Privacy Policy
Data Controller
JEREMY MARCHANDEAU, operating under the LumaFinch brand, is the data controller for data collected on this website.
LumaFinch
- ADDRESS: 229 RUE SAINT-HONORE, 75001 PARIS, France
- EMAIL: [email protected]
Data Collected
Contact Form
When you use our contact form, we collect the following data:
- First and last name
- Email address
- Content of your message
For form security, we use Cloudflare Turnstile as a CAPTCHA alternative to verify that submissions are made by humans rather than automated systems. This solution processes minimal data required for verification.
The form data is stored on our self-hosted CRM system located on our secure server in Germany (European Union).
Booking System
When you book a free 30-minute call with us, we use Calendly (https://calendly.com/) as our booking service. The following data is collected:
- First and last name
- Email address
- Any additional information you provide in the booking form
This data is sent to our Calendly account so we can manage your booking (notifications, cancellations, rescheduling, etc.). The information from the form is also stored on our self-hosted CRM system located on our secure server in Germany (European Union).
Browsing Data
We use a self-hosted instance of Umami (https://umami.is/) as a traffic analysis solution. Our Umami instance is hosted on our VPS with Hetzner in Falkenstein, Germany (European Union). Umami is a privacy-focused analytics tool that does not collect any personally identifiable data. The collected data is anonymous and includes:
- Pages visited
- Duration of visit
- Referring site
- Type of device used
- Country of origin of the connection
Umami does not place any cookies on your browser and does not track individual users.
Processing Purposes
Data is collected for the following purposes:
- Responding to your information and contact requests
- Managing your booking requests for free calls
- Providing our AI consulting and implementation services
- Improving our website and services
- Analyzing website traffic to optimize user experience and content
- Complying with our legal obligations
Legal Basis
The processing of your data is based on:
- Your consent for the processing of data provided through our contact form and booking system
- Our legitimate interest in developing our business and improving our website
- The performance of contracts that we may enter into with you
- Compliance with legal obligations to which we are subject
Retention Period
Data collected through our contact form is retained for a period of 3 years from your last contact with us.
Data collected through Calendly for booking appointments is retained for a period of 1 year after your last appointment.
Anonymous browsing data collected through our self-hosted Umami instance is retained for a period of 12 months.
In all cases, your data is retained for the period strictly necessary for the purposes for which it was collected.
Recipients of Data
The data we collect is intended for our internal use and is not transmitted to third parties, except for:
- Calendly, which processes your booking information
- Cloudflare, which provides security services and Turnstile CAPTCHA alternative for our website
- Our technical subcontractors who may have access to the data as part of their services (maintenance, security)
- Administrative or judicial authorities when required by law
Transfer of Data Outside the European Union
Some of our technical service providers (Calendly and Cloudflare) may host your data outside the European Union. In these cases, we ensure that these transfers are carried out in compliance with applicable regulations regarding the protection of personal data and with an adequate level of protection, particularly through standard contractual clauses approved by the European Commission.
Cloudflare, which provides security services and the Turnstile CAPTCHA alternative, processes some data globally but operates in compliance with GDPR and other data protection regulations.
Our website, our self-hosted CRM system, and our Umami analytics instance are all hosted within the European Union (Germany) and therefore do not involve transfers outside the EU for their primary data storage.
Cookies and Analytics Tools
Analytics
Our website uses a self-hosted instance of Umami (https://umami.is/) as a traffic analysis solution. Umami is a privacy-focused analytics tool that does not collect any personally identifiable data and does not place any cookies in your browser.
Security and Form Protection
Our website uses Cloudflare’s security services, including Turnstile (CAPTCHA alternative) to protect forms from spam and abuse. Cloudflare may use necessary cookies for security purposes and to detect bots or malicious activity. These cookies are essential for the security of our website and protection of user data.
We do not use tracking, advertising, or profiling cookies on our website beyond those strictly necessary for security and functionality.
Your Rights
In accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act, you have the following rights:
- Right of access to your data
- Right of rectification
- Right to erasure (right to be forgotten)
- Right to restriction of processing
- Right to data portability
- Right to object
- Right to define guidelines regarding the fate of your data after your death
To exercise these rights, please contact us at the following email address: [email protected]
Complaints
If you believe, after contacting us, that your rights are not being respected, you can file a complaint with the CNIL:
Commission Nationale de l’Informatique et des Libertés (CNIL)
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
Website: https://www.cnil.fr
Data Security
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of our processing activities, in accordance with industry standards and legal requirements.
Changes to the Privacy Policy
We reserve the right to modify this privacy policy at any time. The version in force is the one published on our website. We encourage you to regularly consult this page to be informed of any changes.
Contact
For any questions regarding this privacy policy, please contact us at the following address: [email protected]
Last updated: May 11, 2025