CXPLY logo
Home

CXPLY Ticketing

AI-powered customer support

CX Survey

Feedback that fuels improvement

Demo Request

Legal

Privacy Policy

Contents

Last updated: —


01

Introduction

CXPLY provides software solutions designed to help businesses manage their interactions with their customers, improve their customer experience, and measure customer satisfaction.

Our offering includes in particular:

  • CXPLY Ticketing, a solution for managing customer interactions and requests;
  • CX Survey, a solution for creating, distributing, collecting and analysing satisfaction surveys.

This Privacy Policy explains how CXPLY collects, uses, protects, retains and, where necessary, shares personal data in connection with:

  • its website;
  • its services;
  • its applications;
  • its CXPLY Ticketing and CX SURVEY platforms;
  • its commercial and support activities;
  • its relationships with its clients, users and partners.

CXPLY attaches particular importance to the protection of personal data and to the confidentiality of the information entrusted to it.

Our approach is based in particular on the principles of transparency, data minimisation, purpose limitation, security, confidentiality and respect for the rights of individuals.


02

Who are we?

The party responsible for this Privacy Policy is:

Company name: CXPLY

Company type: SARL

In this policy, the terms “CXPLY”, “we”, “our” and “us” refer to the company CXPLY.


03

Our solutions

3.1 CXPLY Ticketing

CXPLY Ticketing is a solution that enables businesses to centralise and manage their interactions with their customers and users.

Depending on the configuration chosen by the client, CXPLY Ticketing may process information originating from:

  • emails;
  • chats;
  • forms;
  • integrated telephone communications;
  • social networks or other connected channels;
  • APIs;
  • e-commerce platforms;
  • CRM or ERP systems.

The solution may in particular enable:

  • the creation and management of tickets;
  • the qualification of requests;
  • the assignment of tickets;
  • the tracking of interactions;
  • workflow management;
  • automation;
  • SLA management;
  • reporting;
  • performance analysis;
  • agent assistance;
  • certain features based on artificial intelligence.

04

CX SURVEY

CX SURVEY is a solution that enables businesses to design and manage satisfaction surveys and other questionnaires.

The solution may in particular enable:

  • the creation of surveys;
  • the creation and management of questions;
  • the use of survey templates;
  • the management of a question library;
  • the distribution of surveys;
  • the collection of responses;
  • the management of anonymous or identified surveys depending on the configuration;
  • the collection of comments;
  • the measurement of scores and satisfaction indicators;
  • the analysis of results;
  • the creation of dashboards;
  • the generation of reports;
  • the analysis of responses by different categories.

Surveys may be used in particular following:

  • an interaction with customer service;
  • the resolution of a ticket;
  • a purchase;
  • an order;
  • a delivery;
  • a service;
  • an event;
  • or any other interaction defined by the client.

05

Our role in data processing

The capacity in which CXPLY acts depends on the nature of the processing concerned.

Where CXPLY processes personal data on behalf of a business client, CXPLY generally acts as a processor, while the client determines the purposes and the essential means of the processing.

This applies in particular to data entered into:

  • CXPLY Ticketing;
  • CX SURVEY;
  • tickets;
  • conversations;
  • survey responses;
  • customer databases;
  • imported files;
  • data collected through integrations.

This classification nevertheless depends on the reality of each processing operation and does not result solely from the contract concluded between the parties.

Where CXPLY processes certain data for its own purposes, in particular to manage its commercial, administrative, technical or security relationships, CXPLY may act as a controller.


06

Data we may process

The data processed depends on the service used, the configuration chosen by the client and the features enabled.

6.1 Data relating to CXPLY users

When you use the CXPLY platforms directly, we may process:

  • last name;
  • first name;
  • business email address;
  • telephone number;
  • company;
  • job title;
  • user ID;
  • role and permissions;
  • login information;
  • activity logs;
  • information relating to account security.

07

Data processed in CXPLY Ticketing

Depending on the service configuration, the data may include in particular:

  • last name and first name;
  • email address;
  • telephone number;
  • postal address;
  • company;
  • information relating to an order;
  • information relating to a request;
  • ticket content;
  • messages;
  • conversations;
  • comments;
  • attachments;
  • interaction history;
  • data relating to agents;
  • ticket qualification information;
  • theme;
  • sub-theme;
  • tags;
  • contact type;
  • technical information;
  • data necessary for tracking and reporting.

The content of tickets is determined by the client using CXPLY.

It is not for CXPLY to determine which information the client should collect from its own customers.


08

Data processed in CX Survey

Depending on the survey configuration, CX SURVEY may process:

  • last name;
  • first name;
  • email address;
  • telephone number;
  • customer ID;
  • campaign ID;
  • response ID;
  • date and time of the response;
  • answers to questions;
  • scores;
  • ratings;
  • comments;
  • open-ended responses;
  • technical data necessary for the operation of the questionnaire.

