This document is intended for the majority of our customers.
For any questions regarding the SoWeSoft solution, please contact the support service: support@sowesoft.com
Personal Data Protection
SoWeSign, SoWeRise and SoWeDoc Services — Client Users
Version: July 2026
Last updated: 17 August 2026
This notice describes how SoWeSoft processes personal data in connection with the provision of its software services. Its purpose is to ensure the transparency required under Regulation (EU) 2016/679 (hereinafter the “GDPR”) and to clarify SoWeSoft's role and commitments towards data subjects and its clients.
1. Purpose and Scope
This notice applies when SoWeSoft acts as a data processor within the meaning of Article 4(8) of the GDPR, i.e. when it processes personal data on behalf of and under the instructions of its clients in connection with the following services:
- SoWeSign — digital attendance recording and attendance monitoring;
- SoWeRise — training and learning assessment;
- SoWeDoc — electronic document signing.
It does not cover:
- processing carried out by SoWeSoft for its own purposes, for which SoWeSoft acts as data controller and which is covered by a separate notice;
- specific processing involving sensitive data, which is covered by a dedicated notice.
For any questions relating to this notice, you may contact our DPO at: dpo@sowesoft.com.
2. Roles and Responsibilities
When our clients use our services, they determine the purposes and means of the processing carried out using our solutions. Accordingly, the client is the data controller within the meaning of Article 4(7) of the GDPR.
SoWeSoft acts as a data processor. It processes personal data solely on the basis of the documented instructions of the data controller, under the conditions set out in the data processing agreement entered into in accordance with Article 28 of the GDPR, and does not use the data for any other purposes.
In practice, this means that the data controller — your training organisation, employer or the entity making our services available to you — determines, in particular, the data collected, the legal basis for processing, the retention periods and the procedures for exercising your rights.
SoWeSoft assists the data controller with its compliance obligations and provides it with the resources necessary to fulfil those obligations.
3. Identity and Contact Details
Solution provider (data processor)
SoWeSoft — SAS
10 allée Georges Noé, 44860 Saint-Aignan-de-Grand-Lieu, France
SIREN: 829 342 559
Data Protection Officer (DPO)
Fabrice BROCHU
dpo@sowesoft.com
The identity and contact details of the data controller are provided to you by the entity making our services available to you, in its own privacy policy.
4. Purposes of Processing
In connection with the services subscribed to by the client and in accordance with its instructions, SoWeSoft processes personal data for the following purposes:
SoWeSign — attendance recording and monitoring
- recording the attendance of trainers and learners (application, browser, email, etc.);
- monitoring attendance by training session and class;
- managing absences, lateness, early departures and related comments;
- generating attendance certificates;
- securing the attendance data collection process.
SoWeRise — training and learning assessment
- collecting responses to assessment questionnaires;
- measuring training satisfaction and effectiveness;
- assessing acquired knowledge, skills and competencies;
- monitoring learner progress;
- producing reports and dashboards to support decision-making.
SoWeDoc — electronic document signing
- managing and automating the electronic signature process;
- identifying signatories;
- sending signature requests, reminders and confirmations;
- making final signed documents available.
5. Legal Basis for Processing
As a data processor, SoWeSoft does not determine the legal basis for processing carried out through its services.
The legal basis within the meaning of Article 6 of the GDPR — for example, the performance of a contract, compliance with a legal obligation, legitimate interests or consent — is determined by the data controller according to the purposes pursued.
SoWeSoft processes personal data solely on the basis of the documented instructions of the data controller, in accordance with Article 28(3)(a) of the GDPR.
6. Categories of Data Processed
Depending on the services activated and the configuration selected by the client, the following categories of data may be processed:
- Identification data;
- Contact data;
- Connection data;
- Application access and role data;
- Training-related data;
- Attendance and presence data;
- Signature and evidence data;
- Training assessment data (SoWeRise);
- Free-text comments and declarative data;
- Signed documents and content.
Sensitive data. As part of standard use, our services do not require data falling within the special categories referred to in Article 9 of the GDPR, including health data.
The data controller remains responsible for ensuring that such data is not entered, in particular through free-text fields and comments.
Certain specific contexts — for example, the public sector — may involve the processing of sensitive data on behalf of the client. Such processing is covered by a dedicated notice and enhanced safeguards.
6. Categories of Data Subjects
Depending on the services concerned, data subjects include learners, trainers, solution managers and administrators, managers, tutors and document signatories.
