Legal
Privacy policy
Last updated 24 September 2026
This policy explains what personal data Sectius collects through this website and during our engagements, why, for how long, and what you can ask us to do about it. It is written to be read, not to be survived.
Controller
The controller is Sectius SAS, 1 rue de la Section, 75001 Paris, France, registered under RCS Paris 000 000 000.
For any question about this policy or to exercise your rights, write to privacy@sectius.com. We answer within one month, as the GDPR requires.
What we collect and why
Contact form. Name, company, role, work email, country, topic, your message, and optionally your preferred language. We use this solely to answer you and, if it leads to work, to prepare a proposal. The legal basis is our legitimate interest in responding to a business enquiry (Article 6(1)(f)), and your explicit consent for us to store and use the message for that purpose, which you give with the checkbox on the form.
Server logs. Our hosting provider records IP address, request time, requested URL, status code and user agent for a short period, to operate the service and detect abuse. Legal basis: legitimate interest in the security and availability of the site (Article 6(1)(f)).
Analytics. If audience measurement is enabled, it is cookieless and aggregated: no cookie, no identifier stored on your device, no cross-site tracking, no personal profile. See the cookie policy.
Engagement data. During a consulting engagement we process the professional contact details of the people we work with, and whatever documentation the mission requires. That processing is governed by the engagement contract and, where we act as processor, by a data processing agreement.
What we do not do
We do not sell, rent or share personal data with advertisers or data brokers. We do not build behavioural profiles. We do not use your data to train any model. We set no advertising or tracking cookies of any kind.
Retention
Contact form messages: twelve months from the last exchange, then deleted.
Proposals and commercial correspondence that did not lead to a contract: three years from the last contact.
Contract and engagement records: for the duration of the engagement plus the legal limitation and accounting periods that apply, typically ten years for accounting records.
Server logs: up to twelve months.
Mission documentation and evidence: returned or destroyed at the end of the engagement on your instruction, and in any case no later than twelve months after it closes unless a legal obligation requires otherwise.
Recipients and processors
Personal data is accessible to the consultants working on your file and to a small number of processors acting on our instruction: our hosting provider, our transactional email provider for the contact form, and our accounting and document management tools. Each is bound by a data processing agreement.
Where an engagement involves a partner in our network, we tell you beforehand and no personal data is shared without a signed agreement covering it.
Location and transfers
The website and mission data are hosted on infrastructure located in the European Union. Where a processor involves a transfer outside the European Economic Area, it is covered by an adequacy decision or by standard contractual clauses together with a transfer impact assessment, which we will provide on request.
Security
Access to personal data is limited to those who need it, protected by multi-factor authentication, and logged. Data is encrypted in transit and at rest. We apply to ourselves the practices we recommend, including regular testing and a documented incident response procedure.
Your rights
You may request access to your personal data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on our legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting what was lawful before.
Write to privacy@sectius.com. We may ask for proof of identity if there is genuine doubt. You also have the right to lodge a complaint with a supervisory authority, for us Commission nationale de l’informatique et des libertés (CNIL) (www.cnil.fr).
Changes
If this policy changes materially we will update the date above and, where the change affects data we already hold about you, tell you directly.