Introduction
This Privacy Policy explains how ZAFER CESUR SARL ("we", "us", "our", or "Company") collects, uses, discloses, and protects your personal data when you visit our website zafercessur.fr and related services. We are committed to protecting your privacy and ensuring transparent data practices in compliance with applicable regulations including the EU General Data Protection Regulation (GDPR), the UK GDPR, and Canadian privacy laws including the Personal Information Protection and Electronic Documents Act (PIPEDA).
1. Data Controller Identity
The data controller responsible for your personal data is:
ZAFER CESUR SARL
15 Rue de Rivoli Escalier B, Appt 42
75004 Paris, France
For privacy-related inquiries, you may contact us at [email protected] with the subject line "Privacy Request".
2. Personal Data We Collect
We collect personal data in the following categories:
- Identity and Contact Data: Name, email address, phone number, job title, company name, and postal address provided through contact forms or direct communication.
- Form Content: Messages, project descriptions, security assessment details, and other information you submit through our contact or consultation request forms.
- Technical Data: Internet Protocol (IP) address, browser type and version, operating system, device type, language preferences, and device identifiers.
- Usage Data: Pages visited, time spent on each page, referral source, click paths, search queries, and interaction patterns with our website.
- Cookies and Tracking Identifiers: Cookie IDs, session tokens, conversion tracking identifiers, and similar tracking mechanisms as described in Section 4.
- Communication Records: Email correspondence, support tickets, and inquiry history.
We do not collect special-category personal data (such as racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification, health data, or data concerning sex life or sexual orientation) unless you explicitly provide it and we have obtained your explicit consent and established a legal basis for processing. We do not collect government-issued identification numbers, financial account details, or payment card information unless required for a specific contracted service.
3. Why We Process Your Data (Legal Basis)
Under the GDPR and UK GDPR, we process your personal data on the following lawful bases:
- Contract Performance (Article 6(1)(b)): Processing necessary to respond to your consultation request, provide cybersecurity services, and fulfill contractual obligations.
- Consent (Article 6(1)(a)): Processing analytics and marketing cookies based on your explicit, informed consent recorded via our cookie consent mechanism.
- Legitimate Interest (Article 6(1)(f)): Security, fraud prevention, infrastructure protection, website optimization, and business analytics where our interests do not override your rights.
- Legal Obligation (Article 6(1)(c)): Processing required by Canadian privacy law (PIPEDA), EU data protection regulations, or other applicable legal requirements.
Automated Decision-Making (Article 22): We do not engage in automated decision-making or algorithmic profiling that produces legal or similarly significant effects on you. Decisions regarding service eligibility, pricing, or risk assessment are made by qualified professionals in consultation with our team.
4. Cookies and Tracking Technologies
We use cookies, pixels, and similar tracking technologies to enhance your experience and gather analytics. Cookies are organized into three categories:
4.1 Essential Cookies (No Consent Required)
These cookies are necessary for the website to function and are always active:
- _site_session: Maintains your session state and user preferences. First-party. Retention: Session to 12 months.
- cookie_consent: Records your cookie consent choices. First-party. Retention: 12 months.
- CSRF tokens: Protect against cross-site request forgery attacks. First-party. Retention: Session.
4.2 Analytics Cookies (Consent Required)
These cookies measure how visitors use our site to improve performance and user experience. They are activated only upon your consent:
- _ga: Google Analytics 4 user identifier. Third-party. Retention: 2 years.
- _ga_XXXXXXXXXX: GA4 session state (10-character GA4 property ID). Third-party. Retention: 2 years.
- Analytics Provider: Google LLC. IP addresses are anonymized. Data retention: 14 months. Privacy policy: policies.google.com/privacy.
4.3 Marketing Cookies (Consent Required)
These cookies enable personalized advertising, conversion tracking, and audience targeting across platforms. They are activated only upon your consent:
- _gcl_au: Google Ads conversion linker. Third-party. Retention: 90 days.
- _fbp: Meta Pixel browser identifier for cross-site tracking and audience building. Third-party. Retention: 90 days.
- _fbc: Meta Pixel click identifier (set when a click ID is provided). Third-party. Retention: 90 days.
- Providers: Google LLC and Meta Platforms, Inc. These providers use cookies for remarketing, custom audience creation, and lookalike audience generation.
