License agreement Cryptopass

This agreement (the « Agreement ») is signed between Ercom SAS (« Ercom ») and yourself, acting on behalf of a company or other entity, you warrant that you are duly authorized to enter into this Cryptopass license Agreement on behalf of such company or other entity (the “Customer”), and governs your use of the Cryptopass Solution and related documentation during the subscription period.


1.         Cryptopass: The secure and professional messaging and communication solution
Cryptopass (Hereafter referred to as “Solution”), is a solution that offers a service that guarantees end-to-end encryption of communications. It is designed to secure communications (audio, video, instant messaging, file transfer) within an organization as well as to other organizations. The Solution is used by the end user designated by the Customer (hereinafter a “User”).

For your information, the Solution is under the regulation concerning the dual-use goods and/or means of cryptography.

For additional information on Cryptopass, refer to our website https://ercom.com/cryptopass/ (le « Website »).

It is important to note that, there are significant differences between Cryptopass and mobile, fixed telephony and SMS services. Cryptopass does not allow access to emergency services, such as police, firefighter or hospitals, or any other connection to emergency call centers. Users may, however, contact emergency services through mobile or fixed telephone services or another service on which Cryptopass does not interfere.


2.         Offers Cryptopass
2.1     Offers « Cryptopass » (hereafter referred to as the « Offer »), as described on the Website are characterized by:

–          A professional system offering administration capabilities: mobile fleet and user management within an organization,

–          Secure exchanges guaranteeing a very high level of encryption: only authorized persons concerned by the communication have access to it, there is no possible interception of the content of these exchanges,

–          A user experience combining rich functionality with ease of use,

–          A SaaS (Software as a Service) solution subscribed directly on the Website: no infrastructure is required by organizations wishing to use it. Cryptopass is a Service accessible directly on the Ercom cloud for Customers located in one of the countries eligible for the Offer.

2.2     Sales conditions:

Offers are available, depending on the Offer subscribed, with or without commitment as follows:

–          Offer without commitment, renewable from month to month “Offer without commitment”.

–          12-month commitment Offer “Offer with commitment”.

The characteristics, support levels and associated financial conditions of each Offer are described on the Website https://ercom.com/cryptopass/.

Prices on the Website are indicated in EUROS, net of any tax (including withholding taxes).

3.         Eligibility – Access to the Cryptopass Solution
3.1     Eligibility: Subscription to the Cryptopass Solution is reserved for professional Customers whose registered office is located in France (the “Territory”) for the duration of the Agreement.

The subscription will thus be possible if the Customer can prove, (i) a registration address located on the Territory, and (ii), a European telephone number or an intra-community VAT number. In addition, in order to subscribe to certain options offered with the Cryptopass Solution, the Customer must have an e-mail address whose e-mail domain is eligible for the Cryptopass Service.

Within thirty (30) days from the Effective Date of the Agreement, the Customer must send Ercom a copy of the documents certifying that the Customer is located in the Territory. If the Customer fails to communicate the documents requested by Ercom at the end of this thirty (30) day period, Ercom shall be entitled, after sending the Customer a letter by electronic means that has remained without effect at the end of a four (4) day period, to terminate this Agreement, without any right for the Customer to any refund.

3.2     Effective date: the subscription takes effect on the date of acceptance by Ercom of the Customer’s purchase order via the Website.

3.3     Users deployment : As it targets a large segment, Cryptopass focuses on the easy deployment of the Solution :

·         The Customer subscribes to an Offer on the Website,

·         The Customer designates an administrator on the Website (the “Administrator”) who manages the Customer’s account,

·         On the date of confirmation of the order, the Administrator receives by email the connection information to the administration interface of the Solution and declares the Customer’s Users authorized to use the Solution directly on the administration interface (only the telephone number is necessary),

·         The Users download on their device the Cryptopass application from Apple and Android stores,

·         Users enrol their device and are ready use the Cryptopass Solution,

·         At any time, the Administrator, managing the Customer’s License, can modify the Users list (deletion of a User and declaration of a new User replacing the previous)

The administration interface will be accessible through a standard navigator with a secure connection. The identifiers will be sent by email to the Administrator once the order has been validated.

