Privacy policy
This English translation is provided for convenience. In case of any discrepancy, the French version prevails.
Open Web Agency attaches great importance to the protection of your personal data. This policy explains what data is collected on this website, why, how long it is kept and how to exercise your rights. It is drawn up in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the French Data Protection Act (loi n° 78-17 du 6 janvier 1978, « Informatique et Libertés »).
1. Data controller
The controller of your data is Nassim Redjem EI, a sole trader (entrepreneur individuel) trading as Open Web Agency (SIRET 828 734 111 00036), registered at 4 avenue de Verdun, 06240 Beausoleil, France.
For any question about your personal data, you can contact us by email at contact@openwebagency.com.
2. Data collected and purposes
We only collect the data needed for each purpose, and only when you provide it yourself.
- “Free audit” form: first name, last name, work email, website address and industry. This data is used solely to carry out the audit you requested, to send you its results and to discuss it with you. Your request is stored in our database, hosted in the European Union, and sent to us by email. It is never sold or used for marketing without your consent.
- Email exchanges: the information you choose to send us, used to reply to you.
- Booking a meeting: when you book a slot, your name, your email and any information you add are sent to the Cal.com booking service in order to arrange the meeting.
- Technical data: when you visit, our hosting provider processes your IP address and information about your browser, solely to display the website and protect it against abuse and attacks.
The website does not currently use any audience measurement tool.
3. Legal bases
- Audit form and meeting bookings: your consent (Article 6(1)(a) GDPR), given by ticking the box provided and submitting the form. You may withdraw it at any time.
- Replies to your emails: pre-contractual measures taken at your request (Article 6(1)(b) GDPR).
- Technical data: our legitimate interest in keeping the website secure and working properly (Article 6(1)(f) GDPR).
- If you become a client: performance of the contract (Article 6(1)(b)) and compliance with our legal obligations, including accounting obligations (Article 6(1)(c)).
4. Recipients and processors
Your data is intended solely for Open Web Agency. It is never sold, rented or transferred to third parties.
We use technical service providers (processors within the meaning of the GDPR), who process your data only on our instructions and solely for the needs of the service:
- Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, United States): website hosting, protection against attacks, database of audit requests (hosted in the European Union) and sending of form notifications.
- Cal.com, Inc.: meeting booking service.
- Zoho Corporation B.V. (Netherlands): hosting of our mailbox (contact@openwebagency.com), in its European data centres.
5. Transfers outside the European Union
Some of our providers are based in the United States. These transfers are covered by the safeguards provided for by the GDPR: the European Commission’s adequacy decision (EU–US Data Privacy Framework) where the provider is certified under it, or the standard contractual clauses adopted by the European Commission.
6. Retention periods
- Audit and meeting requests and exchanges with prospects: 3 years from our last exchange, then automatic deletion. If you withdraw your consent or ask for erasure before then, your data is deleted without delay.
- Client data: for the whole contractual relationship, then 5 years for evidential purposes (Article 2224 of the French Civil Code). Accounting records are kept for 10 years (Article L123-22 of the French Commercial Code).
- Requests to exercise your rights: 1 year, so that we can show how we responded.
- Technical connection data: a limited period set by our hosting provider for security purposes.
7. Your rights
Under the GDPR and the French Data Protection Act, you have the following rights over your data:
- right of access (Article 15 GDPR);
- right to rectification (Article 16);
- right to erasure (Article 17);
- right to restriction of processing (Article 18);
- right to data portability (Article 20);
- right to object (Article 21);
- right to withdraw your consent at any time, without affecting processing already carried out (Article 7(3));
- right to set instructions regarding what happens to your data after your death (Article 85 of the French Data Protection Act).
To exercise these rights, contact us by email at contact@openwebagency.com. We will reply within one month, which may be extended by two months for complex requests (Article 12(3) GDPR). If we have reasonable doubts about your identity, we may ask you for proof of identity.
If, after contacting us, you believe your rights have not been respected, you can lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online at cnil.fr.
9. Security
We implement appropriate technical and organisational measures to protect your data: encrypted connection (HTTPS) across the whole website, a strict content security policy, and access to data limited to the people handling your request.
10. Changes to this policy
This policy may change, in particular when a new service is added. The version in force is always the one published on this page. Last updated: 30 September 2026.