4.4 Server-Side and Advanced Tracking
Beyond cookies, we may use server-side tracking, pixel tags (web beacons), and conversion APIs to measure campaign performance. Meta Conversion API and Google Server-Side GTM may receive hashed identifiers, event data, and conversion information for attribution and audience segmentation.
5. Consent (EEA, UK, and Canadian Residents)
For EU and UK Residents: Under the GDPR and UK GDPR (Article 6(1)(a)), we obtain your explicit, informed, freely given, and specific consent before activating analytics or marketing cookies. Consent is recorded in the cookie_consent browser cookie with a retention period of 12 months. You may withdraw or modify your consent at any time by clicking "Manage Preferences" in the cookie banner or footer. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
For Canadian Residents: We comply with PIPEDA requirements for collection, use, and disclosure. Marketing and analytics cookies require your affirmative consent. You may opt out at any time.
6. Data Sharing and Third-Party Service Providers
We share personal data with the following third-party service providers, who act as data processors or joint controllers:
6.1 Google LLC (Analytics, Ads, Tag Manager)
- Services: Google Analytics 4 (usage analytics), Google Ads (conversion tracking and remarketing), Google Tag Manager (tag deployment).
- Data Shared: Cookie IDs, page views, events, user interactions, conversion data, remarketing lists.
- Purpose: Measure campaign performance, optimize ads, understand user behavior, build custom and lookalike audiences.
- Privacy Policy: policies.google.com/privacy
- Data Processing Agreement: Google LLC is certified under the EU-US Data Privacy Framework and UK Extension.
6.2 Meta Platforms, Inc. (Pixel, Custom Audiences, Conversion API)
- Services: Meta Pixel (conversion tracking), Custom Audience targeting, Meta Conversion API.
- Data Shared: Cookie IDs, browser identifiers, event data, hashed user identifiers (email, phone), conversion information, audience membership.
- Purpose: Measure ad performance, create custom audiences, build lookalike audiences, retarget visitors.
- Privacy Policy: facebook.com/privacy/policy
- Data Processing Agreement: Meta is certified under the EU-US Data Privacy Framework and UK Extension.
6.3 Cloudflare, Inc. (CDN and Security)
- Services: Content delivery, DDoS protection, Web Application Firewall.
- Data Shared: IP addresses, request metadata, threat signals.
- Purpose: Site performance, security, and abuse prevention.
- Privacy Policy: cloudflare.com/privacypolicy/
Data Sale Restriction: We do not sell personal data as defined by privacy regulations. These providers may not use site data for their own independent commercial purposes beyond fulfilling contracted services.
7. International Data Transfers
Your personal data may be transferred outside the European Economic Area (EEA) and United Kingdom, including to Canada and the United States, where Google LLC, Meta Platforms, and other service providers process data. These transfers are protected by:
- EU-US Data Privacy Framework (DPF): Primary mechanism for transfers from the EU to the US (effective July 10, 2023). Google LLC and Meta Platforms are certified participants.
- UK Extension to the UK-US DPF: Covers transfers from the UK.
- Swiss-US DPF: Covers transfers from Switzerland (if applicable).
- Standard Contractual Clauses (SCCs): EU 2021/914 and UK International Data Transfer Agreement (IDTA) as fallback mechanisms.
- Adequacy Decisions: Canada is recognized by the EU as having an adequate level of data protection for certain transfers.
By submitting data through our website, you acknowledge these transfers and the legal mechanisms protecting them.
8. Data Retention
We retain personal data only as long as necessary:
- Contact Form Submissions: 2 years from last interaction (for follow-up and dispute resolution).
- Analytics Data: 14 months (Google Analytics default retention).
- Marketing Cookies: Per cookie lifetime (30–90 days typically).
- Email Correspondence: Duration of relationship plus 1 year after final contact.
- Server Logs: 90 days.
- Cookie Consent Records: 3 years (for audit and compliance documentation).
- Legal and Tax Records: Per applicable law (typically 6–10 years for business records and invoices).
Upon request and after identity verification, we will delete your personal data, subject to legal retention obligations.
9. Your Rights Under GDPR and UK GDPR
If you are a resident of the EEA or UK, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data we hold.
- Right to Rectification (Article 16): Correct inaccurate or incomplete data.
