Privacy Policy

Last updated: July 26, 2026

1. Data Controller

The data controller is Sébastien COGET, contactable at contact@sebastien-coget.fr.

2. Data Collected

We process the following data:

  • Contact-form submissions (name, email, subject, message) — transmitted to Brevo to send you a notification email. They are not stored in our database. You can unsubscribe from further notifications at any time via the unsubscribe link included in every email.
  • Chat conversations with the digital twin — stored in our Payload CMS.
  • Cloudflare Turnstile cf_clearance cookie for bot protection — set by Cloudflare.
  • localStorage keys theme and digital-twin-chat-id — stored only in your browser.
  • Self-hosted Plausible analytics — page URL, referrer, anonymized browser/operating-system/device type, approximate country (IP address is dropped after the geographic lookup, not stored), and your web-vitals metrics (LCP, CLS, INP). No cookies, no localStorage, no persistent identifiers, no fingerprinting. Events are stored on our own infrastructure (analytics.sebastien-coget.fr).
  • Server-side Glitchtip error tracking — error message, stack trace, URL, user-agent, and the server's IP address when an exception occurs. Emails and phone numbers appearing in event breadcrumbs are automatically replaced with [email] and [phone] before being sent. No cookies are set in your browser (the error-tracking SDK is initialized server-side only). Events are stored on our own infrastructure (errors.sebastien-coget.fr).

3. Purposes

Contact forms: to respond to your inquiry (Art. 6(1)(b) contract / pre-contractual measures). Chat: to provide the digital-twin service (Art. 6(1)(f) legitimate interest). Turnstile: bot protection (Art. 6(1)(f) legitimate interest, CNIL strictly-necessary exemption). Analytics: aggregated, cookie-less audience measurement (Art. 6(1)(f) legitimate interest). Error tracking: diagnose and fix production issues (Art. 6(1)(f) legitimate interest).

4. Recipients

Email submissions are sent via Brevo (data processor, EU-based). Cloudflare processes Turnstile events globally. Plausible and Glitchtip are self-hosted on our own infrastructure (analytics.sebastien-coget.fr and errors.sebastien-coget.fr) and act as our data processors. We share data with no other third parties.

5. Retention

Contact-form submissions are not stored in our database. Chat sessions: persisted to Payload CMS until you clear them via the digital-twin-chat-id localStorage key. Plausible events: retained for up to 24 months in our self-hosted ClickHouse (aggregated statistics beyond that). Glitchtip events: retained for up to 90 days in our self-hosted Postgres.

6. Your Rights

You have the right to access, rectify, erase, restrict processing, object, and port your personal data. To exercise any right, email contact@sebastien-coget.fr. You may also lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés, www.cnil.fr).

7. Cookies and localStorage

We use the following:

  • cf_clearance (Cloudflare Turnstile, strictly necessary, set by Cloudflare for the duration of your visit, typically ~30 minutes, exempt from consent per CNIL).
  • localStorage theme (your light/dark preference, no third party).
  • localStorage digital-twin-chat-id (UUID, no third party).

No cookies are set for analytics or error tracking. Plausible is cookie-less by design, and the Glitchtip SDK is initialized server-side only (no client SDK in the browser, so no sentry-sid or sentry-ssid cookies are ever set). No advertising cookies, no third-party tracking.