AtelierLa Refonte
Back to home
  1. Home
  2. /
  3. Privacy policy

Privacy policy

Last updated: 8 July 2026

The purpose of this privacy policy is to inform users of the l’Atelier SEO platform, available at https://atelier.la-refonte.fr (hereinafter “the Platform”), how their personal data is collected, processed and protected, in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and the French Data Protection Act of 6 January 1978 as amended.


1. Identity of the data controller

The data controller is:

SEGUROV LIMITED LLC
1603 Capitol Avenue, Suite 413A, 3157 Cheyenne, Wyoming 82001
United States

Represented by Rémi Segura, in his capacity as manager.

Contact address for any question relating to personal data : contact@la-refonte.fr

2. Representative in the European Union

In accordance with article 27 of the GDPR, SEGUROV LIMITED LLC, established outside the European Union, has designated a representative within the Union:

Rémi Segura, sole trader
13 rue de Méon, 64000 Pau, France
Contact: contact@la-refonte.fr

The representative may be contacted directly by any data subject and by any supervisory authority regarding any question relating to the processing of their personal data.


3. Data collected and purposes of processing

3.1 User account data

When accessing a personal workspace on the Platform (demo workspace for prospects, client workspace for clients), the following data is collected:

DataPurposeLegal basis
Email addressIdentification and access to the personal workspacePerformance of the contract / pre-contractual measures
Password (stored in hashed form)Securing access to the accountPerformance of the contract

3.2 Data related to use of the service

DataPurposeLegal basis
URLs of the websites analysedCarrying out the SEO audit, competitive analysis, performance monitoringPerformance of the contract
History of conversations with the Iris AI assistantProviding a personalised and continuous advisory servicePerformance of the contract
Action plans and change history (clients only)Operational monitoring of SEO recommendations and traceability of the actions takenPerformance of the contract

3.3 Data from Google Search Console and Google Analytics

When the user connects their Google Search Console (GSC) and/or Google Analytics (GA4) accounts to the Platform, the following data is retrieved in read-only mode:

  • Search Console: impressions, clicks, average positions and search queries associated with the sites validated by the user;
  • Google Analytics: audience statistics, traffic sources and visitor behaviour on the properties declared by the user.

No data is modified: the Platform performs read operations only, in order to present the data back to the user who owns the account.

This data is used exclusively to present users with their own SEO performance statistics in a unified dashboard, and to provide the Iris AI assistant with relevant context when answering.

This data is never sold, never used for advertising purposes, and never used to train artificial intelligence models. See section 8 for details of compliance with the Google API Services User Data Policy.

3.4 Google authentication tokens (OAuth)

To allow periodic retrieval of GSC and GA data, the Platform stores the access and refresh tokens issued by Google when the user connects via OAuth.

  • These tokens are stored in encrypted form on our servers.
  • They are strictly limited to the scopes requested: https://www.googleapis.com/auth/webmasters.readonly and https://www.googleapis.com/auth/analytics.readonly.
  • They may be revoked at any time by the user, entirely on their own, in two ways: directly from the Platform, freely accessible, via the “Revoke Google access” button in their workspace settings (demo or client workspace alike), which passes the revocation on to Google immediately and purges the corresponding tokens from our servers; or directly from their Google account, via the page https://myaccount.google.com/permissions.
  • A deletion request may also be sent by the user to contact@la-refonte.fr; revocation and token deletion are then carried out manually by us.
  • In the event of revocation, the OAuth tokens and all Google data previously retrieved are deleted from our servers within a maximum of 30 days — deletion being immediate when revocation is performed from the Platform.
  • If the user account is deleted, the tokens are permanently removed from our servers.

3.5 B2B sales prospecting data

As part of our B2B sales prospecting activity, we collect and process professional data (first name, last name, job title, professional email address, company) relating to professionals who may be interested in our services.

  • Collection sources: the professional prospecting tools Pharrow, FullEnrich and Dropcontact, which aggregate public professional data.
  • Sending tool: the Instantly platform is used to send and track prospecting email campaigns.
  • Legal basis: legitimate interest (article 6.1.f of the GDPR), in line with the recommendations of the French data protection authority (CNIL) on B2B prospecting.
  • Retention period: prospected contacts who have not responded are kept for a maximum of 2 years from the last contact, then deleted.
  • Right to object: anyone may object at any time to receiving our commercial communications, either by clicking the unsubscribe link in every email or by writing to contact@la-refonte.fr. Objections are handled as quickly as possible.

4. Cookies and trackers

The Platform uses no audience measurement, advertising tracking or profiling cookies.

Only strictly necessary cookies are placed, for the operation of the Platform:

  • A session cookie, keeping the user signed in to their workspace;
  • An authentication cookie, securing the user session.

These technical cookies are exempt from consent in accordance with the CNIL’s recommendation, as they are essential to providing the service requested by the user.


5. Processors and recipients of the data

We use processors to host and operate the Platform. Each of them is bound to us by a processing agreement compliant with article 28 of the GDPR.

5.1 Hosting

ProcessorRoleLocation
Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany)Hosting of the Platform and storage of all dataGermany (EU)

5.2 Artificial intelligence model providers

The Iris AI assistant relies on several third-party language models to formulate its answers. When the user interacts with Iris, certain context data (audit excerpts, relevant GSC/GA data, conversation history) may be transmitted to these providers, exclusively to allow the answer requested by the user to be generated.

ProcessorRoleLocation
Anthropic PBCProvision of a language model (Claude) used by IrisUnited States
OpenAI OpCo, LLCProvision of a language model (GPT) used by IrisUnited States
Google LLCProvision of a language model (Gemini) used by IrisUnited States
Hangzhou DeepSeek Artificial Intelligence Co., Ltd.Provision of a language model (DeepSeek) used by IrisChina

These providers process the data solely to generate the requested answer. None of these providers uses data transmitted via the API to train their models, in accordance with their respective policies applicable to API calls in a professional environment.

