Privacy Policy
Version updated on 17 July 2026
ESUS, a simplified joint-stock company with a sole shareholder (société par actions simplifiée à associé unique), registered with the Paris Trade and Companies Register under number 845 249 358, with its registered office at 58 rue de Paradis, 75010 Paris, France, represented by Mr Charles GOMBERT, its President, duly authorised for the purposes hereof (hereinafter "EZUS"), pays particular attention to the protection of personal data and undertakes to protect it in accordance with applicable regulations, and in particular Regulation (EU) No 2016/679 of 27 April 2016, known as the "General Data Protection Regulation" or "GDPR", and French Law No 78-17 of 6 January 1978 as amended, known as the "French Data Protection Act" (hereinafter the "Applicable Data Protection Law").
For the purposes of this privacy policy (hereinafter the "Privacy Policy"), capitalised terms have the meaning given to them in Article 1 "Definitions" below.
When collecting the personal data (hereinafter the "Personal Data") of users of the Site (hereinafter respectively the "Data Subjects" and the "Site") and of the Services, EZUS carries out processing operations in respect of which it qualifies as "data controller" within the meaning of the aforementioned texts.
For any question relating to this Privacy Policy or to the processing of their Personal Data, the Data Subject may contact EZUS's data protection contact (Data Protection Officer) at the following address: operations@ezus.io.
EZUS undertakes to comply at all times with the requirements of the Applicable Data Protection Law and to process Personal Data only under the conditions set out below.
1. Definitions
"Client": means any professional, natural or legal person, registered with the trade and companies register or any equivalent register, being a client of EZUS, who has subscribed to the Platform in accordance with EZUS's general terms and conditions of sale.
"Content(s)": means all textual and graphic content present on the Platform, including without limitation the structure and pages of the Platform, the software and the Data analysis and monitoring methods, and the texts, videos, animations, sections, drawings, illustrations and images present on the Platform.
"Agreement": means the contractual set of documents binding the Client to EZUS, including the general terms and conditions of sale and/or of use, governing access to and use of the Solution.
"Data": means all data distributed, processed and/or generated through the Platform when used by the User.
"Commercial Document": means the document (quote, proposal, programme, etc.) generated by the Professional using the Platform and intended to be sent to the Professional's own clients via an Ezus Link.
"Ezus Link": means the link (a trademark registered by ESUS) allowing the Professional to send a Commercial Document to its clients.
"Data Subject": means any natural person whose Personal Data is processed by EZUS under this Privacy Policy (in particular Users and visitors of the Site).
"Platform": means the platform named "EZUS", a SaaS software solution intended for travel and tourism professionals for the creation, management and transmission of commercial documents and the management of their files, made available to Users by EZUS from a computer or via a mobile application available on the Android and iOS app stores.
"Professional": means the Client, a travel or tourism professional acting in the course of its business and using the Platform to produce and send Commercial Documents.
"Resources": means the external files and documents that the Professional provides to the Platform for use within a Commercial Document sent to its clients through an Ezus Link.
"Services": means all services performed by EZUS in the performance of the Agreement, and more specifically the digital services provided via the Solution.
"Site": means the website published by EZUS and accessible at ezus.io, as well as its subdomains, through which EZUS presents and provides access to its Services.
"Solution": means the EZUS SaaS software solution, together with all web Services accessible via the Platform, the features of which are described on the Site.
"User": means the natural person who benefits from the Services provided by the Platform and granted to the Client in accordance with the Agreement binding it to EZUS, acting on behalf of the Client, holding an account allowing them to access and use the Platform, regardless of their location and the means of access.