The client using CX SURVEY determines in particular:

  • the questions asked;
  • the data requested;
  • the individuals surveyed;
  • the purpose of the survey;
  • whether the survey is anonymous or identified;
  • the retention period for the responses.

09

Anonymous surveys

CX SURVEY may allow the client to configure a survey as anonymous.

When this option is enabled, CXPLY implements the technical mechanisms provided in order to limit the direct association between a response and the identity of the respondent.

However, whether a survey is genuinely anonymous also depends on:

  • the data requested in the questionnaire;
  • the link used to access the survey;
  • the distribution channel;
  • the parameters configured by the client;
  • any data collected by third-party services used to distribute the survey.

The client remains responsible for verifying that the chosen configuration achieves the intended level of anonymity.


10

Purposes of processing

Data may be processed in order to:

Provide our services

  • enable access to the platforms;
  • host the data;
  • process tickets;
  • manage surveys;
  • collect responses;
  • generate dashboards;
  • operate integrations.

Provide support

  • respond to requests;
  • diagnose incidents;
  • resolve technical problems;
  • assist users.

Ensure security

  • detect abnormal behaviour;
  • prevent unauthorised access;
  • protect infrastructure;
  • analyse incidents;
  • maintain security logs.

Improve our products

We may use certain technical and statistical data in order to improve the performance, stability, usability and security of CXPLY.

Where personal data is used for this purpose, CXPLY applies the principles of minimisation and the applicable regulatory requirements.

Manage our business

  • contract management;
  • invoicing;
  • accounting;
  • commercial management;
  • supplier management;
  • legal obligations;
  • fraud prevention.

11

Legal bases

Where the GDPR or an equivalent regulation applies, CXPLY relies on the legal basis appropriate to the processing concerned.

Depending on the situation, this may be:

  • the performance of a contract;
  • compliance with a legal obligation;
  • our legitimate interest;
  • the consent of the data subject;
  • the need to protect the vital interests of a person.

Where consent is required, it is obtained in accordance with the procedures laid down by the applicable regulation.


12

Data entered by our clients

Where you are the customer of a business using CXPLY, data concerning you may have been entered into CXPLY by that business.

For example, a business may use CXPLY to:

  • manage your request;
  • respond to your complaint;
  • track your order;
  • manage a conversation;
  • send you a satisfaction survey.

In this context, the business concerned generally remains the controller of your data, while CXPLY acts as a technical provider or processor.

To exercise your rights concerning this data, you may first contact the business with which you have a relationship.


13

Data relating to satisfaction surveys

When you respond to a survey created by a CXPLY client, the information you provide is primarily processed on behalf of that client.

The client is responsible for determining:

  • the purpose of the survey;
  • the legal basis;
  • the data collected;
  • the retention period;
  • the recipients;
  • the procedures for exercising rights.

CXPLY provides the technical infrastructure necessary to carry out the survey and to process the responses in accordance with the applicable instructions.


14

Sensitive data

CXPLY is not intended to systematically collect special categories of personal data.

Clients must avoid collecting sensitive data in CXPLY where it is not necessary for their purposes.

Where the processing of sensitive data is necessary, the client must ensure that it has the appropriate legal basis and that the necessary protective measures are implemented.


15

Artificial intelligence

Certain CXPLY features may use artificial intelligence technologies.

Depending on the features enabled, AI may in particular be used to:

  • classify tickets;
  • identify themes or sub-themes;
  • suggest categories;
  • route tickets to agents;
  • summarise conversations;
  • analyse responses;
  • suggest replies;
  • assist agents;
  • automate certain operations.

The results produced by artificial intelligence may contain errors.

They must be regarded as assistance tools and not as a final decision where human intervention is necessary.


16

Use of data for training AI models

Unless the client has given explicit and documented agreement, personal data processed on behalf of a client is not used by CXPLY to train artificial intelligence models for CXPLY's own commercial purposes.

Where third-party AI providers are used, their roles and the applicable conditions are documented in the contracts and documents relating to processors.


17

Data hosting

CXPLY may offer several architecture models.

17.1 CXPLY Cloud

The data is hosted on infrastructure managed by CXPLY or by its hosting providers.

17.2 Customer Cloud

CXPLY may be deployed in the cloud environment controlled by the client.

17.3 On-Premise

CXPLY may be installed directly within the client's infrastructure.

17.4 External database

CXPLY may be configured to use a database controlled by the client.

This architecture allows the client in particular to retain control of its data infrastructure in accordance with the requirements of its organisation.


18

Responsibility depending on the architecture

Where CXPLY is hosted by CXPLY, we are responsible for the components placed under our control.

Where CXPLY is installed in the client's environment, the client remains responsible for the elements placed under its control.

