1. Data Controller
The data controller for personal data processed in connection with the Blog is:
CL Corporate Affairs Consulting E.I.
Registered office: 1 avenue de l’Observatoire, 75006 Paris, France
Representative office: Avenue de Tervueren 103, B-1040 Brussels, Belgium
SIREN: 902 992 189
Director of Publication: César Lesage
Contact: via the Blog contact form (/contactpage-blog.html) or by post at the address above.
2. Personal Data We Collect
2.1 Anonymous audience measurement
When you visit a Blog page, the following technical data is collected for statistical purposes only:
- truncated and anonymised IP address (last octet removed before storage);
- pages visited, date and time, approximate session duration;
- referral source (the URL of the site that brought you to the Blog, if any);
- browser and device category (e.g. “Chrome, desktop”);
- approximate country of origin, derived from the truncated IP.
This data is collected via Umami, an open-source analytics tool that we self-host on our own infrastructure. No identifier is shared with any third party. No persistent cookie is set for this purpose.
2.2 Data submitted via the Blog contact form
If you write to the editor through the dedicated form at /contactpage-blog.html, we collect:
- last name, first name;
- email address (required);
- phone number, company / organisation (optional);
- subject and content of your message;
- date and time of submission;
- a transient anti-abuse verification token (Cloudflare Turnstile, see Section 6).
2.3 What we do not collect
The Blog does not currently offer a newsletter, does not host public comments, does not require account registration, does not run advertising trackers, does not build advertising or behavioural profiles, and does not use your data for AI model training.
3. Legal Basis (Article 6 GDPR)
- Audience measurement: legitimate interest of the editor (Article 6(1)(f) GDPR) in producing aggregate, anonymous statistics for editorial improvement. This processing is exempt from prior consent under Article 5(3) of Directive 2002/58/EC (ePrivacy), as confirmed by the French CNIL for privacy-preserving, self-hosted analytics.
- Contact form submissions: your consent (Article 6(1)(a) GDPR), expressed by submitting the form, for the sole purpose of responding to your enquiry.
- Anti-abuse verification: legitimate interest (Article 6(1)(f) GDPR) in protecting the form against automated abuse.
4. Purposes of Processing
- understanding which subjects and articles interest readers (aggregated, anonymous);
- responding to enquiries received via the Blog contact form;
- detecting and preventing abuse (spam, automated scraping, attacks);
- complying with applicable legal obligations.
We do not use your data for commercial profiling, behavioural advertising, AI/LLM training, or resale to third parties.
5. Retention Periods
- Audience measurement data: individual visit records are pruned after 13 months; aggregated statistics may be retained up to 25 months.
- Contact form submissions: retained for up to 36 months from the last interaction, then deleted, unless a longer retention is required by law (commercial correspondence: 5 years under Article L.123-22 of the French Commercial Code).
- Anti-abuse tokens: not retained; processed only at the moment of submission.
- Server logs: 30 days, for security and incident response purposes only.
6. Recipients & Third Parties
Your data is processed only by the editor and by the following technical service providers, strictly within their respective roles:
- Umami Analytics — open-source, self-hosted on our own server (umami.cl.eu.com). No data leaves our infrastructure.
- Cloudflare, Inc. — provides Turnstile (anti-bot challenge on the contact form) and edge content delivery. Cloudflare processes minimal technical signals (IP address, browser fingerprint) for the strict purpose of these services. See the Cloudflare Privacy Policy.
- Google LLC — Google Translate (optional). If you voluntarily activate the integrated translation button on a Blog page, your request and the page text are transmitted to Google for translation. We do not control this third-party processing. See the Google Privacy Policy.
We do not sell, rent or share your personal data with any other third party.
7. International Transfers
Our hosting and analytics infrastructure is located within the European Economic Area (EEA). Cloudflare may route traffic through its globally distributed network; transfers outside the EEA rely on the European Commission’s Standard Contractual Clauses (Article 46 GDPR). Google Translate, if used voluntarily, processes data internationally under its own framework.
8. Cookies
The Blog does not set advertising, tracking or profiling cookies. Umami does not set cookies. A strictly functional cookie may be set by Cloudflare Turnstile only if you submit the contact form, solely for anti-spam verification, and is deleted at the end of your session.
9. Your Rights under GDPR
You may exercise the following rights, free of charge, at any time:
- right of access (Article 15);
- right to rectification (Article 16);
- right to erasure — “right to be forgotten” (Article 17);
- right to restriction of processing (Article 18);
- right to data portability (Article 20);
- right to object (Article 21);
- right to withdraw consent at any time (Article 7(3));
- right to lodge a complaint with a supervisory authority — in France, the CNIL; or with the supervisory authority of your country of residence within the EEA.
To exercise any of these rights, please contact us via the Blog contact form: /contactpage-blog.html. We will respond within one month (extendable by two further months for complex requests, Article 12(3) GDPR).
10. Security
We apply appropriate technical and organisational measures to protect your data: TLS encryption in transit, regular security updates, restricted server access, end-to-end encryption for sensitive contact form fields where applicable, and incident-response procedures. No transmission over the Internet can be guaranteed to be 100% secure. In the event of a personal data breach likely to result in a high risk to your rights, we will notify affected individuals as required by Article 34 GDPR.
11. Children
The Blog is intended for an adult professional audience. We do not knowingly collect personal data from individuals under 16. If you believe a minor has submitted data, please contact us so we may delete it.
12. Updates to this Policy
This Policy may be updated to reflect changes in our practices or in applicable law. The version in force is the one published on this page, dated above. Previous versions are available on request.
13. Contact
For any privacy-related question, or to exercise your rights:
- via the Blog contact form: /contactpage-blog.html;
- by post: CL Corporate Affairs Consulting, 1 avenue de l’Observatoire, 75006 Paris, France, or Avenue de Tervueren 103, B-1040 Brussels, Belgium.