Privacy Policy

Data Controller

JEREMY MARCHANDEAU, operating under the LumaFinch brand, is the data controller for data collected on this website.

LumaFinch

Data Collected

Contact Form

When you use our contact form, we collect the following data:

  • First and last name
  • Email address
  • Content of your message

For form security, we use Cloudflare Turnstile as a CAPTCHA alternative to verify that submissions are made by humans rather than automated systems. This solution processes minimal data required for verification.

The form data is stored on our self-hosted CRM system located on our secure server in Germany (European Union).

Booking System

When you book a free 30-minute call with us, we use Calendly (https://calendly.com/) as our booking service. The following data is collected:

  • First and last name
  • Email address
  • Any additional information you provide in the booking form

This data is sent to our Calendly account so we can manage your booking (notifications, cancellations, rescheduling, etc.). The information from the form is also stored on our self-hosted CRM system located on our secure server in Germany (European Union).

Browsing Data

We use a self-hosted instance of Umami (https://umami.is/) as a traffic analysis solution. Our Umami instance is hosted on our VPS with Hetzner in Falkenstein, Germany (European Union). Umami is a privacy-focused analytics tool that does not collect any personally identifiable data. The collected data is anonymous and includes:

  • Pages visited
  • Duration of visit
  • Referring site
  • Type of device used
  • Country of origin of the connection

Umami does not place any cookies on your browser and does not track individual users.

Processing Purposes

Data is collected for the following purposes:

  • Responding to your information and contact requests
  • Managing your booking requests for free calls
  • Providing our AI consulting and implementation services
  • Improving our website and services
  • Analyzing website traffic to optimize user experience and content
  • Complying with our legal obligations

The processing of your data is based on:

  • Your consent for the processing of data provided through our contact form and booking system
  • Our legitimate interest in developing our business and improving our website
  • The performance of contracts that we may enter into with you
  • Compliance with legal obligations to which we are subject

Retention Period

Data collected through our contact form is retained for a period of 3 years from your last contact with us.

Data collected through Calendly for booking appointments is retained for a period of 1 year after your last appointment.

Anonymous browsing data collected through our self-hosted Umami instance is retained for a period of 12 months.

In all cases, your data is retained for the period strictly necessary for the purposes for which it was collected.

Recipients of Data

The data we collect is intended for our internal use and is not transmitted to third parties, except for:

  • Calendly, which processes your booking information
  • Cloudflare, which provides security services and Turnstile CAPTCHA alternative for our website
  • Our technical subcontractors who may have access to the data as part of their services (maintenance, security)
  • Administrative or judicial authorities when required by law

Transfer of Data Outside the European Union

Some of our technical service providers (Calendly and Cloudflare) may host your data outside the European Union. In these cases, we ensure that these transfers are carried out in compliance with applicable regulations regarding the protection of personal data and with an adequate level of protection, particularly through standard contractual clauses approved by the European Commission.

Cloudflare, which provides security services and the Turnstile CAPTCHA alternative, processes some data globally but operates in compliance with GDPR and other data protection regulations.

Our website, our self-hosted CRM system, and our Umami analytics instance are all hosted within the European Union (Germany) and therefore do not involve transfers outside the EU for their primary data storage.

Cookies and Analytics Tools

Analytics

Our website uses a self-hosted instance of Umami (https://umami.is/) as a traffic analysis solution. Umami is a privacy-focused analytics tool that does not collect any personally identifiable data and does not place any cookies in your browser.

Security and Form Protection

Our website uses Cloudflare’s security services, including Turnstile (CAPTCHA alternative) to protect forms from spam and abuse. Cloudflare may use necessary cookies for security purposes and to detect bots or malicious activity. These cookies are essential for the security of our website and protection of user data.

We do not use tracking, advertising, or profiling cookies on our website beyond those strictly necessary for security and functionality.

Your Rights

In accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act, you have the following rights:

  • Right of access to your data
  • Right of rectification
  • Right to erasure (right to be forgotten)
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to define guidelines regarding the fate of your data after your death

To exercise these rights, please contact us at the following email address: [email protected]

Complaints

If you believe, after contacting us, that your rights are not being respected, you can file a complaint with the CNIL:

Commission Nationale de l’Informatique et des Libertés (CNIL)
3 Place de Fontenoy
TSA 80715
75334 PARIS CEDEX 07
Website: https://www.cnil.fr

Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of our processing activities, in accordance with industry standards and legal requirements.

Changes to the Privacy Policy

We reserve the right to modify this privacy policy at any time. The version in force is the one published on our website. We encourage you to regularly consult this page to be informed of any changes.

Contact

For any questions regarding this privacy policy, please contact us at the following address: [email protected]


Last updated: May 11, 2025