3.4     For a User, enrolment consists of associating a device to his/her phone number. This is performed by a verification code sent through SMS for the time being.

Once enrolled, the User access the application on the device and can establish a secure communication with any other User on the system.

3.5     Adding of Users: Only an Administrator can invite, via the Cryptopass administration interface, new Users. Thus, when a User other than an Administrator wishes to invite new User, he will have to make a request to an Administrator.

For this purpose, the Customer, through the Administrator, must order new licenses from Ercom for the number of additional Users desired. New licenses are subscribed with or without commitment depending on the Offer subscribed.

The fee corresponding to the addition of these Users is calculated and invoiced in advance, under the conditions defined in article 5.2.

The addition of Users is possible at any time, under the conditions defined above.

3.6     Reduction of the number of Users:

–          Offer with commitment: When the Customer wishes to reduce the number of Users, the Administrator must, at the latest one (1) month before the end of his commitment period, send Ercom, via the administration interface, a notification of request to delete User account. The reduction will be effective only on the 1st day of the new subscription period.

–          Offer without commitment: When the Customer wishes to reduce the number of Users, the Administrator sends a notification of request to delete User account via the administration interface. Such request may be made at any time but may only be effective on the first day of the upcoming calendar month and subject to 15 days’ notice from the date on which Ercom is notified.

4.         Duration and Termination
4.1     Renewals and termination :

4.1.1      Offer without commitment: Subscription is automatically renewed from month to month for each authorized User until terminated by either party.

At any time, the Customer may cancel its subscription simply by sending a notification of deletion of all User accounts on the administration interface. Termination shall be effected on the last day of the current month, subject to 15 days’ notice from the date of receipt of the notice of termination.

Ercom may terminate the Agreement at the end of a calendar month, subject to 30 days’ notice

4.1.2      Offer with commitment: At the end of each subscription period, the subscription is automatically renewed, for a new period of twelve (12) months, for each of the authorized Users, unless terminated by registered letter with acknowledgement of receipt sent by one or other of the Parties or more simply for the Customer by sending a notification of deletion of all User accounts on the administration interface, at least fifteen (15) days before the end date of the current subscription period.

The termination takes effect on the last day of the subscription period.

4.1.3      In any case (Offer with or without commitment), if the Customer commits a substantial breach of this Agreement, and in particular in the event of non-payment of the fee on its due date, Ercom may (without prejudice to Article 3.1) temporarily suspend Users’ access rights to Cryptopass or terminate the Agreement if the default shall not be remedied after a period of fifteen (15) days following notification to the Customer.

4.2     Consequences: At the end of the Customer’s subscription, which may result in particular from the termination of the Agreement, Users will be disconnected and their rights removed from the Cryptopass platform. They will no longer be able to communicate from the application. Termination of the Agreement before the end of the firm commitment period shall not give rise to any reimbursement from Ercom.

4.3     Survival: The provisions of this Agreement which, due to their nature, are intended to apply after the termination of the Agreement or the expiry of the rights to use Cryptopass, survive such an event.

5.         User Fees
5.1     Invoicing. Licence fees are invoiced at 100% in advance, for the subscription period of the Offer, on the date of acceptance of the Customer’s order.

For the Offer without commitment, the first invoice is made prorata temporis over the current month.

Ercom may change its prices at any time at its sole discretion upon ninety (90) days written notice to Customer, and such changes shall be effective for all Orders made by Customer and received by Ercom after ninety (90) days from such notice. The termination of the licenses by the Customer before the end of the firm commitment period shall not give rise to any reimbursement from Ercom.

5.2     Adding of Users. If Users are added during the month or during the subscription period, new licenses are invoiced at the rates in force as follows:

–          New licenses Offer without commitment: invoiced 100% in advance on the date of acceptance of the order, pro rata temporis over the current month ;

–          New licences Offer with commitment: invoiced 100% in advance on the date of acceptance of the order, for the firm duration of the commitment (remaining duration of the first licences).

