Privacy policy

Privacy policy

Privacy policy

four40 is committed to protecting and respecting your privacy


We want you to feel safe when we process your personal data. Our Privacy Notice explains how we ensure that your personal data is handled in compliance with applicable legislation and it applies to our processing of personal data, in the capacity of data controller relating to our customers and users of our services, visitors to our websites, and to other business contacts.


And because it may be what you care most about, let us start by saying that none of your company or personal data is and will ever be used to train external AI services.

Any AI service embedded in four40 App and Services is either self-hosted on our end or customer's end, or leveraging private technologies (OpenAI). In the latter case, we use enterprise-grade infrastructures (in AWS or Azure) to silo your proprietary data from the models we use to query and retrieve it.


If you are a user of our services, you either use our services as:

  • a consumer user ("Consumer User”), for example, if you have signed up for our services yourself, visiting our website, or if you apply for a job; or

  • a user invited to use a service by a company or other entity which is a customer of ours (“User of Company Subscriber”), for example, if you are invited to use the services by your employer.


Please note that some of our processing of personal data differs depending on if you are a Consumer User or a User of Company Subscriber, which is why we ensure to always state in our Privacy Notice if the processing only applies for a particular group of users. If you are a User of a Company Subscriber, we process your personal data in the capacity of data processor, when providing our services to our company subscriber (i.e., the entity that invited you to use the service, for example, your employer). In relation to such processing, the company subscriber is data controller and hence responsible for providing information to you about its processing of personal data.

We only use your personal data for the purposes specified in this Privacy Notice and not in any manner that is incompatible with those purposes.



1. General


four40, 951 169 572 R.C.S. Paris, (“four40,” "us," “we,” or "our") is committed to protecting and respecting your privacy. We want you to feel that we respect your privacy when we process your personal data. This Privacy Notice (“Privacy Notice”) explains how we ensure that your personal data is handled in compliance with applicable legislation and applies to all of our processing of personal data relating to our customers and users of our services, visitors to our websites, and to other business contacts. We use your personal data to be able to operate our business and meet our obligations and responsibilities in relation to applicable legislation and good industry practice.



2. Data controller


four40 is the data controller for the processing of your personal data and is responsible for ensuring that the processing is carried out in accordance with applicable legislation. If you have any questions regarding the processing of your personal data, you will find our contact details at the end of this Privacy Notice.



3. Our use of your personal data 


3.1 The purposes of processing


We use your personal data for the following purposes:

  • If you are a Consumer User, to provide and manage our services;

  • If you are a User of a Company Subscriber, to administer the agreement with our subscriber;

  • Administration and provision of support services and account services;

  • To improve our services by training our algorithms;

  • For statistics, analysis, and business development;

  • To market our services through newsletters, social media, publications, and events;

  • To prevent fraud and other abuse;

  • To comply with legal obligations;

  • To establish and defend legal claims; and

  • To enable mergers, divestitures, restructuring, reorganization, dissolution, and other sale or transfers of four40 assets.


3.2 Categories of personal data processed

User

  • Name

  • Email

  • Username

  • Password

  • Alphanumeric identifier

Content

  • Search queries: end-user’s submitted queries

  • Third-party content: content from Subscriber’s pre-approved integrations

    • From Google Calendar integration

    • From Slack integration

Activity

  • Event logs (e.g., action taken, event type, event location, timestamp, client ID, user ID, and channel ID)

  • Cookies

  • Session information (e.g., frequency, average and actual duration, quantity, quality, network activity, and network connectivity)

  • Session facilitator/participant ID

  • Support

    • Troubleshooting subject

    • Problem description

    • Post-session feedback

    • User-supplied attachments (e.g., recordings, transcripts or screenshots, text, post-session feedback)

  • Billing and administration

    • First and last name

    • Signature

    • Email

    • Phone number

    • Address


3.3 How we process your personal data for each purpose


Below you can find more information about our processing of your personal data in relation to our purposes of processing:



3.3.1 Purpose : If you are a Consumer User, to provide and manage our services


Categories of personal data we process :
● User
● Content
● Device
● User Activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to provide you with our services and use of our services and to communicate with you.

Legal basis :
The processing is necessary for the purpose of fulfilling the agreement with you, including administering our services.

Retention period :
Personal data stored to provide and manage our services will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as you have an account to use our services or websites, or as set forth in our agreement. We may also need to store your personal data for a reasonable time thereafter in order to fulfill any surviving terms of our agreements.

Your rights :
Please see below for information about your rights.



3.3.2 Purpose : If you are a User of a Company Subscriber, to administer the agreement with our subscribers


Categories of personal data we process :
● Technical support and feedback
● Billing and administration
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to be able to administrate the agreement with the Company Subscriber by processing information such as the contact person at the Company Subscriber.

Legal basis :
The processing is necessary for our legitimate interest in processing your personal data in order to administer the agreement with our customers, which we assess, outweighs the data subjects’ interest in privacy.

Retention period :
Personal data stored to administer the agreement with our customer will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as the agreement is valid, and you are the appointed contact person or similar. We may also need to store your personal data for a reasonable time thereafter in order to fulfill any surviving terms of our agreement with our customer.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.3 Purpose : Administration and provision of support services and account services


Categories of personal data we process :
● Technical support and feedback
● Billing and administration
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to provide our support services, account services, etc.

Legal basis :
The processing is necessary for our legitimate interest in processing your personal data in order to administer the provision of our services, which we assess outweighs the data subjects’ interest in privacy.

Retention period :
Personal data stored to administer the provision of the services will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as you are a user of the services. We may also need to store your personal data for a reasonable time thereafter in order to administer the ending of your account and fulfill any terms of our agreement with our customer.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.




3.3.4 Purpose : To improve our services by training our algorithms


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to improve our services by training our algorithms.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Legal basis :
Processing is necessary for our legitimate interest in improving our services by training our algorithms, which we assess outweighs the data subjects’ interest in privacy.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Retention period :
We store your personal data as long as necessary in order to train and improve the algorithms used in our services. We will not store such personal data for a longer time period than one year without anonymizing it.Your rights : You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.5 Purpose : For statistics, analysis, business development, and recruiting


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We use your personal data within our market and customer analyses of our services which mainly constitute usage statistics and data from customer analyses.We also use third party tracking services to provide relevant and tailored services. We do not share your personal data with partners of four40.The result of our analysis is used to get insight into the needs of our users.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Legal basis :
Processing is necessary for our legitimate interest in analyzing the use of our services and websites in order to improve our business and services or develop new services, which we assess outweighs the data subjects’ interest in privacy.Your consent, in relation to the processing of personal data in the form of cookies that is not necessary for the function of the service, in order to analyze the use of our website and our services.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Retention period :
Personal data stored in order to create statistics, analysis, and business development will be retained as long as necessary to fulfill the purpose, but no longer than one year without anonymizing it.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. When our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. Please see below for more information about your rights.



