PRIVACY POLICY

RGPD-2025-04 — PRIVACY POLICY

1. Purpose of the Policy

This Privacy Policy explains how personal data is collected, processed, and protected when using the website www.erysan.com

(“the Website”) and when purchasing services from Erysan, the trade name of the sole proprietorship of Guillem BLASCO.

The Policy complies with:

  • the General Data Protection Regulation (EU) 2016/679 (“GDPR”),
  • the French Data Protection Act (Law No. 78-17 as amended).

2. Data Controller

Guillem BLASCO
Sole Proprietorship – Trade Name: Erysan
SIRET: 991 718 388 00010
Registered Address: 59 Impasse Saint Dominique, 83000 Toulon, France
E-mail: contact@erysan.com


3. Personal Data Collected

3.1. Contact Form or Email

  • Name
  • E-mail address
  • Information provided voluntarily in the message

3.2. Service Purchase

  • Identity
  • E-mail address
  • Address (for invoicing if necessary)
  • Payment-related information (processed by a secure payment provider)
  • Responses to the diagnostic questionnaire

3.3. Technical Data

  • IP address (temporarily in technical logs)
  • Browser and device information
  • Functional cookies only (no marketing cookies)

3.4. Sensitive Data

Erysan does not request sensitive data.
If provided voluntarily by the Client, such data is used solely for the execution of the requested service and not for any secondary purpose.


4. Purposes of Processing

Personal data may be processed for the following purposes:

  1. Responding to contact requests
  2. Delivering the services purchased
  3. Preparing invoices and fulfilling legal obligations
  4. Ensuring the Website’s security and technical functioning
  5. Managing GDPR-related requests
  6. Improving the Website through anonymous technical analysis

5. Legal Basis for Processing (Article 6 GDPR)

  • Contract performance: providing purchased services
  • Legal obligation: invoicing, accounting
  • Legitimate interest: Website security, fraud prevention
  • Consent: for cookies where applicable (none used by default)

6. Data Retention Periods

CategoryRetention Period
Contact form submissions12 months
Service-related documents5 years (legal requirement)
Technical logs12 months
Emails24 months
CookiesAs specified in the Cookie Policy

Data is never retained beyond what is strictly necessary.


7. Recipients of Personal Data

Data is accessible only to:

  • the data controller (Guillem BLASCO),
  • technical service providers essential to the Website’s functioning,
  • payment service providers (if used).

Data is never sold or shared for commercial purposes.


8. Subprocessors

Hosting – IONOS SARL (France)

7, place de la Gare
57200 Sarreguemines
France
Website: https://www.ionos.fr

IONOS provides secure hosting and server infrastructure, including technical logs.

Email and Website Tools

Depending on configuration, the Website may use third-party tools for emailing or technical features.
All subprocessors comply with GDPR or provide adequate safeguards.

Internal Use of AI

Any use of AI tools is strictly for internal back-office analysis.
AI tools are not visible to users, do not perform automated decision-making, and do not profile users.
This does not constitute automated processing under GDPR Articles 21–22.


9. International Data Transfers

Data is hosted within the European Union (France, IONOS SARL).

If technical operations require transfers outside the EU (e.g., email routing), such transfers are subject to:

  • Standard Contractual Clauses,
    or
  • a valid adequacy decision.

10. Data Security Measures

Erysan implements reasonable and appropriate technical and organizational measures, including:

  • secure hosting with IONOS,
  • SSL encryption (HTTPS),
  • restricted data access,
  • regular updates of the CMS and plugins,
  • technical logging,
  • minimization of collected data.

11. User Rights

In accordance with Articles 15–22 GDPR, users have the right to:

  • access their data,
  • rectify incorrect or incomplete data,
  • request deletion,
  • request restriction of processing,
  • object to processing,
  • receive their data in a portable format,
  • withdraw consent where applicable.

Requests may be sent to:
📧 contact@erysan.com

A response will be provided within 30 days.


12. Cookies

The Website uses only functional cookies necessary for basic technical operation.
Details are available in the Cookie Policy (COOK-2025-05).


13. No Automated Decision-Making

No automated decision-making or profiling is performed using user data.


14. Updates to the Policy

Erysan may update this Policy from time to time.
The applicable version is the one published on the Website at the time of use.


15. Complaints

Users may lodge a complaint with the French Data Protection Authority (CNIL):
www.cnil.fr