Privacy Policy
This page describes the personal data that goes through marcm.fr: what I collect, why, how long I keep it, which providers handle it and in which countries. It also sets out my commitments when I process data on behalf of a client. The French version prevails.
Data controller
Marc Muller, sole proprietor (entrepreneur individuel, EI), trading as Marc M
13 rue des Peupliers, 57950 Montigny-lès-Metz, France
Email: marc@muller.im
I have not appointed a data protection officer: your requests come straight to me.
What I collect, and why
The site asks you for nothing until you fill in a form or book a call. Here is each processing activity, with its purpose, its legal basis under GDPR article 6 and its retention period.
Forms: contact, order, audit, Echo
- Data:
- What you type in, for example your name, email, phone number if you give it, your business, your website address and your message. The site also records the sending date, your browser and a fingerprint of your IP address, never the address itself.
- Why:
- Answer your request, prepare a quote, follow up on our exchange.
- Legal basis:
- Your consent, given by ticking the box before sending (GDPR article 6.1.a). You can withdraw it at any time by email.
- Retention:
- 12 months in the site database, hosted by Cloudflare, then deleted automatically. A request I copy into my request tracker stays there for up to 24 months after sending.
Training waiting list
- Data:
- Your email.
- Why:
- Write to you on the day the training opens, and nothing else.
- Legal basis:
- Your consent (article 6.1.a), which you withdraw by asking me by email.
- Retention:
- 24 months at most, like other requests.
Video call bookings
- Data:
- Your name, email, chosen slot and any message, entered on Cal.com.
- Why:
- Organise the call.
- Legal basis:
- Pre-contractual steps taken at your request (article 6.1.b).
- Retention:
- As long as my Cal.com account is active, under Cal.com policy.
Email exchanges
- Data:
- Your address, the content of messages and their attachments.
- Why:
- Correspond with you.
- Legal basis:
- My legitimate interest in answering people who write to me (article 6.1.f), or the contract if you are a client.
- Retention:
- 36 months.
Clients: project file, quotes and invoices
- Data:
- Your contact details, the content and files you entrust to me, including those uploaded at onboarding, your quotes and invoices.
- Why:
- Deliver, invoice and follow up the service.
- Legal basis:
- Performance of the contract (article 6.1.b); for invoices, a legal obligation (article 6.1.c).
- Retention:
- For the duration of the relationship, then 12 months. Accounting records: ten years (French Commercial Code, article L123-22).
Audience measurement
- Data:
- The page viewed, the referring site, your browser, operating system, device type and country. No cookie, no identifier stored on your device.
- Why:
- Know which pages are read, to improve the site.
- Legal basis:
- My legitimate interest (article 6.1.f).
- Retention:
- The one set by my Umami plan: Umami's public price list ranges from six months to five years depending on the plan. I only look at aggregate statistics.
Host's technical logs
- Data:
- Your IP address and traffic routing data.
- Why:
- Serve the pages and protect the site.
- Legal basis:
- My legitimate interest (article 6.1.f).
- Retention:
- Not documented: Cloudflare does not publish a precise retention period.
Cookies
The public pages of marcm.fr set no cookie and store nothing in your browser. That is why the site shows no cookie banner.
Only password-protected areas (site administration, private folders) may use a session cookie or session storage, which the login requires.
Providers and transfers outside the European Union
These providers process data on my behalf: they are my processors under the GDPR. For each one, the table gives the countries where data is processed and the legal basis for its transfer outside the European Union, taken from its official documentation or from the official Data Privacy Framework list.
"Not documented" means the provider does not publish the information; "not verified" means I could not check it.
| Provider | Role and data | Countries | Transfer basis | Sources |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting of the site and of the functions that receive form submissions; storage of the requests sent through the forms, of files uploaded by clients and of the administration area data (quotes, invoices). Processes IP addresses and traffic routing data. | United States (headquarters); global network of data centres. | EU-US Data Privacy Framework (Cloudflare, Inc. is certified) and standard contractual clauses. | |
| Scaleway SAS | Delivers the requests received through the forms to my mailbox. Receives the fields you fill in, including your email, set as the reply-to address. | France: French company, email sending service located in its Paris region. | No transfer outside the European Union: its data processing agreement locates its services in the Union and rules out any transfer outside it without informing me beforehand. | |
| Umami Software, Inc. | Cookie-free audience measurement. Receives, for each page view, the IP address and browser characteristics; according to Umami, no data that could identify you is kept. | United States (headquarters); servers in the United States and the European Union. Storage region used for marcm.fr: not verified. | Standard contractual clauses, incorporated into its data processing agreement. Umami is not on the Data Privacy Framework list. | |
| GitHub, Inc. | Tracking of requests and project files, in private repositories: contact details and content of requests, project files. | United States; storage in several countries, including the United States. | EU-US Data Privacy Framework (GitHub is certified) and standard contractual clauses. | |
| Google (Google Workspace) | My mailbox marc@muller.im: receives form submissions and our email exchanges. | Any country where Google or its subprocessors maintain facilities, including the United States (Google LLC headquarters). | Standard contractual clauses or another recognised mechanism, including the EU-US Data Privacy Framework (Google LLC is certified). | |
| Cal.com, Inc. | Video call booking: name, email, chosen slot and any message. | United States; some Cal.com subprocessors process data elsewhere. | Standard contractual clauses or an adequacy mechanism, according to Cal.com. Cal.com is not on the Data Privacy Framework list. |
If you message me on WhatsApp, the exchange goes through WhatsApp (Meta), under the terms you accepted as a user of that service: it is not a provider of this site.
My duties as data controller
- GDPR article 30 requires me to record these processing activities in a record of processing activities.
- If a personal data breach puts your rights and freedoms at risk, I notify the CNIL, the French data protection authority, within 72 hours of becoming aware of it (article 33) and, if the risk is high, I inform you without undue delay (article 34).
- I update this page when a provider changes.
- The whole site is served over an encrypted connection (HTTPS), and requests are tracked in private repositories.
- No personal data is sold or transferred, and none is used for marketing you did not ask for.
When I process data for a client
When I build or maintain a client's website, the data of its visitors, for example messages sent through its form, belongs to the client: the client is the controller, and I act as its processor under GDPR article 28. In that role, I commit to:
- process that data only on the client's documented instructions, and tell the client if an instruction seems to breach the regulation;
- keep that data confidential;
- protect it with security measures appropriate to the risk;
- use only the providers I have told the client about, bound by a data processing agreement, and inform the client before adding or replacing one so that it can object;
- help the client answer people who exercise their rights, and meet its own security obligations;
- at the end of the service, at the client's choice, return the data and then delete it, copies included, unless the law requires keeping it;
- notify the client of any personal data breach without undue delay after becoming aware of it, so that the client can, where required, notify the CNIL within 72 hours (article 33).
A client site's providers are those of that site, which are not necessarily those of marcm.fr.
For client Google Business Profile access and the Google APIs used on behalf of clients, see the French version, which prevails.
Your rights
You can access your data, have it corrected or erased, restrict its processing, object to it, receive it in a readable format, and withdraw your consent at any time when consent is the legal basis.
Write to marc@muller.im: I answer within one month (GDPR article 12).
If you believe your rights are not respected, you can lodge a complaint with the CNIL at cnil.fr.
Last updated: 11 September 2026