DATA PROTECTION
Privacy policy.
This policy describes how ExpertiaX SASU collects, uses, and protects your personal data when you use expertiax.com. It complies with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).
Last updated: 28 April 2026
DATA CONTROLLER
ExpertiaX SASU is the data controller for personal data collected on expertiax.com. ExpertiaX SASU 60 rue François Ier, 75008 Paris RCS Paris 992 018 234 contact@expertiax.com
DATA COLLECTED
What data we collect.
We collect only the data strictly necessary for the purposes described below. No data is collected without your knowledge.
Via the contact form
When you complete the contact form at /contact, we collect:
- · Full name (required)
- · Company (required)
- · Professional e-mail address (required)
- · Type of requirement (required)
- · Scope — number of agents (optional)
- · Desired timeline (optional)
- · Free-text message (required)
Via audience measurement
We use Plausible Analytics, a privacy-friendly solution that sets no cookies and collects no personal data. The information gathered is anonymised and aggregated: page views, visit duration, device type, traffic source. No information allows individual identification.
Via anti-spam protection
We use Google reCAPTCHA v3 to protect the contact form against automated submissions (spam). reCAPTCHA may collect technical information relating to your browsing behaviour (mouse movements, completion time, etc.) in order to assess whether a submission is human. This data is processed by Google in accordance with its own privacy policy: https://policies.google.com/privacy
PURPOSE OF PROCESSING
Why we collect this data.
Data collected via the contact form is processed exclusively for the following purposes:
- · Responding to your enquiry
- · Qualifying your requirement and preparing a productive conversation
- · Scheduling an appointment
- · Maintaining a record of our commercial exchanges
No data is used for unsolicited commercial prospecting, targeted advertising, or resale to third parties.
LEGAL BASIS
The processing of your personal data is based on your explicit consent, as expressed by the voluntary submission of the contact form (Article 6.1(a) GDPR). For anonymised audience measurement via Plausible, processing is based on the legitimate interest of ExpertiaX SASU in measuring the use of its website (Article 6.1(f) GDPR).
RETENTION PERIOD
How long we retain your data.
Contact form data is retained for 36 months from the date of our last exchange. This period corresponds to the standard retention period recognised by the CNIL for B2B commercial prospecting. At the end of this period, your data is automatically deleted from our systems, unless a longer legal retention obligation applies (for example, where a contract has been entered into, commercial data is retained for 10 years after the end of the contract for accounting and tax purposes). Plausible audience measurement data is retained in anonymised, aggregated form for a maximum period of 24 months.
RECIPIENTS AND PROCESSORS
Who receives your data.
Your data is accessible solely to Yassine Rogui, President of ExpertiaX SASU, and is never sold or transferred to third parties for commercial purposes. To ensure the operation of the website and the processing of your enquiry, we engage the following technical processors:
- · Amazon Web Services EMEA SARL — Website hosting (Luxembourg, EU)
- · IONOS SE — SMTP messaging service (Germany, EU)
- · Google LLC — reCAPTCHA v3 anti-spam (United States, transfer governed by Standard Contractual Clauses of the European Commission)
- · Plausible Insights OÜ — Anonymised audience analytics (Estonia, EU)
- · n8n GmbH — Internal workflow orchestration (Germany, EU)
- · Notion Labs Inc. — Internal commercial lead tracking (United States, transfer governed by Standard Contractual Clauses of the European Commission)
Each of these processors is contractually bound to maintain the confidentiality of your data and to implement appropriate security measures.
YOUR RIGHTS
How to exercise your rights.
Under the GDPR and the French Data Protection Act, you have the following rights regarding your personal data:
- · Right of access — obtain a copy of the data held about you
- · Right of rectification — correct inaccurate or incomplete data
- · Right of erasure ('right to be forgotten') — request the deletion of your data
- · Right to object — object to the processing of your data
- · Right to restriction of processing — request the temporary suspension of a processing activity
- · Right to data portability — receive your data in a structured, machine-readable format
- · Right to give instructions regarding the use of your data after death
To exercise any of these rights, please write to us at:
contact@expertiax.comWe undertake to respond to your request within one month, in accordance with Article 12 GDPR.
If you consider that the processing of your data does not comply with the applicable regulations, you may also lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr
SECURITY
ExpertiaX SASU implements appropriate technical and organisational measures to ensure the security of your personal data: encrypted communications (HTTPS/TLS), access authentication, regular backups, and the selection of processors that comply with GDPR requirements. However, as no transmission or storage system is 100% infallible, ExpertiaX SASU cannot guarantee absolute security. We undertake to inform you without undue delay in the event of a significant security incident affecting your data (Article 34 GDPR).
UPDATES
This privacy policy may be updated at any time, in particular in response to regulatory changes or changes to our practices. The date of the most recent update is shown at the top of the page. Material changes will be notified to you by e-mail if you are in an active commercial relationship with ExpertiaX SASU.
CONTACT
For any enquiries regarding this privacy policy or the processing of your data:
contact@expertiax.com