3.3.6 Purpose : To market our Company and services through newsletters, social media, publications, and events


Categories of personal data we process :
● Billing and administration
● IP Address
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data within the scope of our marketing, as we provide relevant and tailored communication to our audience. We do not share your personal data with our affiliates and / or partners.

Legal basis :
Processing is necessary for the purposes of our legitimate interests to be able to market our services. four40’s legitimate interest outweighs the data subjects’ right to privacy as four40 processes personal data that is not characterized by sensitivity to data subjects’ integrity and because the data subject has the right to object to the processing of his or her personal data for marketing purposes.Your consent, in relation to our processing of your anonymized personal data in social media, publications, and events.

Retention period :
Personal data processed to contact you for marketing purposes will be stored for one year from the date when we collected your data or the date when we last used your data to contact you. You may at any time unsubscribe from our mailings. If you unsubscribe, you will no longer receive mailings.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. When our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. Please see below for more information about your rights.



3.3.7 Purpose : To prevent fraud and other abuse


Categories of personal data we process :
● User

● Content

● Device

● User activity
● Technical support and feedback

● Any additional information you share through email / chat communication with us


What we do :
We process your personal data in order to prevent fraud and other abuse of our services or etc


Legal basis :
Processing is necessary for our legitimate interest of preventing fraud related to our services and ensuring that our services and/or websites are not used for other purposes than intended which overrides the interest of protection of your privacy.


Retention period :
We will store your personal data for the purposes to prevent fraud and other abuse as long as you are necessary to fulfill the purpose but no longer than one year.


Your rights :

You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.8 Purpose : To comply with legal obligations


Categories of personal data we process :
● User

● Content

● Device

● User activity
● Technical support and feedback

● Any additional information you share through email / chat communication with us


What we do :
We process your personal data in order to prevent fraud and other abuse of our services or etc.


Legal basis :
We need to process personal data to comply with our legal obligations under applicable legislation, and to respond to your request to exercise your rights under the GDPR.


Retention period :
We will store your personal data as long as necessary for us to fulfill our legal obligations as applicable with the local jurisdiction.


Your rights :

Please see below for more information about your rights.



3.3.9 Purpose : To establish and defend against legal claims


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
In case of a dispute, we are entitled to process your personal data to establish, exercise, or defend the legal claim.

Legal basis :
Processing is necessary for the purposes of our legitimate interests of the establishment, exercise, or defense of legal claims. In case of a dispute, we are entitled to process your personal data since we assess that our interest in safeguarding our interests in a dispute overrides your interest in the protection of your privacy.

Retention period :
We will store your data for the purposes of establishing or defending four40 against legal claims for as long as you can make legal claims against us. This means that we may store personal data during any warranty period and until any limitation period has expired. 

Your rights :
Please see below for more information about your rights.



4. Collection of personal data


4.1 Personal data you provide to us


The personal data that we process about you is data that you have provided us with or that we have otherwise acquired as part of the provision of our services. 


We collect personal data:

  • If you are a User of a Company Subscriber, when we initiate a business relationship with a new company subscriber;

  • When you create an account to use our services or create a new user for that account;

  • When you submit user-interaction data to our services;

  • When you complete transactions through our websites, such as fulfilling an order for our services;

  • When you perform search queries on our websites;

  • When you contact our support team;

  • Through online forms and otherwise through our websites;

  • When you apply for a job;

  • When you seek general information about the company;

  • Through emails sent to and from four40; and

  • When you share information with us through other means, such as meetings, conversations, social media, or online forms.



4.2 Personal data that we collect from other sources


We may also collect or receive information about you from other sources such as public registers. If you are a User of a Company Subscriber, we may collect personal data provided by the company subscriber, for example when the company subscriber invites you to use the service. We collect personal data from other sources such as:

  • If you are a User of a Company Subscriber, the company subscriber;


We may in the future collect personal data from the following sources

  • LinkedIn Website Retargeting;

  • Google Analytics (Google Ireland Limited);

  • Google Tag Manager (Google Ireland Limited);

  • Facebook Ads conversion tracking (Facebook pixel) (Facebook Ireland Ltd).




5. Retention of personal data


We retain your personal data only for as long as necessary for the purposes for which we originally collected the data in accordance with this Privacy Notice. When we no longer need to save your data, we will remove it from our systems, databases, and backups. The retention time depends on the context and cannot in all cases be specified, in that case, we will provide information about the factors deciding the retention time.

If return or destruction is impracticable or incidentally prohibited by a valid legal order, four40 shall take measures to inform you and block such personal data from any further processing (except to the extent necessary for its continued hosting or processing required by applicable law) and shall continue to appropriately protect the personal data remaining in its possession, custody, or control and, where any authorized sub-processor continues to possess personal data, require the authorized sub-processor to take the same measures that would be required of four40.

For more detailed information on how long we retain your personal data in relation to our purposes of the processing, see Section 3.


6. With whom do we share your personal data?


We may share personal data with third parties that are trusted recipients and with whom we have an agreement ensuring that your personal data is processed in accordance with this Privacy Notice. We may share data with:

  • If you are a User of a Company Subscriber, the respective Company Subscriber under the terms of the Agreement;

  • Our subsidiaries and affiliates;

  • Third party service providers such as:

    • Google (Google Ireland Limited),

    • Open AI (Open AI LP),

    • Slack (Slack Technologies, LLC),

    • Tally (Typeform SL),

    • Amazon Web Services;

  • A buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of four40's assets;


In certain circumstances, we may also need to disclose personal data upon the request from authorities or to third parties in connection with court proceedings or business acquisition or combination processes, or other similar processes.


We do not and will not sell your personal data.



7. Where do we use your personal data?


four40 will process your personal data within the EU/EEA. However, we occasionally need to transfer personal data to third countries, either directly or through our sub-processors. If we engage in such transfer, we will ensure that there is a legal basis for the transfer and that the level of protection is equivalent to that applicable within the EU/EEA, either by ensuring that the country has an adequate level of protection, that we have taken adequate protective measures such as the European Commission’s standard contractual clauses, that you have given your explicit consent or that the transfer is necessary with regards to the purposes set out in article 49 of the GDPR.



8. Your rights


8.1 Our responsibilities for your rights


In the capacity of data controller, we are responsible for ensuring that your personal data is processed in compliance with applicable laws and that you can exercise your rights. You may contact us at any time if you wish to exercise your rights. You will find our contact details at the end of this Privacy Notice.

We have an obligation to respond to your requests to exercise your rights within one month of receiving your request. If your request is complex or if we have received many requests, we have the right to extend this deadline to two more months. If we are unable to take the action you request within one month, we will inform you of the reason for the delay and of your right to lodge a complaint with a supervisory authority and to seek judicial remedy.

