Privacy Policy
Controller: VenteGrid
Version: 1.0
Effective: 13 August 2026
Contact: [email protected]
Authoritative version: the French text alone is binding
In plain words
- The presentation website measures its audience. Part of that measurement uses no cookies and does not identify you.
- In the software, the data of your customers, suppliers and employees belongs to you. We host it for you, and we do nothing else with it.
- We never sell, rent or exchange any data. Ever.
- We protect that data using reasonable, state-of-the-art means. No system is impregnable, and we do not claim otherwise.
- You can ask for access to your data, its correction or its deletion.
This summary is provided for convenience only. Only the full text below is binding, and only in its French version.
1. Legal framework
VenteGrid processes personal data in accordance with applicable regulations, including:
- Cameroonian legislation on the protection of personal data, on cybersecurity and cybercrime, and on electronic commerce;
- the African Union Convention on Cyber Security and Personal Data Protection, known as the Malabo Convention;
- the national data protection legislation of the country in which the Customer operates, where it applies to that Customer.
Where several legal systems apply, VenteGrid follows the principles common to them all: lawfulness, fairness, purpose limitation, minimisation, accuracy, storage limitation, integrity and confidentiality.
2. Who is responsible for what
The following distinction is essential and governs this entire policy.
| Data concerned | VenteGrid's role | Customer's role |
|---|---|---|
| Customer account data, billing, support, marketing | Controller | Data subject |
| Data entered in the software: end customers, suppliers, employees, sales | Processor, acting on the Customer's instructions | Controller |
Key clause
For the data the Customer enters into MonGerant, the Customer is the controller. VenteGrid acts only as a processor, on its documented instructions, and solely for the purposes of performing the Service.
It is therefore for the Customer alone to determine the purposes of its processing, to have a valid legal basis, to inform the individuals concerned, to obtain consent where required, to respond to the exercise of their rights, and to complete any formalities required by the authority of its country.
VenteGrid processes that data for no other purpose, accesses it only in the cases set out in article 7, and discloses it to no third party outside those cases.
3. Data processed by the presentation website
www.ventegrid.com is a presentation website. It has no form and no account: the visitor enters no data into it.
It does, however, measure its audience, and may load advertising partners' trackers. The tools involved, their purposes, retention periods and how to refuse them are set out in the Cookie Policy, which forms an integral part of this policy.
The measurements collected concern browsing behaviour. They contain no name, no email address and no telephone number. Advertising partners' trackers do, however, allow those companies, acting on their own behalf, to match the visit to an account held with them.
Only a language preference may be stored in the visitor's browser local storage. That information never leaves the device and allows no identification. See the Cookie Policy.
The website host keeps connection logs, which may include an IP address, for technical and security reasons. Those logs are the host's responsibility, are kept for a limited time, and are used by VenteGrid only in the event of a security incident.
If a visitor writes to [email protected], their message and email address are processed in order to answer them, under the conditions of article 5.
4. Data processed by the software
4.1 Customer data, where VenteGrid is the controller
- Identification and account: company name, names of representatives and users, position, email address, telephone number, postal address, login credentials and passwords stored as irreversible hashes.
- Contract life: plan subscribed, options, invoices, payments, payment incidents.
- Support: exchanges with support, incident descriptions, attachments sent.
- Technical logs: connection dates and times, IP address, device and browser type, sensitive actions performed in the Service (creation, modification, deletion, cancellation), for security and traceability purposes.
4.2 Data entered by the Customer, where VenteGrid is a processor
The Customer alone determines what data it introduces into the Service. It may relate to:
- its end customers: name, contact details, purchase history, loyalty points, balances and receivables;
- its suppliers: contact details, orders, invoices;
- its employees: identity, position, access rights, till operations, sales performance.
Sensitive data
The Service is neither designed nor intended to receive sensitive data within the meaning of applicable regulations, in particular health, biometric, genetic or judicial data, or data revealing political, religious or trade union opinions or sexual orientation.
The Customer undertakes not to introduce such data into the Service. Failing that, it bears sole responsibility and indemnifies VenteGrid against all consequences.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing and performing the Service | Performance of the contract |
| Managing the account and users | Performance of the contract |
| Invoicing, debt recovery, accounting | Legal obligation and performance of the contract |
| Support and incident resolution | Performance of the contract |
| Security, logging, fraud prevention | VenteGrid's legitimate interest |
| Improving the Service using anonymised statistics | VenteGrid's legitimate interest |
| Informing customers about changes to the Service | Performance of the contract |
| Business-to-business marketing | Legitimate interest, with a right to object at any time |
| Establishing, exercising and defending rights | VenteGrid's legitimate interest |
| Audience measurement and advertising on the presentation website | VenteGrid's legitimate interest, with the option to refuse |
6. The Customer's obligations
As controller of the data it introduces into the Service, the Customer undertakes to:
- process only lawfully collected data that is adequate, relevant and limited to what is necessary;
- inform the individuals concerned (end customers, suppliers, employees) of the existence of the processing, its purposes and their rights;
- obtain consent where applicable regulations require it, in particular for marketing;
- respond itself to the exercise of those individuals' rights, VenteGrid having no contractual relationship with them;
- configure its Users' access rights correctly and revoke them in good time;
- complete any formalities required by the data protection authority of its country.
The Customer indemnifies VenteGrid against any claim, action or sanction resulting from a breach of these obligations, in accordance with article 18 of the GTU.
