Data protection
Data protection policy
What we collect, why, for how long, and how to take back control of it.
This is a translation provided for convenience. In the event of any discrepancy, the French version prevails.
Last updated
17 August 2026
Who processes your data
The data controller is MCEM SAS, trading under the name Maeliom, with registered office at 60 rue François 1er, 75008 Paris, France (SIRET 943 245 936 00019).
For any question about your data, or to exercise your rights: contact@maeliom.com.
Our commitments
Three principles govern this site, and all three can be verified from the source code:
- Collect nothing we do not need. Audience measurement is anonymous and aggregated: no cookie, no persistent identifier, no tracking from one site to another. We know how many pages are viewed, not who views them.
- Entrust nothing to a third party without need. The typefaces are hosted on our own domain rather than loaded from an outside service: your IP address is passed to nobody in order to display them.
- Embed no third-party content. No embedded video, no map, no social media button — all components that normally place trackers without your knowledge.
The data we collect
The contact form
When you write to us through the form, we receive what you enter: name, company where applicable, email address, subject and the content of your message. Those fields are the only things sent; nothing is collected in the background.
Downloading a guide
To receive a guide, you give your first name, surname, company, role and email address. Those five fields are the only ones sent. The document reaches you by email and never appears on screen: that email, and nothing else, is what confirms the address exists.
The anti-bot check
The form is protected by Cloudflare Turnstile, which checks that the submission comes from a person and not a program. It processes technical data (IP address, browser characteristics, interactions with the page) for as long as it takes to reach its verdict. Unlike comparable systems, Turnstile sets no tracking cookie and is not used to profile visitors across sites.
Hosting logs
Like any web server, the one hosting this site records the requests it receives: IP address, date, page requested, browser type. These logs serve the technical operation and security of the service. They are not used commercially, nor combined with other data.
Why, and on what lawful basis
- To answer your enquiry — lawful basis: your consent, given by ticking the box on the form, which you may withdraw at any time.
- To follow up the relationship if a conversation begins — lawful basis: steps taken at your request prior to entering a contract, then performance of the contract.
- Sending you the guide you asked for — legal basis: carrying out the request you have just made.
- Writing to you once to ask whether the guide was of use — legal basis: our legitimate interest in knowing whether what we publish is useful, addressed to someone in their professional capacity. A word in reply is enough to stop it, and we do not press the point.
- To protect the form from automated submissions and to maintain the security of the service — lawful basis: our legitimate interest in not seeing the tool misused.
Your data is not used for profiling, automated decision-making or marketing campaigns. The only approach we allow ourselves is the single follow-up described above: one message, once, on a professional matter. Your data is never sold, rented or exchanged.
Who else has access
Your data is processed by MCEM SAS. Three suppliers act as processors, each within a limited scope:
- Brevo (a French company) — delivery of form messages to our inbox. Data hosted within the European Union.
- Cloudflare — anti-bot checking of the form.
- Vercel (a US company) — delivery of the site and technical logs. The servers are located outside the European Union.
None of these suppliers is permitted to use your data for its own purposes. Beyond them, no data is disclosed to third parties, save where we are under a legal obligation to do so.
Transfers outside the European Union
Message delivery takes place within the European Union. The anti-bot check may involve processing by a company established in the United States; that transfer is governed by the safeguards set out in Chapter V of the General Data Protection Regulation.
How long we keep it
- Enquiries with no follow-up — three years from the last exchange.
- Exchanges that led to an engagement — the duration of the contractual relationship, then the periods required for accounting and tax purposes.
- Details given to receive a guide — three years from the download, or immediately if you object.
- Hosting logs — six months.
- Anti-bot verification token — for as long as the check takes, a matter of seconds.
Cookies and local storage
This site sets no cookies. No advertising, no social networks, no tracker that would follow you from one site to the next. The only audience measurement is described below, and it is designed to store nothing on your device — which is why no consent banner is shown to you.
One technical item is recorded by your browser, in its session storage: a flag noting that the opening animation has already been shown to you, so that it is not repeated on every page. It contains no personal data, never leaves your device, and disappears when the tab is closed. On that basis it falls within the exemptions from consent.
Audience measurement
To understand what interests our visitors, we use Plausible Analytics, a tool hosted in the European Union. It sets no cookies, creates no persistent identifier and does not follow you across sites. It measures aggregate trends — pages viewed, referral source, country, device type — without ever building a profile or allowing you to be re-identified.
The data is collected for our use alone, is neither sold nor shared, and travels through our own domain rather than a third-party service. On that basis — limited, anonymous measurement with no cross-referencing — this falls under the exemptions from consent recommended by the French data protection authority (CNIL).
Your rights
The General Data Protection Regulation gives you, over data concerning you, a right of:
- d’access — to know what we hold, and obtain a copy;
- de rectification — to correct inaccurate information;
- d’erasure — to request its deletion;
- de restriction — to freeze its use;
- d’objection — to refuse processing based on our legitimate interest;
- à la portability — to receive it in a reusable format;
- de withdraw your consent at any time, without affecting what was done beforehand.
These rights are exercised by email to contact@maeliom.com. We reply within one month. You may be asked to prove your identity if reasonable doubt remains.
If our answer does not satisfy you, you may refer the matter to the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.
Security
The site is served over HTTPS. Messages travel encrypted to our inbox. Access to the data is limited to those who need it in order to reply — in practice, to the founder.
Changes to this policy
Any substantial change — a new tool, a new purpose, a new processor — will be recorded here, with the date at the top of the page updated. We encourage you to check it before sending us any information.