Privacy Policy
This English version is provided for convenience. In the event of any conflict or inconsistency between the two versions, the French version prevails.
1. Controller and roles
Ekomy operates a customer-review management platform for e-commerce merchants: post-purchase review collection by email and WhatsApp, moderation, analysis, and publication on the merchant’s storefront through an embeddable widget.
The entity operating Ekomy is Otospex Solutions LLC, a limited liability company (LLC) organized under the laws of the State of New Mexico, USA, trading under the business name “Ekomy”, whose registered office is at 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, USA. It operates together with its affiliated Tunisian company Otospex Solutions SARL, 17 Avenue Bourguiba, 4180 Houmet Souk, Djerba, Tunisia, through which local operations are conducted.
Any question relating to personal data may be sent to privacy@ekomy.io.
Roles depend on the purpose of the processing:
- For the data of a merchant’s end customers (contact details, orders, reviews): the merchant is the controller; Ekomy acts as a processor, on the merchant’s instructions and under a data processing agreement (DPA) available on request.
- For merchant accounts (identification and usage data of platform users) and for visitors to this website: Ekomy is the controller.
2. Data we process
In providing the service, we process the following categories:
- Merchant account data: name, business email address, phone number, password (hashed), settings of the connected store.
- End-customer data transmitted by the merchant’s store: name, email address, phone number, and order metadata (order reference, ordered products, date), including the content of order notifications sent by the store. This data is used exclusively to send and track review invitations.
- Invitation dispatch records: recipient, channel used (email or WhatsApp), dispatch status, access token for the review submission page.
- Review content: rating, text, any photos, the customer’s display name, merchant replies, moderation status.
- Messages exchanged through connected channels (WhatsApp, Messenger, Instagram): content of conversations between the end customer and the merchant, conversation identifiers, timestamps — processed to provide customer messaging and follow-up of requests.
- Technical logs and audit records: technical events needed for security, traceability and compliance. Compliance records use pseudonymized identifiers (cryptographic fingerprints), not the data in clear form.
- Access logs of this website: when you visit, the hosting server records standard access logs (IP address, browser, pages visited, timestamp), used solely for security and diagnostic purposes and kept for a short, defined period.
We do not collect any “special category” (sensitive) data and we do not sell any personal data.
3. WhatsApp and Meta flows
- WhatsApp invitations: when the merchant activates this channel, review invitations are sent through Meta’s WhatsApp Business Cloud API, using only message templates approved by Meta. The recipient’s number and the message content pass through Meta’s infrastructure in accordance with the WhatsApp Business platform terms.
- Inbound messaging: messages sent to the merchant on WhatsApp, Messenger or Instagram are received and processed so that the merchant can reply to them from a unified workspace.
- Data obtained from Meta platforms is used only to provide the service described in this policy, never for our own advertising purposes, for profiling or for resale. Meta’s privacy policy is available on Meta’s website.
- Deletion of the data linked to these channels is described on the Data deletion page.
4. Legal bases
- Performance of a contract: providing the platform to the merchant (accounts, store synchronization, invitation dispatch, moderation, widget).
- Legitimate interest: the merchant’s interest in collecting post-purchase feedback from its own customers, with due regard for individuals’ rights; security and integrity of the service.
- Consent: non-essential cookies and trackers on this site (see the cookie policy) — none are used to date; consent will be collected before any future activation.
- Legal obligation: keeping compliance records (erasure requests, pseudonymized audit records).
5. Retention periods
- Data is kept for the duration of the contract between Ekomy and the merchant, then deleted or anonymized.
- Where erasure is requested, deletion is carried out under the process described on the Data deletion page, with a cancellable 7-day grace period unless immediate execution is requested.
- Encrypted backups containing residual copies expire no later than 30 days after erasure; after any backup restoration, erasures are re-applied before the system returns to service.
- Pseudonymized compliance records (fingerprints of erased identifiers, log of requests) are kept for a defined period as evidence of compliance with legal obligations, with restricted access.
- Website access logs are kept for a short, defined period, for security purposes only.
- Your cookie consent choice (see the cookie policy) is stored locally in your browser, under your control, for a maximum of 12 months before you are asked again.
- When a review is erased in standard mode, the author’s identity is removed (displayed as “Anonymous”); the review text may be retained for the merchant. That text is de-identified, not anonymized: if it contains identifying elements, the data subject or the merchant may request full deletion of the review.
6. Recipients and processors
Data is accessible only to authorized Ekomy teams and to the following providers, each bound by data protection commitments:
- Hosting: Hetzner Online GmbH (Germany / Finland) — hosting of the platform and the data.
- Meta Platforms (WhatsApp Business Platform) — routing of WhatsApp messages, and of the Messenger/Instagram channels when the merchant connects them.
- Email dispatch provider: the provider selected to send invitations will be published in the register of processors, available on request at privacy@ekomy.io, before the first campaigns are sent.
- Processing by language models (sentiment analysis and assistance): the selected provider or providers will be published in the register of processors, available on request at privacy@ekomy.io.
We maintain an up-to-date register of processors, available on request at privacy@ekomy.io. The merchant is informed of any change in accordance with the DPA.
7. Transfers outside the European Union
Primary hosting is located in the European Union. Exchanges with Meta Platforms may involve transfers to the United States, governed by standard contractual clauses and, where applicable, the Data Privacy Framework. For merchants established outside the EU (notably in Tunisia), data moves between the EU and the merchant’s country as part of providing the service.
Since Ekomy is established in the United States and has an affiliated Tunisian company, authorized Ekomy staff access the data from the United States and from Tunisia. These controller-side transfers will be governed by appropriate safeguards, in particular standard contractual clauses, supplemented where required by additional measures.
8. Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, portability and objection.
- End customers of a merchant: since the merchant is the controller, you can exercise your rights directly with the merchant; you can also write to privacy@ekomy.io — we forward the request to the merchant concerned and assist with its handling, or handle directly what falls under our own responsibility.
- Merchants and visitors: write to privacy@ekomy.io.
We reply within 30 days. You may lodge a complaint with the CNIL (France, cnil.fr) or the INPDP (Tunisia), or with the supervisory authority of your country of residence.
9. Data deletion
The full arrangements for requesting and carrying out deletion (scope, timelines, confirmation) are described on the dedicated page: Data deletion.
10. Security
We implement appropriate technical and organizational measures, including:
- encryption in transit (TLS);
- encryption at rest of sensitive fields (access tokens for connected services, identifiers subject to an erasure request);
- logical segregation of each merchant’s data (multi-tenant architecture);
- handling of erasure requests by a dedicated engine, with an execution log and re-application of erasures after any backup restoration.
These measures are strengthened on an ongoing basis; since no system offers absolute security, we notify data breaches in accordance with applicable regulations.
11. Cookies
To date this site uses no cookies and no third-party trackers. The details, together with how the consent banner will work before any future activation of audience-measurement or advertising trackers, are set out in the cookie policy.
12. Contact and changes
For any question: privacy@ekomy.io. This policy is versioned; any substantial change is flagged on this page with its effective date. Version 1.1 — last updated 1 August 2026.