2. Overview of Personal Data processing
EZUS carries out the following processing operations on Data Subjects' Personal Data:
| Purpose | Legal basis | Categories of data processed |
|---|---|---|
| Management of account opening and use | Performance of the Agreement / general terms and conditions of sale | First and last name Email address Mobile number |
| Payment, purchase, invoicing | Performance of the Agreement and legal obligation (accounting retention) | Connection logs Account identification data Payment data (processed by Stripe) |
| Operational management of the Site and the Platform (support, maintenance and after-sales service in particular) | Performance of the Agreement / legitimate interest | All Personal Data processed via the account Any information sent to the support team |
| Communication with the Data Subject by any means made available to them (email, telephone, etc.) | EZUS's legitimate interest (and consent for unsolicited prospecting) | Email address First and last name Any information provided when making contact |
| Improvement of the performance and features of the Site and the Services | EZUS's legitimate interest | Usage statistics (cookies) First and last name IP address Connection logs |
| Prevention and detection of fraud and malware, and management of security incidents | EZUS's legitimate interest and legal obligation | Connection logs IP address |
Whether the entry of Personal Data is mandatory or optional is specified at the time of collection, by an asterisk placed next to the data that must be provided. The mandatory provision of certain Personal Data is necessary for EZUS to fulfil the aforementioned purposes. Optional data allows EZUS to better understand the Data Subject in order to provide services better suited to their needs.
3. Personal Data retention periods
In accordance with the general terms and conditions of use, the Data Subject's Personal Data is collected through their account and during their use of the Site and the Platform, and is retained for the following periods:
- Account and usage data: for the entire duration of the contractual relationship, then archived for up to three (3) years from the closure of the account or the last contact;
- Browsing on the Site and the Platform: for the duration of the visit and then, once it has ended, for the cookie retention period referred to in Article 9;
- Communications with EZUS, by any means whatsoever: for a period of three (3) years from the last contact;
- Invoicing data and accounting records: for ten (10) years in accordance with Article L. 123-22 of the French Commercial Code;
- Payment data: EZUS does not retain bank card data, which is processed directly by its payment provider (Stripe); transaction data is retained under the conditions provided for by that provider and by applicable regulations.
Beyond the aforementioned periods, Personal Data is archived by EZUS in a secure environment for the applicable statutory limitation period, for evidentiary purposes in connection with the establishment, exercise or defence of legal claims.
4. Recipients of Personal Data
Save where required by law or by court order, EZUS will never disclose, assign, rent out or transfer the Personal Data it processes to third parties other than the recipients listed below.
These providers act as EZUS's "processors" within the meaning of the Applicable Data Protection Law, on EZUS's instructions, and receive only the data strictly necessary for the performance of their assignments, under contractual conditions that comply with the Applicable Data Protection Law and that may not derogate from this article:
| Provider | Purpose | Data location | Transfer outside the EU |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting of the Site, the Platform and the databases | European Union (data centres in Ireland) | No (data stored in the EU) |
| Stripe | Online payment service and processing of payment data | United States / EU | Yes |
| PandaDoc | Management and transmission of contractual documents and information | United States | Yes |
| Intercom | Customer support and ticketing | United States / EU | Yes |
| Atlassian (Jira) | Tracking of requests and product improvements incorporating customer feedback | United States / EU | Yes |
| Google (Google Workspace: Gmail, Drive, etc.) | Management of communications and exchanges | United States / EU | Yes |
| Webflow | Management of the website and inbound requests | United States | Yes |
Personal Data may also be shared with third-party cookie publishers, under the conditions set out in Article 9. Each provider makes its own privacy policy available, which the Data Subject is invited to consult.
5. Security measures implemented
EZUS implements appropriate technical and organisational measures to ensure the security and confidentiality of Personal Data, and in particular:
- ensuring the physical and logical security of the servers hosting the Site and the Platform and, in particular, the integrity of the network and servers against any external malicious act or any known cyberattack; the servers are protected against intrusion by a firewall, and security updates for operating systems and antivirus software are installed regularly;
- implementing encryption of data in transit and at rest, segregation of environments, management of authorisations and access control based on the principle of least privilege;
- implementing and maintaining security and confidentiality measures that take into account Personal Data protection principles and are appropriate to the risk that their processing poses to the rights and freedoms of Data Subjects, in accordance with the Applicable Data Protection Law; these measures aim to (i) protect Personal Data against destruction, loss, alteration or disclosure to unauthorised third parties and (ii) ensure the restoration of its availability and access to it in a timely manner in the event of a physical or technical incident;
- regularly testing, analysing and evaluating the effectiveness of the aforementioned security measures.
