Callback request

Privacy policy - RGPD

Last updated: September 2026 

1. About us

The data controller for the personal data described in this policy is E.I.H.F. (trading as Isofroid), a single-member simplified joint-stock company with a share capital of 79,990.00 euros, registered with the Lyon Trade and Companies Register under number 352 570 758, whose registered office is situated at 47 rue de la Noyeraie – 69490 Sarcey, France.

Contact: contact@eihf-isofroid.com

2. Data Protection Officer (DPO)

If you have any questions regarding the processing of your personal data or wish to exercise your rights, you may contact our Data Protection Officer at the address given above.

3. The data we collect, why we collect it, and the legal basis for doing so

The data we collect, as well as the purposes and legal bases for the associated processing, vary depending on the nature of our relationship with you.

3.1 Customers and prospective customers

We collect: surname, first name, job title, work email address, telephone number, company address, preferred language for correspondence, and a record of our communications.

Purpose Legal basis (Article 6 of the GDPR)
Processing enquiries, quotations, orders, invoicing and after-sales service Performance of the contract, or pre-contractual measures taken at your request (Art. 6-1(b))
Monitoring of the business relationship and targeted communications Legitimate interest: developing and managing our B2B business relationship (Art. 6(1)(f))
Sending newsletters Consent is obtained via a tick box that is not pre-ticked; consent may be withdrawn at any time via the unsubscribe link included in every email (Art. 6-1-a)
Statistical analysis of website traffic Legitimate interest in anonymised audience measurement, or consent where non-essential cookies are used — see our cookie management banner (Art. 6(1)(f) or 6(1)(a))

3.2 Partners and subcontractors

We collect the business contact details of contact persons at our business partners and subcontractors (name, job title, work email address, telephone number).

Purpose Legal basis (Article 6 of the GDPR)
Management of contractual and operational relationships with our partners and subcontractors Performance of the contract entered into with the partner organisation, or a legitimate interest in the proper management of our business relationships in respect of contacts who are not themselves signatories to the contract (Art. 6(1)(b) or 6(1)(f))

3.3 Job applicants

We collect: CVs, cover letters, contact details and career history, as part of our recruitment process, which is managed in-house by E.I.H.F.

Purpose Legal basis (Article 6 of the GDPR)
Management of applications and the recruitment process Pre-contractual measures taken at your request (Art. 6(1)(b))

4. Shelf life

Category Storage life
Customers For the entire duration of the business relationship, followed by archiving limited to the applicable statutory limitation period (in particular 5 years in respect of contractual liability), without prejudice to the accounting and tax storage periods required by law (10 years for accounting documents)
Prospects who have never been customers 3 years from the last contact
Partners and subcontractors The duration of the contractual relationship, plus the applicable statutory limitation period
Job applicants A maximum of 2 years after the last contact with the candidate, unless the candidate has expressly agreed to a longer storage period (CV database); deletion or anonymisation thereafter

5. Recipients of the data

Your data is intended for authorised teams at E.I.H.F. and, where applicable, the Seiven Group, in the course of their respective duties, as well as for our technical service providers (web hosting, sales management and email tools) acting as data processors within the meaning of Article 28 of the GDPR. No data is sold to third parties.

6. Data transfers outside the European Union

Your data is hosted within the European Union. Where some of our service providers are located outside the European Union, such transfers are governed by appropriate safeguards, such as the standard contractual clauses adopted by the European Commission.

7. Data security

We implement appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, disclosure, alteration or destruction.

8. Your rights

In accordance with the GDPR, you have the following rights in relation to your personal data: the right of access, rectification, erasure, restriction of processing, objection and data portability, as well as the right to withdraw your consent at any time where processing is based on consent, without this affecting the lawfulness of any processing carried out prior to such withdrawal.

You also have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — or via www.cnil.fr, if you believe that the processing of your data constitutes a breach of the GDPR.

To exercise these rights, you may contact us at the address given in section 1. We undertake to respond to your request within one (1) month, which may be extended by a further two months in the event of complexity or a high volume of requests.

9. Cookies

For further information on the cookies used on the Website and how to manage them, please refer to the cookie management banner on the Website.

10. Updates to this policy

This policy may be amended at any time, in particular to comply with any changes in legislation, regulations, case law or technical developments. The date of the last update is shown at the top of this document.