Privacy policy
Last updated on
This policy describes the processing of personal data carried out by the
cercle.digital website. It answers Articles 12 to 14 of Regulation (EU)
2016/679, the General Data Protection Regulation.
1. Controller
Cercle Digital, a French simplified joint-stock company registered with the Paris trade and companies register.
- Registered office: to be defined at a later stage
- SIREN number: to be defined at a later stage
- Contact address for any question relating to data: to be defined at a later stage
No data protection officer has been appointed to date. The company falls under none of the three mandatory appointment cases of Article 37 of the Regulation.
2. What the site collects
The site is static and has no account area and no order processing. Two processing operations take place, and two only: audience measurement, which happens on every page, and the contact form, which happens only if you use it.
2.1 Audience measurement
It uses Umami, free software installed on the company’s own infrastructure at
umami.cercle.digital. No third-party provider is involved and no data leaves
that infrastructure.
The data recorded for each page viewed is the following, and nothing else:
| Data | Example |
|---|---|
| Page path | /realisations/ |
| Page title | Work |
| Referring domain and path | google.com |
| Campaign parameters present in the address | utm_source=linkedin |
| Browser, operating system, device type | Firefox, Windows, desktop |
| Screen resolution | 1920x1080 |
| Browser language | fr-FR |
| Country, region, city | France, Île-de-France, Paris |
| Date and time | 7 August 2026, 14:31 |
No IP address is recorded. The IP address is read on receipt of the measurement to derive country, region and city, then discarded. It appears in no table of the database.
The session identifier is a hash computed from the site, the hostname, the IP address and the browser. It changes every day and allows neither tracking a person from one day to the next, nor from one site to another.
Actions counted
Besides pages viewed, the measurement counts a few actions, so as to know what works on the site and what does not: that a form was started, sent or refused, which button led to it, which outbound link was followed.
Each action records a name and, sometimes, one detail. The list is complete:
| Action counted | Detail recorded |
|---|---|
| Contact form started | — |
| Contact form sent | The subject chosen from the drop-down list |
| Send refused | The reason for the refusal (reseau, relais-indisponible…) |
| Send stopped by an incorrectly filled field | The field’s name (sujet, message…) and how many |
| Form locked on opening | — |
| Click on a button leading to contact | The page it starts from, and the job opening if there is one |
| Click on a link leaving the site | The destination (insiders, pixelcrash, linkedin…) |
These details are chosen from fixed lists written into the site’s code. None of them comes from what you type: neither your name, nor your email address, nor your company, nor the content of your message, nor the text entered in the site’s search box ever reaches the audience measurement.
An action is recorded with the same context data as a page view — the data listed above — and under the same daily session identifier. It adds nothing else.
2.2 Contact form
The Contact us page carries a form. It is the only place on the site where you enter anything, and it opens only if you want it to.
The data transmitted is what you write, and nothing else:
| Data | Required |
|---|---|
| First and last name | yes |
| Email address | yes |
| Company | no |
| Subject, chosen from a closed list | yes |
| Message | yes |
Nothing is stored along the way. The form writes to no database: it hands the request to a relay server, which checks it and then passes it on, as is, to a mailbox, by email. That server opens neither file nor database; once the message is delivered, it keeps nothing of it. The address of that mailbox appears nowhere on the site — not in the pages, not in the code served to your browser — which puts it out of reach of the robots that harvest addresses.
Your email address is used to answer you. It feeds no mailing list, is passed to nobody and serves no prospecting purpose.
The anti-robot check
A form open on the Internet receives, unprotected, automated submissions by the hundred. The check used here asks you neither to decipher an image nor to copy out characters: your browser computes a series of hashes while you write. The operation costs a fraction of a second to someone sending one message, and becomes prohibitive to someone sending a thousand. No third-party service is involved, and nothing is written to your browser.
This check needs to recognise a network from one attempt to the next, so that the difficulty rises in the face of repeated sending. It does not keep your IP address: it computes a hash of it, salted with a server secret, from which the address cannot be derived. That hash lives in memory, twenty-four hours at most, is written to no disk and vanishes on any restart. It travels with the delivered message, where it serves to recognise a series of abusive sends.
2.3 Trackers
The site sets no cookie. Audience measurement works without cookies and without a persistent identifier; the contact form and its anti-robot check use none either.
Nothing is written to your browser storage. The details, and how to check for yourself, are on the No cookies page.
3. Purpose and legal basis
| Processing | Purpose | Legal basis |
|---|---|---|
| Audience measurement | Understand site traffic and the origin of visits, in order to improve content | Legitimate interest, Article 6(1)(f) |
| Contact form | Receive your request and answer it | Consent, Article 6(1)(a) |
| Anti-robot check on the form | Prevent automated use of the form and unsolicited mail | Legitimate interest, Article 6(1)(f), and the security obligation of Article 32 |
The legitimate interest pursued by the measurement is knowledge of the audience of a corporate website. It is balanced against your rights and freedoms: the measurement sets no cookie, records no IP address, produces no profile and tracks nobody across sites.
Consent to the form is what you give by ticking the box before sending. It is refused server-side if the box is not ticked: without it, the message is not relayed at all. Withdrawing it is moot once the message has gone, but its erasure can be requested (§7).
The legitimate interest pursued by the anti-robot check is keeping the form in service. It is balanced against your rights: the check keeps no IP address, sets nothing in your browser, calls no third-party service and allows no identification.
4. Retention period
| Data | Period |
|---|---|
| Audience measurement | to be defined at a later stage. The chosen period must not exceed twenty-five months, beyond which the CNIL requires a review |
| Message received through the form | Three years from the last exchange, then deletion from the mailbox |
| Network hash from the anti-robot check | Twenty-four hours at most, in memory only |
The relay server keeps nothing of the message: the period above is that of the mailbox, the only place where it survives. That three-year period is taken from the CNIL recommendation on business-to-business prospecting data.
5. Recipients
Measurement data is disclosed to nobody. It is accessible only to those people within the company who need it to follow site traffic. No processor is involved in that operation.
Messages from the form are read only by those people within the company able to answer them. One processor is involved, and one only: the email provider that carries and hosts the mailbox. Its company name and country of establishment are to be defined at a later stage.
6. Transfers outside the European Union
None. The site, the audience measurement and the form’s relay server are hosted on infrastructure located in France, described in the legal notice.
7. Your rights
The Regulation grants you rights of access, rectification, erasure, restriction, objection and portability over your data.
On messages from the form, these rights are exercised without difficulty: the message carries your name and your address, it can be found and deleted.
On measurement data and on the network hash of the anti-robot check, exercising them meets a limit that must be stated plainly: neither carries an identifier that would allow yours to be found. The company is therefore in the situation of Article 11 of the Regulation, which does not require keeping additional data for the sole purpose of identifying a person. If you provide us with elements allowing you to be identified, we will act on your request.
Requests should be sent to the dedicated email address, to be defined at a later stage.
You may lodge a complaint with the Commission nationale de l’informatique et des
libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at
cnil.fr.
8. Security
The site is served exclusively over HTTPS. Measurement data is stored on infrastructure with restricted and authenticated access.
The contact form calls for three particular measures:
- the destination address is known only to the relay server, through an environment variable. It is neither in the pages, nor in the code served to the browser, nor in the source repository;
- the message is carried to the mail relay over an encrypted link, and the service refuses to authenticate over a link that is not;
- the relay server keeps neither the message, nor your name, nor your address. Its operational log retains only the event, the network hash and the chosen subject; the content of the message never appears in it.
9. Changes
This policy may change. The date of last update appears at the top of the document. Any substantial change will be signalled on the site.