DATA PROTECTION
Privacy Policy
Last updated: April 20, 2026
This policy describes how IM Consulting processes personal data collected through the im-consulting.frwebsite, in compliance with the General Data Protection Regulation (EU Regulation 2016/679, "GDPR") and the French Data Protection Act of 6 January 1978, as amended.
Data controller
The data controller is Mickaël Ilic, operating under the brand IM Consulting.
Contact: contact@im-consulting.fr
Processing purposes
Your data is collected and processed for the following purposes:
- Contact form and diagnostic request handling: responding to your business inquiries or qualifying a project.
- Client engagement management: performing contractual services, invoicing, reporting.
- Audience measurement: analyzing website traffic via Google Analytics 4 with IP anonymization.
Legal basis
- Consent (art. 6-1-a GDPR) for audience measurement cookies (Google Analytics 4).
- Legitimate interest (art. 6-1-f GDPR) for processing inbound business requests (contact form and diagnostic).
- Contractual performance (art. 6-1-b GDPR) for the management of ongoing client engagements.
Data collected
Depending on the context, we may collect:
- Identification data: first name, last name, professional email, phone, company.
- Content of exchanges: messages submitted via the contact form or by email.
- Technical and audience data: technical cookies (authentication session), analytics cookies (GA4 with anonymized IP).
Retention periods
- Prospects: 3 years from the last contact.
- Clients: 5 years after the end of the engagement (tax and accounting obligations).
- Analytics cookies: 13 months maximum, in line with CNIL (French DPA) guidelines.
- Invoicing data: 10 years (article L123-22 of the French Commercial Code).
Recipients
Your data is handled exclusively by Mickaël Ilic. Technical sub-processors may be involved, subject to strict contractual terms:
- Vercel Inc. (website hosting — USA).
- Google LLC (Google Analytics 4 — USA).
- Supabase Inc. (database for the authenticated client area — European Union).
No data is sold or transferred to third parties for commercial purposes.
Transfers outside the EU
Some sub-processors (Vercel, Google) are located in the United States. These transfers are framed by:
- The Standard Contractual Clauses (SCCs) adopted by the European Commission.
- The EU-US Data Privacy Framework (adequacy decision validated by the European Commission in July 2023).
Your rights
Under the GDPR, you have the following rights over your data:
- Right of access and communication.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten").
- Right to data portability.
- Right to object and to restrict processing.
- Right to withdraw consent at any time.
- Right to set directives regarding the fate of your data after your death.
To exercise these rights, contact us at contact@im-consulting.fr. If our response is not satisfactory, you may lodge a complaint with the CNIL (cnil.fr), the French data protection authority.
Cookies
The website uses the following cookies:
- Technical cookies(NextAuth authentication session): essential to the website's operation, exempt from consent.
- Analytics cookies (Google Analytics 4): retained for 13 months maximum, subject to your consent via the banner displayed on your first visit.
No third-party advertising tracking cookie is set. You can withdraw your consent at any time from the banner or your browser settings.
Security
We implement appropriate technical and organizational measures to protect your data against loss, disclosure or unauthorized access (HTTPS encryption, strong authentication, access logs).
Applicable law
This policy is governed by French law and European Union law.