01Data controller
The controller of the personal data collected through this site and in the course of the commercial relationship is:
- Company name
- Codesia — a limited liability company (SARL) with share capital of 5,000 euros
- Registered office
- 14 Boulevard Albert Einstein, 44300 Nantes
- SIRET number
- 105 803 944 00013, registered with the Nantes Trade and Companies Register
This policy concerns exclusively the processing that Codesia carries out in its capacity as data controller, that is, for the purposes of its own business. Processing carried out by Codesia as a processor on behalf of its clients is governed by a data processing agreement (DPA) appended to each service contract, in accordance with Article 28 of the GDPR.
No data protection officer (DPO) has been appointed, as such an appointment is not mandatory given Codesia's activity. Questions relating to personal data are handled by an internal contact, who can be reached at rgpd@codesia.fr.
02Data collected
Codesia collects and processes the following personal data, depending on the context of the interaction:
- When visiting the site: browsing data and technical data strictly necessary for the operation of the site, under the conditions set out in Article 8 of this policy.
- When booking a discovery call: last name, first name, work email address, phone number, company name, job title, company size (optional), a description of the tasks or automation needs and any context shared voluntarily, as well as the chosen appointment slot. This form and the appointment-booking module are developed and operated by Codesia; processing of the booking relies on third-party providers acting as processors, in particular a calendar service, specified in Articles 4 and 9.
- During the discovery call: last name, first name, job title, professional contact details, company name, and information about the business and the needs expressed.
- For commercial prospecting: last name, first name, job title, professional contact details, company name and information about its business. This data is collected either directly from the individual, or indirectly from publicly accessible professional sources (the company's website, professional directories, professional social networks) or from professional data-enrichment providers.
- In the course of the commercial relationship: last name, first name, job title, professional contact details, company name and address, SIRET number, billing data and, where applicable, bank details.
03Purposes and legal bases for processing
Personal data is collected and processed for the following purposes:
- Responding to enquiries and arranging the discovery call requested via the site's form. Legal basis: Codesia's legitimate interest in responding to enquiries received (Article 6(1)(f) of the GDPR) or the performance of pre-contractual measures taken at the request of the data subject (Article 6(1)(b) of the GDPR).
- Conducting the discovery call and assessing whether a collaboration is relevant. Legal basis: performance of pre-contractual measures taken at the request of the data subject (Article 6(1)(b) of the GDPR).
- Carrying out commercial prospecting aimed at professionals, including by electronic means. Legal basis: Codesia's legitimate interest in developing its business among professionals whose activity is related to its services (Article 6(1)(f) of the GDPR). Electronic prospecting is sent to professional contacts in connection with their profession; every message includes a simple way to object to any further contact.
- Managing the commercial relationship (drawing up contracts, invoicing, monitoring the P1, P2 and P3 services). Legal basis: performance of the contract to which the data subject is a party (Article 6(1)(b) of the GDPR). Providing the data necessary to conclude and perform the contract is mandatory; failing this, Codesia is unable to provide the service.
- Sending recurring commercial and editorial communications (news, content, new services). Legal basis: the data subject's consent for prospects (Article 6(1)(a) of the GDPR); Codesia's legitimate interest with respect to its existing clients, for products and services similar to those already provided (Article 6(1)(f) of the GDPR). Consent may be withdrawn and the right to object exercised at any time, in particular via the unsubscribe link included in every message.
- Complying with applicable legal and regulatory obligations (accounting and tax obligations). Legal basis: compliance with a legal obligation to which Codesia is subject (Article 6(1)(c) of the GDPR).
- Receiving and handling requests to exercise rights. Legal basis: compliance with a legal obligation (Article 6(1)(c) of the GDPR, under Articles 12 to 22 of the GDPR).
Codesia does not carry out any solely automated decision-making producing legal effects concerning data subjects or significantly affecting them within the meaning of Article 22 of the GDPR.
04Recipients of the data
The personal data collected is intended for Codesia's authorised staff. It is not shared with any third party, except in the following cases:
- the technical providers acting on Codesia's behalf: the site host (Hostinger), the calendar and appointment-scheduling service (Google), the email and office-software provider and, where applicable, a sales-tracking tool. These providers act as processors and are subject to contractual data protection obligations compliant with Article 28 of the GDPR.
- the accounting and invoicing platform acting as the accountant (Dougs), the bank (Qonto) and, where applicable, the tax authorities, in connection with invoicing and accounting and tax obligations.
- the administrative or judicial authorities, where Codesia is required to meet a legal obligation.
Codesia never sells, rents or transfers the personal data of its users, prospects or clients to third parties for commercial purposes.
