Privacy policy
Last updated: September 26, 2026.
This policy covers the developpia.fr website and the rdv.developpia.fr booking tool (called “Créno”), both published by DeveloppIA. The data controller is DeveloppIA, which can be reached at contact@developpia.fr. The publisher’s full contact details appear in the legal notice.
Three different situations, three different kinds of processing. Pick the one that applies to you.
1. You visit the developpia.fr website
The website does not set any advertising cookies. A technical marker is kept in your browser for the duration of your visit, solely so the opening animation does not play again: it contains no personal data and is never transmitted.
Audience measurement (Google Analytics 4). To know which pages are read and where visits come from, we use Google Analytics. It loads when the website’s pages open, except on the SEO test and booking pages. Google Analytics sets cookies (_ga, _ga_*, for 13 months at most) and receives the pages viewed, the length of the visit, the type of device and browser, and your IP address, which Google truncates before any storage. We do not enable advertising features or “Google signals”: this data is used for statistics only. You can opt out at any time with the button below: measurement then stops on this device.
Our host, Vercel, keeps technical logs (IP address, page requested, date) to ensure the service runs properly and securely. We do not use them for profiling.
2. You request a diagnostic or an appointment
When you fill in the booking form, we record the following information.
| Data | Why |
|---|---|
| First name, last name | To know who we are speaking with during the call |
| Phone number | To call you at the agreed time, or call you back if no time slot was chosen |
| Email address, if you provide it | To send you the confirmation, the video call link and the reminder before the call |
| Answers to the questions asked before the time slot | To prepare the call and check that our services fit your situation |
| Practice name and city | To analyze your search visibility from public sources before the call |
| Time zone, origin of the visit (advertising campaign) | To display the correct times, and to know which ad brought you to us |
| The course of the call and the call notes | To follow up commercially from one appointment to the next |
Legal basis: the performance of pre-contractual measures taken at your request (Article 6(1)(b) GDPR) for booking the appointment, and our legitimate interest in following up on our business exchanges (Article 6(1)(f)) for the call notes.
Retention period: three years from our last exchange, in line with the recommendation of the CNIL (the French data protection authority) on prospecting. After that period, the record is deleted. If you become a client, contract-related data is kept for the duration of the relationship and then for the statutory limitation period.
Search visibility analysis: to prepare the call, we look at public information about your practice (your website, your Google Business Profile, your position in search results). This is data that is already published, and we never supplement it by purchasing any data file.
3. You connect your Google Calendar to Créno
This section only concerns members of the DeveloppIA team who use Créno to manage their calendar. People who book an appointment never connect a Google account.
What Créno asks Google for
| Permission | What Créno does with it |
|---|---|
openid, email | Shows in the settings which Google address is connected, so you know which account you are signed in with |
calendar.freebusy | Reads your busy times, and only that, so it never offers a time slot when you are not available |
calendar.calendarlist.readonly | Lists your calendars to know which ones to check before offering a time slot |
calendar.events | Creates the appointment event and its Google Meet link in your primary calendar, moves it if it is rescheduled, deletes it if it is canceled |
What Créno does not do
- It does not read the content, title or attendees of your other events. From reading your calendar, it keeps only untitled “busy” time ranges.
- It does not touch any calendar other than your primary calendar. Shared calendars are read, never modified.
- It does not transfer your Google data to anyone, does not sell it, does not use it for advertising and does not use it to train an artificial intelligence model, whether ours or a third party’s.
- No human looks at it, unless you ask us for help with a specific problem, for security reasons, or if the law requires us to.
Limited use of Google data. Créno’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What is stored, and where
Créno stores your Google address, the list of your calendars and a connection token that lets it come back to read your availability without asking for your password again. Your Google password is never sent to us and we have no access to it.
Créno also keeps a snapshot of your busy times for the coming days, replaced after each successful read. Its only purpose is to keep blocking those times if Google temporarily stops responding, so that a slot already taken is not offered to someone else.
All of this is stored in our Supabase database, hosted in the West Europe (Paris) region. Exchanges are encrypted in transit and access to the database is restricted to the application server.
How to cut off access
- From Créno: Settings, then disconnect the calendar.
- From Google, at any time and without notifying us: myaccount.google.com/connections, choose Creno, then remove access.
In both cases, the connection token becomes unusable and we erase it. Events already created remain in your calendar: they belong to you.
4. The service providers involved
We do not sell or rent any data. We rely on the following providers, each for a specific function.
| Provider | Role | Where |
|---|---|---|
| Vercel Inc. | Hosting of the website and the application | United States, European Commission standard contractual clauses |
| Supabase | Database | European Union (Paris) |
| Google Ireland Ltd. | Calendar and Meet video calls; Google Analytics (audience measurement) | European Union, with safeguarded transfers |
| Resend | Sending confirmation and reminder emails | United States, standard contractual clauses |
| Slack | Internal team alerts when a booking is made | United States, standard contractual clauses |
5. Your rights
Regulation (EU) 2016/679 and the French Data Protection Act (loi Informatique et Libertés) give you the right to access, rectify, erase, restrict, object to and port your data, as well as the right to set instructions regarding what happens to it after your death.
To exercise these rights, write to contact@developpia.fr. We reply within one month. If you are not satisfied with the reply, you can lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris, France (cnil.fr).
6. Security
Access to the application is password-protected, exchanges take place over HTTPS, connection tokens are stored out of the browser’s reach and access to the database is limited to the server. No system is infallible: in the event of a data breach likely to expose you to a risk, we would inform you and notify the CNIL within the time limits set by the GDPR.
7. Changes
This policy may change if our tools change. The date of the last update appears at the top of the page. A significant change would be notified to you directly.
8. Contact us
For any question about your data: contact@developpia.fr.