Skip to content

Legal

Legal notices.

Last updated: 1 August 2026 — LCEN, GDPR & EU AI Act

1. Legal Notice — LCEN

1.1 Publisher identification

This website corpshore.fr (hereinafter "the Site") is published by Corpshore Solutions Corporation (hereinafter "Corpshore" or "the Publisher"), a company incorporated under Canadian law with its registered office in Toronto, Ontario, Canada. Through this Site, Corpshore conducts commercial outreach to French and Francophone businesses seeking to outsource some or all of their operational, IT or artificial intelligence functions. The commercial brand Corpshore France designates all commercial and contractual operations of Corpshore Solutions Corporation in the French, Belgian, Swiss and Luxembourg markets and, more broadly, across the global Francophone market. This legal notice is published in compliance with the requirements of French Law No. 2004-575 of 21 June 2004 for confidence in the digital economy (LCEN), particularly Article 6 III, which requires publishers of online public communication services to publish identification information enabling users to obtain the publisher's contact details.

Corporate nameCorpshore Solutions Corporation
Legal formCorporation (Province of Ontario, Canada — Business Corporations Act)
Registered officeToronto, Ontario, Canada
Email addressinfo@corpshore.solutions
Group websitehttps://corpshore.solutions/france/
Main businessBPO, IT and AI outsourcing services provider
Markets servedFrance, Belgium, Switzerland, Luxembourg and global Francophone market
GDPR classificationData controller for Site data; data processor for data processed on behalf of its clients

1.2 Website hosting

The site corpshore.fr is hosted by Vercel Inc., a company incorporated under US law. Corpshore has entered into a Data Processing Agreement (DPA) with Vercel Inc. that complies with the requirements of Article 28 of the General Data Protection Regulation (GDPR), including Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021 (Implementing Decision 2021/914/EU) to cover transfers of personal data to the United States, a country not benefiting from an adequacy decision under Article 45 of the GDPR for all processing activities. Vercel deploys the Site via a global content delivery network (CDN) with nodes located in Europe, minimising transatlantic transfers of browsing data.

HostVercel Inc.
Address340 Pine Street, Suite 701, San Francisco, CA 94104, United States
Websitevercel.com
InfrastructureGlobal CDN, data centres in North America and Europe
GDPR complianceSigned DPA, Standard Contractual Clauses (SCCs 2021/914/EU)

1.3 Publication director

The publication director within the meaning of Article 6 III of the LCEN is the legal representative of Corpshore Solutions Corporation. Any request relating to the editorial content of this Site should be addressed to info@corpshore.solutions. Requests must clearly state their purpose and, in the case of notification of unlawful content under Article 6 I 7° of the LCEN, must include the requester's contact details, a precise description of the reported content and its exact location on the Site. Corpshore undertakes to process any notification of manifestly unlawful content as soon as possible and to carry out removals required by law.

1.4 Intellectual property and copyright

All elements constituting this Site — including, without limitation, texts, articles, case studies, comparative data, graphics, photographs, illustrations, logos, icons, typography, sounds, videos, animations, databases, software, source code, interfaces and information architecture — are protected by intellectual property law, and in particular by copyright as defined in Articles L.111-1 et seq. of the French Intellectual Property Code (CPI). These elements are the exclusive property of Corpshore Solutions Corporation or of third parties who have granted Corpshore a licence to use them.

Any reproduction, representation, modification, publication, transmission, distortion or decompilation, in whole or in part, by any means and on any medium, without Corpshore's express prior authorisation, is strictly prohibited and would constitute an infringement punishable under Articles L.335-2 et seq. of the CPI, with penalties of up to three years' imprisonment and €300,000 in fines. The databases on the Site are protected by the database producer right under Articles L.341-1 et seq. of the CPI and European Directive 96/9/EC. It is expressly prohibited to extract or re-use these databases, even partially, without authorisation.

By way of exception to the above restrictions, users are permitted, within the framework of the short quotation provided for in Article L.122-5 3° of the CPI, to reproduce extracts from the Site for press, educational, research or information purposes, provided an explicit attribution mentioning the source 'Corpshore France (corpshore.fr)' and the date of consultation is included. These exceptions are exercised only to the extent necessary for the purpose pursued and may not impair the normal exploitation of the works or cause unjustified prejudice to Corpshore's legitimate interests.