You will not be charged for requesting information, for communication, or measures that we carry out. However, if your request is manifestly unfounded or excessive, we may charge an administrative fee for providing the information or taking the action requested or refuse to act on your request altogether.


8.2 Your rights to access, rectification, erasure, and restriction


You have the right to request:


Access to your personal data. This means that you have the right to request access to the personal data that we hold about you. You also have the right to be provided, at no cost, a copy of the personal data about you that we are processing. We have the right to charge a reasonable administration fee if you request further copies. If you make a request in electronic form, e.g. via email, we will provide you with the information in a commonly used electronic format.

Rectification of your personal data. At your request or on our own initiative, we will correct, anonymize, delete or complement data that is inaccurate, incomplete, or misleading. You also have the right to complete any incomplete personal data if something relevant is missing.


Erasure of your personal data. You have the right to request that we delete your personal data if there is no compelling reason for us to continue processing the data. Personal data should therefore be erased if:

  • it is no longer needed for the purpose for which we collected it;

  • we process your personal data based on the consent provided by you and you withdraw your consent;

  • you object to us processing your data based on a legitimate interest assessment and we have no compelling interest that overrides your interests and rights;

  • we have processed the personal data unlawfully;

  • or we have a legal obligation to erase personal data.

However, there may be legal requirements or other compelling reasons that prevent us from immediately erasing your personal data. We will then stop processing your personal data for purposes other than in compliance with the law or where there are no compelling legitimate grounds for doing so.

In the event you would like to exercise your right for the erasure of your personal data, please use this form and send an email with the subject line “Erasure of Personal Data Request” and the completed form attached to contact@four40.work

We will confirm receipt of the completed form and take reasonable steps to ensure you are the data subject. Upon verification, we will complete the erasure without undue delay.


Restriction of processing. This means that we temporarily restrict the processing of your data. You have the right to request restriction when:

  • you consider your data to be inaccurate and you have requested rectification as defined above, while we establish the accuracy of the data;

  • the processing is unlawful and you do not want the data to be erased;

  • as the personal data controller, we no longer need the personal data for our processing purposes, but you need them to be able to establish, exercise, or defend a legal claim;

  • or you have objected to processing as defined in Section 9.3.1, while waiting for us to consider whether our legitimate interests override yours.


We will take all reasonable measures possible to notify everyone who has received personal data as stated in Section 7 above if we have rectified, erased, or restricted access to your personal data after you have requested us to do so. If you request information on recipients of your personal data, we will inform you about the recipients.


Your right to object to processing


You have the right to object to the processing of your personal data if our processing is based upon legitimate interests (see Section 3 above). If you object to such processing, we will only continue to process your data if we have compelling reasons for doing so that override your interests.

If you do not wish that we use your personal data for direct marketing, you have the right to object to such processing by contacting us. We will cease to use your data for that purpose when we have received your objection.


Your right to withdraw your consent


When we need your consent in order to process your personal data, you always have the right to withdraw such consent at any time by contacting us.


Your right to data portability


You have the right to data portability. This means the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that these data are transferred to another personal data controller. The right to data portability only applies when the processing is being carried out by automated means and our lawful basis for processing your data is the performance of an agreement between you and us or your consent.


Your right to complain to a supervisory authority


You have the right to lodge a complaint with the French Data Protection Authority if you are not satisfied with our processing of your personal data.



9. Protection of your personal data


We always want you to feel confident about providing us with your personal data. We have therefore taken appropriate security measures to protect your personal data against unauthorized access, alteration, and erasure. Even though we work hard to protect your data, no security measures are perfect or impenetrable. Should a security breach occur that may materially impact you or your personal data, e.g., risk of fraud or identity theft, we will contact you to explain what action you can take to mitigate potential adverse effects of the breach.

We strongly advise you to be cautious and to protect your own personal data. You are responsible for keeping your passwords confidential and avoiding others from observing your personal data when us10. Cookies

We use cookies that may include personal data to improve, analyze and administer our websites and services and your experience of them. You can find more information about this in our Cookie Notice.



10. Changes to the Privacy Notice


We have the right to make changes to this Privacy Notice at any time. When we make changes that are not purely editorial, such as formatting, typographical error corrections, or other changes that do not materially affect you, we will inform you of these changes and what they mean for you before they become effective.



12. Contact detail


Do not hesitate to contact us if you have any questions about this Privacy Notice, our processing of your personal data, or if you wish to exercise your rights.


For any inquiries, please contact us at contact@four40.work

four40 is committed to protecting and respecting your privacy


We want you to feel safe when we process your personal data. Our Privacy Notice explains how we ensure that your personal data is handled in compliance with applicable legislation and it applies to our processing of personal data, in the capacity of data controller relating to our customers and users of our services, visitors to our websites, and to other business contacts.


And because it may be what you care most about, let us start by saying that none of your company or personal data is and will ever be used to train external AI services.

Any AI service embedded in four40 App and Services is either self-hosted on our end or customer's end, or leveraging private technologies (OpenAI). In the latter case, we use enterprise-grade infrastructures (in AWS or Azure) to silo your proprietary data from the models we use to query and retrieve it.


If you are a user of our services, you either use our services as:

  • a consumer user ("Consumer User”), for example, if you have signed up for our services yourself, visiting our website, or if you apply for a job; or

  • a user invited to use a service by a company or other entity which is a customer of ours (“User of Company Subscriber”), for example, if you are invited to use the services by your employer.


Please note that some of our processing of personal data differs depending on if you are a Consumer User or a User of Company Subscriber, which is why we ensure to always state in our Privacy Notice if the processing only applies for a particular group of users. If you are a User of a Company Subscriber, we process your personal data in the capacity of data processor, when providing our services to our company subscriber (i.e., the entity that invited you to use the service, for example, your employer). In relation to such processing, the company subscriber is data controller and hence responsible for providing information to you about its processing of personal data.

We only use your personal data for the purposes specified in this Privacy Notice and not in any manner that is incompatible with those purposes.



1. General


four40, 951 169 572 R.C.S. Paris, (“four40,” "us," “we,” or "our") is committed to protecting and respecting your privacy. We want you to feel that we respect your privacy when we process your personal data. This Privacy Notice (“Privacy Notice”) explains how we ensure that your personal data is handled in compliance with applicable legislation and applies to all of our processing of personal data relating to our customers and users of our services, visitors to our websites, and to other business contacts. We use your personal data to be able to operate our business and meet our obligations and responsibilities in relation to applicable legislation and good industry practice.



2. Data controller


four40 is the data controller for the processing of your personal data and is responsible for ensuring that the processing is carried out in accordance with applicable legislation. If you have any questions regarding the processing of your personal data, you will find our contact details at the end of this Privacy Notice.



