Skip to content

Privacy policy

Last updated on

This policy describes the processing of personal data carried out by the cercle.digital website. It answers Articles 12 to 14 of Regulation (EU) 2016/679, the General Data Protection Regulation.

1. Controller

Cercle Digital, a French simplified joint-stock company registered with the Paris trade and companies register.

  • Registered office: to be defined at a later stage
  • SIREN number: to be defined at a later stage
  • Contact address for any question relating to data: to be defined at a later stage

No data protection officer has been appointed to date. The company falls under none of the three mandatory appointment cases of Article 37 of the Regulation.

2. What the site collects

The site is static and has no account area and no order processing. Two processing operations take place, and two only: audience measurement, which happens on every page, and the contact form, which happens only if you use it.

2.1 Audience measurement

It uses Umami, free software installed on the company’s own infrastructure at umami.cercle.digital. No third-party provider is involved and no data leaves that infrastructure.

The data recorded for each page viewed is the following, and nothing else:

DataExample
Page path/realisations/
Page titleWork
Referring domain and pathgoogle.com
Campaign parameters present in the addressutm_source=linkedin
Browser, operating system, device typeFirefox, Windows, desktop
Screen resolution1920x1080
Browser languagefr-FR
Country, region, cityFrance, Île-de-France, Paris
Date and time7 August 2026, 14:31

No IP address is recorded. The IP address is read on receipt of the measurement to derive country, region and city, then discarded. It appears in no table of the database.

The session identifier is a hash computed from the site, the hostname, the IP address and the browser. It changes every day and allows neither tracking a person from one day to the next, nor from one site to another.

Actions counted

Besides pages viewed, the measurement counts a few actions, so as to know what works on the site and what does not: that a form was started, sent or refused, which button led to it, which outbound link was followed.

Each action records a name and, sometimes, one detail. The list is complete:

Action countedDetail recorded
Contact form started
Contact form sentThe subject chosen from the drop-down list
Send refusedThe reason for the refusal (reseau, relais-indisponible…)
Send stopped by an incorrectly filled fieldThe field’s name (sujet, message…) and how many
Form locked on opening
Click on a button leading to contactThe page it starts from, and the job opening if there is one
Click on a link leaving the siteThe destination (insiders, pixelcrash, linkedin…)

These details are chosen from fixed lists written into the site’s code. None of them comes from what you type: neither your name, nor your email address, nor your company, nor the content of your message, nor the text entered in the site’s search box ever reaches the audience measurement.

An action is recorded with the same context data as a page view — the data listed above — and under the same daily session identifier. It adds nothing else.

2.2 Contact form

The Contact us page carries a form. It is the only place on the site where you enter anything, and it opens only if you want it to.

The data transmitted is what you write, and nothing else:

DataRequired
First and last nameyes
Email addressyes
Companyno
Subject, chosen from a closed listyes
Messageyes

Nothing is stored along the way. The form writes to no database: it hands the request to a relay server, which checks it and then passes it on, as is, to a mailbox, by email. That server opens neither file nor database; once the message is delivered, it keeps nothing of it. The address of that mailbox appears nowhere on the site — not in the pages, not in the code served to your browser — which puts it out of reach of the robots that harvest addresses.

Your email address is used to answer you. It feeds no mailing list, is passed to nobody and serves no prospecting purpose.

The anti-robot check

A form open on the Internet receives, unprotected, automated submissions by the hundred. The check used here asks you neither to decipher an image nor to copy out characters: your browser computes a series of hashes while you write. The operation costs a fraction of a second to someone sending one message, and becomes prohibitive to someone sending a thousand. No third-party service is involved, and nothing is written to your browser.

This check needs to recognise a network from one attempt to the next, so that the difficulty rises in the face of repeated sending. It does not keep your IP address: it computes a hash of it, salted with a server secret, from which the address cannot be derived. That hash lives in memory, twenty-four hours at most, is written to no disk and vanishes on any restart. It travels with the delivered message, where it serves to recognise a series of abusive sends.

2.3 Trackers

The site sets no cookie. Audience measurement works without cookies and without a persistent identifier; the contact form and its anti-robot check use none either.

Nothing is written to your browser storage. The details, and how to check for yourself, are on the No cookies page.

ProcessingPurposeLegal basis
Audience measurementUnderstand site traffic and the origin of visits, in order to improve contentLegitimate interest, Article 6(1)(f)
Contact formReceive your request and answer itConsent, Article 6(1)(a)
Anti-robot check on the formPrevent automated use of the form and unsolicited mailLegitimate interest, Article 6(1)(f), and the security obligation of Article 32

The legitimate interest pursued by the measurement is knowledge of the audience of a corporate website. It is balanced against your rights and freedoms: the measurement sets no cookie, records no IP address, produces no profile and tracks nobody across sites.

Consent to the form is what you give by ticking the box before sending. It is refused server-side if the box is not ticked: without it, the message is not relayed at all. Withdrawing it is moot once the message has gone, but its erasure can be requested (§7).

The legitimate interest pursued by the anti-robot check is keeping the form in service. It is balanced against your rights: the check keeps no IP address, sets nothing in your browser, calls no third-party service and allows no identification.

4. Retention period

DataPeriod
Audience measurementto be defined at a later stage. The chosen period must not exceed twenty-five months, beyond which the CNIL requires a review
Message received through the formThree years from the last exchange, then deletion from the mailbox
Network hash from the anti-robot checkTwenty-four hours at most, in memory only

The relay server keeps nothing of the message: the period above is that of the mailbox, the only place where it survives. That three-year period is taken from the CNIL recommendation on business-to-business prospecting data.

5. Recipients

Measurement data is disclosed to nobody. It is accessible only to those people within the company who need it to follow site traffic. No processor is involved in that operation.

Messages from the form are read only by those people within the company able to answer them. One processor is involved, and one only: the email provider that carries and hosts the mailbox. Its company name and country of establishment are to be defined at a later stage.

6. Transfers outside the European Union

None. The site, the audience measurement and the form’s relay server are hosted on infrastructure located in France, described in the legal notice.

7. Your rights

The Regulation grants you rights of access, rectification, erasure, restriction, objection and portability over your data.

On messages from the form, these rights are exercised without difficulty: the message carries your name and your address, it can be found and deleted.

On measurement data and on the network hash of the anti-robot check, exercising them meets a limit that must be stated plainly: neither carries an identifier that would allow yours to be found. The company is therefore in the situation of Article 11 of the Regulation, which does not require keeping additional data for the sole purpose of identifying a person. If you provide us with elements allowing you to be identified, we will act on your request.

Requests should be sent to the dedicated email address, to be defined at a later stage.

You may lodge a complaint with the Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or at cnil.fr.

8. Security

The site is served exclusively over HTTPS. Measurement data is stored on infrastructure with restricted and authenticated access.

The contact form calls for three particular measures:

  1. the destination address is known only to the relay server, through an environment variable. It is neither in the pages, nor in the code served to the browser, nor in the source repository;
  2. the message is carried to the mail relay over an encrypted link, and the service refuses to authenticate over a link that is not;
  3. the relay server keeps neither the message, nor your name, nor your address. Its operational log retains only the event, the network hash and the chosen subject; the content of the message never appears in it.

9. Changes

This policy may change. The date of last update appears at the top of the document. Any substantial change will be signalled on the site.