Privacy Policy

Last updated: 2026-02-12

Calyo Consulting respects your privacy. This page explains what data we collect, why, and how we process it.

Controller

Calyo Consulting has not appointed a Data Protection Officer (DPO). For any question regarding your personal data, contact: [email protected]

Data we collect

Registered users (Calyo One)

  • Account information: name, email, company name
  • Subscription data: plan, dates, status
  • Payment data: managed by Stripe (we do not store card numbers)
  • Usage data: activated modules, logins

Prospects (interactive tools)

  • Contact information: first name, last name, email, phone, company
  • Scores and results from assessment tools
  • Personal data (name, phone, company) is encrypted using AES-256-GCM in the database. Only the email address is stored in plain text for correspondence purposes.

Website visitors

  • Technical data (IP address, visited pages, user agent) for security purposes
  • Analytics cookies (Google Analytics): subject to your consent. You can accept or decline via the cookie banner displayed on your first visit. If declined, no analytics data is collected.
PurposeLegal basis
Managing your Calyo One accountContract performance
Processing paymentsContract performance
B2B prospecting (interactive tools)Legitimate interests
Security and fraud preventionLegitimate interests
Analytics (GA4)Consent
Administrative audit logLegitimate interests

Retention

DataDuration
User accountsUntil account deletion
Payment data (Stripe)Per legal obligations (10 years accounting)
Leads (tool prospects)24 months after collection (automatic deletion)
Tool usage quotas24 months after last use
Audit logs (IP)90 days (IP automatically masked after)
Technical logsUp to 12 months
Deletion tokens24 hours

Processors and transfers

ProcessorUsageLocationSafeguards
StripeOnline paymentsUSAEU-US Data Privacy Framework, PCI DSS
Google AnalyticsStatistics (if accepted)USAEU-US Data Privacy Framework, IP anonymized
Authentik (self-hosted)Authentication, MFAFrance (dedicated server)No transfer outside EU
MinIO (self-hosted)File storageFrance (dedicated server)No transfer outside EU
Redis (self-hosted)Cache and sessionsFrance (dedicated server)No transfer outside EU
Maddy (self-hosted)Transactional email serverFrance (dedicated server)No transfer outside EU
Gotenberg (self-hosted)PDF document generationFrance (dedicated server)No transfer outside EU
PostgreSQL (self-hosted)DatabaseFrance (dedicated server)No transfer outside EU

Self-hosted components run on our dedicated servers in France. No data is transferred outside the EU except to Stripe and Google Analytics (if accepted), both covered by the EU-US Data Privacy Framework.

Your rights

Under the GDPR, you have the following rights:

  • Access: obtain a copy of your data
  • Rectification: correct inaccurate data
  • Erasure: delete your account and data
  • Restriction: restrict processing
  • Objection: object to processing
  • Portability: receive your data in a structured format

Automated exercise of your rights

If you have a Calyo One account, you can exercise your rights directly from your My Account page:

  • Export my data: download all your data (profile, subscriptions, payments, modules) in JSON format
  • Delete my account: request account deletion. A confirmation email will be sent. After confirmation, your account and all associated data will be permanently deleted.

Note: deleting your account does not delete prospecting data (leads) associated with your email, which is retained under our legitimate interest for 24 months.

For any other request: contact us at [email protected] with the subject of your request. You may also file a complaint with the competent supervisory authority (CNIL in France: www.cnil.fr).

Cookies

CookiePurposeDurationConsent
calyo_sessionUser session (HttpOnly)SessionNot required (essential)
calyo_logged_inLogin indicator (UI)7 daysNot required (essential)
calyo_cookie_consentCookie choice1 yearNot required (preference)
calyo_verified_leadTool email verification marker (email only)30 daysNot required (functional)
Google Analytics (_ga, _ga_*)Statistics14 monthsRequired (banner)

Local storage (localStorage)

KeyPurposeDuration
themeLight/dark theme preferencePermanent (clearable by user)
calyo_cookie_consentCookie choice backupPermanent (clearable by user)

This data stays on your device only and is never sent to our servers.

Security

We implement technical and organizational measures to protect your data:

  • AES-256-GCM encryption of sensitive personal data
  • Mandatory multi-factor authentication (MFA)
  • JWT sessions signed with HMAC-SHA256, HttpOnly/Secure/SameSite cookies
  • Rate limiting on authentication endpoints
  • SHA-256 hashing of sensitive tokens (recovery, deletion)
  • Automatic IP masking in audit logs after 90 days

Updates

We may update this policy. Last update: 2026-02-12