CaféCafé

Privacy policy

Last updated : July 15, 2021

This privacy policy (this "Privacy Policy") governs and describes how BUFU, Inc. and its subsidiary BUFU S.A.S. (each the "Company", "we," "us" or "our") may collect, use, and disclose personal data of users of the Company's website accessible at https://at.cafe (the "Website") and users of the Company's web, mobile application and other platforms (the "Application", the Website, the Application and other platforms being collectively referred to as the "Services").

We collect and process your personal data in compliance with applicable laws and regulations and in particular with French Law No. 78-17 of January 6, 1978, known as "Informatique et Libertés" and the General Data Protection Regulation No. 2016/79 of April 27, 2016.

1. Identity of the entity responsible for collecting data

The entities responsible for collecting and processing your personal data are BUFU, Inc., a Delaware corporation having its registered office at 651 N Broad St, Suite 206, Middletown, DE 19709 United States of America, and its subsidiary BUFU S.A.S., a French société par actions simplifiée, with a share capital of EUR 1,000, its registered office at 5 avenue du Général De Gaulle, 94160 Saint-Mandé, France, registered with the Trade and Companies Register of Créteil under number 890 556 368.

Contact details :

BUFU Inc.
651 N Broad St, Suite 206
Middletown, DE 19709
United States of America

Or

BUFU S.A.S.
5 avenue du Général De Gaulle
94160 Saint-Mandé
France

2. Collecting personal data

2.1. What is personal data ?

Personal data means any data that enables a natural person to be identified, directly or indirectly (the "Personal Data").

2.2. Which Personal Data do we collect ?

The Company may collect some Personal Data:

  • Information about the user's identity: surname, first names, day and month of birth, telephone number, profile picture, biography;

  • Information about the user's professional activity: days worked, days off, place of work, job position;

  • Registration information allowing the person to use the Services: email*, password, IP address, credit card information;

Information fields marked with an asterisk are required fields.

You can always refuse to complete these required fields, in which case we will inform you of the consequences of this refusal.

2.3. How do we collect Personal Data ?

Personal Data is collected directly by the Company, in particular when you use the Services and when you contact the Company.

Your Personal Data is collected for example when you :

  • browse on the Website ;
  • use the chatbot on the Website;
  • create an account and use the Application;
  • access your user account;
  • use the Application;
  • contact customer service.

3. How do we use Personal Data?

3.1. What are the legal basis for processing your personal Data ?

  • Your express consent to such processing ;
  • The legitimate interest of the Company ;
  • The execution of an agreement entered with us in connection with the use of the Services ;
  • Compliance with a legal or regulatory obligation applicable to the Company.

3.2. Why is Personal Data collected ?

Your Personal Data is collected in order for us to :

  • provide the Services ;
  • maintain the safety of your Personal Data;
  • send you emails to help you use the Services;
  • have commercial and service usage statistics;

The Company will only collect Personal Data that is adequate, relevant and strictly necessary for these purposes.

4. Recipients of Personal Data

The following persons will have access to some of your Personal Data :

  • Persons working within the Company or for the Company (managers, employees, interns, freelancers);

  • The Company's subcontractors (Website host, CRM, cloud platform, payment platform, plugins, HRIS, etc.) such as AWS (Amazon Web Services), Stripe, Intercom, Tableau and Amplitude;

  • If applicable, accountants, lawyers, auditors, court officers, public bodies, ministerial officers and bodies responsible for debt collection.

5. Transfer of Personal Data outside European Union

The Website is hosted by AWS in the United States.

Furthermore, depending on the subcontractors, some Personal Data can be transferred outside the European Union.

The transfer of your Personal Data outside the European Union, if any, is secured as follows:

The country outside the European Union has been deemed to offer an adequate level of protection by a decision of the European Commission;

The transfer of your Personal Data in this context is secured by means of a specific contract governing the transfer of your data outside the European Union, based on the standard contractual clauses between a data controller and a data processor approved by the European Commission, adapted to the specificities of the transfers implemented for the needs of each of the services provided by our data processors.

6. Personal data storage period

Personal Data will be kept for the period of time necessary to fulfill the purposes set forth in section 3 above.

Personal Data related to sending you information will be deleted three (3) years after you unsubscribe from our mailing list.

Personal Data related to the provision of the Services will be deleted five (5) years after you unsubscribe from the Services.

Information collected via Cookies used by the Company is kept for thirteen (13) months.

7. Safety

The Company undertakes to take all useful precautions, organizational and technical measures appropriate to preserve the security, integrity and confidentiality of your Personal Data and in particular to avoid their destruction, loss, theft, alteration or unauthorized access.

In order to reinforce the security of your Personal Data, we invite you to choose a complex password and to take all precautions to keep it secret, to log out after each session, to avoid logging in on a computer that does not belong to you, and to avoid logging in to your account via a public wifi network.

8. Our Policy on "Do Not Track" Signals under the California Online Protection Act (CalOPPA)

We do not support Do Not Track ("DNT"). Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

You can enable or disable Do Not Track by visiting the preferences or settings page of your web browser.

9. Your rights

9.1. What are your rights ?

You have the following rights regarding your Personal Data:

  • Right to information: the right to obtain clear information about the use of your Personal Data and your rights;

  • Right of access: the right to obtain your Personal Data;

  • Right to object: right to object to the use of your Personal Data;

  • Right of rectification: right to rectify inaccurate or incomplete Personal Data;

  • Right of limitation: right to request to freeze the use of one\'s Personal Data for a certain period of time;

  • Right to portability: the right to receive one\'s Personal Data in a readable format and to request their transfer to the recipient of one\'s choice;

  • Right to be forgotten: the right to request the deletion of Personal Data and to prohibit any future collection of Personal Data;

  • Right to send a complaint to the Commission Nationale de l\'Informatique et des

  • des Libertés (CNIL);

  • Right to define instructions after your death: the right to define instructions concerning the conservation, deletion and communication of your Personal Data after your death.

These instructions can be general, i.e. they concern all of your Personal Information. In this case, they must be transmitted to a trusted digital third party certified by the CNIL.

These directives may be specific, i.e. they relate only to your Personal Data processed by the Company. In this case, they must be transmitted to the Company.

You may change or revoke your instructions at any time.

For any additional information, do not hesitate to go on the website of the CNIL.

9.2. How to exercise your rights?

To exercise your rights, you can contact the Company at the following e-mail address dpo@at.cafe and provide a photocopy of your identity card with your signature.

To exercise your right to send a complaint to the CNIL, you can contact the CNIL on its website or by mail at the following address :

CNIL - Service des Plaintes

3 Place de Fontenoy - TSA 80715

75334 PARIS CEDEX 07

10. Modifications

We reserve the right to, at our sole discretion, amend this privacy policy at any moment, in whole or in part. Those amendments will be effective from the publication of the new policy. If you continue to use the Services after the publication of the amendments, you will be deemed to have acknowledged and accepted the new policy. On the contrary, and if the new policy is unacceptable to you, you shall stop using the Services.

Please regularly access the latest privacy policy published on our Website.

Try Café with your
team today