Privacy policy

Last updated: September 26, 2026.

This policy covers the developpia.fr website and the rdv.developpia.fr booking tool (called “Créno”), both published by DeveloppIA. The data controller is DeveloppIA, which can be reached at contact@developpia.fr. The publisher’s full contact details appear in the legal notice.

Three different situations, three different kinds of processing. Pick the one that applies to you.

1. You visit the developpia.fr website

The website does not set any advertising cookies. A technical marker is kept in your browser for the duration of your visit, solely so the opening animation does not play again: it contains no personal data and is never transmitted.

Audience measurement (Google Analytics 4). To know which pages are read and where visits come from, we use Google Analytics. It loads when the website’s pages open, except on the SEO test and booking pages. Google Analytics sets cookies (_ga, _ga_*, for 13 months at most) and receives the pages viewed, the length of the visit, the type of device and browser, and your IP address, which Google truncates before any storage. We do not enable advertising features or “Google signals”: this data is used for statistics only. You can opt out at any time with the button below: measurement then stops on this device.

Our host, Vercel, keeps technical logs (IP address, page requested, date) to ensure the service runs properly and securely. We do not use them for profiling.

2. You request a diagnostic or an appointment

When you fill in the booking form, we record the following information.

DataWhy
First name, last nameTo know who we are speaking with during the call
Phone numberTo call you at the agreed time, or call you back if no time slot was chosen
Email address, if you provide itTo send you the confirmation, the video call link and the reminder before the call
Answers to the questions asked before the time slotTo prepare the call and check that our services fit your situation
Practice name and cityTo analyze your search visibility from public sources before the call
Time zone, origin of the visit (advertising campaign)To display the correct times, and to know which ad brought you to us
The course of the call and the call notesTo follow up commercially from one appointment to the next

Legal basis: the performance of pre-contractual measures taken at your request (Article 6(1)(b) GDPR) for booking the appointment, and our legitimate interest in following up on our business exchanges (Article 6(1)(f)) for the call notes.

Retention period: three years from our last exchange, in line with the recommendation of the CNIL (the French data protection authority) on prospecting. After that period, the record is deleted. If you become a client, contract-related data is kept for the duration of the relationship and then for the statutory limitation period.

Search visibility analysis: to prepare the call, we look at public information about your practice (your website, your Google Business Profile, your position in search results). This is data that is already published, and we never supplement it by purchasing any data file.

3. You connect your Google Calendar to Créno

This section only concerns members of the DeveloppIA team who use Créno to manage their calendar. People who book an appointment never connect a Google account.

What Créno asks Google for

PermissionWhat Créno does with it
openid, emailShows in the settings which Google address is connected, so you know which account you are signed in with
calendar.freebusyReads your busy times, and only that, so it never offers a time slot when you are not available
calendar.calendarlist.readonlyLists your calendars to know which ones to check before offering a time slot
calendar.eventsCreates the appointment event and its Google Meet link in your primary calendar, moves it if it is rescheduled, deletes it if it is canceled

What Créno does not do

Limited use of Google data. Créno’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

What is stored, and where

Créno stores your Google address, the list of your calendars and a connection token that lets it come back to read your availability without asking for your password again. Your Google password is never sent to us and we have no access to it.

Créno also keeps a snapshot of your busy times for the coming days, replaced after each successful read. Its only purpose is to keep blocking those times if Google temporarily stops responding, so that a slot already taken is not offered to someone else.

All of this is stored in our Supabase database, hosted in the West Europe (Paris) region. Exchanges are encrypted in transit and access to the database is restricted to the application server.

How to cut off access

In both cases, the connection token becomes unusable and we erase it. Events already created remain in your calendar: they belong to you.

4. The service providers involved

We do not sell or rent any data. We rely on the following providers, each for a specific function.

ProviderRoleWhere
Vercel Inc.Hosting of the website and the applicationUnited States, European Commission standard contractual clauses
SupabaseDatabaseEuropean Union (Paris)
Google Ireland Ltd.Calendar and Meet video calls; Google Analytics (audience measurement)European Union, with safeguarded transfers
ResendSending confirmation and reminder emailsUnited States, standard contractual clauses
SlackInternal team alerts when a booking is madeUnited States, standard contractual clauses

5. Your rights

Regulation (EU) 2016/679 and the French Data Protection Act (loi Informatique et Libertés) give you the right to access, rectify, erase, restrict, object to and port your data, as well as the right to set instructions regarding what happens to it after your death.

To exercise these rights, write to contact@developpia.fr. We reply within one month. If you are not satisfied with the reply, you can lodge a complaint with the CNIL, 3 place de Fontenoy, 75007 Paris, France (cnil.fr).

6. Security

Access to the application is password-protected, exchanges take place over HTTPS, connection tokens are stored out of the browser’s reach and access to the database is limited to the server. No system is infallible: in the event of a data breach likely to expose you to a risk, we would inform you and notify the CNIL within the time limits set by the GDPR.

7. Changes

This policy may change if our tools change. The date of the last update appears at the top of the page. A significant change would be notified to you directly.

8. Contact us

For any question about your data: contact@developpia.fr.