7. Source of the Data
Data is primarily provided by the client, in particular through integration with its information systems — for example, an ERP or HRIS — through file imports or by entering data into the solutions.
Certain data is also collected directly when users log in to the applications, record attendance, complete questionnaires or sign documents.
8. Recipients and Sub-processors
Authorised SoWeSoft personnel. Data may be accessed, on a need-to-know basis, by SoWeSoft teams responsible for development, technical support, information security and project monitoring.
Sub-processors. In accordance with Article 28 of the GDPR, SoWeSoft uses sub-processors selected on the basis of the data protection safeguards they provide.
As of the date of this notice:
| Sub-processor | Role | Location |
|---|---|---|
| Microsoft (Azure) | Hosting | European Union (France & Germany) |
| OVHcloud | Hosting | France |
The data controller is informed of any intended addition or replacement of a sub-processor and has the opportunity to raise objections in accordance with Article 28(2) of the GDPR.
9. Transfers Outside the European Union
Personal data is hosted within the European Union (France and Germany). SoWeSoft does not transfer personal data outside the European Union / European Economic Area.
Where a sub-processor belongs to a group established outside the European Union, any potential access is subject to appropriate safeguards within the meaning of Article 46 of the GDPR, including the European Commission's Standard Contractual Clauses.
10. Data Retention Periods
As a data processor, SoWeSoft retains data in accordance with the instructions of the data controller and the legal obligations applicable to the data controller.
For guidance:
- Active data (accounts, attendance, assessment and connection data): retained for the duration of the contractual relationship between the data controller and SoWeSoft and for the period during which the service is used;
- Signed documents and content retained as evidence (attendance certificates, certificates of completion and signed documents): archived for up to 10 years in accordance with obligations relating to proof of completion of training activities and the accounting obligations applicable to the data controller.
At the end of the contractual relationship, and in accordance with Article 28(3)(g) of the GDPR, data is, at the data controller's choice, returned or deleted from SoWeSoft's databases, unless there is a legal obligation to retain it.
11. Data Security
In accordance with Article 32 of the GDPR, SoWeSoft implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption in transit: TLS 1.2 / 1.3 exclusively (earlier versions disabled), HTTPS mandatory in production;
- Encryption at rest: AES-256;
- Access control: multi-factor authentication (MFA) deployed across the information system, least-privilege principle and access logging;
- Business continuity and backups: daily backups (7-day + 5-week retention), tested and operational disaster recovery plan, with a Recovery Time Objective (RTO) of 4 hours;
- Application security: vulnerability and penetration testing and continuous monitoring of the environment;
- Organisation: employee awareness training and regular security audits.
SoWeSoft has also initiated an ISO/IEC 27001 certification process, with certification targeted for the end of 2027.
12. Personal Data Breach
In the event of a personal data breach, SoWeSoft will notify the data controller without undue delay after becoming aware of it, in accordance with Article 33(2) of the GDPR.
SoWeSoft will also provide the necessary assistance to assess the breach and, where applicable, notify the supervisory authority and the affected data subjects.
13. Your Rights Regarding Your Data
In accordance with the GDPR, you have the following rights in relation to your personal data:
- right of access (Article 15);
- right to rectification (Article 16);
- right to erasure (Article 17);
- right to restriction of processing (Article 18);
- right to data portability (Article 20), where the applicable conditions are met;
- right to object (Article 21);
- right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you (Article 22).
Our services are not intended to make such decisions: assessment and attendance monitoring remain under the control of the data controller and trainers.
How can you exercise your rights?
These rights must be exercised with the data controller, i.e. the entity making our services available to you (your training organisation, employer, etc.).
As a data processor, SoWeSoft provides the data controller with the means necessary to respond to your requests and assists it in accordance with Article 28(3)(e) of the GDPR.
If you are unable to identify or contact the data controller, you may contact our Data Protection Officer at dpo@sowesoft.com, who will forward your request.
14. Complaint to the CNIL
If, after contacting the data controller or our DPO, you believe that your rights have not been respected, you may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL):
CNIL — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
Telephone: 01 53 73 22 22 — www.cnil.fr
15. Amendments to this Notice
SoWeSoft may amend this notice to reflect changes to its services, sub-processors or the regulatory framework.
The applicable version is the version published at the usual address of our services on the date it is consulted.
NB : j’ai volontairement conservé la numérotation du document d’origine, qui comporte deux sections « 6 » (« Catégories de données traitées » puis « Catégories de personnes concernées »).