Legal information — Comunik

Privacy Policy

Last updated: 6 August 2026

Introduction

This policy describes how Comunik processes personal data in connection with the Sphère platform — web application and mobile applications.

It is addressed both to client organisations and to the individuals who use the platform. It supplements, without replacing, the contractual commitments made to each client organisation.

Two distinct roles, not to be confused

Sphère is a professional platform deployed on behalf of client organisations. That entails two different regimes:

Identity and contacts

Full identification details are set out in the legal notice.

Data processed

The categories below depend on the modules actually subscribed to and enabled by the client organisation. A module that is not enabled produces no data.

Account and identity

Surname, first name, email address, username, phone number, profile picture, job title, language, time zone, role and organisation membership.

Authentication and security

Password hash (never the password in clear text), session tokens, active devices and sessions, additional authentication factors, sign-in logs. Any biometric data used to unlock the mobile application stays on the device and is never transmitted to us.

Communications

Content and collaborative work

Uploaded files and their versions, share links, notes, tasks, calendar events and attendees, contact and organisation records.

Notifications

Device tokens required to deliver notifications (Apple Push Notification service, Firebase Cloud Messaging), and notification preferences.

Camera and microphone

The mobile application accesses the camera and the microphone during calls and video conferences, as well as when the user takes a photo or records a voice message. The audio and video streams of a communication are transmitted to participants in real time and are not retained by the application; a recording only takes place if the client organisation has enabled that feature, in which case it follows the regime for content described above. Access is never permanent: it is requested by the operating system and limited to the duration of use.

Location

The mobile application accesses the device's location only when the user chooses to share it in a conversation. The location is then captured once, at the moment of sending, and transmitted as message content to the recipients of that conversation, in the same way as a text or an attachment.

No reading is performed in the background, continuously or periodically: the application does not track the user's movements and keeps no location history. Permission to access location can be denied or withdrawn at any time in the operating system settings, without preventing the use of the application's other features.

Depending on the setting chosen by the user on their device, the transmitted location may be precise or approximate.

Technical data

IP address, device and browser type, application version, timestamps and access logs, error logs, aggregated usage metrics.

Diagnostics and crash reports

When the application encounters an error, a technical report is sent to our diagnostics tool (Firebase Crashlytics, provided by Google). That report contains the technical state of the application at the time of the incident, the device model, the operating system version and an installation identifier. It contains no conversation content, message, file or account data. This information is used solely to fix failures. It is retained by the diagnostics tool for a limited period, then deleted automatically.

We also measure the application's performance (start-up times, network request durations) using Firebase Performance Monitoring, provided by Google. These measurements are technical and contain no conversation content, message, file or account data.

Purposes

Legal bases

Recipients and sub-processors

We do not sell, rent or trade personal data. Data may be disclosed:

Location and transfers

The platform's servers are hosted with professional infrastructure providers. The exact location depends on the deployment agreed with each client organisation and is set out in its contract.

Certain services inseparable from operation — mobile device notifications, social messaging platforms — involve a transfer to providers established outside the client organisation's country. Such transfers rely on the safeguards provided for by applicable law.

Retention periods

Deletion operations are detailed in the account and data deletion page.

Security

These certifications cover Comunik as an organisation. Certification of a scope of the platform itself is a separate undertaking.

No measure makes a system invulnerable. In the event of a data breach likely to create a risk to individuals, we inform the client organisation concerned without undue delay and, where applicable law requires it, the competent authority.

Your rights

Subject to applicable law, you have rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw a consent given and to lodge a complaint with the competent supervisory authority.

How to exercise them:

We respond within one month, extendable where a request is complex. Identity verification may be required before any request is processed.

Minors

The platform is a professional tool. Accounts are opened by an organisation for adults acting in a professional capacity. We do not knowingly collect data concerning minors. Were such data reported to us, it would be deleted.

Changes to this policy

This policy may change. The version in force is the one published at https://legal.comunikcrm.com, dated at the head of the document. Any material change is brought to the attention of client organisations.

Contact

For any question about this policy or your data: privacy@comunikcrm.com.