Privacy Policy
Last Updated: 23/02/2026.
1. Introduction
This privacy policy describes how EAGR, a French simplified joint-stock company (SAS) with its registered office at 3 Rue Donatello, 92400 Courbevoie, France ("Eagr", "we", "our"), collects, uses, and protects personal data of visitors to its website and users of its platform ("Users").
Eagr acts as the data controller under the EU General Data Protection Regulation (GDPR) and applicable French data protection laws.
Contact: support@eagr.ai
Data Protection Officer: dpo@eagr.ai
2. Data we collect
Data provided by the client company:
User's first and last name
Professional email address
Internal organizational structure (manager/report relationships)
Data collected automatically on the website:
Browsing data (pages visited, visit duration, traffic source)
IP address (anonymized)
Browser type and device
Cookies and similar technologies (see Section 7)
Data collected through the product:
Platform usage data
Conversation content analyzed as part of the coaching service
3. How we use your data
We process your personal data to:
Provide and improve our AI coaching service
Manage user authentication and access
Represent organizational structure within the application
Analyze website traffic and optimize user experience
Communicate with prospects and customers
Comply with legal obligations
4. Legal basis for processing
Performance of a contract between Eagr and the client company
Legitimate interest for service improvement and audience analytics
Consent for non-essential cookies and marketing communications
5. Data retention
Product user data: duration of the contract + 3 months
Prospect data: 3 years from the last contact
Browsing data: 13 months maximum
6. Data sharing
We do not sell your personal data. Data may be shared with:
Technical service providers: hosting (Scaleway, France), analytics (see Section 7)
AI providers: for real-time coaching features. No personal data (name, email) is transmitted. Only non-personal data (anonymized skill framework excerpts) may be transmitted in encrypted form.
All service providers are selected for their data protection guarantees and bound by GDPR-compliant contractual obligations.
7. Cookies and similar technologies
Our website uses the following tools:
Google Analytics (Analytics) — Audience measurement and site performance. Duration: 13 months.
PostHog (Analytics) — User behavior analysis on the website. Duration: 12 months.
HubSpot (Marketing) — Prospect interaction tracking, forms, and chat. Duration: 13 months.
Essential cookies are required for the site to function and do not require consent.
Analytics and marketing cookies are only set after your consent via our cookie banner. You can change your preferences at any time.
8. Data security
We implement appropriate technical and organizational measures:
Encryption of data in transit (HTTPS/TLS) and at rest
Strict access controls and logging
Hosting on secure Scaleway servers in France
Regular security testing
9. Your rights under GDPR
If you are located in the European Economic Area, you have the right to:
Access your personal data
Rectify inaccurate data
Erase your data
Restrict processing
Object to processing
Data portability
Withdraw consent for cookies at any time
To exercise your rights: dpo@eagr.ai. We respond within 72 hours.
You may also lodge a complaint with your local data protection authority.
10. Your rights under CCPA (California residents)
If you are a California resident, you have the right to:
Know what personal information we collect and how it is used
Delete your personal information
Opt-out of the sale of your personal information (note: we do not sell personal data)
Non-discrimination for exercising your privacy rights
To exercise your CCPA rights: dpo@eagr.ai
11. International data transfers
Your data is primarily hosted in France (EU). When data is processed by AI providers located outside the EU, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
12. Data breach notification
In the event of a data breach, Eagr will notify the competent authority (CNIL) within 72 hours in accordance with GDPR, and inform affected individuals if the breach poses a high risk to their rights.
13. Changes to this policy
We may update this policy at any time. The current version is the one published on our website. For material changes, we will notify users by email or through a website notification.
