ABEE

    Enterprise

    Security, data and compliance

    This page is written for security officers, IT leaders and buyers. It describes how the ABEE platform and this website process data. Items not yet validated are flagged explicitly rather than asserted.

    PrincipleABEE processes only the data required by the front-of-house interaction, within a scope validated by the client. Each integration follows least privilege, each interaction is logged, and retention periods are contractually defined. On this website, analytics run only after explicit consent, and forms keep working when consent is declined.

    Data processing

    ABEE processes only the data required by the front-of-house interaction: a visitor's declared identity, the reason for a call, the request made, the person concerned. Purposes are documented per deployment.

    Hosting

    Hosting arrangements are defined contractually for each deployment, according to client requirements. Retained configurations are documented in the technical file handed to the client.

    Encryption

    Exchanges between interfaces, the platform and integrated systems are encrypted in transit. Applicable parameters are documented in the client technical file.

    Access rights

    Least privilege: each integration has an explicitly authorized data scope and action set, validated by the client's IT and security leadership.

    Retention periods

    Retention periods for interactions and visitor data are agreed with the client according to purpose, then applied automatically.

    Sub-processors

    The list of sub-processors involved in the processing is provided to the client and updated on any change.

    GDPR

    Processing is designed for GDPR compliance: minimisation, defined purpose, information of data subjects, exercise of rights, data processing agreement.

    Security assessments

    ABEE answers client security questionnaires and takes part in architecture reviews. No certification is claimed on this site until it is effectively obtained.

    Business continuity

    Availability commitments and recovery procedures are defined contractually per deployment. No generic SLA is published on this site.

    Incident management

    Qualification procedure, client notification and, where applicable, notification of the competent authorities within regulatory deadlines.

    DPA

    A data processing agreement is signed with each client, specifying purposes, data categories, retention, sub-processors and security measures.

    Interaction transparency

    Callers and visitors are informed that they are interacting with an automated agent, and access to a human remains available.

    Website privacy

    Analytics consent and form handling

    Analytics run only after consent

    No analytics or marketing script is loaded when the page opens. Measurement tags (GA4 / Tag Manager, third-party visitor tracking) are injected only once explicit consent is given through the banner, using Consent Mode v2 signals.

    If you decline

    Declining stops the analytics layer entirely: no tag is injected, no page view or interaction event is sent, and identifiers already stored locally are purged. The site remains fully usable — no feature is gated behind consent.

    Forms still work without tracking

    The demo and contact forms are a separate processing activity, based on your request and on ABEE's legitimate interest in answering it. They are submitted and answered even when analytics are declined; in that case no behavioural event, journey attribution or marketing identifier is associated with the submission.

    What form data is used for

    Form fields are used to reply to your request and to prepare a demonstration. They are not sold, not used for third-party advertising, and are kept for the period needed to handle the commercial relationship.

    Changing your mind

    Consent can be withdrawn at any time from the cookie banner. Withdrawal takes effect immediately for future navigation and clears the analytics storage created during the consented session.

    Full details are available in the privacy policy.

    Questions fréquentes

    Is ABEE ISO 27001 or HDS certified?

    No certification is claimed on this site until it is effectively obtained. Certification requirements applicable to a project are reviewed during scoping.

    Where is the data hosted?

    Hosting is defined contractually for each deployment, according to client requirements. Retained configurations are documented in the technical file.

    What happens if I refuse analytics cookies?

    No analytics or marketing script is loaded, no event is collected, and previously stored analytics identifiers are removed. The website and its forms keep working normally.

    Are demo form submissions tracked?

    Only when analytics consent has been given. If you decline, the form is still submitted and answered, but no behavioural event or attribution is attached to it.

    How do I exercise my GDPR rights?

    Requests can be sent to contact@abeeconnect.com. Where ABEE acts as a processor, the request is forwarded to the controller, i.e. the client.

    Are conversations recorded?

    Recording and retention terms are defined with the client, according to purpose and applicable legal obligations.

    Go further

    Documentation, resources and related pages

    A security questionnaire to send us?

    Our teams answer security questionnaires and take part in architecture reviews under NDA.