Privacy policy
The purpose of this privacy policy is to inform users of the l’Atelier SEO platform, available at https://atelier.la-refonte.fr (hereinafter “the Platform”), how their personal data is collected, processed and protected, in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and the French Data Protection Act of 6 January 1978 as amended.
1. Identity of the data controller
The data controller is:
SEGUROV LIMITED LLC
1603 Capitol Avenue, Suite 413A, 3157 Cheyenne, Wyoming 82001
United States
Represented by Rémi Segura, in his capacity as manager.
Contact address for any question relating to personal data : contact@la-refonte.fr
2. Representative in the European Union
In accordance with article 27 of the GDPR, SEGUROV LIMITED LLC, established outside the European Union, has designated a representative within the Union:
Rémi Segura, sole trader
13 rue de Méon, 64000 Pau, France
Contact: contact@la-refonte.fr
The representative may be contacted directly by any data subject and by any supervisory authority regarding any question relating to the processing of their personal data.
3. Data collected and purposes of processing
3.1 User account data
When accessing a personal workspace on the Platform (demo workspace for prospects, client workspace for clients), the following data is collected:
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Identification and access to the personal workspace | Performance of the contract / pre-contractual measures |
| Password (stored in hashed form) | Securing access to the account | Performance of the contract |
3.2 Data related to use of the service
| Data | Purpose | Legal basis |
|---|---|---|
| URLs of the websites analysed | Carrying out the SEO audit, competitive analysis, performance monitoring | Performance of the contract |
| History of conversations with the Iris AI assistant | Providing a personalised and continuous advisory service | Performance of the contract |
| Action plans and change history (clients only) | Operational monitoring of SEO recommendations and traceability of the actions taken | Performance of the contract |
3.3 Data from Google Search Console and Google Analytics
When the user connects their Google Search Console (GSC) and/or Google Analytics (GA4) accounts to the Platform, the following data is retrieved in read-only mode:
- Search Console: impressions, clicks, average positions and search queries associated with the sites validated by the user;
- Google Analytics: audience statistics, traffic sources and visitor behaviour on the properties declared by the user.
No data is modified: the Platform performs read operations only, in order to present the data back to the user who owns the account.
This data is used exclusively to present users with their own SEO performance statistics in a unified dashboard, and to provide the Iris AI assistant with relevant context when answering.
This data is never sold, never used for advertising purposes, and never used to train artificial intelligence models. See section 8 for details of compliance with the Google API Services User Data Policy.
3.4 Google authentication tokens (OAuth)
To allow periodic retrieval of GSC and GA data, the Platform stores the access and refresh tokens issued by Google when the user connects via OAuth.
- These tokens are stored in encrypted form on our servers.
- They are strictly limited to the scopes requested:
https://www.googleapis.com/auth/webmasters.readonlyandhttps://www.googleapis.com/auth/analytics.readonly. - They may be revoked at any time by the user, entirely on their own, in two ways: directly from the Platform, freely accessible, via the “Revoke Google access” button in their workspace settings (demo or client workspace alike), which passes the revocation on to Google immediately and purges the corresponding tokens from our servers; or directly from their Google account, via the page https://myaccount.google.com/permissions.
- A deletion request may also be sent by the user to contact@la-refonte.fr; revocation and token deletion are then carried out manually by us.
- In the event of revocation, the OAuth tokens and all Google data previously retrieved are deleted from our servers within a maximum of 30 days — deletion being immediate when revocation is performed from the Platform.
- If the user account is deleted, the tokens are permanently removed from our servers.
3.5 B2B sales prospecting data
As part of our B2B sales prospecting activity, we collect and process professional data (first name, last name, job title, professional email address, company) relating to professionals who may be interested in our services.
- Collection sources: the professional prospecting tools Pharrow, FullEnrich and Dropcontact, which aggregate public professional data.
- Sending tool: the Instantly platform is used to send and track prospecting email campaigns.
- Legal basis: legitimate interest (article 6.1.f of the GDPR), in line with the recommendations of the French data protection authority (CNIL) on B2B prospecting.
- Retention period: prospected contacts who have not responded are kept for a maximum of 2 years from the last contact, then deleted.
- Right to object: anyone may object at any time to receiving our commercial communications, either by clicking the unsubscribe link in every email or by writing to contact@la-refonte.fr. Objections are handled as quickly as possible.
4. Cookies and trackers
The Platform uses no audience measurement, advertising tracking or profiling cookies.
Only strictly necessary cookies are placed, for the operation of the Platform:
- A session cookie, keeping the user signed in to their workspace;
- An authentication cookie, securing the user session.
These technical cookies are exempt from consent in accordance with the CNIL’s recommendation, as they are essential to providing the service requested by the user.
5. Processors and recipients of the data
We use processors to host and operate the Platform. Each of them is bound to us by a processing agreement compliant with article 28 of the GDPR.
5.1 Hosting
| Processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany) | Hosting of the Platform and storage of all data | Germany (EU) |
5.2 Artificial intelligence model providers
The Iris AI assistant relies on several third-party language models to formulate its answers. When the user interacts with Iris, certain context data (audit excerpts, relevant GSC/GA data, conversation history) may be transmitted to these providers, exclusively to allow the answer requested by the user to be generated.
| Processor | Role | Location |
|---|---|---|
| Anthropic PBC | Provision of a language model (Claude) used by Iris | United States |
| OpenAI OpCo, LLC | Provision of a language model (GPT) used by Iris | United States |
| Google LLC | Provision of a language model (Gemini) used by Iris | United States |
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | Provision of a language model (DeepSeek) used by Iris | China |
These providers process the data solely to generate the requested answer. None of these providers uses data transmitted via the API to train their models, in accordance with their respective policies applicable to API calls in a professional environment.