6. Transfer of Personal Data outside the European Union
Some of EZUS's providers mentioned in Article 4 hereof belong to groups of companies whose holding entity is located outside the European Economic Area. As a result, some Data Subjects' Personal Data may be transferred to third countries (in particular to the United States).
The Data Subject is informed that these companies may be subject to legal, governmental or judicial obligations to disclose data, including Personal Data, regardless of where that data is hosted.
EZUS ensures at all times that these transfers take place under appropriate security and confidentiality conditions guaranteeing a level of Personal Data protection equivalent to that required within the European Union, in accordance with the Applicable Data Protection Law, in particular by relying on (i) the provider's adherence to the EU–US Data Privacy Framework where it is certified, or (ii) the conclusion of the standard contractual clauses adopted by the European Commission, supplemented where applicable by additional measures following a transfer impact assessment.
7. Data Subjects' rights over their Personal Data
Data Subjects have the following rights over their Personal Data at all times:
- Right of access: to obtain confirmation of the processing of their Personal Data as well as a certain amount of information about the processing operations, it being understood that this information is in any event provided in this document;
- Right to rectification: to obtain the rectification of their Personal Data where it is inaccurate or incomplete;
- Right to erasure ("right to be forgotten"): to obtain the erasure of their Personal Data where it is no longer necessary in relation to the purposes for which it was collected, or where the Data Subject objects to the processing;
- Right to restriction of processing: to obtain the restriction of processing in the cases provided for by the GDPR, in particular where the Data Subject contests the accuracy of the data or where they still need it retained for the establishment, exercise or defence of legal claims;
- Right to data portability: to receive the Personal Data they have provided to EZUS in a structured, commonly used and machine-readable format, or to request its transmission to another data controller;
- Right to object: to object at any time, on grounds relating to their particular situation, to the processing of their Personal Data, and in particular to object without giving reasons to commercial prospecting, including related profiling;
- Withdrawal of consent: to withdraw their consent to the future processing of their Personal Data where the processing is based on consent, without such withdrawal affecting the lawfulness of prior processing;
- Post-mortem directives: to define directives regarding the retention, erasure and communication of their Personal Data after their death, in accordance with Article 85 of the French Data Protection Act;
- Right to lodge a complaint: to lodge a complaint with the French data protection authority (Commission Nationale de l'Informatique et des Libertés, "CNIL") if the Data Subject considers that the processing carried out by EZUS constitutes a breach of the Applicable Data Protection Law.
The CNIL can be contacted by post (CNIL — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France) or via the online form available at: https://www.cnil.fr/fr/plaintes.
Data Subjects may exercise their rights at any time with EZUS by email at the following address: operations@ezus.io (or contact@ezus.io). Where there is reasonable doubt as to the identity of the requester, EZUS may request proof of identity. EZUS endeavours to respond to any request within one (1) month of receipt, extendable by two (2) months depending on the complexity and number of requests.
8. Hypertext links
The Site and the Platform may contain hypertext links to third-party websites. EZUS has no control over the content of third-party websites referenced by hypertext links. These sites are published by third-party companies that are independent of EZUS. EZUS therefore cannot accept any liability for the content, advertising, services or any other information available on or from these sites. The Data Subject acknowledges that they are solely responsible for accessing and using these sites.
The Data Subject is not authorised to create a hypertext link to the Site or the Platform without EZUS's prior express consent.
9. Cookie management
EZUS uses cookies for the proper functioning of the Site and the Platform and to track and analyse traffic on them. A "cookie" is a small data file sent to the Data Subject's browser by a web server and stored on their device; it cannot under any circumstances damage that device.
