Introduction
The protection of your privacy and your personal data is a priority for Brevo and all of the entities within the group ("Brevo" or "we" or "our" or "us"). The terms with capital letters that are not defined in this Policy shall have the meaning assigned to them in the Brevo Terms of Service.
Brevo only collects, uses, retains, and shares Personal Data as is adequate and relevant to the specific, express purposes described below or as reasonably necessary and proportionate to (i) provide the Services or for (ii) other purposes that we disclose to you. We work to ensure that our privacy practices are compatible with the context of how we collected your Personal Data in the first place.
The types of Personal Data we collect and how it is used depends on how you interact with us, such as a Website visitor, a Brevo customer using the Services or representative of a customer or as a Customer's contact or recipient. Therefore, this privacy policy (the "Policy") applies to:
All users and representatives of Brevo's Customers (the "Customers");
The contacts (recipients of electronic communications, contacts of sales opportunities, registered clients etc.) uploaded on the Software by Brevo's Customers and/or collected via the Software by Brevo's Customers (the "Contacts") when their data are not processed by Brevo on behalf of its Customers;
All visitors of Brevo's website ("Website Users"), i.e. https://fr.Brevo.com (the "Website").
(together also referred to as "you" or "your").
This Policy aims to inform you in a clear and comprehensive manner of the processing of your personal data carried out in accordance with the privacy laws that apply to us, including the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the "GDPR") and any applicable domestic privacy legislations.
This Policy may be updated at any time as a result of, among others, legal, technical or commercial changes. In such cases, Brevo will take appropriate measures to inform you of such changes, where they are significant. We recommend that you refer to this Policy regularly to ensure that you are aware of the latest version. Brevo Customers may use the information contained in this Policy to provide necessary information to the Contacts. You accept this Privacy Policy and consent to Brevo's collection, use, and disclosure of your information as described below by accepting this Privacy Policy where given the opportunity or by using or accessing our Services in any manner. If you do not agree with this Privacy Policy, do not use our Services.
To know more about the concepts of "personal data", "data subjects", "controller", processor", "processing", "purpose", "GDPR" and more, please read the section "Definitions" at the end of this Policy.
WHO IS THE DATA CONTROLLER FOR THE PROCESSING OF YOUR PERSONAL DATA?
The entity of the Brevo group acting as a data controller for the processing of your personal data (i.e., determining the purposes and means of the processing of your personal data) for the processing described in Section 3 of this Policy is the Brevo entity with which you have a contract and in case you have subscribed to a paying plan, the company which is invoicing your organization. Depending on your location, the data controller may be Sendinblue France (SAS), Sendinblue North-America (Inc.) or Sendinblue Germany (GmbH).
The parent company of the Brevo group Sendinblue, a French société par actions simplifiée, whose registered office is located at 17 rue Salneuve, 75017 Paris, France, registered in the Paris Trade and Companies Register under number 498 019 298. Sendinblue is doing business as Brevo.
WHAT IS THE SCOPE OF THIS POLICY?
If you are a Contact, please note that Brevo is acting as data controller only for the specific purposes described in the Section 3 of this Policy. For all other processing that involve your personal data (storage of content, sending of emails, creation of statistics on behalf of Customers, etc.), Brevo does not act as a data controller meaning that it has no influence and does not decide on such processing of your personal data (please be reminded in this regard that Brevo does not send electronic communications on its own behalf but only on behalf and under the instructions of its Customers, except where detailed in Section 3) and, therefore, this Policy may not apply. Brevo will act for these other processing as a data processor and our Customers are acting as data controllers and are the sole entities that can ensure the proper exercise of your rights described in Section 8 (11 for the US) of this Policy (deletion, access, limitation etc.). To learn more about how our Customers process your personal data as data controllers and how you can exercise your rights with them, please see their own privacy policy. If you want to know about how we process personal data as a data processor, please refer to our Data Processing Agreement.
Brevo proposes optional specific apps/features through its Software (WhatsApp Messages, Facebook Ad, Google Fonts & Google ReCAPTCHA, Cloudflare Turnstile, OpenAI…) the list of which can be found in our Terms and Conditions. These apps/features are provided by third-party providers that Brevo does not control and towards which it does not provide any specific warranty. Therefore, for processing carried out for the provision and in the context of such apps/features, Brevo is not liable and the third-party providers act in accordance with the qualification that their policies / terms and conditions provide. If you wish to use those features, we strongly recommend you to read to the relevant privacy policy of each third-party provider to know more about the processing of your personal data.
If you have any questions, please do not hesitate to contact us through the contact details indicated in Section 9 of this Policy (11 for the US). We will do our best to help you and answer any question you may have.
FOR WHAT PURPOSES IS YOUR PERSONAL DATA COLLECTED AND PROCESSED?
Brevo collects and processes personal data that is relevant, adequate, not excessive and strictly necessary for the purposes pursued.
You will find below a table listing the relevant information related to the processing of personal data, where Brevo acts as a data controller, and in particular: The different purposes of the processing operations; The categories of personal data collected; The legal basis on which we rely to carry out the processing; How long we keep your personal data.
For full details on purposes, data collected, legal basis and retention periods, please refer to Brevo's official privacy policy. This summary is provided for your convenience in the context of Nær Events' use of Brevo and related services.
SOURCE OF COLLECTION
We collect Personal Data from the following sources: directly from you when you contact us or sign up; from our service providers where necessary to operate the waitlist and events; and automatically when you visit our site (e.g. cookies, usage data) as described in our and our providers' policies.
TO WHOM DO WE DISCLOSE YOUR PERSONAL DATA?
Personal data may be shared with authorized internal staff, service providers (e.g. hosting, email, analytics), and where required by law with authorities. All recipients are bound by confidentiality and appropriate safeguards.
WHAT ARE YOUR RIGHTS?
You have the right to access, rectify, erase, restrict processing, data portability, and to object, as well as the right to lodge a complaint with a supervisory authority. To exercise these rights, contact us using the details in the contact section. When Brevo is the data controller, you may also contact Brevo as set out in their policy.
HOW TO CONTACT US
For questions about this Policy or Nær Events' processing of your data, please contact us via the contact details provided on our website or in our signup communications. For matters where Brevo is the data controller, refer to Brevo's contact details in their policy.
CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. We will indicate the last revised date at the top of the page. Your continued use of our services after changes constitutes acceptance of the updated policy. We encourage you to review this Policy periodically.
DEFINITIONS
"Controller" means the natural or legal person which determines the purposes and means of the processing of personal data. "Data subject" means an identified or identifiable natural person. "GDPR" means Regulation (EU) 2016/679. "Processor" means a natural or legal person which processes personal data on behalf of the controller. "Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation or set of operations performed on personal data (collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, etc.).