Privacy Policy
Last updated on 08/29/2026
Summary
In accordance with Article 12 of Regulation (EU) 2016/679, this summary outlines the essential elements of the processing activities implemented. It does not replace the detailed information provided in sections 1 through 9.
- Data controller: SAS Noqode, 29 rue de la Croix Blanche, 78200 Mantes-la-Jolie (section 1).
- Main purposes: responding to contact and quote requests, performing requested audits, managing business relationships, and measuring site traffic (sections 2 and 3).
- Legal bases: depending on the processing activity, performance of pre-contractual measures or the contract, consent, legitimate interest, or legal obligation (section 2).
- Recipients: authorized personnel at SAS Noqode and the subcontractors listed in section 5. No data is transferred, sold, or rented to third parties for commercial purposes.
- Transfers outside the European Union: some processing activities involve a transfer, primarily to the United States, governed by the European Commission's standard contractual clauses or the Data Privacy Framework (section 5).
- Retention periods: from 12 months to 10 years depending on the purpose (section 2).
- Rights of data subjects: access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and post-mortem directives, exercisable by contacting amaury.deluca@noqode.fr. You have the right to lodge a complaint with the CNIL (section 6).
1. Identity of the data controller
Data Controller: SAS Noqode, 29 rue de la Croix Blanche, 78200 Mantes-la-Jolie, France. SIRET: 10249425900017. RCS Versailles: 102 494 259 B. Email address: contact@noqode.fr.
Data Protection Officer: Amaury DE LUCA, amaury.deluca@noqode.fr.
This policy applies to visitors of the website, prospects, and clients of SAS Noqode.
2. Summary table of processing activities
The summary below indicates the data involved, the legal basis, and the retention period for each processing activity. Details can be found in section 3.
- Contact and project inquiry — Identity, contact details, company, message. Pre-contractual measures. 3 years after last contact.
- Referral program — Identity, contact details, referred company, budget. Pre-contractual measures and contract. 3 years, and 10 years for accounting records.
- AEO Audit — Website URL, name, job title, email address. Consent and legitimate interest. 3 years.
- Book an appointment — Identity, email address, time slot. Pre-contractual measures. 3 years.
- Chatbot — Content of communications. Legitimate interest. 12 months.
- Audience measurement — Cookie identifiers, IP address, browsing activity. Consent. 13 months for cookies, 25 months for data.
- Advertising — Advertising identifiers, browsing activity. Consent. 13 months.
- Proof of cookie consent — Technical identifier, choice made, date. Legal obligation. 3 years.
- Customer relationship management — Identity, contact details, communication history. Legitimate interest. 3 years after last contact.
3. Detailed description of processing activities
Only data strictly necessary for each purpose is collected, in accordance with the data minimization principle set out in Article 5.1.c of the GDPR. No data belonging to the special categories referred to in Article 9 of the GDPR is collected.
3.1 Contact forms and project inquiries
- Data: last name, first name, email address, phone number, company name, message content.
- Purpose: responding to your request, qualifying your project, and providing a quote.
- Legal basis: performance of pre-contractual measures taken at your request (Article 6.1.b of the GDPR).
- Retention: 3 years from your last contact.
3.2 Referral Program
- Data: Name, company, email address, phone number, name of the referred company, budget range, message, and your acceptance of this policy.
- Purpose: To process your referral, contact you, and manage the payment of your commission if applicable.
- Legal basis: Performance of pre-contractual measures and subsequent execution of the contract (Article 6.1.b of the GDPR).
- Retention: 3 years after the last contact, and 10 years for accounting documents related to a paid commission (Article L123-22 of the French Commercial Code).
3.3 AEO Audit
- Data: Website URL to be analyzed, full name, job title, and professional email address.
- Purpose: To generate your visibility score on AI-powered answer engines, provide you with access to the report, and contact you regarding your project if necessary.
- Legal basis: Your consent (Article 6.1.a of the GDPR) for conducting the audit and accessing the report, and the legitimate interest of SAS Noqode (Article 6.1.f of the GDPR) for potential commercial follow-up related to your professional activity, which you may object to at any time.
- Technical details: The submitted URL and associated analysis requests are sent to the Anthropic, OpenAI, and Perplexity APIs to generate the report; the results are stored in a Supabase database.
- Retention: 3 years from the date of the request.
3.4 Online appointment scheduling
- Data: name, email address, selected time slot, time zone, and information entered during booking.
- Purpose: scheduling and confirming a scoping meeting.
- Legal basis: performance of pre-contractual measures (Article 6.1.b of the GDPR).
- Processor: Cal.com, Inc., whose booking module is integrated into the site.
- Retention: 3 years from the date of the appointment.
3.5 Conversational assistant
- Data: content of messages exchanged with the assistant, timestamp, and the page from which the conversation is initiated.
- Purpose: answering your questions and directing you to the right contact person.
- Legal basis: legitimate interest of SAS Noqode in informing its visitors (Article 6.1.f of the GDPR).
- Technical procedures: your messages are transmitted to Anthropic and OpenAI APIs to generate the response; this content is not used to train artificial intelligence models, and conversation history is stored in a Supabase database.
- Retention: 12 months. It is recommended that you do not share any confidential or sensitive information with the assistant.
3.6 Audience measurement
- Data: cookie identifiers, IP address, pages visited, visit duration, device and browser type, referral source.
- Purpose: understand site usage and improve it.
- Legal basis: your consent (Article 6.1.a of the GDPR), collected via the cookie banner.