The information collected through cookies is strictly intended for EZUS, in compliance with the Applicable Data Protection Law. Cookies from third-party publishers allow those publishers to access the information collected through their cookies, in accordance with the terms specified in the table below.
Cookie consent is collected and managed by the Axeptio solution. EZUS uses the following cookies:
Strictly necessary cookies
These cookies are essential to the proper functioning of the Site and the Platform. They are generally only set in response to actions taken by the Data Subject (requesting services, filling in forms). The Data Subject can configure their browser to block them, but certain features will then no longer be accessible. These cookies do not store any information that personally identifies the Data Subject.
| Cookie name | Purpose / publisher | Retention period |
|---|---|---|
axeptio_cookies | Axeptio (consent management) – stores the Data Subject's cookie consent choices | 12 months |
axeptio_authorized_vendors | Axeptio (consent management) – stores the services/publishers authorised by the Data Subject | 12 months |
axeptio_all_vendors | Axeptio (consent management) – list of services/publishers presented for consent | 12 months |
__session / connect.sid | EZUS – maintains the User's session and authentication | Session |
csrf_token | EZUS – security: protection against cross-site request forgery (CSRF) | Session |
__stripe_mid | Stripe – fraud prevention during payments | 1 year |
__stripe_sid | Stripe – fraud prevention during payments | 30 minutes |
Performance / functionality cookies
These cookies provide features and personalisation of the user experience based on previous visits and selections. They are only placed after the Data Subject's consent has been obtained.
| Cookie name | Purpose / publisher | Retention period |
|---|---|---|
_ga | Google Analytics – distinguishes users (audience measurement) | 13 months |
_ga_<ID> | Google Analytics – stores the session state (GA4) | 13 months |
_gid | Google Analytics – distinguishes users | 24 hours |
_gat | Google Analytics – throttles the request rate | 1 minute |
intercom-id-<ID> | Intercom – anonymous visitor identifier (support / chat) | 9 months |
intercom-session-<ID> | Intercom – support chat session | 7 days |
intercom-device-id-<ID> | Intercom – device identifier for support | 9 months |
Advertising targeting cookies
These cookies, which may be set by EZUS's advertising partners via the Site and the Platform, may be used to build a profile of the Data Subject's interests in order to show them relevant advertising on other websites. They are only placed after the Data Subject's consent has been obtained.
| Cookie name | Purpose / publisher | Retention period |
|---|---|---|
_gcl_au | Google Ads (Conversion Linker) – measures the effectiveness of advertising campaigns | 3 months |
_fbp | Meta / Facebook (Pixel) – advertising delivery and measurement | 3 months |
li_sugr | LinkedIn – browser identification for advertising purposes | 3 months |
bcookie | LinkedIn – browser identifier for advertising and social features | 1 year |
The Data Subject is free to consent to all or part of the cookies (other than strictly necessary cookies) used by EZUS. They can make their choice on their first connection, accepting or refusing category by category, with refusal being as simple as acceptance. They may also withdraw their consent at any time by clicking on the following link.
The Data Subject can also configure their browser to accept or disable cookies. Instructions on cookies for the most commonly used browsers are available at the following links:
- Microsoft Edge: view instructions
- Mozilla Firefox: view instructions
- Google Chrome: view instructions
- Apple Safari (iPhone/iPad): view instructions
- Apple Safari (Mac): view instructions
- Google Analytics opt-out: opt-out add-on
10. Changes to the Privacy Policy
EZUS reserves the right to amend this Privacy Policy at any time in order to adapt it to legal, regulatory, case-law or technical developments, or to changes in its Services. The applicable version is the one in force on the date the Data Subject connects. In the event of a substantial change, EZUS will inform Data Subjects by any appropriate means before the changes take effect.
This is an English translation provided for information purposes only. In the event of any discrepancy, the French version of this Privacy Policy shall prevail.
Safety & compliance
The security of your data is our top priority. Ezus is GDPR compliant and we conduct regular external audits to ensure that your security is at the highest level.