5.3 Sales prospecting

ProcessorRoleLocation
PharrowEnrichment of professional dataEuropean Union
FullEnrichEnrichment of professional dataEuropean Union
DropcontactEnrichment of professional dataFrance (EU)
InstantlySending and tracking of B2B prospecting campaignsUnited States

6. Data transfers outside the European Union

Some of the processors listed in section 5 are established outside the European Union (United States, China).

6.1 Transfers to the United States

Transfers to the US-based processors (Anthropic PBC, OpenAI OpCo LLC, Google LLC, Instantly) are governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission in its implementing decision (EU) 2021/914 of 4 June 2021, which constitute appropriate safeguards within the meaning of article 46 of the GDPR.

Some of these processors may also be certified under the EU–US Data Privacy Framework (DPF), providing an additional guarantee of protection.

6.2 Transfers to China

Transfers to Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (China) are likewise governed by the European Commission’s Standard Contractual Clauses.

We draw the user’s attention to the fact that China does not benefit from an adequacy decision of the European Commission. Although the SCCs constitute an appropriate contractual safeguard, a user who does not wish their data to pass through this provider may request this at contact@la-refonte.fr: we will then restrict their use of Iris to US and European providers only.


7. Data retention periods

Type of dataRetention period
User account data (email, hashed password)Until the account is deleted
URLs of the websites analysed, Iris history, action plans, change historyUntil the account is deleted
Google OAuth tokens (GSC/GA)Until revoked by the user or the account is deleted
GSC / GA data retrieved via the APIUntil the account is deleted
Sales prospecting contacts2 years from the last contact, then deleted
Technical and security logs12 months maximum

8. Compliance with the Google API Services User Data Policy

The Platform’s use of the Google Search Console and Google Analytics APIs is strictly compliant with the Google API Services User Data Policy, including the “Limited Use” requirements.

In particular:

  • Data obtained through Google APIs is used exclusively to provide the user with features that are visible within the Platform (dashboard, SEO analyses, answers from the Iris assistant).
  • Data obtained through Google APIs is never transferred to third parties, except where necessary to provide the service (AI model providers under section 5.2) or where required by law.
  • Data obtained through Google APIs is never used for advertising purposes, including retargeting, personalised advertising or interest-based advertising.
  • Data obtained through Google APIs is never used to train artificial intelligence models, whether developed by us or by third parties.
  • No human may read data obtained through Google APIs, except: (i) with the user’s prior explicit permission, (ii) for purposes strictly necessary to security (investigating abuse, for example), (iii) to comply with a legal obligation, or (iv) in aggregated and anonymised form for internal operational purposes.

A dedicated “Google API Services User Data Policy Disclosure” page is available for further detail.


9. Data security

We implement appropriate technical and organisational measures to ensure the security and confidentiality of personal data:

  • Hosting with a European provider (Hetzner, Germany) certified ISO 27001;
  • Encryption of passwords (hashing) and of OAuth tokens at rest;
  • Encryption of communications (HTTPS/TLS);
  • Access to data restricted to authorised personnel only;
  • Regular backups and access logging.

10. Rights of data subjects

In accordance with articles 15 to 22 of the GDPR, every person has the following rights over their personal data:

  • Right of access to the data concerning them;
  • Right to rectification of inaccurate or incomplete data;
  • Right to erasure (“right to be forgotten”);
  • Right to restriction of processing;
  • Right to data portability;
  • Right to object to processing, in particular to sales prospecting;
  • Right to give directives regarding the fate of their data after death;
  • Right to lodge a complaint with the French data protection authority (CNIL — www.cnil.fr).

These rights may be exercised by writing to contact@la-refonte.fr. A response is provided within a maximum of one month from receipt of the request, in accordance with article 12 of the GDPR.

Proof of identity may be requested in the event of reasonable doubt as to the identity of the applicant.


11. Account deletion

Deletion of a user account (demo or client workspace) is carried out manually by the l’Atelier SEO administrative team, at the user’s request sent by any means (email to contact@la-refonte.fr, WhatsApp, Slack, or verbally during a conversation).

Deletion entails:

  • Permanent deletion of the account data, the Iris history, the action plans and the change history;
  • Revocation and deletion of the Google OAuth tokens;
  • Deletion of the GSC/GA data previously retrieved.

A maximum period of 30 days applies for carrying out the deletion, save where retention is legally required.


12. Minimum age

Access to the Platform is reserved for people aged at least 15. We do not knowingly collect data concerning minors under 15. Should such collection come to our attention, the data concerned would be deleted immediately.


13. Changes to the privacy policy

This policy may be amended at any time to reflect legal, regulatory or technical developments. The version in force is always the one published at https://atelier.la-refonte.fr/politique-de-confidentialite/. The date of the last update is shown at the top of the document.


14. Governing law

This privacy policy is governed by French law and by the General Data Protection Regulation. Any dispute relating to its interpretation or performance falls within the jurisdiction of the French courts.


15. Language

This English text is a translation provided for convenience. The French version prevails: in the event of any discrepancy or difference of interpretation between the two, the French version available at https://atelier.la-refonte.fr/politique-de-confidentialite/ is the one that governs.


For any question regarding this privacy policy or the processing of your personal data, contact us at contact@la-refonte.fr.

AtelierLa Refonte

SEO & generative AI agency. Published by SEGUROV LIMITED LLC.

contact@la-refonte.fr

Legal information

  • Privacy policy
  • Terms of use
  • Google API Services User Data Policy

© 2026 La Refonte All rights reserved.