1.5 Trademarks and distinctive signs

The trade names 'Corpshore', 'Corpshore France', 'Corpshore AI' and 'Corpshore Solutions', together with the associated logos, logotypes, slogans and visual signs, are trademarks of Corpshore Solutions Corporation, protected in France, Canada and all countries where Corpshore operates. Any unauthorised use of these trademarks — including for commercial identification, advertising (SEA/SEM), creating consumer confusion or reputational damage — constitutes a trademark infringement that may engage the civil and criminal liability of the infringer. Third-party brand names mentioned on this Site (including Zoho, Vercel, Salesforce, Zendesk, OpenAI, Anthropic, Mistral AI, UiPath, Outsource Accelerator) belong to their respective owners and are used solely for descriptive and identification purposes, without any affiliation, endorsement or sponsorship implied.

1.6 Hyperlinks

This Site contains hyperlinks to third-party websites provided for information and convenience purposes only. Corpshore exercises no editorial control over the content, privacy policies, commercial practices or regulatory compliance of these third-party sites. The inclusion of a link to a third-party site does not constitute Corpshore's endorsement of that site's content, services or the organisation that runs it. Corpshore cannot be held liable for any damage arising from the use of these third-party sites. Users who access a third-party site via a link on this Site do so at their own risk and on their own responsibility.

The creation of hyperlinks pointing to pages of this Site is permitted provided that: (i) the link is clearly identified as pointing to the Corpshore France site; (ii) the content of the originating site is not likely to damage Corpshore's image or reputation; (iii) the originating site is not an unlawful, offensive or contrary-to-public-order site; (iv) the linking does not use framing, inline linking or other techniques that could create confusion as to the origin of the content. Any other method of linking, including deep linking or use of Corpshore metadata in commercial generative AI systems, is subject to prior written authorisation from Corpshore Solutions Corporation.

1.7 Liability limitation

Corpshore endeavours to ensure the accuracy, completeness and currency of the information published on this Site. However, the information available is provided for information purposes only and does not constitute, unless expressly stated otherwise, a contractual offer, professional advice, investment advice or a guarantee of results. The figures presented in the interactive tools (savings calculator, workforce planner, model comparator, maturity assessment, SLA builder, GDPR checker) are automatic estimates based on average market parameters and cannot substitute for a personalised analysis by a qualified consultant. Corpshore cannot be held liable for decisions made solely on the basis of the results of these tools.

Corpshore cannot be held liable for direct or indirect damages — including loss of business, loss of profits, loss of data, reputational damage, business interruption or any other financial or commercial damage — resulting from the use of or inability to use the Site, from access to inaccurate or incomplete information, or from the acts of third parties on the internet network. Corpshore reserves the right to modify, correct, interrupt or suspend access to all or part of the Site at any time and without notice, in particular for technical maintenance, regulatory updates or force majeure. This limitation of liability applies to the fullest extent permitted by applicable French law and may not be interpreted as an exclusion of liability for damages caused by fraud or gross negligence.

1.8 Applicable law and jurisdiction

These legal notices are governed by French law. In the event of a dispute relating to the use of this Site or the interpretation of these legal notices, and in the absence of an amicable resolution within thirty (30) days of notification of the dispute by recorded delivery letter, the parties agree to submit the dispute to the competent courts of Paris. For disputes involving consumers residing in the European Union, these consumers retain the right to use the Online Dispute Resolution platform set up by the European Commission (ec.europa.eu/consumers/odr). Users acknowledge that all applicable consumer law provisions in their country of residence remain applicable when they contract with Corpshore as consumers.

2. Privacy Policy — GDPR

2.1 Data controller

The data controller for personal data collected via the site corpshore.fr is Corpshore Solutions Corporation, Toronto, Ontario, Canada. Corpshore Solutions Corporation determines the purposes and means of data processing carried out in the context of operating the Site, managing contact requests and job applications. For data processed in the context of services performed on behalf of clients (processing of client data in BPO, IT or AI mode), Corpshore Solutions Corporation acts as a data processor within the meaning of Article 4(8) of the GDPR and Article 28 of the same regulation.

2.2 Data Protection Officer (DPO)

Corpshore has appointed a GDPR contact person acting as the point of contact for all questions relating to the protection of personal data. This contact can be reached at: info@corpshore.solutions. Any request relating to the exercise of your rights, any question concerning data processing carried out by Corpshore, or any notification of a potential data breach may be addressed to the same email address. Corpshore undertakes to respond to any request within a maximum period of thirty (30) calendar days in accordance with Article 12 of the GDPR, and to inform you as soon as possible if this period were to be extended under the conditions provided for in Article 12(3) of the GDPR.