3. Our use of your personal data 


3.1 The purposes of processing


We use your personal data for the following purposes:

  • If you are a Consumer User, to provide and manage our services;

  • If you are a User of a Company Subscriber, to administer the agreement with our subscriber;

  • Administration and provision of support services and account services;

  • To improve our services by training our algorithms;

  • For statistics, analysis, and business development;

  • To market our services through newsletters, social media, publications, and events;

  • To prevent fraud and other abuse;

  • To comply with legal obligations;

  • To establish and defend legal claims; and

  • To enable mergers, divestitures, restructuring, reorganization, dissolution, and other sale or transfers of four40 assets.


3.2 Categories of personal data processed

User

  • Name

  • Email

  • Username

  • Password

  • Alphanumeric identifier

Content

  • Search queries: end-user’s submitted queries

  • Third-party content: content from Subscriber’s pre-approved integrations

    • From Google Calendar integration

    • From Slack integration

Activity

  • Event logs (e.g., action taken, event type, event location, timestamp, client ID, user ID, and channel ID)

  • Cookies

  • Session information (e.g., frequency, average and actual duration, quantity, quality, network activity, and network connectivity)

  • Session facilitator/participant ID

  • Support

    • Troubleshooting subject

    • Problem description

    • Post-session feedback

    • User-supplied attachments (e.g., recordings, transcripts or screenshots, text, post-session feedback)

  • Billing and administration

    • First and last name

    • Signature

    • Email

    • Phone number

    • Address


3.3 How we process your personal data for each purpose


Below you can find more information about our processing of your personal data in relation to our purposes of processing:



3.3.1 Purpose : If you are a Consumer User, to provide and manage our services


Categories of personal data we process :
● User
● Content
● Device
● User Activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to provide you with our services and use of our services and to communicate with you.

Legal basis :
The processing is necessary for the purpose of fulfilling the agreement with you, including administering our services.

Retention period :
Personal data stored to provide and manage our services will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as you have an account to use our services or websites, or as set forth in our agreement. We may also need to store your personal data for a reasonable time thereafter in order to fulfill any surviving terms of our agreements.

Your rights :
Please see below for information about your rights.



3.3.2 Purpose : If you are a User of a Company Subscriber, to administer the agreement with our subscribers


Categories of personal data we process :
● Technical support and feedback
● Billing and administration
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to be able to administrate the agreement with the Company Subscriber by processing information such as the contact person at the Company Subscriber.

Legal basis :
The processing is necessary for our legitimate interest in processing your personal data in order to administer the agreement with our customers, which we assess, outweighs the data subjects’ interest in privacy.

Retention period :
Personal data stored to administer the agreement with our customer will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as the agreement is valid, and you are the appointed contact person or similar. We may also need to store your personal data for a reasonable time thereafter in order to fulfill any surviving terms of our agreement with our customer.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.3 Purpose : Administration and provision of support services and account services


Categories of personal data we process :
● Technical support and feedback
● Billing and administration
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to provide our support services, account services, etc.

Legal basis :
The processing is necessary for our legitimate interest in processing your personal data in order to administer the provision of our services, which we assess outweighs the data subjects’ interest in privacy.

Retention period :
Personal data stored to administer the provision of the services will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as you are a user of the services. We may also need to store your personal data for a reasonable time thereafter in order to administer the ending of your account and fulfill any terms of our agreement with our customer.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.




3.3.4 Purpose : To improve our services by training our algorithms


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to improve our services by training our algorithms.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Legal basis :
Processing is necessary for our legitimate interest in improving our services by training our algorithms, which we assess outweighs the data subjects’ interest in privacy.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Retention period :
We store your personal data as long as necessary in order to train and improve the algorithms used in our services. We will not store such personal data for a longer time period than one year without anonymizing it.Your rights : You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.5 Purpose : For statistics, analysis, business development, and recruiting


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We use your personal data within our market and customer analyses of our services which mainly constitute usage statistics and data from customer analyses.We also use third party tracking services to provide relevant and tailored services. We do not share your personal data with partners of four40.The result of our analysis is used to get insight into the needs of our users.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Legal basis :
Processing is necessary for our legitimate interest in analyzing the use of our services and websites in order to improve our business and services or develop new services, which we assess outweighs the data subjects’ interest in privacy.Your consent, in relation to the processing of personal data in the form of cookies that is not necessary for the function of the service, in order to analyze the use of our website and our services.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Retention period :
Personal data stored in order to create statistics, analysis, and business development will be retained as long as necessary to fulfill the purpose, but no longer than one year without anonymizing it.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. When our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. Please see below for more information about your rights.



3.3.6 Purpose : To market our Company and services through newsletters, social media, publications, and events


Categories of personal data we process :
● Billing and administration
● IP Address
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data within the scope of our marketing, as we provide relevant and tailored communication to our audience. We do not share your personal data with our affiliates and / or partners.

Legal basis :
Processing is necessary for the purposes of our legitimate interests to be able to market our services. four40’s legitimate interest outweighs the data subjects’ right to privacy as four40 processes personal data that is not characterized by sensitivity to data subjects’ integrity and because the data subject has the right to object to the processing of his or her personal data for marketing purposes.Your consent, in relation to our processing of your anonymized personal data in social media, publications, and events.

Retention period :
Personal data processed to contact you for marketing purposes will be stored for one year from the date when we collected your data or the date when we last used your data to contact you. You may at any time unsubscribe from our mailings. If you unsubscribe, you will no longer receive mailings.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. When our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. Please see below for more information about your rights.



3.3.7 Purpose : To prevent fraud and other abuse


Categories of personal data we process :
● User

● Content

● Device

● User activity
● Technical support and feedback

● Any additional information you share through email / chat communication with us


What we do :
We process your personal data in order to prevent fraud and other abuse of our services or etc


Legal basis :
Processing is necessary for our legitimate interest of preventing fraud related to our services and ensuring that our services and/or websites are not used for other purposes than intended which overrides the interest of protection of your privacy.


Retention period :
We will store your personal data for the purposes to prevent fraud and other abuse as long as you are necessary to fulfill the purpose but no longer than one year.


Your rights :

You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.8 Purpose : To comply with legal obligations


Categories of personal data we process :
● User

● Content

● Device

● User activity
● Technical support and feedback

● Any additional information you share through email / chat communication with us


What we do :
We process your personal data in order to prevent fraud and other abuse of our services or etc.


Legal basis :
We need to process personal data to comply with our legal obligations under applicable legislation, and to respond to your request to exercise your rights under the GDPR.


Retention period :
We will store your personal data as long as necessary for us to fulfill our legal obligations as applicable with the local jurisdiction.


Your rights :

Please see below for more information about your rights.



3.3.9 Purpose : To establish and defend against legal claims


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
In case of a dispute, we are entitled to process your personal data to establish, exercise, or defend the legal claim.

Legal basis :
Processing is necessary for the purposes of our legitimate interests of the establishment, exercise, or defense of legal claims. In case of a dispute, we are entitled to process your personal data since we assess that our interest in safeguarding our interests in a dispute overrides your interest in the protection of your privacy.

