Privacy policy
What we collect, why, for how long — and how to exercise your rights. No jargon.
Last updated: July 4, 2026
Data we collect
We only collect data you voluntarily submit through the site forms (contact form and project brief):
- Identity and contact: name, email address, phone (optional)
- Your request: subject, message, type of need, sector, timeline
- Scoping: estimated budget (optional) and preferred language
Why we use it
This data is used exclusively to answer your request, prepare a first call and scope your project. Commercial follow-up via the project brief only happens with your explicit consent (checkbox). We never sell or rent your data to third parties.
Legal basis: your consent (GDPR article 6.1.a) for follow-up, and our legitimate interest (article 6.1.f) to answer a request you initiate.
Where it is stored and for how long
Your messages are sent to our team by email and kept in our secured database, hosted on cloud infrastructure (Vercel / data hosting partners). Some providers may be located outside the European Union; they provide GDPR-compliant safeguards (standard contractual clauses).
Requests are kept for as long as needed to process them and follow up on the business relationship, then deleted. You can request early deletion at any time.
Cookies
The site uses a single functional cookie, exempt from consent:
- NEXT_LOCALE — remembers your preferred language (French or English) for 12 months.
- You can choose not to store this preference from the banner or the footer “Cookie settings” link.
- No advertising, third-party analytics or social network cookie is set.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to and port your data. To exercise these rights, write to dianah.consulting@gmail.com — we reply within 30 days. You may also lodge a complaint with your supervisory authority (CNIL in France, cnil.fr).
Security
The site applies strict security measures: end-to-end HTTPS encryption, hardened security headers (Content Security Policy), systematic server-side data validation and request throttling to prevent abuse.