2.3 Data collected and processed

Corpshore collects and processes different categories of personal data depending on your interaction with the site corpshore.fr. The following processing activities are implemented:

  • Contact data (contact form): last name, first name, professional email address, phone number (optional), company (optional), country of residence, service of interest, free message
  • Application data (careers form): last name, first name, email address, phone number, CV, cover letter, relevant professional information
  • Interactive tool usage data: role type (calculator), contact volume (planner), maturity assessment answers, SLA configuration, GDPR checker results — stored locally in the browser (localStorage) and transmitted to Zoho CRM upon contact form submission
  • Browsing data: IP address (anonymised), browser type, operating system, pages visited, visit duration, referral source — collected by Vercel server access logs
  • GDPR traceability data: date and time of consent, version of Terms of Use accepted, newsletter opt-in

2.4 Processing purposes and lawful bases

PurposeLawful basis (GDPR)Retention periodRelevant sub-processors
Responding to contact requestsArt. 6.1.b — pre-contractual measures3 years from last contactZoho CRM (India), Vercel (USA)
Managing job applicationsArt. 6.1.b — pre-contractual measures2 years from application (with consent)Zoho Recruit (India)
Sending commercial communications (newsletter)Art. 6.1.a — explicit consentUntil withdrawal of consent (unsubscribe)Zoho Campaigns (India)
Improving interactive tools and statistical analysisArt. 6.1.f — Corpshore's legitimate interest13 months (anonymised aggregate data)Vercel Analytics (USA)
Security and fraud preventionArt. 6.1.f — legitimate interest12 rolling months (access logs)Vercel Inc. (USA)
Compliance with legal obligations (LCEN, GDPR, commercial law)Art. 6.1.c — legal obligationApplicable legal period (5 to 10 years depending on type)

2.5 Recipients and sub-processors

Personal data collected via corpshore.fr may be transmitted to the following categories of recipients and sub-processors, in strict compliance with the purposes defined above and subject to appropriate contractual guarantees in accordance with Articles 28 and 44 to 49 of the GDPR:

  • Zoho Corporation Pvt. Ltd. (India) — CRM, recruitment and email campaign platform; DPA and SCCs applicable; transfers to India covered by CCTs compliant with Decision 2021/914/EU
  • Vercel Inc. (United States) — website hosting and access logs; signed DPA; modular SCCs applicable for transfers to the USA
  • Cloudflare Inc. (United States) — anti-bot protection (Turnstile) for the contact form; processing limited to session data
  • Calendly, LLC (United States) — appointment scheduling; data entered in the Calendly widget is transmitted directly to Calendly under its own terms of use
  • Internal Corpshore teams — access limited to authorised personnel (sales, talent teams, management) on a need-to-know basis
  • Judicial and administrative authorities — upon judicial or administrative requisition under the conditions provided for by law

2.6 International data transfers

Some of Corpshore's sub-processors are established outside the European Economic Area (EEA). In such cases, Corpshore ensures that these transfers are covered by appropriate safeguards in accordance with Chapter V of the GDPR, and in particular by the Standard Contractual Clauses (SCCs) adopted by the European Commission on 4 June 2021 (Implementing Decision (EU) 2021/914). For transfers to the United States, Corpshore relies on modular SCCs coupled with a Transfer Impact Assessment (TIA) documenting the absence of a substantial risk to the rights and freedoms of data subjects in light of applicable US legislation (FISA, EO 12333). For transfers to India (Zoho), the SCCs are supplemented by additional contractual measures taking into account the specificities of Indian data protection law (PDPB/DPDPA 2023).

2.7 Data subjects' rights

In accordance with Articles 15 to 22 of the GDPR and French Law No. 78-17 of 6 January 1978 as amended (Data Protection Act), any person whose data is processed by Corpshore has the following rights, which they may exercise at any time by contacting the DPO at info@corpshore.solutions:

RightGDPR ArticleDescription
AccessArt. 15Obtain a copy of your personal data and information about their processing
RectificationArt. 16Have your inaccurate or incomplete data corrected
Erasure (right to be forgotten)Art. 17Request deletion of your data in the cases provided for by law
RestrictionArt. 18Request temporary suspension of processing in cases of dispute
PortabilityArt. 20Receive your data in a structured, machine-readable format
ObjectionArt. 21Object to processing based on legitimate interest or for prospecting purposes
Withdrawal of consentArt. 7(3)Withdraw your consent at any time for processing based on it
Post-mortem instructionsArt. 85 LILDefine what happens to your data after your death

Corpshore may ask for proof of your identity (copy of an official document) before responding to your request, in order to prevent identity theft. If Corpshore does not respond satisfactorily within thirty days, or if you believe your rights are not being respected, you have the right to lodge a complaint with the French Data Protection Authority (CNIL), 3 Place de Fontenoy – TSA 80715 – 75334 Paris Cedex 07, accessible online at www.cnil.fr. Persons residing in another EU Member State may also contact the competent supervisory authority in their country of residence.