Retention period :
We will store your data for the purposes of establishing or defending four40 against legal claims for as long as you can make legal claims against us. This means that we may store personal data during any warranty period and until any limitation period has expired. 

Your rights :
Please see below for more information about your rights.



4. Collection of personal data


4.1 Personal data you provide to us


The personal data that we process about you is data that you have provided us with or that we have otherwise acquired as part of the provision of our services. 


We collect personal data:

  • If you are a User of a Company Subscriber, when we initiate a business relationship with a new company subscriber;

  • When you create an account to use our services or create a new user for that account;

  • When you submit user-interaction data to our services;

  • When you complete transactions through our websites, such as fulfilling an order for our services;

  • When you perform search queries on our websites;

  • When you contact our support team;

  • Through online forms and otherwise through our websites;

  • When you apply for a job;

  • When you seek general information about the company;

  • Through emails sent to and from four40; and

  • When you share information with us through other means, such as meetings, conversations, social media, or online forms.



4.2 Personal data that we collect from other sources


We may also collect or receive information about you from other sources such as public registers. If you are a User of a Company Subscriber, we may collect personal data provided by the company subscriber, for example when the company subscriber invites you to use the service. We collect personal data from other sources such as:

  • If you are a User of a Company Subscriber, the company subscriber;


We may in the future collect personal data from the following sources

  • LinkedIn Website Retargeting;

  • Google Analytics (Google Ireland Limited);

  • Google Tag Manager (Google Ireland Limited);

  • Facebook Ads conversion tracking (Facebook pixel) (Facebook Ireland Ltd).




5. Retention of personal data


We retain your personal data only for as long as necessary for the purposes for which we originally collected the data in accordance with this Privacy Notice. When we no longer need to save your data, we will remove it from our systems, databases, and backups. The retention time depends on the context and cannot in all cases be specified, in that case, we will provide information about the factors deciding the retention time.

If return or destruction is impracticable or incidentally prohibited by a valid legal order, four40 shall take measures to inform you and block such personal data from any further processing (except to the extent necessary for its continued hosting or processing required by applicable law) and shall continue to appropriately protect the personal data remaining in its possession, custody, or control and, where any authorized sub-processor continues to possess personal data, require the authorized sub-processor to take the same measures that would be required of four40.

For more detailed information on how long we retain your personal data in relation to our purposes of the processing, see Section 3.


6. With whom do we share your personal data?


We may share personal data with third parties that are trusted recipients and with whom we have an agreement ensuring that your personal data is processed in accordance with this Privacy Notice. We may share data with:

  • If you are a User of a Company Subscriber, the respective Company Subscriber under the terms of the Agreement;

  • Our subsidiaries and affiliates;

  • Third party service providers such as:

    • Google (Google Ireland Limited),

    • Open AI (Open AI LP),

    • Slack (Slack Technologies, LLC),

    • Tally (Typeform SL),

    • Amazon Web Services;

  • A buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of four40's assets;


In certain circumstances, we may also need to disclose personal data upon the request from authorities or to third parties in connection with court proceedings or business acquisition or combination processes, or other similar processes.


We do not and will not sell your personal data.



7. Where do we use your personal data?


four40 will process your personal data within the EU/EEA. However, we occasionally need to transfer personal data to third countries, either directly or through our sub-processors. If we engage in such transfer, we will ensure that there is a legal basis for the transfer and that the level of protection is equivalent to that applicable within the EU/EEA, either by ensuring that the country has an adequate level of protection, that we have taken adequate protective measures such as the European Commission’s standard contractual clauses, that you have given your explicit consent or that the transfer is necessary with regards to the purposes set out in article 49 of the GDPR.



8. Your rights


8.1 Our responsibilities for your rights


In the capacity of data controller, we are responsible for ensuring that your personal data is processed in compliance with applicable laws and that you can exercise your rights. You may contact us at any time if you wish to exercise your rights. You will find our contact details at the end of this Privacy Notice.

We have an obligation to respond to your requests to exercise your rights within one month of receiving your request. If your request is complex or if we have received many requests, we have the right to extend this deadline to two more months. If we are unable to take the action you request within one month, we will inform you of the reason for the delay and of your right to lodge a complaint with a supervisory authority and to seek judicial remedy.

You will not be charged for requesting information, for communication, or measures that we carry out. However, if your request is manifestly unfounded or excessive, we may charge an administrative fee for providing the information or taking the action requested or refuse to act on your request altogether.


8.2 Your rights to access, rectification, erasure, and restriction


You have the right to request:


Access to your personal data. This means that you have the right to request access to the personal data that we hold about you. You also have the right to be provided, at no cost, a copy of the personal data about you that we are processing. We have the right to charge a reasonable administration fee if you request further copies. If you make a request in electronic form, e.g. via email, we will provide you with the information in a commonly used electronic format.

Rectification of your personal data. At your request or on our own initiative, we will correct, anonymize, delete or complement data that is inaccurate, incomplete, or misleading. You also have the right to complete any incomplete personal data if something relevant is missing.


Erasure of your personal data. You have the right to request that we delete your personal data if there is no compelling reason for us to continue processing the data. Personal data should therefore be erased if:

  • it is no longer needed for the purpose for which we collected it;

  • we process your personal data based on the consent provided by you and you withdraw your consent;

  • you object to us processing your data based on a legitimate interest assessment and we have no compelling interest that overrides your interests and rights;

  • we have processed the personal data unlawfully;

  • or we have a legal obligation to erase personal data.

However, there may be legal requirements or other compelling reasons that prevent us from immediately erasing your personal data. We will then stop processing your personal data for purposes other than in compliance with the law or where there are no compelling legitimate grounds for doing so.

In the event you would like to exercise your right for the erasure of your personal data, please use this form and send an email with the subject line “Erasure of Personal Data Request” and the completed form attached to contact@four40.work

We will confirm receipt of the completed form and take reasonable steps to ensure you are the data subject. Upon verification, we will complete the erasure without undue delay.


Restriction of processing. This means that we temporarily restrict the processing of your data. You have the right to request restriction when:

  • you consider your data to be inaccurate and you have requested rectification as defined above, while we establish the accuracy of the data;

  • the processing is unlawful and you do not want the data to be erased;

  • as the personal data controller, we no longer need the personal data for our processing purposes, but you need them to be able to establish, exercise, or defend a legal claim;

  • or you have objected to processing as defined in Section 9.3.1, while waiting for us to consider whether our legitimate interests override yours.


We will take all reasonable measures possible to notify everyone who has received personal data as stated in Section 7 above if we have rectified, erased, or restricted access to your personal data after you have requested us to do so. If you request information on recipients of your personal data, we will inform you about the recipients.


