IBIFACE places the utmost importance on the protection of your personal data. This policy details how your data is collected, processed and retained, in compliance with theGeneral Data Protection Regulation (GDPR).
Data controller
- IBIFACE — [legal form to be completed]
- Registered office: 1 rue du Bel Air, 95370 Montigny-lès-Cormeilles, France
- Contact: [email protected]
- Data Protection Officer: [email protected]
Data collected
Contact form
- Name and surname
- Business email address
- Phone (optional)
- Company name (optional)
- Services of interest
- Message content
Newsletter subscription
- Email address
Technical data (server logs)
- IP address (anonymised after 30 days)
- Browser user-agent
- Pages visited, timestamps
Purposes & legal bases
- Responding to contact requests — legal basis: pre-contractual measures (GDPR Art. 6.1.b).
- Sending our newsletter — legal basis: explicit consent (GDPR Art. 6.1.a).
- Securing the site — legal basis: legitimate interest (GDPR Art. 6.1.f).
- Aggregated, anonymised audience statistics— no tracking cookie, no individual profiling.
Recipients
Your data is accessible only to authorised IBIFACE members with a legitimate need to know. We rely on the following sub-processors, all contractually bound by GDPR compliance:
- FormSubmit (contact and newsletter forms) — hosted in the European Union.
- Site hosting provider — [to be completed] — hosted in the European Union.
No data is transferred outside the European Economic Area without appropriate safeguards (Standard Contractual Clauses).
Retention periods
- Contact requests: 3 years from the last exchange.
- Newsletter: until unsubscription, which you may exercise at any time.
- Server logs: 12 months maximum, with IP anonymisation after 30 days.
Cookies
This site uses no advertising or profiling tracking cookies. The only technical cookies required for operation (theme preference, consent, language preference) are stored locally in your browser and are not transmitted to any third party.
Security
- TLS 1.3 encryption for all communications
- Strict Content Security Policy (CSP)
- Controlled access with strong authentication
- Logging and continuous monitoring
- Encrypted, tested backups
- Ongoing CVE monitoring with critical patches applied within 24 business hours
Your rights
Under the GDPR, you have the following rights over your personal data:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to portability
- Right to object
- Right to withdraw consent at any time
- Right to lodge a complaint with the French supervisory authority CNIL (www.cnil.fr)
To exercise these rights, write to[email protected]. We respond to any legitimate request within one month, as required by GDPR Article 12.
Changes
This policy may be revised to reflect regulatory or operational changes. The last update date appears at the top of this page. Material changes are notified to newsletter subscribers.