Privacy policy.
In accordance with Regulation (EU) 2016/679 (GDPR) and the amended French Data Protection Act, this page explains how your personal data is collected and processed on tmgconseil
Data controller
TMG CONSEIL - SASU with share capital of €500 - SIREN 924 986 946 - registered office: 1400 Rue de la Castelle, 34070 Montpellier - contact address: bonjour@
Data collected and purposes
Contact form
When you complete the form on the Get in touch (or email us at bonjour@
- Your first and last name, email address and any information you voluntarily provide in your message.
- Purpose : to answer your enquiry and, where applicable, formalise a consulting engagement.
- Legal basis : legitimate interests under Article 6(1)(f) GDPR and, where applicable, pre-contractual steps taken at your request under Article 6(1)(b) GDPR.
- Retention period : 3 years from the last exchange if no contractual relationship is established. Records required for a contracted engagement are retained in accordance with applicable legal and accounting obligations.
Audience measurement
The website uses Plausible
- No cookie is placed on your device.
- No IP address is stored and no persistent identifier or fingerprint is generated.
- Statistics are aggregated and anonymous: page views, referral source, device type and country.
- Purpose : understand the audience and improve the website.
- Legal basis : legitimate interests under Article 6(1)(f) GDPR. Because the system is anonymous, prior consent is not required under CNIL guidance on exempt audience measurement solutions.
Technical server logs
To ensure website availability, security and maintenance, the server records technical logs containing the IP address, user agent (browser and operating system) and timestamp of HTTP requests.
- Purpose : information system security, abuse prevention and troubleshooting.
- Legal basis : legitimate interests under Article 6(1)(f) GDPR.
- Retention period : 30 days, followed by deletion or anonymisation.
Recipients, tools and processors
Your personal data is never transferred, rented or sold. It may be processed by the following tools and processors, selected for their data protection safeguards:
| Processor | Role | Location |
|---|---|---|
| Pulse SARL | Website hosting and server logs | France |
| Plausible | Anonymous audience measurement | Estonia (EU) |
| Google | Business email (Google Workspace) for receiving contact emails | Ireland (EU) |
| Self-hosted Cal.diy instance | Appointment booking, availability and confirmation page | France |
| Internal PostgreSQL, Redis and Mailpit | Technical appointment storage, application cache and email deliverability testing | France |
Transfers outside the European Union
The tools listed above are selected to limit transfers outside the European Union. Where a provider may process certain data outside the EU, that processing must remain covered by the contractual safeguards required by the GDPR.
Your rights
Under Articles 15 to 22 GDPR, you may exercise the following rights over your personal data at any time:
- Right of access, rectification and erasure;
- Right to restrict processing and right to object;
- Right to data portability;
- Right to define instructions regarding your data after your death.
To exercise these rights, email bonjour@
You also have the right to lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL) - 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 - cnil
Cookies and storage
The website's static pages tmgconseil
Security
The website is served exclusively over HTTPS with TLS encryption. Static pages use a restrictive Content Security Policy (CSP), with HSTS, X-Content-Type-Options and Referrer-Policy headers enabled. Any backups are encrypted and stored on infrastructure located in the European Union.
Updates to this policy
This policy may be updated at any time to reflect changes in the tools used or the regulatory framework. Any material update will be indicated on this page.