Your right to object to processing


You have the right to object to the processing of your personal data if our processing is based upon legitimate interests (see Section 3 above). If you object to such processing, we will only continue to process your data if we have compelling reasons for doing so that override your interests.

If you do not wish that we use your personal data for direct marketing, you have the right to object to such processing by contacting us. We will cease to use your data for that purpose when we have received your objection.


Your right to withdraw your consent


When we need your consent in order to process your personal data, you always have the right to withdraw such consent at any time by contacting us.


Your right to data portability


You have the right to data portability. This means the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that these data are transferred to another personal data controller. The right to data portability only applies when the processing is being carried out by automated means and our lawful basis for processing your data is the performance of an agreement between you and us or your consent.


Your right to complain to a supervisory authority


You have the right to lodge a complaint with the French Data Protection Authority if you are not satisfied with our processing of your personal data.



9. Protection of your personal data


We always want you to feel confident about providing us with your personal data. We have therefore taken appropriate security measures to protect your personal data against unauthorized access, alteration, and erasure. Even though we work hard to protect your data, no security measures are perfect or impenetrable. Should a security breach occur that may materially impact you or your personal data, e.g., risk of fraud or identity theft, we will contact you to explain what action you can take to mitigate potential adverse effects of the breach.

We strongly advise you to be cautious and to protect your own personal data. You are responsible for keeping your passwords confidential and avoiding others from observing your personal data when us10. Cookies

We use cookies that may include personal data to improve, analyze and administer our websites and services and your experience of them. You can find more information about this in our Cookie Notice.



10. Changes to the Privacy Notice


We have the right to make changes to this Privacy Notice at any time. When we make changes that are not purely editorial, such as formatting, typographical error corrections, or other changes that do not materially affect you, we will inform you of these changes and what they mean for you before they become effective.



12. Contact detail


Do not hesitate to contact us if you have any questions about this Privacy Notice, our processing of your personal data, or if you wish to exercise your rights.


For any inquiries, please contact us at contact@four40.work

four40 is committed to protecting and respecting your privacy


We want you to feel safe when we process your personal data. Our Privacy Notice explains how we ensure that your personal data is handled in compliance with applicable legislation and it applies to our processing of personal data, in the capacity of data controller relating to our customers and users of our services, visitors to our websites, and to other business contacts.


And because it may be what you care most about, let us start by saying that none of your company or personal data is and will ever be used to train external AI services.

Any AI service embedded in four40 App and Services is either self-hosted on our end or customer's end, or leveraging private technologies (OpenAI). In the latter case, we use enterprise-grade infrastructures (in AWS or Azure) to silo your proprietary data from the models we use to query and retrieve it.


If you are a user of our services, you either use our services as:

  • a consumer user ("Consumer User”), for example, if you have signed up for our services yourself, visiting our website, or if you apply for a job; or

  • a user invited to use a service by a company or other entity which is a customer of ours (“User of Company Subscriber”), for example, if you are invited to use the services by your employer.


Please note that some of our processing of personal data differs depending on if you are a Consumer User or a User of Company Subscriber, which is why we ensure to always state in our Privacy Notice if the processing only applies for a particular group of users. If you are a User of a Company Subscriber, we process your personal data in the capacity of data processor, when providing our services to our company subscriber (i.e., the entity that invited you to use the service, for example, your employer). In relation to such processing, the company subscriber is data controller and hence responsible for providing information to you about its processing of personal data.

We only use your personal data for the purposes specified in this Privacy Notice and not in any manner that is incompatible with those purposes.



1. General


four40, 951 169 572 R.C.S. Paris, (“four40,” "us," “we,” or "our") is committed to protecting and respecting your privacy. We want you to feel that we respect your privacy when we process your personal data. This Privacy Notice (“Privacy Notice”) explains how we ensure that your personal data is handled in compliance with applicable legislation and applies to all of our processing of personal data relating to our customers and users of our services, visitors to our websites, and to other business contacts. We use your personal data to be able to operate our business and meet our obligations and responsibilities in relation to applicable legislation and good industry practice.



2. Data controller


four40 is the data controller for the processing of your personal data and is responsible for ensuring that the processing is carried out in accordance with applicable legislation. If you have any questions regarding the processing of your personal data, you will find our contact details at the end of this Privacy Notice.



3. Our use of your personal data 


3.1 The purposes of processing


We use your personal data for the following purposes:

  • If you are a Consumer User, to provide and manage our services;

  • If you are a User of a Company Subscriber, to administer the agreement with our subscriber;

  • Administration and provision of support services and account services;

  • To improve our services by training our algorithms;

  • For statistics, analysis, and business development;

  • To market our services through newsletters, social media, publications, and events;

  • To prevent fraud and other abuse;

  • To comply with legal obligations;

  • To establish and defend legal claims; and

  • To enable mergers, divestitures, restructuring, reorganization, dissolution, and other sale or transfers of four40 assets.


3.2 Categories of personal data processed

User

  • Name

  • Email

  • Username

  • Password

  • Alphanumeric identifier

Content

  • Search queries: end-user’s submitted queries

  • Third-party content: content from Subscriber’s pre-approved integrations

    • From Google Calendar integration

    • From Slack integration

Activity

  • Event logs (e.g., action taken, event type, event location, timestamp, client ID, user ID, and channel ID)

  • Cookies

  • Session information (e.g., frequency, average and actual duration, quantity, quality, network activity, and network connectivity)

  • Session facilitator/participant ID

  • Support

    • Troubleshooting subject

    • Problem description

    • Post-session feedback

    • User-supplied attachments (e.g., recordings, transcripts or screenshots, text, post-session feedback)

  • Billing and administration

    • First and last name

    • Signature

    • Email

    • Phone number

    • Address


3.3 How we process your personal data for each purpose


Below you can find more information about our processing of your personal data in relation to our purposes of processing:



3.3.1 Purpose : If you are a Consumer User, to provide and manage our services


Categories of personal data we process :
● User
● Content
● Device
● User Activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to provide you with our services and use of our services and to communicate with you.

Legal basis :
The processing is necessary for the purpose of fulfilling the agreement with you, including administering our services.

Retention period :
Personal data stored to provide and manage our services will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as you have an account to use our services or websites, or as set forth in our agreement. We may also need to store your personal data for a reasonable time thereafter in order to fulfill any surviving terms of our agreements.

Your rights :
Please see below for information about your rights.



3.3.2 Purpose : If you are a User of a Company Subscriber, to administer the agreement with our subscribers


Categories of personal data we process :
● Technical support and feedback
● Billing and administration
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to be able to administrate the agreement with the Company Subscriber by processing information such as the contact person at the Company Subscriber.

Legal basis :
The processing is necessary for our legitimate interest in processing your personal data in order to administer the agreement with our customers, which we assess, outweighs the data subjects’ interest in privacy.

