Privacy policy
Last updated: September 11, 2026.
This policy describes how EACHR collects, uses and protects the personal data processed on eachr.co and in the app.eachr.co application, whether you are a website visitor, the administrator of a client company, a partner office manager or an employee of a company using eachr.
Who is responsible for what
For website, account, billing and partner program data, EACHR (15 rue de Sully, 21850 Saint-Apollinaire, France, contact@eachr.co) is the data controller.
For employee data entered in the application (employee records, expense reports, absences, time, payroll, documents, communication, onboarding and offboarding journeys, reminders), the client company is the controller and EACHR acts as a processor, on its instructions. This relationship is governed by the data processing agreement (DPA) available on the website.
An office manager or firm administering a client company's workspace does so on behalf of that company, under their own contract.
Data collected
Depending on how you use eachr, the following categories may be processed:
- Account and access: first and last name, email address, role, linked companies, Google identifier if you choose that sign-in, one-time sign-in codes, employees' personal access links (there is no password).
- Employee record: identity, contact details, position, manager, site, start and end dates, contract type, probation period, working time, seniority, training, attached documents (contract, amendments, documents requested on arrival).
- Expense reports: amounts, dates, categories, client or project allocation, receipts and their automatic reading, advances, approval and reimbursement status.
- Absences: requests, types, dates, leave and TOIL balances, supporting documents. An absence document may contain health data (sick note): it is only accessible to authorized people in the company.
- Time and activities: timesheets, timestamped clock-ins when the clock-in feature is enabled, schedules, projects, overtime and rest.
- Payroll: monthly variable elements, payslips uploaded by the company. During a grouped upload, the social security number printed on each payslip is used only to match it to the right employee.
- Communication and reminders: announcements, company documents, suggested perks, end-of-probation, medical check-up, anniversary and review dates.
- Billing and commissions: company name, address, billing email, payment history, commissions due to partners. Bank details and card numbers are never stored by eachr, they are handled directly by Stripe.
- Logs and technical data: history of uploads, views and downloads of sealed documents, IP address, browser type, sign-in logs, session identifiers.
Purposes
- Provide, operate, secure and maintain the service and its modules.
- Manage accounts, authentication, employee access and email notifications.
- Read receipts automatically to pre-fill expense reports.
- Bill subscriptions and compute partner commissions.
- Answer support and contact requests.
- Meet legal and accounting obligations, including record retention.
- Measure usage of the public demo (no analytics on real accounts nor on the website).
Legal bases
- Performance of the contract (art. 6.1.b GDPR) for providing the service, billing and the partner program.
- Documented instructions of the client company (art. 28 GDPR) for employee data processed on its behalf.
- Legal obligation (art. 6.1.c GDPR) for keeping accounting records.
- Legitimate interest (art. 6.1.f GDPR) for security, abuse prevention and service improvement.
Retention periods
- Account data: for the duration of the subscription, then 3 years after the last activity.
- Employee data: for the duration of the contract with the client company, then 60 days for export before deletion, subject to legal retention obligations.
- Expense receipts and accounting records: 10 years (legal obligation).
- Billing data: 10 years (art. L.123-22 of the French Commercial Code).
- Demo accounts: purged automatically after a few hours.
- Technical logs: 12 months maximum.
Processors and recipients
EACHR relies on the following processors to provide the service:
- Application and website hosting: Vercel Inc., United States.
- Database and authentication: Supabase Inc., servers in the European Union (Frankfurt).
- File storage (receipts, payslips, documents): Cloudflare Inc., storage restricted to the European Union jurisdiction.
- Automatic receipt reading: Anthropic PBC, United States. Transmitted images are used only for extraction and are not used to train models.
- Payments: Stripe Payments Europe, Limited, Ireland.
- Transactional emails: Resend Inc., United States.
- Sign in with Google (optional): Google Ireland Limited, Ireland.
- Application error tracking: Functional Software Inc. (Sentry), data hosted in the European Union.
- Abuse protection (rate limiting): Upstash Inc., United States.
- Usage measurement of the public demo only: PostHog Inc.
Transfers outside the European Union
Data is stored in the European Union. Some processors are established in the United States: the resulting transfers are governed by the Standard Contractual Clauses adopted by the European Commission and, where the provider is certified, by the EU-US Data Privacy Framework.
Security
Encryption in transit (TLS) and at rest with the hosting providers, strict isolation between companies, employee access through revocable personal links, documents sealed with a SHA-256 fingerprint and an access log, error monitoring. Details are on the Security page.
Your rights
You have the right to access, rectify, erase, port, object to and restrict the processing of your data.
If you are an employee of a company using eachr, address your request to your employer first, as the controller; EACHR assists them in answering. In any case, you can write to contact@eachr.co.
You also have the right to lodge a complaint with the CNIL (www.cnil.fr).
Cookies
eachr only uses cookies strictly necessary for the service to work (authentication, session, language). No advertising cookie or third-party tracker is set.
Minors
The service is intended for professional use and is not designed for people under 16.
Changes
This policy may be updated. The date at the top of the page indicates the last revision.