Episto.fr Chat Privacy Policy
Last updated : 20 July 2026
What is the purpose of our Privacy Policy?
Jering SAS (hereinafter "Episto"), which manages the Episto questionnaire platform, places great importance on the protection and confidentiality of your personal data, which represents, for us, a mark of seriousness and trust.
In this regard, our Privacy Policy for personal data precisely reflects our commitment to comply with applicable rules regarding personal data protection within Episto and, more specifically, those of the General Data Protection Regulation ("GDPR").
In particular, our Privacy Policy aims to inform you about how and why we process your personal data within the framework of the services that we provide to you.
Who is our Privacy Policy addressed to?
Our Privacy Policy is addressed to you, regardless of your place of residence, as long as you are at least 15 years old and are users of our Episto questionnaire platform.If you are under the legal age detailed above, you are not allowed to use our services
without the prior and explicit consent of one of your parents or the holder of parental authority, which must be sent to us by email at dpo@episto.fr.If you believe that we hold personal data about your children without consent, we invite you to contact us at the dedicated address detailed above.
Why do we process your personal data and on what basis?
We process your personal data mainly for the following reasons:
- To use and benefit from our service and all its features (e.g. access to our platform, respond to the surveys and polls we offer, etc.) based on our terms and conditions of use and on your consent when the questionnaire implies the processing of sensitive data as defined in Article 9 of the GDPR.
- To be contacted for new surveys based on your consent.
- To ensure and enhance the security and quality of our services on a daily basis (e.g. statistics, data security, etc.) based on our legal obligations, our terms of use, and our legitimate interest in ensuring the proper functioning of our services.
Your data is collected directly from you as soon as you are a user of our Episto questionnaire platform, and we commit to processing your data only for the reasons described above.
IMPORTANT : In the context of using our platform, we use artificial intelligence (AI) to ensure the operation of our services, particularly the generation of questions posed in the context of submitted surveys. We would also like to specify that the responses transmitted to the AI are processed in such a way as to prevent the tool from directly identifying you. If any of them were to contain data that directly identifies you, it would be flagged as a “PII” (personally identifiable information) and excluded from any analysis performed by the AI. We nevertheless recommend that you remain vigilant regarding the use of our tool and ensure that you anonymize your responses and requests to protect your personal data.
What personal data do we process and for how long?
We have summarized below the categories of personal data as well as their respective retention periods :
- Personal identification data (e.g., name, first name, etc.) and contact details (e.g., email address) retained for a period of up to 3 years.
- Email address retained for a maximum period of 3 years from the last contact we had with you regarding our new surveys.
- Data related to lifestyle habits (e.g., hobbies, tastes, etc.) retained for a maximum period of 3 years.
- Sensitive data (if applicable) (e.g., sexual orientation, political sensitivity, etc.) retained for a maximum period of 3 years.
- Connection data (e.g., logs, IP address, etc.) retained for a period of 1 year.
- Images and photographs (only when you choose to respond using video mode) retained for a maximum period of 6 months.
- Voice (only when you choose to respond using voice mode) retained for a maximum period of 6 months.
Upon expiration of the applicable retention periods, the deletion of your personal data is irreversible and we will no longer be able to provide it to you after this period. At most, we can only retain anonymous data for statistical purposes.
Please also note that in case of disputes., we are required to retain the entirety of the data concerning you for the entire duration of the file processing even after the expiration of the retention periods described earlier.
What rights do you have to control the use of your personal data?
The applicable data protection regulations grant you specific rights that you can exercise, at any time and free of charge, in order to control the use we make of your data.
- Right of access and copy of your personal data provided that this request does not conflict with business secrecy, confidentiality, or the secrecy of correspondence.
- Right to rectification of personal data that may be incorrect, outdated, or incomplete.
- Right to you oppose to the processing of your personal data when it is based on our legitimate interest, unless legitimate and compelling reasons justify that processing and prevail over your interests, rights, and freedoms.
- Right to request erasure (“right to be forgotten”) of your personal data that are not essential for the proper functioning of our services.
- Right to restriction of your personal data that allows for the monitoring of the use of your data in case of dispute regarding the legitimacy of processing.
- Right to data portability of your data which allows you to retrieve some of your personal data in order to store or easily transfer it from one information system to another.
- Right to give instructions on the fate of your data in the event of death either through your intermediary, or by the intermediary of a trusted third party or heir.
For a request to be taken into account, it is imperative that it is made directly by you, or your representative at the address dpo@episto.fr.
Requests cannot come from anyone other than you or your representative. We may therefore ask you to provide proof of identity in case of doubt about the identity of the applicant, as well as a justification of representation.
We will respond to your request within the best delays with a maximum limit of a maximum deadline of one month from its receipt, unless the request is technically complex or if we receive many requests at the same time. In this case, the response time may be up to three months maximum.
Please note that we may still refuse to respond to any request excessive or unfounded in particular regarding its repetitive.
Who can access your personal data?
Your personal data is processed by our teams and by our technical service providers solely for the purpose of operating our service.
We specify that we screen all our technical service providers before hiring them to ensure that they scrupulously comply with the applicable rules regarding personal data protection.
FURTHERMORE, WE GUARANTEE THAT WE WILL NEVER TRANSFER OR SELL YOUR DATA TO THIRD PARTIES OR COMMERCIAL PARTNERS.
Can your personal data be transferred outside the European Union?
The personal data processed by our Episto questionnaire platform is exclusively hosted on servers located within the European Union.
Moreover, we do our utmost to use only technical tools whose servers are also located within the European Union. If, however, this is not the case, we ensure that they implement the appropriate safeguards required to ensure the confidentiality and protection of your personal data.
How do we protect your personal data?
We implement the technical means and organizational measures to guarantee the security of your personal data on a daily basis and, in particular, to combat any risk of destruction, loss, alteration, or disclosure.
Technical security measures
- Anti-bot for users ("Front" side).
- User password encryption ("Back" side).
- Complex passwords enforced for users ("Front" side) at login.
- Complex passwords enforced for users ("Back" side) at login.
- Encryption of the "users" database at rest and in transit.
- HTTPS protocol.
- Regular penetration testing.
- Access traceability.
- Duplication of the user database on backup servers.
Organizational security measures
- Access badge.
- Information systems charter.
- Policy for managing permissions and passwords.
- Information systems security policy.
- Data breach management procedure.
- Management procedure for individuals' rights.
- Rules of good conduct.
- Awareness and training of teams twice a year.
Do we use cookies when you browse our platform?
We guarantee that we do not use any advertising or statistical cookies as part of our platform's operation..
We only use technical cookies necessary for the proper functioning of our platform, which we advise you not to remove, and which do not require a cookie banner.
However, if you still wish to oppose their use, you can use your browser settings by following these instructions: Chrome, Microsoft Edge, Safari, Firefox and Opera.
Who can you contact for more information on the use of your personal data?
To best ensure the protection and integrity of your data, we have officially appointed an independent Data Protection Officer (“DPO”) with our regulatory authority.
You can contact our DPO at any time and free of charge at dpo@episto.fr to obtain more information or details on how we process your data.
How can you contact the CNIL?
You can contact the “National Commission on Informatics and Liberties” or “CNIL” at any time at the following contact details: Complaints Service of the CNIL, 3 place de Fontenoy - TSA 80751, 75334 Paris Cedex 07 or by phone at 01.53.73.22.22.
Can the Privacy Policy be modified?
We may modify our Privacy Policy at any time to adapt to new legal requirements as well as to new processes that we may implement in the future.
Ready to discover Episto solutions?
Reliable, quick, and actionable insights for your next decisions.