5.3     Payments. Payments must be made in euros, online on the Website, and according to the authorized means of payment proposed on the Website. The Customer is required to provide complete and accurate billing information and contact information. The Customer guarantees that he has the necessary authorizations to use the payment method chosen at the time of validation of the order. Any incident of payment at the time of subscription will result in automatic cancellation of the order and immediate termination of the Agreement.


The Customer undertakes, for the duration of the Agreement, to keep accurate bank details and must notify Ercom as soon as possible in the event of any change concerning them. In the event of a payment incident during performance of the Agreement, Ercom may suspend immediately and without prior notice the rights of access and use of the Solution, which prevents normal use of the Solution by Users, until payment is regulated by the Customer. If the Customer fails to regularize the situation after a period of fifteen (15) days following notification to the Customer by Ercom, Ercom shall be entitled to terminate the Agreement with immediate effect in accordance with the provisions of article 4.1.3.

5.4     Taxes. Any taxes or duties related to the Cryptopass Solution subscription, including any associated penalties or interest (collectively the “Taxes”), shall be borne by the Customer.

5.5     Default. If payment is not made within the period specified in this Agreement, then, any unpaid amount shall automatically and without any prior formality, accrue interest on a daily basis until the date when it is paid in full, including the principal amount, interest, fees and expenses, at a rate equal to the prime rate equal to the French legal interest rate plus five (5) points of percent-age, without prejudice to the fixed indemnity provided for in article L.441-6 of the Code de Commerce and damages that Ercom reserves the right to claim in court proceedings. The parties agree that any expenses (court expenses, fees, costs, attorney’s and bailiff’s fees…) related to the collection of the amounts due and unpaid by Customer shall constitute part of the principal amount owed to Ercom.

6.         Maintenance
6.1     Guarantee of proper operation and maintenance. Ercom shall ensure the correct functioning of the Solution within the scope of the maintenance services that Ercom provides to the Customer from the date of availability of the Solution for the Users.

6.2     Cryptopass Support Center. The Cryptopass support center is open Monday to Friday from 9 am to 6 pm (metropolitan French time) excluding public holidays. Access available is via our website https://desk.cryptopass.fr. The Cryptopass support is available only to Administrator, and it provides answers to technical questions about the Cryptopass technology, handles any operating problems and collects any requests for enhancements (without any commitment of implementation). When a complete support request (issuer, reason, severity, type, description) is received by Ercom, a ticket number is sent to the Administrator by email within 4 business hours. Depending on the package subscribed by the Customer, Ercom can offer different levels of support, allowing the Customer to benefit from additional services and support levels. These support levels are described in the Support Conditions and corresponding documentation available on the Website. The content of the support levels as well as the scope of the maintenance services depends on the Support Conditions subscribed by the Customer.

6.3     Hosting. In the event of a problem with the availability of the Solution, the Support center contacts the Ercom partner responsible for hosting the Solution to ensure recovery as soon as possible. Except contrary conditions described in the Support Conditions subscribed by the Customer, there is no commitment of availability and recovery in the Offer, as acknowledged and accepted by the Customer. The hosting partner does not and cannot have access to the shared data, the data is not stored in clear on the servers but only on the Users’ devices. Ercom reserves the right at any time to change its partner for accommodation without having to inform the Customer.

6.4     Not included. The support does not include any requests regarding the Customer’s IT network environment, User training, issues resulting from negligence, misuse of the Solution or any problem related to the hosting. The limited warranties set forth in this Agreement are the only warranties granted by Ercom to the Customer and, to the fullest extent permitted by applicable law, Ercom warrants all other warranties.

7.         Use of the Solution by the Customer
7.1     Principles. The Customer shall follow by the End-user’s instructions available in the documentation and not use the Solution for illegal or unlawful purposes, including infringement of intellectual property rights, or otherwise than for its own purposes.