Retention period :
Personal data stored to administer the agreement with our customer will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as the agreement is valid, and you are the appointed contact person or similar. We may also need to store your personal data for a reasonable time thereafter in order to fulfill any surviving terms of our agreement with our customer.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.3 Purpose : Administration and provision of support services and account services


Categories of personal data we process :
● Technical support and feedback
● Billing and administration
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to provide our support services, account services, etc.

Legal basis :
The processing is necessary for our legitimate interest in processing your personal data in order to administer the provision of our services, which we assess outweighs the data subjects’ interest in privacy.

Retention period :
Personal data stored to administer the provision of the services will be stored during the time period that it is necessary in order to fulfill the purposes with our processing, which is usually as long as you are a user of the services. We may also need to store your personal data for a reasonable time thereafter in order to administer the ending of your account and fulfill any terms of our agreement with our customer.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.




3.3.4 Purpose : To improve our services by training our algorithms


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data in order to improve our services by training our algorithms.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Legal basis :
Processing is necessary for our legitimate interest in improving our services by training our algorithms, which we assess outweighs the data subjects’ interest in privacy.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Retention period :
We store your personal data as long as necessary in order to train and improve the algorithms used in our services. We will not store such personal data for a longer time period than one year without anonymizing it.Your rights : You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.5 Purpose : For statistics, analysis, business development, and recruiting


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
We use your personal data within our market and customer analyses of our services which mainly constitute usage statistics and data from customer analyses.We also use third party tracking services to provide relevant and tailored services. We do not share your personal data with partners of four40.The result of our analysis is used to get insight into the needs of our users.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Legal basis :
Processing is necessary for our legitimate interest in analyzing the use of our services and websites in order to improve our business and services or develop new services, which we assess outweighs the data subjects’ interest in privacy.Your consent, in relation to the processing of personal data in the form of cookies that is not necessary for the function of the service, in order to analyze the use of our website and our services.We will ensure the personal data is pseudonymized and anonymized to the extent possible for us to fulfill the purpose of processing.

Retention period :
Personal data stored in order to create statistics, analysis, and business development will be retained as long as necessary to fulfill the purpose, but no longer than one year without anonymizing it.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. When our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. Please see below for more information about your rights.



3.3.6 Purpose : To market our Company and services through newsletters, social media, publications, and events


Categories of personal data we process :
● Billing and administration
● IP Address
● Any additional information you share through email / chat communication with us

What we do :
We process your personal data within the scope of our marketing, as we provide relevant and tailored communication to our audience. We do not share your personal data with our affiliates and / or partners.

Legal basis :
Processing is necessary for the purposes of our legitimate interests to be able to market our services. four40’s legitimate interest outweighs the data subjects’ right to privacy as four40 processes personal data that is not characterized by sensitivity to data subjects’ integrity and because the data subject has the right to object to the processing of his or her personal data for marketing purposes.Your consent, in relation to our processing of your anonymized personal data in social media, publications, and events.

Retention period :
Personal data processed to contact you for marketing purposes will be stored for one year from the date when we collected your data or the date when we last used your data to contact you. You may at any time unsubscribe from our mailings. If you unsubscribe, you will no longer receive mailings.

Your rights :
You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. When our processing of your personal data is based on your consent you have the right to withdraw your consent at any time. Please see below for more information about your rights.



3.3.7 Purpose : To prevent fraud and other abuse


Categories of personal data we process :
● User

● Content

● Device

● User activity
● Technical support and feedback

● Any additional information you share through email / chat communication with us


What we do :
We process your personal data in order to prevent fraud and other abuse of our services or etc


Legal basis :
Processing is necessary for our legitimate interest of preventing fraud related to our services and ensuring that our services and/or websites are not used for other purposes than intended which overrides the interest of protection of your privacy.


Retention period :
We will store your personal data for the purposes to prevent fraud and other abuse as long as you are necessary to fulfill the purpose but no longer than one year.


Your rights :

You have the right to object to the processing of your personal data based upon legitimate interest as legal basis. Please see below for more information about your rights.



3.3.8 Purpose : To comply with legal obligations


Categories of personal data we process :
● User

● Content

● Device

● User activity
● Technical support and feedback

● Any additional information you share through email / chat communication with us


What we do :
We process your personal data in order to prevent fraud and other abuse of our services or etc.


Legal basis :
We need to process personal data to comply with our legal obligations under applicable legislation, and to respond to your request to exercise your rights under the GDPR.


Retention period :
We will store your personal data as long as necessary for us to fulfill our legal obligations as applicable with the local jurisdiction.


Your rights :

Please see below for more information about your rights.



3.3.9 Purpose : To establish and defend against legal claims


Categories of personal data we process :
● User
● Content
● Device
● User activity
● Technical support and feedback
● Any additional information you share through email / chat communication with us

What we do :
In case of a dispute, we are entitled to process your personal data to establish, exercise, or defend the legal claim.

Legal basis :
Processing is necessary for the purposes of our legitimate interests of the establishment, exercise, or defense of legal claims. In case of a dispute, we are entitled to process your personal data since we assess that our interest in safeguarding our interests in a dispute overrides your interest in the protection of your privacy.

Retention period :
We will store your data for the purposes of establishing or defending four40 against legal claims for as long as you can make legal claims against us. This means that we may store personal data during any warranty period and until any limitation period has expired. 

Your rights :
Please see below for more information about your rights.



4. Collection of personal data


4.1 Personal data you provide to us


The personal data that we process about you is data that you have provided us with or that we have otherwise acquired as part of the provision of our services. 


We collect personal data:

  • If you are a User of a Company Subscriber, when we initiate a business relationship with a new company subscriber;

  • When you create an account to use our services or create a new user for that account;

  • When you submit user-interaction data to our services;

  • When you complete transactions through our websites, such as fulfilling an order for our services;

  • When you perform search queries on our websites;

  • When you contact our support team;

  • Through online forms and otherwise through our websites;

  • When you apply for a job;

  • When you seek general information about the company;

  • Through emails sent to and from four40; and

  • When you share information with us through other means, such as meetings, conversations, social media, or online forms.



4.2 Personal data that we collect from other sources


We may also collect or receive information about you from other sources such as public registers. If you are a User of a Company Subscriber, we may collect personal data provided by the company subscriber, for example when the company subscriber invites you to use the service. We collect personal data from other sources such as:

  • If you are a User of a Company Subscriber, the company subscriber;


We may in the future collect personal data from the following sources

  • LinkedIn Website Retargeting;

  • Google Analytics (Google Ireland Limited);

  • Google Tag Manager (Google Ireland Limited);

  • Facebook Ads conversion tracking (Facebook pixel) (Facebook Ireland Ltd).




5. Retention of personal data


We retain your personal data only for as long as necessary for the purposes for which we originally collected the data in accordance with this Privacy Notice. When we no longer need to save your data, we will remove it from our systems, databases, and backups. The retention time depends on the context and cannot in all cases be specified, in that case, we will provide information about the factors deciding the retention time.