2.8 Data security

Corpshore implements appropriate technical and organisational measures to ensure the security of personal data processed, in accordance with Article 32 of the GDPR, taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as risks to the rights and freedoms of individuals. These measures include: encryption of data in transit (TLS 1.3) and at rest, role-based access control (RBAC) and the principle of least privilege, pseudonymisation of analytical data, regular security audits, a data breach management procedure respecting the notification deadlines imposed by Article 33 of the GDPR (notification to the CNIL within 72 hours) and Article 34 (notification to data subjects in the event of high risk), and regular staff training on data security and confidentiality.

2.9 Automated decisions and profiling

Corpshore does not carry out any profiling or entirely automated decision-making within the meaning of Article 22 of the GDPR with respect to persons using the site corpshore.fr. The interactive tools available on the Site (calculator, planner, assessment) produce algorithmic results provided for information purposes only and always require the intervention of a Corpshore consultant before leading to a commercial proposal or contractual relationship. No decision significantly affecting a natural person is made solely on the basis of the results of these tools.

3. Terms of Use

3.1 Purpose and acceptance

These Terms of Use (hereinafter 'the Terms') aim to define the conditions of access to and use of the site corpshore.fr (hereinafter 'the Site') and the services and tools made available to users. They apply to any user accessing the Site, whether a professional (B2B) or an individual, regardless of their geographical location. Access to the Site implies full and unconditional acceptance of these Terms. If you do not accept these Terms in their entirety, you must refrain from using the Site. Corpshore reserves the right to modify these Terms at any time, modifications taking effect upon publication on the Site. Continued use of the Site after modification of the Terms constitutes acceptance of the new conditions.

3.2 Access to the Site and availability

The Site is accessible free of charge to any user with internet access. The costs of such access (hardware, software, internet subscription) are solely the responsibility of the user. Corpshore implements all reasonable means to ensure continuous Site availability, but cannot guarantee uninterrupted availability or rule out interruptions related to maintenance, technical failures, cyberattacks (DDoS, etc.) or force majeure events. Corpshore reserves the right to limit, suspend or interrupt access to the Site or some of its features at any time and without notice, in particular in the event of a serious breach by a user of these Terms. Users are solely responsible for the equipment and internet connection necessary for access to the Site.

3.3 Use of interactive tools

The Site makes six interactive tools available free of charge for information purposes: (i) a savings calculator to estimate the cost differential between an in-house French team and a Corpshore team; (ii) a delivery model comparator; (iii) an outsourcing maturity assessment; (iv) a workforce planner based on an Erlang C approximation; (v) an SLA configuration builder; and (vi) a GDPR compliance checker. These tools use average market data and parameters, and their results are provided for information purposes only. They do not constitute a commercial offer, contractual commitment or professional advice. Results may vary significantly depending on your organisation's specifics. Corpshore expressly advises against making strategic or investment decisions based solely on these tool results without prior validation by a qualified consultant.

3.4 Prohibited conduct

Use of the Site is subject to compliance with these Terms and all applicable laws and regulations. In particular, it is prohibited to:

  • Using the Site for unlawful, fraudulent or public order-contrary purposes
  • Attempting to gain unauthorised access to Corpshore's computer systems, databases or networks
  • Introducing or distributing computer viruses, Trojans, malware or any other harmful code via the Site
  • Scraping, data mining or any automated content extraction without express authorisation
  • Using the Site's interactive tools to build competitive databases or for hostile competitive intelligence purposes
  • Impersonating Corpshore or its representatives, or creating confusion with the Corpshore brand
  • Using the Site to harass, threaten or defame Corpshore, its employees, clients or partners
  • Circumventing or attempting to circumvent security measures put in place by Corpshore, including the Turnstile anti-bot protection system

Any breach of these prohibitions entails the civil and, where applicable, criminal liability of the perpetrator. Corpshore reserves the right to take any appropriate interim measures, initiate any necessary legal proceedings and cooperate with competent authorities in the event of a breach of these Terms.