7.2     End-User License – Privacy Policy. Users must accept the terms of the End-User license and the Privacy Policy that are communicated at the creation of their account. This license is accepted by each User when he / she creates his / her account, and it is the Customer’s responsibility to ensure that the Users he / she has designated have accepted this documents.

7.3     Customer network Infrastructure. The Solution, accessible remotely by the Users, is installed in an Ercom partner who ensures the hosting and the availability. The Customer remains solely responsible for the conditions under which the Solution is made available and available to Users. It shall be responsible for putting in place the resources, equipment, systems, software, means of communication and security, both physical and logical, and more generally, any element capable of ensuring the level of service it wishes the Users to benefit from.

7.4     Customer Return. The Customer agrees to provide Ercom during the Agreement period and at the end of the Agreement, an assessment of the use of the Solution, its ergonomics, its performance and its needs with regard to the functionality of the Solution. The implementation or the development of enhancements, modifications and evolutions of the Solution recommended by the Customer will be at Ercom’s sole discretion.

8.         Personal Data
8.1     Purpose :

The Customer collects and transmits to Ercom the personal data (« Personal Data »):

–          Of Customer contacts so that Ercom can ensure the proper execution of the Agreement, and

–          The Personal Data of Users so that Ercom activates and manages their licenses to use the Solution.


The Customer warrants to Ercom that this collection and transmission of the Personal Data of the Customer contacts and Users is carried out in accordance with the applicable regulations on personal data processing and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter the “GPDR”) and the law of 6 January 1978 as amended, in particular that the individuals concerned are informed that Ercom is the addressee of their Personal Data.


8.2     Personal Data processing:

Ercom undertakes to comply with the applicable regulations on personal data processing and, in particular, the GDPR and the law of 6 January 1978 as amended, in all its data collection, hosting and processing activities under the Agreement.


8.3     Information regarding Customer Contacts:

The legal basis of the processing by Ercom is Ercom’s legitimate interest in ensuring the proper execution of this Agreement (order and delivery procedure, follow-up of the Partner account, invoicing).

The recipients of this Personal Data are Ercom staff members or authorized subcontractors in charge of the supervision and management, in whole or in part, of the Agreement.

This Personal Data is retained for a period of three (3) years following the expiration or termination of the Agreement or the termination of any contractual relationship with the Customer or any affiliate of the Customer.

At the time of the first communication with the data subjects, Ercom informs them of this processing and of their rights in accordance with Article 14 of the GDPR and the law of 6 January 1978 as amended


8.4     Information regarding Users:

The purpose and duration, as well as the nature and purpose of the processing, the type of Personal Data, the categories of data subject, as well as the obligations and rights of Ercom and the Users of the Solution are specified in the Cryptopass privacy policy accessible from the download shop of the Solution or on request by contacting Ercom at the following email address: dpo@ercom.fr.

The Privacy Policy and the Cryptopass General Terms and Conditions of Use relating to the Solution are communicated to Users at the time of their first connection. This communication is carried out directly by Ercom.

Furthermore, it is the Customer’s responsibility to inform to inform the Users himself of the indirect collection of Personal Data at the same time as they are communicated to Ercom.


8.5     Exercise of data subjects’ rights:

If the data subjects contact Ercom directly for exercising one of the data subjects’ rights conferred by the GDPR, such as: right of access, to rectification, erasure and to object, right to rectification of processing, right to data portability, or withdrawal of consent, Ercom shall inform the Customer without delay and, in any event, grant their request within the time limits and under the conditions provided for in the GDPR and the law of 6 January 1978 as amended.

If the data subjects contact the Customer for exercising one of the data subjects’ rights conferred by the GDPR, the Customer shall immediately inform Ercom, which shall grant their request within the time limits and under the conditions provided for in the GDPR and in the law of 6 January 1978 as amended.


8.6     Sub-contracting:

Ercom may engage a processor to carry out specific processing activities in accordance with Article 28 of the GDPR and the law of 6 January 1978 as amended.