- Right to Erasure (Article 17): Request deletion ("right to be forgotten") in certain circumstances.
- Right to Restrict Processing (Article 18): Request limitation of how we use your data.
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to Object (Article 21): Opt out of marketing communications and certain processing.
- Right to Withdraw Consent (Article 7(3)): Withdraw consent for cookies and targeted marketing at any time.
- Right to Lodge a Complaint: File a complaint with your local supervisory authority.
To exercise these rights, email [email protected] with the subject "Data Subject Rights Request" and specify which right you wish to exercise. We will respond within 30 days (extendable by 60 days for complex requests) and may request identity verification.
Supervisory Authorities:
- European Union (general): European Data Protection Board (edpb.europa.eu)
- United Kingdom: Information Commissioner's Office (ico.org.uk)
- Germany: Federal Data Protection Officer (bfdi.bund.de)
- France: Commission Nationale Informatique et Libertés (cnil.fr)
10. Canadian Privacy Rights (PIPEDA)
If you are a Canadian resident, PIPEDA grants you the right to:
- Request access to personal data we hold about you.
- Request correction of inaccurate information.
- Request deletion of personal data in certain circumstances.
- Opt out of marketing and promotional communications.
- Request information about how your data is used and who it is shared with.
Submit requests to [email protected]. We will respond within 30 days and may request identity verification.
11. US State Privacy Laws (CCPA / CPRA, VCDPA, NVDA)
California (CCPA / CPRA): If you are a California resident, you have the right to know what data we collect, to delete it, to opt out of sale or sharing, and to correct inaccurate information. We do not sell personal data as defined by CCPA. We do engage in cross-context behavioral advertising, and you may opt out via our cookie preferences panel. Submit requests to [email protected] with subject "California Privacy Request". Authorized agents may submit with written proof of authority. We do not discriminate based on privacy requests.
Virginia (VCDPA): Virginia residents may request access, correction, deletion, data portability, and opt-out of targeted advertising. Submit via [email protected] with subject "Virginia Privacy Request". We will respond within 45 days. Appeals of refusals may be submitted; unresolved appeals are referred to the Virginia Attorney General.
Nevada (NVDA): Nevada residents may opt out of the sale of personal information. While we do not currently sell personal information under Nevada law, you may submit an opt-out preference by emailing [email protected] with subject "Nevada Do Not Sell Request".
12. Children and Minors
This website is not directed at individuals under 16 years of age. We do not knowingly collect personal data from minors. If we discover that we have collected data from a child under 16 without verifiable parental consent, we will delete it promptly. Parents or guardians who believe their child's data has been collected should contact us immediately at [email protected].
13. Do Not Track (DNT) Signals
This website does not currently respond to "Do Not Track" (DNT) browser signals due to lack of industry-wide standardization. Third-party service providers (Google, Meta, Cloudflare) have their own DNT policies. You may adjust your browser or device settings to limit tracking, or use our cookie preferences to disable analytics and marketing cookies.
14. Account and Data Deletion
To request permanent deletion of your personal data, email [email protected] with subject "Data Deletion Request". We will verify your identity and process the request within 30 days, subject to legal retention obligations and ongoing service contracts.
15. Business Transfers
If ZAFER CESUR SARL undergoes a merger, acquisition, asset sale, bankruptcy, financing, or other business transaction, your personal data may be transferred as part of that transaction. We will notify affected individuals via a prominent notice on our website if such transfer materially changes the purposes or recipients of data processing. Your continued use of the website following such notification constitutes acceptance of the updated practices.
16. Security
We implement industry-standard technical, administrative, and physical safeguards to protect personal data against unauthorized access, alteration, and destruction, including encryption (TLS/SSL), access controls, and regular security assessments. However, no method of transmission or storage is 100% secure. You acknowledge the inherent risks of online communication and consent to assume these risks.
17. Policy Changes
We may update this Privacy Policy at any time. Material changes will be announced via a prominent notice on our website at least 14 days before the change takes effect. Your continued use of the website following such notice constitutes acceptance of the updated policy. The "Last Updated" date at the top of this page reflects the most recent revision.
18. Contact Us
For privacy questions, data subject requests, or complaints, contact us at:
ZAFER CESUR SARL
15 Rue de Rivoli Escalier B, Appt 42
75004 Paris, France