If return or destruction is impracticable or incidentally prohibited by a valid legal order, four40 shall take measures to inform you and block such personal data from any further processing (except to the extent necessary for its continued hosting or processing required by applicable law) and shall continue to appropriately protect the personal data remaining in its possession, custody, or control and, where any authorized sub-processor continues to possess personal data, require the authorized sub-processor to take the same measures that would be required of four40.

For more detailed information on how long we retain your personal data in relation to our purposes of the processing, see Section 3.


6. With whom do we share your personal data?


We may share personal data with third parties that are trusted recipients and with whom we have an agreement ensuring that your personal data is processed in accordance with this Privacy Notice. We may share data with:

  • If you are a User of a Company Subscriber, the respective Company Subscriber under the terms of the Agreement;

  • Our subsidiaries and affiliates;

  • Third party service providers such as:

    • Google (Google Ireland Limited),

    • Open AI (Open AI LP),

    • Slack (Slack Technologies, LLC),

    • Tally (Typeform SL),

    • Amazon Web Services;

  • A buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of four40's assets;


In certain circumstances, we may also need to disclose personal data upon the request from authorities or to third parties in connection with court proceedings or business acquisition or combination processes, or other similar processes.


We do not and will not sell your personal data.



7. Where do we use your personal data?


four40 will process your personal data within the EU/EEA. However, we occasionally need to transfer personal data to third countries, either directly or through our sub-processors. If we engage in such transfer, we will ensure that there is a legal basis for the transfer and that the level of protection is equivalent to that applicable within the EU/EEA, either by ensuring that the country has an adequate level of protection, that we have taken adequate protective measures such as the European Commission’s standard contractual clauses, that you have given your explicit consent or that the transfer is necessary with regards to the purposes set out in article 49 of the GDPR.



8. Your rights


8.1 Our responsibilities for your rights


In the capacity of data controller, we are responsible for ensuring that your personal data is processed in compliance with applicable laws and that you can exercise your rights. You may contact us at any time if you wish to exercise your rights. You will find our contact details at the end of this Privacy Notice.

We have an obligation to respond to your requests to exercise your rights within one month of receiving your request. If your request is complex or if we have received many requests, we have the right to extend this deadline to two more months. If we are unable to take the action you request within one month, we will inform you of the reason for the delay and of your right to lodge a complaint with a supervisory authority and to seek judicial remedy.

You will not be charged for requesting information, for communication, or measures that we carry out. However, if your request is manifestly unfounded or excessive, we may charge an administrative fee for providing the information or taking the action requested or refuse to act on your request altogether.


8.2 Your rights to access, rectification, erasure, and restriction


You have the right to request:


Access to your personal data. This means that you have the right to request access to the personal data that we hold about you. You also have the right to be provided, at no cost, a copy of the personal data about you that we are processing. We have the right to charge a reasonable administration fee if you request further copies. If you make a request in electronic form, e.g. via email, we will provide you with the information in a commonly used electronic format.

Rectification of your personal data. At your request or on our own initiative, we will correct, anonymize, delete or complement data that is inaccurate, incomplete, or misleading. You also have the right to complete any incomplete personal data if something relevant is missing.


Erasure of your personal data. You have the right to request that we delete your personal data if there is no compelling reason for us to continue processing the data. Personal data should therefore be erased if:

  • it is no longer needed for the purpose for which we collected it;

  • we process your personal data based on the consent provided by you and you withdraw your consent;

  • you object to us processing your data based on a legitimate interest assessment and we have no compelling interest that overrides your interests and rights;

  • we have processed the personal data unlawfully;

  • or we have a legal obligation to erase personal data.

However, there may be legal requirements or other compelling reasons that prevent us from immediately erasing your personal data. We will then stop processing your personal data for purposes other than in compliance with the law or where there are no compelling legitimate grounds for doing so.

In the event you would like to exercise your right for the erasure of your personal data, please use this form and send an email with the subject line “Erasure of Personal Data Request” and the completed form attached to contact@four40.work

We will confirm receipt of the completed form and take reasonable steps to ensure you are the data subject. Upon verification, we will complete the erasure without undue delay.


Restriction of processing. This means that we temporarily restrict the processing of your data. You have the right to request restriction when:

  • you consider your data to be inaccurate and you have requested rectification as defined above, while we establish the accuracy of the data;

  • the processing is unlawful and you do not want the data to be erased;

  • as the personal data controller, we no longer need the personal data for our processing purposes, but you need them to be able to establish, exercise, or defend a legal claim;

  • or you have objected to processing as defined in Section 9.3.1, while waiting for us to consider whether our legitimate interests override yours.


We will take all reasonable measures possible to notify everyone who has received personal data as stated in Section 7 above if we have rectified, erased, or restricted access to your personal data after you have requested us to do so. If you request information on recipients of your personal data, we will inform you about the recipients.


Your right to object to processing


You have the right to object to the processing of your personal data if our processing is based upon legitimate interests (see Section 3 above). If you object to such processing, we will only continue to process your data if we have compelling reasons for doing so that override your interests.

If you do not wish that we use your personal data for direct marketing, you have the right to object to such processing by contacting us. We will cease to use your data for that purpose when we have received your objection.


Your right to withdraw your consent


When we need your consent in order to process your personal data, you always have the right to withdraw such consent at any time by contacting us.


Your right to data portability


You have the right to data portability. This means the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that these data are transferred to another personal data controller. The right to data portability only applies when the processing is being carried out by automated means and our lawful basis for processing your data is the performance of an agreement between you and us or your consent.


Your right to complain to a supervisory authority


You have the right to lodge a complaint with the French Data Protection Authority if you are not satisfied with our processing of your personal data.



9. Protection of your personal data


We always want you to feel confident about providing us with your personal data. We have therefore taken appropriate security measures to protect your personal data against unauthorized access, alteration, and erasure. Even though we work hard to protect your data, no security measures are perfect or impenetrable. Should a security breach occur that may materially impact you or your personal data, e.g., risk of fraud or identity theft, we will contact you to explain what action you can take to mitigate potential adverse effects of the breach.

We strongly advise you to be cautious and to protect your own personal data. You are responsible for keeping your passwords confidential and avoiding others from observing your personal data when us10. Cookies

We use cookies that may include personal data to improve, analyze and administer our websites and services and your experience of them. You can find more information about this in our Cookie Notice.



10. Changes to the Privacy Notice


We have the right to make changes to this Privacy Notice at any time. When we make changes that are not purely editorial, such as formatting, typographical error corrections, or other changes that do not materially affect you, we will inform you of these changes and what they mean for you before they become effective.



12. Contact detail


Do not hesitate to contact us if you have any questions about this Privacy Notice, our processing of your personal data, or if you wish to exercise your rights.


For any inquiries, please contact us at contact@four40.work