7. Recipients and subcontractors
Data is accessible only to those who need it:
- authorised VenteGrid staff, within the limits of their duties and under a confidentiality undertaking;
- technical subcontractors: the host, the email delivery operator where that option is subscribed, the payment provider, the backup service. Each is bound by confidentiality and security undertakings at least equivalent to those of this policy;
- administrative and judicial authorities, on a valid request and within its limits;
- VenteGrid's advisers (lawyers, accountants, auditors), bound by professional secrecy;
- the measurement and advertising partners of the presentation website, for the browsing data described in article 3 and detailed in the Cookie Policy only. Those companies act on their own behalf.
What we do not do
VenteGrid does not sell, rent or exchange its customers' data or the data entered in the Service. It discloses it to no data broker, no advertising network, and no competitor of the Customer.
This undertaking concerns Service data. It does not cover the presentation website's browsing data, which is passed to measurement and advertising partners under the Cookie Policy. The two sets are never matched against each other.
A VenteGrid staff member accesses a Customer's data only in the following cases: a support request from the Customer, maintenance or defect correction, a security incident, or a request from a competent authority. Such access is logged.
The current list of subcontractors is provided to the Customer on written request. VenteGrid may change them, provided an equivalent level of protection is maintained.
8. Location and transfers
Data is hosted on servers located in [hosting country].
Some technical subcontractors may be established outside the Customer's country. In that case, VenteGrid ensures that the transfer rests on appropriate safeguards: contractual confidentiality and security undertakings, and limitation of access and purposes.
The Customer, as controller, acknowledges being informed of this arrangement and accepts it as part of its own obligations regarding data transfers.
9. Retention periods
| Data | Period |
|---|---|
| Data entered in the Service | For the term of the agreement, then 30 days after it ends, in accordance with article 13 of the GTS |
| Account and contact data | Term of the agreement, then 3 years for commercial relationship purposes |
| Invoices and accounting records | 10 years, in accordance with accounting and tax obligations |
| Connection and security logs | 12 months |
| Support exchanges | 3 years from the last exchange |
| Backups | Until rotation, within a maximum of 90 days |
| Prospects who did not subscribe | 3 years from the last contact |
At the end of those periods, data is deleted or irreversibly anonymised. VenteGrid may, however, keep in restricted-access archives only such data as is necessary to meet a legal obligation or to defend its rights, until the applicable limitation periods expire.
10. Security
VenteGrid implements technical and organisational measures appropriate to the nature of the data and to the risks, including:
- encryption of communications between equipment and the Service;
- storage of passwords as irreversible hashes;
- segregation of data between customers;
- internal access limited on a need-to-know basis;
- logging of access and sensitive operations;
- regular backups;
- keeping the software components used up to date.
Best-efforts obligation
These measures are a best-efforts obligation, excluding any obligation to achieve a specific result. No information system is impregnable. VenteGrid does not guarantee the absence of vulnerabilities or the impossibility of a breach, and is not answerable for breaches originating in the Customer's equipment, networks, settings or practices, in the disclosure of credentials, or in the act of a User or a third party.
11. Data breaches
In the event of a personal data breach liable to affect the Customer, VenteGrid informs it in writing within a reasonable time after becoming aware of it, and provides the relevant information: the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken or planned.
It is for the Customer, as controller, to make the notifications incumbent on it to the competent authority of its country and, where applicable, to the individuals concerned.
This information does not constitute an admission of liability by VenteGrid.
12. Individual rights
Every individual concerned has, under the conditions and within the limits of the regulations applicable to them, the following rights: access, rectification, erasure, restriction, objection, portability, and determination of what happens to their data after their death.
12.1 If you are a VenteGrid customer
Send your request to [email protected], stating its subject and enclosing anything allowing your identity to be verified. VenteGrid replies within one (1) month, extendable by two (2) months for complex requests, of which the requester is then informed.
12.2 If you are a customer, supplier or employee of a business using MonGerant
Who to contact
Your data was entered into the Service by the business you deal with. That business is the controller, and it is with that business that your rights are exercised.
VenteGrid, a mere processor, is not authorised to modify or delete that data on its own initiative. A request sent directly to it will be forwarded to the business concerned, with no further processing.
12.3 Limits
A manifestly unfounded or excessive request, in particular a repetitive one, may be refused or give rise to reasonable charges. An erasure request may be refused where retention is necessary to comply with a legal obligation or to defend rights in court.
13. Complaints to an authority
Anyone who considers that their rights have not been respected may lodge a complaint with the competent personal data protection authority in their country.
VenteGrid nevertheless invites any individual concerned to contact it first at [email protected]: most difficulties are settled by a simple exchange.
14. Minors
The Service is intended for businesses and is not designed to be used by minors. VenteGrid does not knowingly collect data concerning minors.
If the Customer introduces data concerning minors into the Service, in particular in its customer relationships, it is for the Customer to ensure compliance with the conditions laid down by applicable regulations and to bear responsibility for it.
15. No automated decisions, no model training
The Service makes no decision producing legal effects or significantly affecting an individual on the sole basis of automated processing.
Data entered by Customers is not used to train artificial intelligence models, nor disclosed to any third party for that purpose.
VenteGrid may produce aggregated and anonymised statistics, allowing the identification of neither a Customer nor an individual, solely to improve the Service.
16. Scope of our undertakings
The undertakings given in this policy are best-efforts obligations. They are assessed by reference to the state of the art, the means reasonably available and the nature of the Service.
VenteGrid's liability under this policy is subject to the limitations and exclusions set out in article 17 of the GTU, to the fullest extent permitted by applicable law.
17. Amendments to this policy
This policy may be amended to reflect changes in the Service, its technical organisation or applicable regulations. The applicable version is the one published on www.ventegrid.com.
Any substantial change is notified to Customers by email or by a notice displayed in the Service, at least thirty (30) days before it takes effect.
A question about your data? Write to [email protected].