Privacy Policy
Last updated: 5 August 2026
#Introduction
This policy describes how Comunik processes personal data in connection with the Sphère platform — web application and mobile applications.
It is addressed both to client organisations and to the individuals who use the platform. It supplements, without replacing, the contractual commitments made to each client organisation.
#Two distinct roles, not to be confused
Sphère is a professional platform deployed on behalf of client organisations. That entails two different regimes:
- Comunik acts as a processor for data handled within a client organisation's workspace: messages, calls, files, contacts, calendars, conversations coming from social channels. The client organisation is the controller: it decides the purposes, the retention settings, and the access granted to its users. For any request concerning that data, contact your organisation first — we can only act on its instructions.
- Comunik acts as a controller for its own processing: client relationship management, billing, support, platform security, and compliance with its legal obligations.
#Identity and contacts
- Publisher: Comunik
- Website: https://www.comunikcrm.com
- Personal data: privacy@comunikcrm.com
- Legal enquiries: legal@comunikcrm.com
- Support: helpdesk@comunikcrm.com
Full identification details are set out in the legal notice.
#Data processed
The categories below depend on the modules actually subscribed to and enabled by the client organisation. A module that is not enabled produces no data.
Account and identity
Surname, first name, email address, username, phone number, profile picture, job title, language, time zone, role and organisation membership.
Authentication and security
Password hash (never the password in clear text), session tokens, active devices and sessions, additional authentication factors, sign-in logs. Any biometric data used to unlock the mobile application stays on the device and is never transmitted to us.
Communications
- Internal messaging: messages, attachments, rooms and participants, read receipts, presence status.
- Telephony and contact centre: call logs (numbers, timestamp, duration, direction and outcome), voicemail, dispositions, and call recordings where the client organisation enables that feature.
- Video meetings: audio and video streams during the meeting, screen sharing, together with recordings, transcripts or translations where those features are enabled.
- Email: mailbox account settings and messages synchronised from the Client's server.
- Social channels: messages and comments exchanged with the public, the correspondent's public profile information, lead forms, files shared in the conversation — for the channels enabled (Facebook, Instagram, WhatsApp and others).
Content and collaborative work
Uploaded files and their versions, share links, notes, tasks, calendar events and attendees, contact and organisation records.
Notifications
Device tokens required to deliver notifications (Apple Push Notification service, Firebase Cloud Messaging), and notification preferences.
Technical data
IP address, device and browser type, application version, timestamps and access logs, error logs, aggregated usage metrics.
#Purposes
- Provide the subscribed features and deliver communications.
- Authenticate users and secure access.
- Maintain availability, diagnose incidents and improve reliability.
- Produce the statistics and activity reports intended for the client organisation.
- Provide support and answer requests.
- Prevent fraud, abuse and use contrary to the terms of use.
- Comply with legal and accounting obligations.
#Legal bases
- Performance of the contract: providing the service to the client organisation and its users.
- Legitimate interests: platform security, prevention of abuse, service improvement.
- Consent: connecting a third-party channel, enabling an optional feature such as recording or transcription, where applicable law requires it.
- Legal obligation: accounting retention, response to a lawful request from authorities.
#Recipients and sub-processors
We do not sell, rent or trade personal data. Data may be disclosed:
- to authorised users of the client organisation, according to the rights it grants them;
- to the infrastructure providers hosting the platform, under contractual confidentiality and security commitments;
- to Apple and Google, for delivering notifications to mobile devices;
- to telecommunications carriers, for routing calls;
- to the social messaging platforms connected by the client organisation, solely for exchanges passing through those channels;
- to the artificial-intelligence model provider chosen by the client organisation, solely for the content it submits to an assistance feature;
- to competent authorities, upon a lawful request and within the limits of applicable law.
#Location and transfers
The platform's servers are hosted with professional infrastructure providers. The exact location depends on the deployment agreed with each client organisation and is set out in its contract.
Certain services inseparable from operation — mobile device notifications, social messaging platforms — involve a transfer to providers established outside the client organisation's country. Such transfers rely on the safeguards provided for by applicable law.
#Retention periods
- Client workspace content (messages, files, call logs, calendars): kept for the duration of the subscription, in accordance with the retention settings defined by the client organisation.
- Usage statistics: up to 24 months.
- Technical and security logs: 12 months at most, unless an investigation is ongoing.
- After an account is deleted or a subscription ends: active data is deleted within 30 days.
- Backups: purged within 90 days.
- Accounting records: kept for the applicable statutory period.
Deletion operations are detailed in the account and data deletion page.
#Security
- Encryption of traffic in transit and encryption of data at rest.
- Isolation of client workspaces: each organisation has its own database.
- Access restricted to authorised staff, on a least-privilege basis.
- Multi-factor authentication available for all accounts.
- Access logging and continuous monitoring.
- Periodic audits and penetration tests, followed by a remediation plan.
- Comunik, the platform's publisher, is ISO 9001 and ISO 27001 certified.
These certifications cover Comunik as an organisation. Certification of a scope of the platform itself is a separate undertaking.
No measure makes a system invulnerable. In the event of a data breach likely to create a risk to individuals, we inform the client organisation concerned without undue delay and, where applicable law requires it, the competent authority.
#Your rights
Subject to applicable law, you have rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw a consent given and to lodge a complaint with the competent supervisory authority.
How to exercise them:
- If your data sits within a client organisation's workspace (your employer, a service you contacted), address your request to that organisation: it is the controller and has the tools to answer. We forward it to them if it reaches us.
- For processing for which we are the controller, write to privacy@comunikcrm.com.
We respond within one month, extendable where a request is complex. Identity verification may be required before any request is processed.
#Minors
The platform is a professional tool. Accounts are opened by an organisation for adults acting in a professional capacity. We do not knowingly collect data concerning minors. Were such data reported to us, it would be deleted.
#Changes to this policy
This policy may change. The version in force is the one published at https://legal.comunikcrm.com, dated at the head of the document. Any material change is brought to the attention of client organisations.
#Contact
For any question about this policy or your data: privacy@comunikcrm.com.