New: the Halo × Pennylane integration by Halentra is live. Take a look
Halentra
Home/Privacy policy

Privacy policy

How Halentra collects, uses and protects your personal data. In plain language, with no small print.

Updated on February 1, 2026

Introduction

At Halentra we take your privacy seriously. This policy explains how we collect, use, disclose and safeguard your information when you visit our website and use our services.

Information we collect

Information you provide to us

We collect the information you give us voluntarily when you register for an account, fill out a form, contact us by email or phone, subscribe to our newsletter, or take part in a survey.

  • Identification data: name, email address, phone number, company name.
  • Account credentials: username and password.
  • Business information: company size, industry, job title.
  • Preferences: language and marketing preferences.

Information collected automatically

  • Usage data: pages visited, time spent, clickstream data.
  • Device information: IP address, browser type, operating system.
  • Cookies and tracking technologies: see our cookie policy for details.

How we use your information

We use the information we collect for four purposes, and nothing else.

01

Service delivery

To provide, maintain and improve our services, including Halo implementations.

02

Communication

To answer your enquiries, send important updates and provide customer support.

03

Marketing

To send promotional materials and newsletters, with your consent.

04

Analytics

To analyse usage patterns and improve our website and services.

If you are in the European Economic Area, we process your personal data on one of the following bases.

  • Consent: when you explicitly agree, for example a newsletter signup.
  • Contract: when processing is necessary to deliver our services.
  • Legitimate interests: business operations, fraud prevention and security.
  • Legal obligation: to comply with applicable laws and regulations.

Data sharing and disclosure

We do not sell your personal data. We share it only in the cases below.

Service providers

We work with trusted third parties for hosting and infrastructure, email delivery, analytics, payment processing and customer support tools.

Third-party access

All third-party service providers are contractually obliged to protect your data and to use it only for the purposes we specify.

Software vendors

When we implement Halo solutions, we work directly with HaloITSM Ltd. as the software vendor, and with authorised resellers and partners for licensing and support.

We may disclose your information when required by law, court order or government request, or to protect our rights and safety.

Your rights (GDPR and CCPA)

You have the following rights over your personal data.

  • Access: request a copy of your personal data.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your data, subject to legal obligations.
  • Restriction: limit how we process your data.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: opt out of marketing communications at any time.

To exercise any of these rights, write to dataprotection@halentra.com.

Data security

We put appropriate technical and organisational measures in place to protect your data.

  • Encryption of data in transit and at rest.
  • Access controls with role-based access and authentication.
  • Regular audits, security assessments and vulnerability scans.
  • Employee training on data protection and security awareness.
  • Incident response procedures for breach notification.
Security notice

We take reasonable precautions, but no method of transmission over the internet is completely secure. We cannot guarantee absolute security.

Data retention

We keep your personal data only as long as necessary for the purposes set out in this policy.

  • Account data: while your account is active, plus legal retention periods.
  • Transaction records: as required by tax and accounting law, typically 7 to 10 years.
  • Marketing data: until you unsubscribe or withdraw consent.
  • Support tickets: typically 3 years, for quality assurance.

International data transfers

Halentra is based in Paris, France. If you are located outside France, your data may be transferred to and processed in France and in other countries where our service providers operate.

In those cases we rely on Standard Contractual Clauses approved by the European Commission, and on adequacy decisions for transfers to approved countries.

Cookies and tracking

We use cookies and similar technologies to run the website, measure its use and improve it. You can manage your preferences at any time from the cookie banner, and our cookie policy sets out every cookie we set and why.

Children's privacy

Our services are not intended for children under 16. We do not knowingly collect personal data from children. If we learn that we have, we delete it promptly.

Changes to this policy

We may update this policy from time to time. When we do, we post the updated version with a new "last updated" date, send an email notification for material changes, and display a notice on the website.

Contact us

If you have questions or concerns about this policy, reach us at:

For data protection matters you can also contact our Data Protection Officer at the same address.

Supervisory authority

If you are in the EEA you have the right to lodge a complaint with your local data protection authority. In France this is the CNIL.

  • Website: www.cnil.fr
  • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

A question about your data?

Write to our data protection team. A real person will reply within one business day.