Privacy Policy
Last updated: September 16, 2026
1. Data controller
Damien Reichhart, acting as an individual publisher based in France, is the data controller ("responsable de traitement") for the personal data described below, within the meaning of the EU General Data Protection Regulation (GDPR / RGPD) and the French Data Protection Act ("Loi Informatique et Libertés"). Contact: [email protected].
2. What data is collected, and why
Contact form
- Data: name, email address, optional subject, and message content.
- Purpose: to respond to your inquiry.
- Legal basis: your consent, given by submitting the form (Art. 6.1.a GDPR).
- Recipients: only Damien Reichhart. The message is relayed by email through Resend, an email-delivery subprocessor described in detail under "Third parties" below, and stored in the Site's private database, accessible only to the publisher, so the exchange can be tracked.
- Retention: up to 24 months after the last exchange, then deleted — unless a longer period is required to establish, exercise, or defend a legal claim.
Technical / connection data
- Data: IP address and request metadata, generated automatically by any visit to the Site.
- Purpose: deliver the Site's content, and keep it available and secure (e.g. bot/DDoS mitigation).
- Legal basis: legitimate interest in operating and securing the Site (Art. 6.1.f GDPR).
- Recipients: Cloudflare, Inc., which relays traffic to the self-hosted origin server through Cloudflare Tunnel and is, by the nature of that role, exposed to this connection metadata — see "Third parties" below for detail. The publisher does not separately collect or store visitor connection logs beyond what that connectivity layer retains.
Admin authentication cookie
A single strictly-necessary session cookie is issued only when signing into the Site's private administration area — it is never set for ordinary visitors browsing the public pages, carries no tracking information, and is exempt from consent under Article 82 of the French Data Protection Act (cookies strictly necessary to a service explicitly requested by the user). No analytics, advertising, or audience-measurement cookies are used on this Site, so no cookie-consent banner is shown. If that changes, this policy will be updated accordingly.
3. Third parties
The Site relies on two external service providers ("subprocessors") to operate. Neither is used for advertising, analytics, or profiling — each is limited to the narrow technical purpose described below.
Cloudflare, Inc.
101 Townsend Street, San Francisco, CA 94107, USA — cloudflare.com
The Site is self-hosted: its application, code, and database run entirely on infrastructure the publisher owns and operates. To make that server reachable on the public internet — without exposing its IP address or opening inbound ports — the publisher routes traffic through Cloudflare Tunnel (cloudflared), a secure outbound-connection service. Cloudflare is not used as a host, CDN, or storage provider for this Site; it acts only as a connectivity layer between visitors and the origin server. By the nature of that role, Cloudflare's network is exposed to visitors' IP addresses and request metadata while relaying traffic, and applies its own security and abuse-prevention processing to that traffic as an independent controller. See Cloudflare's own privacy policy for details of that processing.
Resend (Resend, Inc.)
United States — resend.com
When you submit the Site's contact form, Resend is used purely as a transactional email-delivery API to relay that one message to the publisher's inbox. The name, email address, subject, and message you enter are passed to Resend for that single purpose only; Resend does not use this data for marketing or any other purpose on the publisher's behalf, and it is not used anywhere else on the Site (no newsletter, no mailing list).
4. International data transfers
Cloudflare, Inc. and Resend, Inc., the two subprocessors described above, are US-based companies. Where personal data is transferred outside the European Economic Area, this is done under appropriate safeguards, such as the European Commission's Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework, as offered by each provider.
5. Your rights
Under the GDPR and French law, you have the right to:
- Access the personal data concerning you;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten");
- Restrict or object to processing;
- Data portability;
- Withdraw your consent at any time, for data processed on that basis, without affecting the lawfulness of processing carried out before the withdrawal;
- Lodge a complaint with the French data protection authority, the CNIL (Commission Nationale de l'Informatique et des Libertés) — www.cnil.fr — 3 Place de Fontenoy, 75007 Paris, France.
To exercise these rights, contact [email protected]. A response will be provided within one month, as required by Article 12 of the GDPR.
6. Security
The Site is served exclusively over HTTPS. Its administration area is protected by authentication, and the underlying infrastructure is operated directly by the publisher rather than a third-party host.
7. Changes to this policy
This policy may be updated to reflect changes to the Site's functionality or to applicable law. The date at the top of this page indicates when it was last revised.