This may in particular include:

  • servers;
  • operating systems;
  • network;
  • firewall;
  • database;
  • backups;
  • administrative access;
  • physical security;
  • cloud infrastructure.

Detailed responsibilities are set out in the applicable contract and DPA.


19

Data retention

The retention period depends on:

  • the nature of the data;
  • the purpose of the processing;
  • the contract with the client;
  • legal requirements;
  • the parameters configured in CXPLY.

Where CXPLY acts as a processor, the retention period is primarily determined by the client, in accordance with its legal obligations.

At the end of the contract, the data is returned or deleted in accordance with the DPA and the applicable contractual conditions.


20

Security

CXPLY implements technical and organisational measures intended to protect data against:

  • destruction;
  • loss;
  • alteration;
  • unauthorised disclosure;
  • unauthorised access.

These measures may in particular include:

  • access control;
  • authentication;
  • encryption of communications;
  • logging;
  • monitoring;
  • backups;
  • incident management;
  • vulnerability management;
  • privilege limitation;
  • continuity measures.

The precise measures depend on the architecture and on the service subscribed to.

Security must also be ensured by the client for the components placed under its control.


21

Processors

CXPLY may use specialised providers in order to deliver its services.

These providers may in particular be involved in:

  • hosting;
  • storage;
  • backup;
  • email;
  • telephony;
  • security;
  • monitoring;
  • authentication;
  • support;
  • artificial intelligence;
  • technical infrastructure.

Where these providers process personal data on behalf of CXPLY or of its clients, they are subject to the applicable contractual and regulatory obligations.

CXPLY maintains a list of the main processors concerned where this is required.


22

International transfers

CXPLY may provide its services to clients located in different countries.

Depending on the architecture chosen, data may be processed or hosted in different countries.

Where the GDPR applies, transfers of personal data outside the European Economic Area are governed by the mechanisms provided for by the GDPR, in particular adequacy decisions or, where necessary, the Standard Contractual Clauses of the European Commission.

Where the regulation of another country imposes specific requirements regarding international transfers, CXPLY implements the applicable mechanisms to the extent that they apply to it.


23

Europe and the GDPR

Where the GDPR applies, CXPLY implements the necessary measures corresponding to its role in each processing operation.

Where CXPLY acts as a processor, the applicable obligations are governed in particular by a Data Processing Agreement (DPA).

The DPA sets out in particular:

  • the categories of data;
  • the purposes;
  • the categories of individuals;
  • the security measures;
  • sub-processors;
  • international transfers;
  • assistance obligations;
  • the management of data breaches;
  • the return and deletion of data.

This approach corresponds in particular to the European requirements relating to the contractual framework for processing carried out by processors.


24

Tunisia

CXPLY takes into consideration the applicable Tunisian regulation on the protection of personal data, in particular the provisions of Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data, as well as the applicable texts and requirements.

Where processing operations are subject to Tunisian law, CXPLY takes into account in particular the requirements relating to:

  • collection;
  • use;
  • retention;
  • security;
  • the rights of individuals;
  • international transfers.

Where necessary, the obligations and formalities applicable to processing operations and to international transfers are taken into account within the contractual and technical framework of the service.


25

Africa

CXPLY is designed to be used by businesses located in different African countries.

Data protection requirements may vary from one country to another.

CXPLY takes into consideration the international principles and the national regulations applicable in the jurisdictions concerned.

Where necessary, the CXPLY architecture may be adapted in order to meet the client's specific requirements regarding:

  • hosting;
  • localisation;
  • security;
  • access control;
  • data transfers.

26

Gulf countries and the Middle East

CXPLY may also be offered to businesses located in the Middle East and in the Gulf countries.

Where local regulations apply, CXPLY takes into consideration the requirements relating in particular to:

  • data protection;
  • security;
  • confidentiality;
  • international transfers;
  • data localisation where this is required.

Specific requirements may be defined in the contract, the DPA or the special conditions applicable to the client.


27

Rights of individuals

Where the applicable regulation grants you these rights, you may in particular have the following rights:

  • right of access;
  • right to rectification;
  • right to erasure;
  • right to restriction of processing;
  • right to object;
  • right to data portability;
  • right to withdraw your consent;
  • right to give directives concerning your data after your death, where the applicable regulation provides for this.

Certain rights may be subject to conditions or limitations provided for by the regulation.


28

Exercising your rights

To exercise your rights concerning data processed directly by CXPLY, you may contact us:

support@cxply.com

We may ask you for information enabling us to verify your identity where this is necessary to protect your data.

Where data is processed by CXPLY on behalf of a client, we may direct you to that client, which is generally the controller for the processing concerned.


29

Complaints

If you consider that your data protection rights have not been respected, we encourage you to contact us first so that we can examine your request.

You may also, where the applicable regulation provides for this, contact the competent data protection authority in your country.