3.5 User warranties and liability

By using the Site, you declare and warrant that (i) you have the legal capacity to accept these Terms, (ii) the information you provide via the contact form is accurate, complete and up to date, (iii) you use the Site for legitimate professional purposes or to obtain information about Corpshore's services, (iv) you do not use the Site on behalf of an organisation engaged in unfair competition with Corpshore. You are solely responsible for the data and information you transmit to Corpshore via the Site, and you undertake not to transmit data belonging to third parties without their prior consent.

3.6 Modification and termination

Corpshore reserves the right to modify, supplement or delete all or part of the Site's content, interactive tools or these Terms at any time and without notice. Modifications take effect upon publication on the Site. It is the responsibility of each user to regularly consult the Terms to learn of any modifications. Corpshore may terminate a user's access to the Site at any time, without notice and without compensation, in particular in the event of a breach of these Terms. The provisions of these Terms relating to intellectual property, limitation of liability and applicable law survive any termination or cessation of use of the Site.

3.7 Applicable law and jurisdiction

These Terms are governed by and interpreted in accordance with French law. In the event of a dispute relating to the interpretation or performance of these Terms, and in the absence of an amicable resolution within thirty (30) days of notification of the dispute, the parties agree to submit exclusively to the competent courts of Paris, notwithstanding multiple defendants or third-party claims. This choice of jurisdiction does not deprive consumers residing in the European Union of the protections afforded by the regulations of their Member State of residence.

4. General Terms of Service — BPO, IT & AI

These General Terms of Service ('GTS') apply to all services performed by Corpshore Solutions Corporation in the context of its BPO, IT and AI outsourcing services. They apply by default in the absence of a specific Master Services Agreement signed between the parties. In the event of a conflict between these GTS and the terms of a specific Master Services Agreement or purchase order, the terms of the Master Services Agreement prevail.

4.1 Definitions

  • 'Client': any legal entity having placed an order for services with Corpshore in accordance with these GTS
  • 'Deliverables': all documents, reports, software, source code, data models, documented processes or other results produced by Corpshore in the context of a service
  • 'Client Data': personal data and/or confidential data belonging to the Client or its own clients, processed by Corpshore in the context of services
  • 'SLA' (Service Level Agreement): agreement on service levels defining Corpshore's measurable performance commitments
  • 'Quote': contractual document issued by Corpshore specifying the nature, scope, cost and timelines of proposed services
  • 'FTE' (Full-Time Equivalent): unit of measurement corresponding to a full-time equivalent working according to agreed hours
  • 'Delivery Hub': Corpshore operational site from which services are performed
  • 'Sensitive Data': personal data within the meaning of Article 9 of the GDPR, health data, banking data, data covered by professional secrecy

4.2 Contract formation and ordering

All Corpshore services are preceded by a detailed quote issued by Corpshore following an analysis of the Client's needs. The quote specifies the service scope, expected deliverables, SLA indicators selected, allocated resources (number of FTEs, profiles), unit price and total price, payment terms, service duration, renewal conditions and any prerequisites the Client must fulfil. Signature of the quote or corresponding purchase order by the Client constitutes acceptance of these GTS and the specific conditions in the quote. Any amendment to the contract must be the subject of a new quote signed by both parties. In the absence of signed written acceptance, no services may commence.

4.3 Service levels and penalties

Service levels (SLAs) applicable to each service are defined in the quote or in a specific SLA appendix. SLAs may cover indicators such as: telephone answer rate, CSAT (Customer Satisfaction Score), FCR (First Contact Resolution), back-office processing error rate, email response times, IT system availability, or any other relevant indicator depending on the type of service. In the event of a contractual SLA breach, penalties may apply according to the terms defined in the quote or Master Services Agreement. Penalties are capped at 10% of the monthly amount for the service concerned, unless otherwise explicitly agreed in the Master Services Agreement. Penalties cannot accumulate beyond this monthly cap and are not applicable in the event of a failure attributable to the Client, a sub-contractor designated by the Client, or a force majeure event.

4.4 Pricing, invoicing and payment

Service prices are expressed in euros excluding tax and are indicated in the quote. Corpshore invoices its services as follows: (i) for recurring services (BPO, IT support, dedicated teams), monthly invoicing in arrears based on FTEs actually deployed and hours worked in accordance with the agreed SLA; (ii) for one-off projects (IT development, migration, AI implementation), invoicing by milestones defined in the quote. Invoices are payable upon receipt, unless particular conditions have been negotiated in the Master Services Agreement, with a maximum period of 30 days from the invoice date in accordance with French Commercial Law (NRE Act and LME Act). Any late payment automatically results in the application of late interest at the applicable legal rate plus 10 percentage points, as well as a flat-rate collection fee of €40. Prices are revisable annually based on the SYNTEC index or any other relevant sector index.