In this case, Ercom concludes a contract with the processor defining the purpose and duration of the processing, the nature and purpose of the processing, the type of Personal Data and the categories of data subjects, and Ercom’s obligations and rights.

It is Ercom responsibility to ensure that the processor provides the same sufficient guarantees to implement appropriate technical and organizational measures in such a manner that processing meets the requirements of the GDPR. Where the processor fails to fulfil its data protection obligations, Ercom remains fully liable for the performance by the processor of its obligations.


8.7     Notification of Personal Data breaches :

Ercom shall notify the competent supervisory authority (the CNIL), of the Personal Data breaches without undue delay and, where feasible, not later than 72 hours after having become aware of them, unless the breach in question is unlikely to result in a risk to the right and freedoms of natural persons.

Ercom shall communicate the Personal Data breach to the data subject without undue delay where said breach is likely to result in a high risk to the rights and freedoms of natural persons. The communication to the data subject shall describe in clear and plain language the nature of the Personal Data breach in accordance with section 34 of the GDPR.


8.8     Security measures:

Ercom undertakes to implement technical and organizational measures guaranteeing a level of security adapted to the risk, in particular by storing Personal Data on servers in France to which access is secured by logical and physical restrictions, with access logging.

Ercom ensures that the persons authorized to process Personal Data have undertaken to preserve their confidentiality or are subject to an appropriate legal obligation of confidentiality.

In addition, Customer Contacts may also be transferred to ERCOM processors outside the European Union. Such transfers shall be made, in accordance with Articles 44 and subsequent of the GDPR, on the basis of an adequacy decision or with appropriate safeguards, such as standard clauses adopted by the European Commission.


8.9     Data Protection Officer:

Ercom informs the Customer that its Data Protection Officer can be contacted at the following address: dpo@ercom.fr


8.10  Record of categories of processing activities:

Ercom states that it maintains a written record of all categories of processing activities carried out under its responsibility.

9.         Others clauses
9.1     Ercom’s responsibility. Ercom shall only be liable for direct loss or damage to the Customer, up to the sum of the fees paid by the Customer to Ercom during the six months immediately preceding the date of the initial event which caused this loss, without this limit exceeding the sum of two thousand five hundred Euros (2,500 €). Ercom may suspend the access service to the Solution in case of force majeure, public order, injunction, judicial or administrative decision. The Customer acknowledges the Offer accepted by the Customer is a result of a balance that together constitute the extent of Ercom’s obligations (especially in terms of availability of the Solution and access to the Cryptopass support center), the license-fees, and limitations of liability of Ercom.

9.2     Customer’s responsibility: The Customer must ensure that it is authorized to use the Cryptopass Service in the country where the Customer and the Users are located. The Customer is responsible for any violation of local law or regulation. Ercom shall under no circumstances be liable for damages that may occur to the Customer and Users resulting from the use of the Service in the event of non-compliance by the Customer and/or Users with the law or local regulations.

9.3     Intellectual Property: Ercom grants to the Customer non-exclusive internal right to use of the Solution for internal use only. In this context, and subject to the service payment by the Customer, authorized Users can use the Solution for the duration of the subscription, as long as their account is active. All rights not expressly granted to the Customer are reserved by Ercom. In particular, the Solution remains the Ercom’s property.

9.4     Contractual Documents: The contract between Ercom and the Customer for the use of the Cryptopass Solution according to the Offer consists of this contract, the purchase order sent by the Customer on the Website, and the Cryptopass General Terms and Conditions of Use (T&Cs) that each End-User designated by the Customer must have known and accept before using the Solution.

9.5     Applicable law: The Agreement is governed by the laws of France and shall be interpreted accordingly.

9.6     Jurisdiction: Any dispute or claim arising out of or in connection with the Agreement shall be exclusively brought to the competent courts of Paris, regardless plurality of defendants or action by third parties.


Read “Cryptopass General Terms and Conditions of Use (T&Cs)”

Version 2.0

Protection des données : pourquoi et comment RSSI et DSI doivent-ils collaborer ?