Damitio Advisory ← Back to the site

Privacy

Privacy policy

This policy explains what personal data is processed when you visit damitioadvisory.com or get in touch, why, for how long, and what your rights are under the General Data Protection Regulation (GDPR) and the French loi Informatique et Libertés.

Who is responsible

The data controller is Charles-Thomas Damitio, trading as Damitio Advisory, Paris, France. For any question about this policy or your data, write to [email protected].

The short version

This site sets no cookies and uses no advertising trackers. Audience measurement is cookieless and aggregated. The only personal data I hold about you is what you choose to send me — by email, or by booking a call — and I use it solely to respond to you and, if we work together, to run the engagement.

What is processed, and why

SituationDataPurpose and legal basisRetention
Browsing the siteTechnical data handled by the host (IP address, user agent, pages requested) in server and security logsDelivering the site, security and abuse prevention — legitimate interestShort-term, per Cloudflare's log retention
Audience measurementAggregated, anonymous page-view statistics (Cloudflare Web Analytics — no cookie, no fingerprinting, no individual identification)Understanding how the site is used — legitimate interestAggregated only; no personal data retained
Emailing meYour name, email address, employer where given, and the content of your messageResponding to your request and, where relevant, preparing a proposal — pre-contractual steps and legitimate interestThree years after our last exchange, unless an engagement follows
Booking an intro callName, email address, and any details you enter in the booking form, processed through Google Calendar appointment schedulingOrganising the call — pre-contractual stepsSame as email correspondence
Working togetherContact and professional details, engagement documents and correspondencePerforming the contract; legal and accounting obligationsDuration of the engagement, then statutory retention periods (up to ten years for accounting records)

Who has access

Your data is not sold, rented or shared for marketing. It is accessible only to me and to the service providers needed to run the site and my correspondence, acting on my instructions:

Both providers may process data outside the European Economic Area. Transfers are covered by the European Commission's adequacy decision for the EU-US Data Privacy Framework and/or Standard Contractual Clauses, together with the providers' own security measures.

Cookies

This site does not set cookies or use local storage for tracking purposes. No consent banner is displayed because none is required. If a third-party booking widget is embedded in the future, its cookies will be subject to your prior consent and this policy will be updated.

Your rights

You may at any time ask for access to the personal data I hold about you, ask for it to be corrected or erased, object to or request the restriction of its processing, ask for its portability, and define directives on what happens to it after your death. Where processing is based on legitimate interest, you may object on grounds relating to your particular situation.

To exercise these rights, write to [email protected]. I will respond within one month. If you consider your rights have not been respected, you may lodge a complaint with the French supervisory authority, the CNIL (Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, 75007 Paris — www.cnil.fr).

Security

The site is served exclusively over HTTPS. Email and documents are held on professional Google Workspace accounts protected by two-factor authentication. Access is limited to what is needed for the purposes described above.

Changes to this policy

This policy may be updated to reflect changes in the site, in the services used, or in the law. The date below indicates the current version.

Last updated: September 2026.