4.5 Intellectual property of deliverables

Unless otherwise expressly stipulated in the quote or Master Services Agreement, the intellectual property rights relating to specific deliverables developed by Corpshore on behalf of a Client are transferred to that Client as corresponding payments are made, in accordance with Article L.131-3 of the CPI. This transfer covers the rights of exploitation, reproduction, representation, modification and adaptation of deliverables, for the worldwide territory and for the legal protection period. In any event, Corpshore retains its rights to tools, methodologies, processes, reusable frameworks, code libraries and generic know-how developed independently of the contractual relationship with the Client, which constitute Corpshore's technological assets.

4.6 Confidentiality

Corpshore undertakes to maintain strict confidentiality over all non-public information disclosed by the Client in the context of the contractual relationship, including information relating to its business, clients, processes, financial data and strategic projects. This confidentiality commitment applies to all Corpshore personnel involved in the service and survives termination or expiry of the contract for five (5) years. Corpshore may only disclose this information to third parties, including its sub-contractors, with the Client's prior written consent and provided these third parties are themselves subject to equivalent confidentiality commitments. Exceptions apply to information that has entered the public domain without Corpshore's fault, information known to Corpshore before the contractual relationship, and disclosures required by a legal or regulatory obligation.

4.7 Liability and insurance

Corpshore's liability for any direct damage arising from the performance or non-performance of services is capped at the amount of sums actually received by Corpshore for the services in dispute during the twelve (12) months preceding the damaging event. This limitation of liability does not apply in cases of fraud, gross negligence, death or bodily injury caused by Corpshore's negligence, nor to confidentiality and data protection obligations. Corpshore expressly excludes all liability for indirect damages, including loss of revenue, loss of profits, loss of customers, brand damage or loss of opportunity. Corpshore maintains professional liability insurance covering risks related to its BPO, IT and AI service provider activities, the terms of which are available upon Client request.

4.8 AI-specific provisions

For services involving the development, deployment or use of artificial intelligence systems (hereinafter 'AI systems'), the following provisions apply in addition to these GTS. Corpshore designs, deploys and operates exclusively AI systems classified as minimal risk or limited risk under the taxonomy of Regulation (EU) 2024/1689 on artificial intelligence (EU AI Act). Corpshore does not deploy high-risk AI systems within the meaning of Annex III of the EU AI Act (including AI systems in the areas of employment, workforce management, biometrics, critical infrastructure, education or justice) without specific contractual framing and Client validation. For limited-risk AI systems deployed on the Client's behalf (including chatbots, virtual agents and content generation systems), Corpshore guarantees the implementation of transparency obligations imposed by Article 52 of the EU AI Act, including the obligation to inform end users that they are interacting with an AI system.

AI deliverables (trained models, NLP pipelines, RPA systems, AI assistants) are accompanied by technical documentation comprising: system description and functionalities, training data used and their limitations, performance measured on representative test sets, use cases for which the system is designed and uses for which it should not be used, human oversight mechanisms (human-in-the-loop), as well as maintenance and update procedures. The Client remains responsible for its use of AI systems developed by Corpshore and their compliance with applicable regulation, including the EU AI Act, GDPR and relevant sector laws.

4.9 Duration, termination and transition

Recurring services are entered into for an initial period defined in the quote, generally a minimum of twelve (12) months for dedicated teams, with automatic renewal by successive periods of one year unless a termination notice is sent by recorded delivery letter at least ninety (90) days before the deadline. In the event of early termination of the contract by the Client for convenience (without any breach by Corpshore), the Client undertakes to pay all services corresponding to the contractual notice period, as well as a termination indemnity equal to two (2) months of the average monthly value of services performed during the last three months. In the event of termination for fault attributable to Corpshore, Corpshore's liability is limited in accordance with Article 4.7 above. Corpshore undertakes to ensure an orderly transition during the notice period, including process documentation, successor team training and return of Client Data in agreed formats.