05Data retention period
Personal data is retained for the period strictly necessary for the purpose for which it was collected, in accordance with Article 5(1)(e) of the GDPR:
- Data from the discovery-call booking form: kept for a maximum of twelve (12) months from receipt of the request, unless a commercial relationship begins.
- Data relating to prospects (discovery call, prospecting): kept for a maximum of twenty-four (24) months from the last contact, unless a commercial relationship begins, in line with the CNIL's recommendations on B2B prospecting.
- Data relating to clients (contract, invoicing): kept for the entire duration of the contractual relationship, then archived for ten (10) years from the end of the contract, in accordance with the accounting and tax obligations in force (Article L.123-22 of the French Commercial Code).
- Proof of consent (commercial communications and cookies): kept in line with the CNIL's recommendations so that it can be demonstrated in the event of an inspection.
- Browsing data and cookies: kept for the periods set out in Article 8 of this policy.
Once these periods expire, the data is deleted or irreversibly anonymised.
06Rights of data subjects
In accordance with Articles 15 to 22 of the GDPR, anyone whose data is processed by Codesia has the following rights:
- Right of access: to obtain confirmation that data concerning them is being processed and to obtain a copy of it.
- Right to rectification: to request the correction of inaccurate or incomplete data.
- Right to erasure: to request the deletion of their data, subject to legal retention obligations.
- Right to restriction of processing: to request the suspension of the processing of their data in certain circumstances.
- Right to portability: to receive their data in a structured, commonly used and machine-readable format, or to request that it be transmitted directly to another controller.
- Right to object: to object to the processing of their data based on legitimate interest, including for commercial prospecting purposes.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before its withdrawal.
These rights may be exercised at any time by email at: rgpd@codesia.fr. Codesia undertakes to respond to any request within one (1) month of receiving it. This period may be extended by two (2) months in the event of complexity or a high number of requests, in which case the data subject is informed within the initial one-month period.
Codesia may ask the data subject to prove their identity before acting on their request, in order to prevent any unauthorised access to personal data.
In the event of a complaint, the data subject may lodge a complaint with the French data protection authority, the Commission Nationale de l'Informatique et des Libertés (CNIL): www.cnil.fr.
07Data security
Codesia implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. These measures are intended to protect personal data against any unauthorised access, alteration, accidental or unlawful disclosure or destruction.
08Cookies and trackers
While browsing the codesia.fr site, cookies and other trackers may be placed on the user's device. A tracker is an operation that reads or writes information on the device, most often by means of a small file stored by the browser.
The site uses only cookies and trackers strictly necessary for its operation, including for the operation of the online appointment-booking module developed and operated by Codesia. These trackers do not require the user's consent, in accordance with Article 82 of the French Data Protection Act, and provide the site's essential functions (navigation, security, management of the booking session).
Codesia does not use any analytics, advertising or tracking cookies for marketing purposes. The third-party services used for appointment booking, in particular the calendar service, are called by Codesia server-side and do not place trackers on the user's device. No consent banner is therefore required.
Should such non-essential trackers be deployed in the future, they would only be placed after obtaining the user's prior consent, given freely, specifically, in an informed manner and unambiguously, in line with the CNIL's recommendations. Refusing would then be as simple as accepting, and consent could be revoked at any time, with no impact on access to the site.
09Data transfers outside the European Union
Hosting of the site and orchestration of the automations are carried out on Codesia's infrastructure, within the European Economic Area. Codesia prefers to use providers and solutions located within the European Union. Some processors may, however, process personal data outside the European Economic Area, in particular the calendar service used for appointment booking (Google LLC, United States). The other providers Codesia uses (hosting, accounting and invoicing, banking services) are located within the European Union.
In this case, Codesia ensures that appropriate safeguards are in place in accordance with Chapter V of the GDPR: an adequacy decision of the European Commission, in particular the EU–US Data Privacy Framework to which the provider concerned is certified, or failing that the standard contractual clauses adopted by the European Commission. A copy of the applicable safeguards can be obtained on request at rgpd@codesia.fr.
Apart from the calendar service (Google), the rest of the automation is deployed using a self-hosted n8n instance on Codesia's virtual private server, within the European Economic Area; the data is not shared with the publisher of the n8n software.
10Changes to the privacy policy
Codesia reserves the right to amend this privacy policy at any time in order to adapt it to legal or regulatory developments or to changes in its activities. The date of the last update is shown at the top of this document. Users are encouraged to consult this page regularly to be aware of any changes.
11Contact
For any question regarding this privacy policy or the processing of your personal data, you can contact Codesia at the following address: rgpd@codesia.fr.