- Retention: cookies stored for a maximum of 13 months, audience data kept for a maximum of 25 months.
3.7 Advertising and marketing performance measurement
- Data: advertising identifiers, pages visited, interactions with our content.
- Purpose: measure the effectiveness of our campaigns and send you relevant content.
- Legal basis: your consent (Article 6.1.a of the GDPR).
- Retention period: Maximum of 13 months.
3.8 Proof of cookie consent
- Data: anonymous technical identifier, categories accepted or refused, date and time of the choice.
- Purpose: to demonstrate that your consent was properly obtained, in accordance with Article 7.1 of the GDPR.
- Legal basis: legal obligation (Article 6.1.c of the GDPR).
- Retention period: 3 years from the date of collection.
3.9 Business relationship management
- Data: last name, first name, email address, phone number, company, job title, communication history, and sales follow-up notes.
- Purpose: to track our communications and manage our business relationship; information provided via forms or during meetings is recorded in our customer relationship management tool.
- Legal basis: SAS Noqode's legitimate interest in managing and tracking its business relationships (Article 6.1.f of the GDPR).
- Retention period: 3 years from your last point of contact.
4. Cookies and trackers
A cookie is a file placed on a user's device when visiting a website. In accordance with Article 82 of Law No. 78-17 of January 6, 1978, as amended, the placement of cookies that are not strictly necessary for the service to function is subject to prior consent. No non-essential cookies are placed before you have made your choice. There are four distinct categories:
- Essential: site functionality, security, and remembering your cookie preferences. Consent not required.
- Analytics: audience measurement and browsing statistics. Consent required.
- Marketing: advertising performance measurement. Consent required.
- Personalization: adapting displayed content. Consent required.
Changing your choice: you can change your choice at any time by clicking on the "Cookies" link in the footer. Consent can be granted or withdrawn category by category. Refusal is as simple as acceptance and does not prevent you from browsing the site. Browser settings also allow you to block cookies; however, this may affect certain site features.
5. Data recipients and sub-processors
Data is not sold, rented, or transferred to third parties. It is accessible to authorized SAS Noqode personnel as well as the sub-processors listed below, who act on documented instructions from the data controller under a contract compliant with Article 28 of the GDPR.
- Webflow, Inc. (via Amazon Web Services) — site hosting and form storage. United States. Standard Contractual Clauses and Data Privacy Framework.
- Supabase, Inc. — database hosting conversations and audit results. United States. Standard Contractual Clauses.
- Vercel, Inc. — conversational assistant hosting. United States. Standard Contractual Clauses.
- Anthropic PBC — generation of assistant responses and audit analyses. United States. Standard contractual clauses.
- OpenAI, L.L.C. — generation of assistant responses and audit analyses. United States. Standard contractual clauses.
- Perplexity AI, Inc. — visibility analysis on answer engines. United States. Standard contractual clauses.
- Attio Limited — customer relationship management. United Kingdom. EU-UK adequacy decision.
- Cal.com, Inc. — online appointment scheduling. United States. Standard contractual clauses.
- Google Ireland Limited and Google LLC — audience measurement and advertising. Ireland and United States. Data Privacy Framework.
- Finsweet (Consent Pro) — management and proof of cookie consent. United States. Standard contractual clauses.
Some processing operations involve the transfer of data outside the European Union, primarily to the United States. These transfers are governed, in accordance with Chapter V of the GDPR, either by the adequacy decision regarding the EU-U.S. Data Privacy Framework or by standard contractual clauses adopted by the European Commission via Implementing Decision (EU) 2021/914. Data may also be disclosed to authorized administrative or judicial authorities when required by law.
6. Rights of data subjects
In accordance with Articles 15 to 22 of the GDPR and the amended Act No. 78-17 of January 6, 1978, you have the following rights at any time and free of charge:
- Right of access: obtain confirmation that your data is being processed and receive a copy of it.
- Right to rectification: have inaccurate or incomplete data corrected.
- Right to erasure: request the deletion of your data, within the limits provided by law.
- Right to restriction of processing: request the temporary restriction of your data usage.
- Right to object: object to processing based on our legitimate interest, including for direct marketing purposes.
- Right to data portability: receive your data in a structured, machine-readable format.
- Right to withdraw consent: without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to provide instructions: regarding the handling of your data after your death.
How to exercise your rights: all requests must be sent to amaury.deluca@noqode.fr or by mail to SAS Noqode, 29 rue de la Croix Blanche, 78200 Mantes-la-Jolie. We will respond within the one-month period stipulated by Article 12.3 of the GDPR, which may be extended by two months in cases of complexity. Proof of identity may be requested if there is reasonable doubt regarding the identity of the requester.
Right to lodge a complaint: regardless of any prior contact with SAS Noqode, you have the right to lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or online at www.cnil.fr.
7. Data security
SAS Noqode implements the appropriate technical and organizational measures required by Article 32 of the GDPR: encryption of communications via HTTPS, access restricted to authorized personnel, enhanced authentication for internal tools, and the selection of subcontractors providing sufficient guarantees. As no system can guarantee absolute security, SAS Noqode commits to notifying you of any personal data breach under the conditions set out in Articles 33 and 34 of the GDPR.
8. Automated individual decision-making
No decisions producing legal effects or significantly affecting you are based solely on automated processing, as defined by Article 22 of the GDPR.
9. Changes to this policy
This policy may be updated, particularly to reflect legislative or regulatory changes or the addition of new tools. The date of the last update is shown at the top of the document. Any significant changes will be communicated through an appropriate channel.