5. Data Processing Appendix — GDPR Article 28 (DPA)

This Data Processing Appendix ('DPA') constitutes the sub-processing agreement provided for in Article 28 of the GDPR for all personal data processing that Corpshore Solutions Corporation ('the Processor') performs on behalf of its Clients ('the Controller') in the context of BPO, IT and AI services. In the event of a conflict between this DPA and the GTS or Master Services Agreement, the provisions of this DPA prevail on matters relating to data protection.

5.1 Subject matter, nature and purpose of processing

Corpshore processes personal data on behalf of the Client in the context of services defined in the quote or Master Services Agreement. The nature of the processing varies depending on the type of service: (i) BPO: data entry, verification, classification, indexing and archiving; processing of forms, files, claims and orders containing the Client's clients' personal data; (ii) IT Outsourcing: access to the Client's IT systems likely to contain personal data in the context of technical support, maintenance, development and migration; (iii) AI: processing of training data potentially containing personal data, labelling, annotation, development and deployment of natural language processing models or other AI models used to analyse personal data. The purposes of processing are exclusively those defined by the Controller in the context of its own commercial and operational activities.

5.2 Controller instructions

Corpshore processes personal data only on documented instructions from the Controller, in accordance with Article 28(3)(a) of the GDPR. These instructions are formalised in the quote, Master Services Agreement, this DPA and any subsequent written exchanges. Corpshore immediately informs the Controller if it considers that an instruction violates the GDPR or any other provision of EU or Member State national law. In such cases, Corpshore may suspend execution of the instruction pending its confirmation or modification by the Controller, without this suspension being considered a contractual breach on Corpshore's part.

5.3 Security measures (Article 32 GDPR)

Corpshore implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing carried out on behalf of the Client, in accordance with Article 32 of the GDPR. These measures include, without limitation:

  • Encryption of data in transit (minimum TLS 1.3) and at rest (AES-256) for all sensitive personal data
  • Role-based access control (RBAC) and mandatory multi-factor authentication (MFA) for access to systems processing personal data
  • Continuous access logging and monitoring (SIEM), with automatic alerts in case of suspicious activity
  • Environment segregation (development, test, production) and anonymisation/pseudonymisation of data in non-production environments
  • Annual penetration tests conducted by independent third-party providers and remediation plan for identified vulnerabilities
  • Disaster Recovery Plan (DRP) and Business Continuity Plan (BCP) regularly tested, with RTO/RPO targets defined by service type
  • Mandatory training of all staff on data security and personal data protection issues, renewed annually
  • Documented data breach management procedure complying with Article 33 GDPR deadlines

5.4 Sub-processors (Article 28(2) GDPR)

Corpshore has general authorisation from the Controller to engage sub-processors, subject to prior notification to the Controller and the Controller's right of objection under the conditions of Article 28(2) of the GDPR. Corpshore imposes on all sub-processors the same data protection obligations as those defined in this DPA, in particular through standard contractual clauses or any other appropriate transfer mechanism. The main sub-processors likely to be engaged in the context of Corpshore services are as follows:

Sub-processorCountryRoleTransfer mechanism
Vercel Inc.United StatesClient platform and internal tool hostingSCCs (2021/914/EU) + TIA
Zoho CorporationIndiaCRM, ticketing, HR managementSCCs + additional measures (DPDPA 2023)
Corpshore delivery hubsMorocco, Côte d'Ivoire, Senegal, Philippines, India, etc.BPO processing, IT support, AI tasks per serviceSCCs or adequacy decision depending on country
Atlassian (Jira/Confluence)Australia / EUProject management and internal documentationSCCs + EU sub-processors
Microsoft 365European UnionCollaboration and productivity (EU tenant only)Adequacy decision / MS DPA guarantees

5.5 Data breach notification

In accordance with Article 33 of the GDPR, Corpshore notifies the Controller of any personal data breach affecting the Controller as soon as possible and, if possible, within seventy-two (72) hours of discovering the breach, to enable the Controller to meet its own notification obligations to the CNIL. The notification includes, to the extent possible: (i) a description of the nature of the breach, (ii) the categories and approximate number of data subjects concerned, (iii) the categories and approximate number of records concerned, (iv) the likely consequences of the breach, and (v) measures taken or planned to remedy the breach and mitigate its potential adverse effects. Corpshore maintains internal documentation of all data breaches, whether or not they have been notified to the CNIL, in accordance with Article 33(5) of the GDPR.