For processing subject to the GDPR, it is in particular possible to contact the competent supervisory authority in accordance with the applicable rules.


30

Cookies and similar technologies

The CXPLY website may use cookies and similar technologies.

These technologies may in particular be used to:

  • ensure the operation of the website;
  • secure sessions;
  • remember certain preferences;
  • measure audience;
  • improve the user experience;
  • analyse the performance of the website;
  • carry out certain marketing communications where this is permitted.

Cookies subject to consent are only activated once consent has been obtained where the applicable regulation requires it.

A specific Cookie Policy may detail the cookies and technologies used by CXPLY.


31

Data relating to children

CXPLY's professional services are not directly intended for children.

Clients using CXPLY must take the necessary measures when they collect data relating to minors, in accordance with the laws applicable to their activity and to the context of the processing.


32

Links to third-party services

The CXPLY website or applications may contain links to third-party services.

CXPLY is not responsible for the privacy practices of those services.

We recommend reviewing their privacy policies before transmitting personal data to them.


33

Changes to the Privacy Policy

CXPLY may amend this Privacy Policy in order to take into account:

  • developments in its services;
  • new features;
  • regulatory changes;
  • technical changes;
  • developments in its processing practices.

The most recent version is published on the CXPLY website.

The date of the last update appears at the top of this policy.

© CXPLY – All rights reserved.

International data protection framework

CXPLY operates in an international market and may provide its Solution to clients located in particular in Europe, Africa, the Middle East and other regions of the world.

In this context, CXPLY designs its services in accordance with international principles of privacy and personal data protection, in particular the principles of:

  • lawfulness, fairness and transparency
  • purpose limitation
  • data minimisation
  • accuracy
  • storage limitation
  • confidentiality and security
  • respect for the rights of data subjects
  • accountability and traceability.

Our data protection framework takes into consideration, depending on the countries and the processing operations concerned, the requirements of the European Union General Data Protection Regulation (“GDPR”), Tunisian legislation on the protection of personal data, the national regulations applicable in African countries and the data protection regulations applicable in the countries of the Middle East and the Gulf.

01

European Union and European Economic Area

Where European regulation applies, CXPLY implements the contractual, organisational and technical measures necessary in order to comply with the requirements of the GDPR.

Where CXPLY acts as a processor, processing operations are governed by a Data Processing Agreement (“DPA”) in accordance with the requirements applicable to relationships between controllers and processors.


02

Tunisia

Where processing operations are subject to Tunisian legislation on the protection of personal data, CXPLY takes into consideration in particular the provisions of Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data, as well as the applicable rules and decisions of the competent Tunisian authority.

The Solution may in particular be deployed according to different architectures enabling the client's specific requirements regarding data localisation, hosting and control to be met.

Where necessary, CXPLY and/or the client implement the authorisations, formalities or mechanisms required by the applicable Tunisian regulation, in particular regarding the transfer of personal data abroad.


03

Africa

CXPLY also takes into consideration the international and regional principles applicable in Africa regarding cybersecurity, privacy and the protection of personal data, in particular the principles established by the African Union Convention on Cyber Security and Personal Data Protection, as well as the national legislation applicable in each country.

As data protection regulation may vary significantly from one African country to another, the specific requirements of the country in which the client carries out its activities may be taken into account within the contractual and technical framework applicable to the service.


04

Middle East and Gulf countries

Where the applicable local regulation requires it, CXPLY may adapt the architecture, the hosting arrangements, the transfer mechanisms, the security measures and the contractual commitments in order to meet the requirements applicable to the country concerned.

These requirements may relate in particular to the protection of personal data, confidentiality, data localisation, international transfers, security obligations and the rights of data subjects.


05

Other jurisdictions

Where the Solution is provided to a client located in a jurisdiction with specific rules on the protection of personal data, CXPLY takes into account the legal requirements applicable in that jurisdiction to the extent that they apply to its activities and to its role in the processing concerned.

The client remains responsible for determining the regulatory obligations applicable to its own processing operations, depending on its business sector, the location of the data subjects and the purposes pursued.


06

Principle of local compliance

This Privacy Policy defines an international baseline for data protection.

It may not be interpreted as a statement that a single policy or a single technical configuration would automatically satisfy all the regulations applicable in every country.

Where necessary, specific requirements may be defined in:

  • the client contract;
  • the Data Processing Agreement;
  • the security annexes;
  • the specific hosting conditions;
  • the data localisation conditions;
  • the conditions relating to international transfers;
  • the regulatory requirements specific to the client's country.

CXPLY may therefore offer different deployment architectures, in particular SaaS hosting, hosting within the client's infrastructure, a hybrid architecture or the use of a database controlled by the client.

This flexibility makes it possible to better meet the confidentiality, security, localisation and data governance requirements applicable to the various markets.

© CXPLY – All rights reserved.