Skip to content
Open Web, back to home

Privacy policy

This English translation is provided for convenience. In case of any discrepancy, the French version prevails.

Open Web Agency attaches great importance to the protection of your personal data. This policy explains what data is collected on this website, why, how long it is kept and how to exercise your rights. It is drawn up in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the French Data Protection Act (loi n° 78-17 du 6 janvier 1978, « Informatique et Libertés »).

1. Data controller

The controller of your data is Nassim Redjem EI, a sole trader (entrepreneur individuel) trading as Open Web Agency (SIRET 828 734 111 00036), registered at 4 avenue de Verdun, 06240 Beausoleil, France.

For any question about your personal data, you can contact us by email at contact@openwebagency.com.

2. Data collected and purposes

We only collect the data needed for each purpose, and only when you provide it yourself.

  • “Free audit” form: first name, last name, work email, website address and industry. This data is used solely to carry out the audit you requested, to send you its results and to discuss it with you. Your request is stored in our database, hosted in the European Union, and sent to us by email. It is never sold or used for marketing without your consent.
  • Email exchanges: the information you choose to send us, used to reply to you.
  • Booking a meeting: when you book a slot, your name, your email and any information you add are sent to the Cal.com booking service in order to arrange the meeting.
  • Technical data: when you visit, our hosting provider processes your IP address and information about your browser, solely to display the website and protect it against abuse and attacks.

The website does not currently use any audience measurement tool.

4. Recipients and processors

Your data is intended solely for Open Web Agency. It is never sold, rented or transferred to third parties.

We use technical service providers (processors within the meaning of the GDPR), who process your data only on our instructions and solely for the needs of the service:

  • Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, United States): website hosting, protection against attacks, database of audit requests (hosted in the European Union) and sending of form notifications.
  • Cal.com, Inc.: meeting booking service.
  • Zoho Corporation B.V. (Netherlands): hosting of our mailbox (contact@openwebagency.com), in its European data centres.

5. Transfers outside the European Union

Some of our providers are based in the United States. These transfers are covered by the safeguards provided for by the GDPR: the European Commission’s adequacy decision (EU–US Data Privacy Framework) where the provider is certified under it, or the standard contractual clauses adopted by the European Commission.

6. Retention periods

  • Audit and meeting requests and exchanges with prospects: 3 years from our last exchange, then automatic deletion. If you withdraw your consent or ask for erasure before then, your data is deleted without delay.
  • Client data: for the whole contractual relationship, then 5 years for evidential purposes (Article 2224 of the French Civil Code). Accounting records are kept for 10 years (Article L123-22 of the French Commercial Code).
  • Requests to exercise your rights: 1 year, so that we can show how we responded.
  • Technical connection data: a limited period set by our hosting provider for security purposes.

7. Your rights

Under the GDPR and the French Data Protection Act, you have the following rights over your data:

  • right of access (Article 15 GDPR);
  • right to rectification (Article 16);
  • right to erasure (Article 17);
  • right to restriction of processing (Article 18);
  • right to data portability (Article 20);
  • right to object (Article 21);
  • right to withdraw your consent at any time, without affecting processing already carried out (Article 7(3));
  • right to set instructions regarding what happens to your data after your death (Article 85 of the French Data Protection Act).

To exercise these rights, contact us by email at contact@openwebagency.com. We will reply within one month, which may be extended by two months for complex requests (Article 12(3) GDPR). If we have reasonable doubts about your identity, we may ask you for proof of identity.

If, after contacting us, you believe your rights have not been respected, you can lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online at cnil.fr.

8. Cookies and other trackers

Under Article 82 of the French Data Protection Act and the CNIL guidelines (deliberation no. 2020‑091 of 17 September 2020), consent is required before any tracker that is not essential to the website’s operation is stored.

Open Web Agency does not set any advertising cookies, audience measurement cookies or social media trackers. This is why no consent banner appears when you arrive: there is nothing to accept or refuse.

The website uses a single technical storage item, exempt from consent because it is strictly necessary for the service you request:

  • ow-gpu-tier (browser local storage): remembers your device’s graphics performance level, so that the 3D scenery is displayed at the right quality without measuring it again on every visit. It stays on your device, is never transmitted and expires after 7 days.

You can delete it at any time by clearing this website’s data in your browser settings; the website will simply measure your device’s capabilities again.

Links to third-party websites (cited sources, external services) take you away from our website: those websites apply their own cookie policies.

Should we ever add a tool that requires consent, a module allowing you to accept or refuse, as easily as each other, will be put in place before anything is stored, and this policy will be updated.

9. Security

We implement appropriate technical and organisational measures to protect your data: encrypted connection (HTTPS) across the whole website, a strict content security policy, and access to data limited to the people handling your request.

10. Changes to this policy

This policy may change, in particular when a new service is added. The version in force is always the one published on this page. Last updated: 30 September 2026.