal bases are set out in the table in Section 4, and the rights available to you in respect of this processing are described in Section 11. Where AGICAP engages third-party AI providers, they act as processors on AGICAP's behalf and under its instructions, and any transfer of Personal Data outside the European Union is subject to the safeguards described in Section 9.

AGICAP may use the Personal Data covered by this Privacy Policy to train AI models.


Do we make automated decisions about you?

AGICAP does not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing, including profiling, within the meaning of Article 22 of the GDPR. Should this change, AGICAP will inform you, provide meaningful information about the logic involved as well as the significance and the envisaged consequences of such processing, and you will have the right to obtain human intervention.


Is an MCP available?

Agicap provides its clients with an MCP so that they can connect their Agicap application to their artificial intelligence systems.

In the context of the use of the MCP by Agicap's clients:

  • Agicap acts as a technical intermediary for its clients, who are responsible for the processing carried out by means of the MCP;
  • The data contained in the Agicap application (e.g. personal data, transaction data, cash-flow data) may be transferred to the AI system with which Agicap's MCP is used (e.g. data transferred to Anthropic);
  • The transferred data is retained within the artificial intelligence system for the retention period defined by the client and/or the artificial intelligence system;
  • For further information, you may contact our Data Protection Officer or consult your client agreement.

6. What are the retention periods for your Personal Data?

Personal data is kept in an active database on a case-by-case basis for as long as is necessary for the purposes for which it was collected and processed, or for as long as required by law or regulations. The specific retention period applied to each processing activity is set out in the table under section 4 above.


7. Who do we share your Personal Data with?

In the context of AGICAP's activities and for the purposes identified above, your Personal Data may be transmitted to its internal and external recipients.

a. Internal recipients

Your personal data may be shared with authorized persons within AGICAP who require access in the course of their duties.

Your Personal Data may also be shared with other companies of the AGICAP group where necessary for the purposes described in this Privacy Policy. AGICAP SAS remains the controller in respect of this processing.

b. External recipients: Processors

In the course of its business and for the provision of its Services, AGICAP may share your Personal Data with third-party service providers (hereinafter "Processors" within the meaning of Article 4.8 of the GDPR) that it uses. In such a case, AGICAP undertakes to ensure that:

  • Each Processor is contractually bound to respect the same obligations as ours with regard to the protection of Personal Data.
  • The Processors contractually ensures sufficient guarantees as to the implementation of appropriate technical and organizational measures, so that processing meets the requirements of legislation on the protection of Personal Data and in particular the GDPR.
  • In the event of transfer of Personal Data outside the European Union, the Processors contractually ensures their security and confidentiality.

Thus, AGICAP may share your Personal Data with subcontractors who intervene for the realization of the identified purposes. These may include:

  • Services, accounting and expense management online payment providers.
  • Suppliers of communication tools, database enrichment, CRM, Customer returns, internal logistics and electronic signatures.
  • Suppliers of tools for creating and distributing different advertising formats.
  • Debt collection service providers.
  • Providers specializing in the development of artificial intelligence tools (such as Anthropic or OpenAI).
  • Service providers responsible for administrative management and human resources.
  • Travel management service providers for companies.

c. External recipients: third-party data controllers

In the course of its business, AGICAP may also share data with third-party partners. These may include law firms, accountants, or tax authorities.

d. Special cases

We may also share your Personal Data in the following situations:

  • When a law, regulation, current regulatory provision or court order requires or allows it, or if that disclosure is necessary as a part of an investigation or legal proceedings, either in France or abroad.
  • In the event of an audit performed as part of an investment and/or in the event of an AGICAP entity or assets being transferred to any potential buyer.
  • When we send non-personal data to third parties, such as aggregated statistics generated from Personal Data.

8. Where do we store your Personal Data?

All of the collected Personal Data are hosted in Belgium by Google Cloud Platform, an international company with a reputation for security and reliability. Google Cloud Platform holds numerous security certifications, and that list can be publicly accessed on their website.


9. Do we transfer your Personal Data outside the European Union?

In the context and for the purposes of the processing described in this Privacy Policy, AGICAP and/or its Subcontractors may transfer Personal Data outside the European Union, in particular to the United States. When doing so, AGICAP shall ensure that failing an adequacy decision, transfer is covered by contractual transfer clauses based on the model established by the European Commission, and/or any other appropriate guarantee in accordance with GDPR requirements. Recipients are required to respect the confidentiality of the Personal Data communicated to them and must only use this data on AGICAP's instructions.

In any event, AGICAP's DPO is available to answer any questions that Data Subjects may have and inform them of its obligations in the event of Personal Data transfer, including the countries to which the data is transferred, and the appropriate guarantees implemented.