5.6 Return and deletion of data

At the end of services or upon the Controller's request, Corpshore returns all Client Data in a structured, commonly used and machine-readable format within thirty (30) days of the request or end of service, whichever comes first. After return and written confirmation of receipt by the Controller, Corpshore proceeds to secure deletion of all copies of Client Data stored on its systems and those of its sub-processors, within sixty (60) days. A deletion certificate is issued to the Controller upon request. Corpshore retains, for its own legal and accounting compliance, minimal records (billing metadata, compliance logs) strictly necessary for its legal obligations.

5.7 Audit and verification

Corpshore makes available to the Controller all information necessary to demonstrate compliance with the obligations of this article, in accordance with Article 28(3)(h) of the GDPR. The Controller may, after prior written notice of at least thirty (30) business days and at its own expense, conduct or have conducted by a mandated independent auditor compliance audits of Corpshore's security and data protection measures, within the following limits: (i) a maximum of one (1) time per calendar year, except in the event of a confirmed data breach or reasonable suspicion of non-compliance; (ii) during normal business hours and without disrupting Corpshore's operations; (iii) subject to an enhanced confidentiality agreement between the auditor and Corpshore. Corpshore may also provide third-party audit reports (SOC 2, ISO 27001, sector certifications) as partial or full substitution for an on-site audit.

6. Cookie Policy

The site corpshore.fr uses cookies and similar tracking technologies. A cookie is a small text file deposited on your device when you visit the site. In accordance with Article 82 of the French Data Protection Act and CNIL guidelines, only cookies strictly necessary for the operation of the site may be deposited without prior consent. Any analytical, advertising or personalisation cookie requires your prior consent.

Name / SourceCategoryPurposeLifetime
cf_langStrictly necessaryStores language preference (fr/en)Session
cf_tool_insightsFunctional (localStorage)Stores interactive tool interactions to enrich quotesUntil form submission
__cf_bm (Cloudflare)Strictly necessaryTurnstile anti-bot protection, contact form verification30 minutes
_vercel_*Strictly necessaryVercel deployment management and CDN cacheSession
Google Analytics (disabled)Analytical (with consent)Not deployed on this site — no active GA cookieN/A

You can modify your cookie preferences at any time by accessing your browser settings. Most browsers allow you to refuse cookies, delete existing cookies or be alerted when a cookie is set. Note that disabling certain cookies may affect the proper functioning of the site. To learn more about cookies and the management of your personal data, you can visit the CNIL website (www.cnil.fr).

7. EU AI Act Compliance — Regulation (EU) 2024/1689

Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 establishing harmonised rules on artificial intelligence (the EU AI Act) has been progressively applicable since 2 August 2024. As an artificial intelligence services provider offering AI systems to its clients, Corpshore Solutions Corporation is subject to the obligations applicable to providers and deployers of AI systems according to the risk classification of those systems.

7.1 Classification of Corpshore AI systems

  • NLP systems (natural language processing) for classification and routing of support tickets → Minimal risk (Annex I, outside scope of Title II)
  • Chatbots and virtual agents deployed for customer service → Limited risk (Article 52 — transparency obligation towards the end user)
  • Content generation systems (generative AI) for assisted writing and document synthesis → Limited risk (Article 53 — labelling of AI-generated content)
  • RPA (Robotic Process Automation) pipelines → Minimal risk, no specific EU AI Act obligations
  • Labelled data models and annotation systems → Minimal risk, applicable DPA contractual framework
  • Corpshore does not deploy general-purpose AI systems (GPAI) within the meaning of Article 3(63) or foundation models within the meaning of Article 3(65) of the EU AI Act without specific contractual agreement

7.2 Transparency obligations (Article 52 EU AI Act)

In accordance with Article 52 of the AI Regulation, Corpshore ensures that any AI system it deploys on behalf of a Client that directly interacts with end users is accompanied by a clear information mechanism indicating that the user is interacting with an artificial intelligence system and not a human. This obligation is implemented via interface notices (AI label, chatbot welcome message, AI-generated email signature). Clients who deploy Corpshore AI systems to their own end users assume responsibility for compliance with Article 52 in the context of their own deployment and are required to inform Corpshore to enable compliance of the corresponding interface.

7.3 EU AI Act contact and questions

For any questions relating to the compliance of Corpshore AI systems with Regulation (EU) 2024/1689, in particular for clients wishing to obtain compliance documentation, a risk assessment or a risk classification certificate for a specific AI system, please contact: info@corpshore.solutions

These legal documents are governed by French law and updated in accordance with regulatory developments in LCEN, GDPR and EU AI Act. Last updated: 1 August 2026. Contact: info@corpshore.solutions

📋 Request a quote