Table of contents
Last updated: August 2026. English version provided for convenience. The French version at charik.app/confidentialite is the reference text under French law and GDPR.
1. Introduction
Charik (hereafter “we”, “our” or “Charik”) is committed to protecting the privacy and security of your personal data. This privacy policy explains how we collect, use, share and protect your information when you use our CRM platform.
Charik is operated by Charik SAS, a French simplified joint-stock company with a capital of €100,000, registered with the Paris Trade and Companies Register under number 981 587 793, headquartered at 10 rue de Penthièvre, 75008 Paris, France.
2. Data collected
2.1 Data you provide
- Account information: first name, last name, email address, phone number, company name, job title.
- Content: the data you enter into Charik — contacts, companies, deals, activities, notes and any file you upload.
- Payment information: processed by our payment provider (Stripe); we do not store your card details.
- Communications: the content of the messages you send us via email, chat or forms.
2.2 Data collected automatically
- Usage data: pages visited, features used, connection times, session duration.
- Technical data: IP address, browser type and version, device type, operating system.
- Cookies: see section 8 and our Cookie policy.
2.3 Data from third parties
When you connect Google Workspace or Microsoft 365 to Charik, we access the data these services expose to us within the strict scope of the authorizations you grant (emails, contacts, calendar). This access is governed by the OAuth protocol and can be revoked at any time from your Google or Microsoft account.
3. How we use the data
We use your data to:
- Provide, maintain and improve our CRM service.
- Personalize your experience and suggest relevant features.
- Communicate with you about your account, updates and technical support.
- Ensure the security of our platform and prevent fraud.
- Meet our legal obligations.
- Analyze the use of our service to improve it, in a de-identified or aggregated form where possible.
4. Sharing
We do not sell your personal data. We share data only in the following situations:
- Service providers: hosting (OVHcloud, in France), payment (Stripe), monitoring (Sentry), transactional emails (Mailgun). These providers act as processors on our behalf and are bound by strict data-protection commitments.
- Legal obligations: when required by law or in response to a valid request from a public authority.
- Third-party integrations: only if you explicitly enable an integration (Gmail, Outlook, Pennylane, Brevo, etc.). The scope of data shared is limited to what the integration requires.
5. Data retention
We retain your personal data for as long as your account is active. Once your account is deactivated:
- Personal identification data is kept for 30 days, then deleted or anonymized.
- Billing data is kept for 10 years to meet French legal and tax obligations.
- Data required for the exercise or defense of legal claims is kept for the applicable statute of limitations.
6. Your rights
Under the GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of the personal data we hold about you.
- Right to rectification: correct any inaccurate data.
- Right to erasure: ask for the deletion of your data, subject to legal exceptions.
- Right to restriction: limit the processing of your data.
- Right to portability: receive your data in a structured, commonly used and machine-readable format.
- Right to object: object to the processing of your data on legitimate grounds.
- Right to give directives: define what happens to your data after your death.
To exercise these rights, contact us at [email protected]. We will reply within 30 days. If you consider that your rights are not being respected, you may file a complaint with the French Data Protection Authority (CNIL) at cnil.fr.
7. Security
We implement technical and organizational measures to protect your data:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Strict access control for our teams.
- Regular data backups.
- Continuous security monitoring.
- Regular audits and penetration tests.
- Employee training in cybersecurity.
8. Cookies
Charik uses cookies to remember your preferences, secure your session and measure audience. Details in our Cookie policy.
9. Changes to this policy
We may update this policy. When we do, we update the “Last updated” date at the top of this page. Substantial changes are notified via the cookie banner or by email.
10. Google Workspace Limited Use policy
When you connect your Google Workspace account to Charik, we access certain Google user data (emails, calendar, contacts) with your explicit authorization via OAuth. Our use of this information complies with the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve features visible in Charik’s user interface.
- We do not transfer or sell this data to third parties for advertising or resale purposes.
- We do not use this data for training generalized or third-party artificial intelligence or machine learning models.
- Human access to this data is prohibited except: (i) with your explicit consent, (ii) for security purposes (e.g. investigating a bug), (iii) for legal reasons, or (iv) when the data has been aggregated and anonymized for internal use.
To revoke Charik’s access to your Google Workspace data, log into your Google account and go to myaccount.google.com/permissions.
11. Contact
For any question about this privacy policy or the processing of your personal data, contact:
Charik SAS
Data Protection Officer
10 rue de Penthièvre, 75008 Paris, France
Email: [email protected]