10. What security measures do we have to protect your Personal Data?

In order to ensure the security of the Personal Data you transmit to us, we have implemented appropriate technical and organizational measures to:

  • Prevent unauthorized access, use, modification, destruction, loss, damage or disclosure.
  • To ensure the security and confidentiality of the Personal Data collected by preventing them from being distorted, damaged or communicated to unauthorized third parties.

In particular, the security of your Personal Data is ensured by:

  • A strict access control policy.
  • The use of the TLS protocol to ensure the security of Personal Data in transit.
  • The encryption of the Personal Data present via proven algorithms.
  • An annual security audit of our services by an independent company.

To reinforce this approach to protecting your Personal Data, AGICAP requires that you use a password comprising at least eight characters and at least one character from 3 of the 4 sets (lower case letters, upper case letters, numbers, and special characters). AGICAP has also set up a mechanism to restrict access in the event of the use of incorrect identifiers.


11. What rights do you have regarding the processing of your Personal Data?

In accordance with the GDPR, you have the following rights:

  • Right of access: In accordance with Article 15 of the GDPR, you have the right to ask AGICAP for: (i) your Personal Data in an accessible format; (ii) confirmation that your Personal Data are or are not being processed; (iii) information about the processing purpose, categories of Personal Data processed and who your Personal Data is communicated to; and (iv) the storage period of your Personal Data or the criteria used to determine that period.
  • Right to data portability: In accordance with Article 20 of the GDPR, you have the right to request a copy of your Personal Data from us in a format that is structured, commonly used and machine readable so you can provide them to another data controller.
  • Right to rectification: In accordance with Article 16 of the GDPR, you have the right to ask us to modify, add to and update your Personal Data if they are found to be incorrect, incomplete, ambiguous, or out of date.
  • Right to erasure (right to be forgotten): In accordance with Article 17 of the GDPR, you have the right to ask us to permanently erase your Personal Data as soon as practicable, including when you consider that they are no longer necessary in terms of the purpose for which they were collected or that we are no longer justified in processing them.
  • Right to restrict processing: You have the right to ask us to restrict the processing of all or part of your Personal Data only in the situations described in Article 18 of the GDPR, being:
    • Checking the accuracy of the Personal Data that you dispute.
    • Helping you confirm, exercise or defend your legal rights, even when AGICAP no longer needs your Personal Data.
    • Checking if AGICAP's legitimate interests prevail over yours, in the event that you object to your Personal Data being processed on the basis of AGICAP's legitimate interest.
    • Complying with your request to restrict the use of your Personal Data rather than erasing them, when the processing of that data has proven to be unlawful.
  • Right to object: In accordance with Article 21 of the GDPR, you have the right at any time to object to processing operations whose legal basis is legitimate interest, for reasons relating to the particular situation of the Data Subject, who shall provide same.
  • Right to withdraw consent: Where the processing of your Personal Data is based on your consent, you have the right to withdraw your consent at any time. Withdrawing your consent does not affect the lawfulness of any processing carried out before the withdrawal.
  • Post-mortem rights: you have the right to set out special directives for the storage, erasure and communication of your Personal Data, should you die. Those special directives will only concern the processing implemented by AGICAP and are limited to that sole scope. This right applies where such directives are provided for under applicable local law.

12. What can you do if your Personal Data is breached?

If there is a breach of your Personal Data likely to result in a risk to your rights and freedoms, AGICAP and/or our Processors will notify the competent data protection supervisory authority as soon as possible and preferably within seventy-two (72) hours of becoming aware of the breach. You will also be informed as soon as possible of any Personal Data breach likely to result in greater risk to your rights and freedoms, so you can take all necessary measures, in accordance with the provisions of Article 34 of the GDPR.

Without prejudice to any other administrative or legal recourse, if you believe that the processing of your Personal Data constitutes a breach of current legislation, you can lodge a complaint with the relevant supervisory body (for example, in France, the CNIL). You can exercise this right at any time and at no cost to you, except for any costs arising from postage or your choice to engage a third party to assist and represent you in the process.


Do you have questions about your Personal Data processing or want to exercise your rights?

Please contact AGICAP by emailing our Data Protection Officer at [email protected] and/or posting a letter to AGICAP, 57 Rue de St Cyr, 69009 Lyon, France, or by completing the contact form on our website or Application.

In your email please indicates:

  • Your full name and email address
  • The subject of your request, and if it involves exercising a right:
    • The type of right you want to exercise and the reasons justifying it, and
    • Where appropriate, your request to exercise that right.
    • AGICAP may check your identity before actioning your request.

We will provide you with information about the actions taken as soon as possible, and in any case within one (1) month of receiving your request. This timeframe may be extended to two (2) months for more complex requests.

If we cannot action your request, we will tell you why and inform you of your ability to lodge a complaint with a supervisory body or pursue legal recourse.

There is no cost to exercise these rights. However, in the event of blatantly unfounded or excessive requests, AGICAP reserves the right to (i) require payment of expenses taking into account administrative costs, and (ii) refuse to process those requests.