Privacy

Privacy policy

This policy describes exactly which data the site processes, the purposes, how long it is kept and your rights.

Last updated :

Data controller

This English version is provided for convenience. The French version is the reference.

The data controller is Alain Tardif, the site publisher.

For any question about your data, you can contact him via the contact form (subject “Personal data”).

Data collected

Through the contact form

  • Name
  • Email address
  • Subject
  • Message

Strictly necessary technical data

  • A PHP session, used only for the anti-forgery token (CSRF), the form itself and anti-spam limiting.
  • No IP address is intentionally kept by the application.

The server’s technical logs may be handled by the host under its own terms; the site does not control those logs.

Purposes

  • Reply to requests sent via the form.
  • Understand the context of the message.
  • Secure the form.
  • Prevent automated and abusive submissions.

No commercial prospecting, no profiling, no resale or commercial transfer of the data.

Legal basis

Processing is mainly based on the legitimate interest in replying to requests sent voluntarily through the form.

Where a message concerns an opportunity or a pre-contractual relationship, pre-contractual measures may also be a relevant basis.

As no consent checkbox is required to reply to a request, consent is not presented as the legal basis.

Recipients

  • Alain Tardif.
  • The technical providers essential to hosting and email, strictly within their remit.

No data is passed on to an employer or a client.

Retention period

  • Messages are kept for a maximum of 12 months after the last useful exchange.
  • Earlier deletion is possible on request.
  • Longer retention only applies where a legal obligation or the defence of a right requires it.

Invalid submissions are not durably stored in the logs.

Your rights

  • Right of access.
  • Right to rectification.
  • Right to erasure.
  • Right to restriction of processing.
  • Right to object, where the legal basis allows.

These rights can be exercised via the contact form (subject “Personal data”).

You may also lodge a complaint with the French data protection authority, the CNIL (opens in a new tab).

Proof of identity is requested only where there is reasonable doubt about the requester’s identity.

Security

The measures actually in place are:

  • Server-side data validation.
  • Anti-forgery protection (CSRF).
  • Anti-spam mechanism.
  • Rate limiting of repeated submissions.
  • Protection against header injection.
  • Secrets kept outside the code repository.
  • HTTPS connection in production.

Cookies and local storage

The site uses no advertising, no audience measurement tool, no pixel, no embedded third-party content and no marketing tracker.

It only uses:

  • a PHP session required for the form and its security;
  • the browser’s local storage to remember your appearance preferences (at-theme and at-ambiance).

These preferences are stored only after an action on your part and can be removed by clearing the site data in your browser.

No consent banner is required as long as the site stays in this strictly necessary configuration, without audience measurement or consent-based trackers.