5.3 Sales prospecting
| Processor | Role | Location |
|---|---|---|
| Pharrow | Enrichment of professional data | European Union |
| FullEnrich | Enrichment of professional data | European Union |
| Dropcontact | Enrichment of professional data | France (EU) |
| Instantly | Sending and tracking of B2B prospecting campaigns | United States |
6. Data transfers outside the European Union
Some of the processors listed in section 5 are established outside the European Union (United States, China).
6.1 Transfers to the United States
Transfers to the US-based processors (Anthropic PBC, OpenAI OpCo LLC, Google LLC, Instantly) are governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission in its implementing decision (EU) 2021/914 of 4 June 2021, which constitute appropriate safeguards within the meaning of article 46 of the GDPR.
Some of these processors may also be certified under the EU–US Data Privacy Framework (DPF), providing an additional guarantee of protection.
6.2 Transfers to China
Transfers to Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (China) are likewise governed by the European Commission’s Standard Contractual Clauses.
We draw the user’s attention to the fact that China does not benefit from an adequacy decision of the European Commission. Although the SCCs constitute an appropriate contractual safeguard, a user who does not wish their data to pass through this provider may request this at contact@la-refonte.fr: we will then restrict their use of Iris to US and European providers only.
7. Data retention periods
| Type of data | Retention period |
|---|---|
| User account data (email, hashed password) | Until the account is deleted |
| URLs of the websites analysed, Iris history, action plans, change history | Until the account is deleted |
| Google OAuth tokens (GSC/GA) | Until revoked by the user or the account is deleted |
| GSC / GA data retrieved via the API | Until the account is deleted |
| Sales prospecting contacts | 2 years from the last contact, then deleted |
| Technical and security logs | 12 months maximum |
8. Compliance with the Google API Services User Data Policy
The Platform’s use of the Google Search Console and Google Analytics APIs is strictly compliant with the Google API Services User Data Policy, including the “Limited Use” requirements.
In particular:
- Data obtained through Google APIs is used exclusively to provide the user with features that are visible within the Platform (dashboard, SEO analyses, answers from the Iris assistant).
- Data obtained through Google APIs is never transferred to third parties, except where necessary to provide the service (AI model providers under section 5.2) or where required by law.
- Data obtained through Google APIs is never used for advertising purposes, including retargeting, personalised advertising or interest-based advertising.
- Data obtained through Google APIs is never used to train artificial intelligence models, whether developed by us or by third parties.
- No human may read data obtained through Google APIs, except: (i) with the user’s prior explicit permission, (ii) for purposes strictly necessary to security (investigating abuse, for example), (iii) to comply with a legal obligation, or (iv) in aggregated and anonymised form for internal operational purposes.
A dedicated “Google API Services User Data Policy Disclosure” page is available for further detail.
9. Data security
We implement appropriate technical and organisational measures to ensure the security and confidentiality of personal data:
- Hosting with a European provider (Hetzner, Germany) certified ISO 27001;
- Encryption of passwords (hashing) and of OAuth tokens at rest;
- Encryption of communications (HTTPS/TLS);
- Access to data restricted to authorised personnel only;
- Regular backups and access logging.
10. Rights of data subjects
In accordance with articles 15 to 22 of the GDPR, every person has the following rights over their personal data:
- Right of access to the data concerning them;
- Right to rectification of inaccurate or incomplete data;
- Right to erasure (“right to be forgotten”);
- Right to restriction of processing;
- Right to data portability;
- Right to object to processing, in particular to sales prospecting;
- Right to give directives regarding the fate of their data after death;
- Right to lodge a complaint with the French data protection authority (CNIL — www.cnil.fr).
These rights may be exercised by writing to contact@la-refonte.fr. A response is provided within a maximum of one month from receipt of the request, in accordance with article 12 of the GDPR.
Proof of identity may be requested in the event of reasonable doubt as to the identity of the applicant.
11. Account deletion
Deletion of a user account (demo or client workspace) is carried out manually by the l’Atelier SEO administrative team, at the user’s request sent by any means (email to contact@la-refonte.fr, WhatsApp, Slack, or verbally during a conversation).
Deletion entails:
- Permanent deletion of the account data, the Iris history, the action plans and the change history;
- Revocation and deletion of the Google OAuth tokens;
- Deletion of the GSC/GA data previously retrieved.
A maximum period of 30 days applies for carrying out the deletion, save where retention is legally required.
12. Minimum age
Access to the Platform is reserved for people aged at least 15. We do not knowingly collect data concerning minors under 15. Should such collection come to our attention, the data concerned would be deleted immediately.
13. Changes to the privacy policy
This policy may be amended at any time to reflect legal, regulatory or technical developments. The version in force is always the one published at https://atelier.la-refonte.fr/politique-de-confidentialite/. The date of the last update is shown at the top of the document.
14. Governing law
This privacy policy is governed by French law and by the General Data Protection Regulation. Any dispute relating to its interpretation or performance falls within the jurisdiction of the French courts.
15. Language
This English text is a translation provided for convenience. The French version prevails: in the event of any discrepancy or difference of interpretation between the two, the French version available at https://atelier.la-refonte.fr/politique-de-confidentialite/ is the one that governs.
For any question regarding this privacy policy or the processing of your personal data, contact us at contact@la-refonte.fr.