Privacy Policy – consult-gherio.fr

Privacy Policy

Last updated: August 4, 2026

This policy explains how Consult-Gherio collects, uses, and protects your personal data in compliance with the EU General Data Protection Regulation (GDPR) and the EU AI Act (2024).

1. Data Controller

Consult-Gherio
Website: consult-gherio.fr
Contact: achraf@consult-gherio.fr

2. Data We Collect

  • Email address — via newsletter subscription form
  • Contact data — name, email, message (contact form)
  • Usage data — pages visited, time on site (analytics cookies)
  • Technical data — IP address, browser type, device type (collected automatically by our hosting infrastructure)
  • Location data (coarse) — city/region level, inferred from your IP address for analytics purposes. You may request this not be processed by contacting us.

3. Legal Basis (GDPR Art. 6)

  • Consent (Art. 6.1.a) — newsletter subscriptions, non-essential cookies
  • Contract performance (Art. 6.1.b) — consulting service delivery
  • Legitimate interest (Art. 6.1.f) — website security, fraud prevention, analytics
  • Legal obligation (Art. 6.1.c) — compliance with French and EU law

4. AI Systems & EU AI Act Compliance

This website uses AI-assisted tools (e.g., automated newsletter generation using large language models). These systems are classified as limited-risk under the EU AI Act (2024).

  • AI-generated content is clearly identified as such where applicable.
  • No automated decisions with legal or significant personal effects are applied to users.
  • Personal data used in AI processes is minimized and pseudonymized where possible.
  • AI tools used include: Anthropic Claude (newsletter synthesis), Microsoft Outlook (email delivery), Google Workspace (subscriber management).

5. Hosting & Infrastructure

This website is hosted by OVHcloud, with servers located in France (Europe), ensuring data residency within the EU. [[4](https://www.ovhcloud.com/en/datacenter/europe/france/)]

  • OVHcloud complies with GDPR as a data processor under a Data Processing Agreement (DPA).
  • Data center location: France (Roubaix / Gravelines / Strasbourg regions) [[4](https://www.ovhcloud.com/en/datacenter/europe/france/)]
  • OVHcloud’s own privacy policy: ovhcloud.com/en/personal-data-protection/

6. Third-Party Processors

We share data with the following third parties, each bound by GDPR-compliant Data Processing Agreements or Standard Contractual Clauses (SCCs):

Processor Purpose Location Safeguard
OVHcloud Website hosting France (EU) GDPR DPA
Google Workspace Subscriber list (Google Sheets) EU (configurable) SCCs + DPA
Microsoft (Outlook/365) Email delivery EU data centers SCCs + DPA
Anthropic (Claude AI) Newsletter content generation USA SCCs
Pipedream Workflow automation USA SCCs
Calendly Meeting scheduling USA SCCs

We do not sell your personal data. We do not share your data with third parties beyond the processors listed above, except when required by law or a court order.

7. Data Retention

  • Newsletter subscribers: Until unsubscribe request, then deleted within 30 days
  • Contact inquiries: 3 years from last contact
  • Analytics/cookies data: 13 months (CNIL standard)
  • Server logs (OVH): Up to 12 months per OVHcloud standard practice [[4](https://www.ovhcloud.com/en/datacenter/europe/france/)]
  • Consulting engagement data: 5 years (legal accounting obligation)

8. Security Measures

  • HTTPS encryption — all data in transit is encrypted via SSL/TLS
  • Access control — administrative access restricted to authorized personnel only
  • Data minimization — we only collect what is strictly necessary
  • Hosting security — OVHcloud provides physical and network security at French data centers [[4](https://www.ovhcloud.com/en/datacenter/europe/france/)]
  • Incident response — in the event of a data breach, affected individuals and the CNIL will be notified within 72 hours (GDPR Art. 33–34)

9. Cookies

We use the following types of cookies:

  • Essential cookies — required for the site to function (no consent needed)
  • Analytics cookies — measure site usage (require your consent)

You can withdraw cookie consent at any time by clearing your browser cookies or using our cookie preference center (if available). Analytics data is retained for a maximum of 13 months per CNIL guidelines.

10. Your Rights (GDPR Art. 15–22)

You have the following rights regarding your personal data:

  • Right of access — request a copy of your data
  • Right to rectification — correct inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object — including to AI-assisted processing
  • Right to opt out of location inference — contact us to disable IP-based location processing

To exercise any right, contact: contact@consult-gherio.fr. We will respond within 30 days.

11. Children’s Data

This website is not directed at children under 16. We do not knowingly collect data from minors. If you believe a child has submitted data to us, please contact us immediately for deletion (GDPR Art. 8).

12. Policy Updates

We may update this privacy policy periodically. When we do:

  • The “Last updated” date at the top will be revised
  • Subscribers will be notified by email of material changes
  • Continued use of the site after notification constitutes acceptance

13. Supervisory Authority

You have the right to lodge a complaint with the French data protection authority:

CNIL — Commission Nationale de l’Informatique et des Libertés
Website: www.cnil.fr
Address: 3 Place de Fontenoy, TSA 80715 – 75334 Paris Cedex 07