Privacy

Privacy and data protection policy

Transparency about your data, cookies and your rights.

Last updated: August 2026

1. Preamble and sovereignty commitment

COOKIEFORT (Simplified joint-stock company with share capital of €5,000, registered with the Paris Trade and Companies Register under number 107 807 554, registered office at 5 rue de la Terrasse, 75017 Paris, France) is committed to protecting your privacy and the security of your personal data when you use the website cookiefort.com, our SaaS platform and our related communications.

This policy describes how we collect, use, store and protect your data, in compliance with the General Data Protection Regulation (GDPR) and applicable French data protection law.

Extraterritorial immunity commitment (US Cloud Act / FISA 702)

CookieFort has designed its infrastructure and contractual framework to limit exposure to extraterritorial requests under United States law, including the CLOUD Act and Section 702 of the Foreign Intelligence Surveillance Act (FISA 702).

  • Data sovereignty: production data is hosted within the European Union and/or Switzerland with Infomaniak Network SA, without reliance on US hyperscale cloud providers for the storage of personal data processed on behalf of our customers.
  • No transfer to the United States: we do not intentionally transfer personal data to the United States for hosting or primary processing. Where a sub-processor is established outside the EEA, we apply appropriate safeguards in accordance with Chapter V of the GDPR.

2. Data controller and DPO

The data controller for processing described in this policy is:

  • Organisation: COOKIEFORT SAS
  • SIREN: 107 807 554
  • Registered office: 5 rue de la Terrasse, 75017 Paris, France
  • Legal representative: Mr Khaled Hamadmad, President
  • Data Protection Officer (DPO) contact: cmp@cookiefort.com

3. Processing activities

The table below summarises the main processing activities carried out by CookieFort, the categories of data concerned, the legal basis and retention periods.

PurposeDataLegal basisRetention
Contact or demo requestFirst name, last name, professional email, company, URL, messageLegitimate interest (prospects)3 years from last contact
SaaS account and subscription managementHashed identifiers, email, billing data, logsPerformance of a contractDuration of the contract + 10 years (accounting records)
Payments and invoicingCard data via Stripe, billing address, transactionsPerformance of a contractCommercial relationship + 10 years
Newsletter and communicationsProfessional email, first name, last name, statusB2B legitimate interest / ConsentUntil unsubscribe or 3 years without interaction
Security and fraud preventionTruncated IP addresses, logs, User-AgentLegitimate interest6 rolling months maximum
Sovereign audience measurementAnonymous local session identifierLegitimate interest / CNIL exemption25 months (anonymised statistics)

4. Sub-processors

Your personal data is never sold or rented. CookieFort uses carefully selected sub-processors, bound by contractual obligations consistent with Article 28 of the GDPR:

  • Infomaniak Network SA (Switzerland / European Union) — website and application hosting, data centres located in Switzerland and/or the EU.
  • Stripe Payments Europe Ltd — payment processing, certified PCI-DSS Level 1. Card numbers are never stored on CookieFort servers; payment data is handled directly by Stripe.

5. Unsubscribe and email management

You may unsubscribe from marketing emails at any time using the unsubscribe link included in each message, or by sending a request to cmp@cookiefort.com. We will process your request without undue delay.

6. Security measures

CookieFort implements technical and organisational measures appropriate to the risk, including:

  • Transport encryption: HTTPS with TLS 1.3 for data in transit.
  • Storage encryption: AES-256 encryption at rest for sensitive data.
  • Authentication: passwords hashed with Argon2id or BCrypt; access controls and logging on production systems.

7. Your rights and remedies

Under Articles 15 to 21 of the GDPR, you have the right to access, rectify, erase, restrict processing, object and data portability, where applicable. You may also define directives regarding the storage, erasure and communication of your data after your death, in accordance with French law.

To exercise your rights, contact us by email at cmp@cookiefort.com or by post to: COOKIEFORT SAS – DPO, 5 rue de la Terrasse, 75017 Paris, France. We will respond within 30 days of receipt of your request, subject to proof of identity where necessary.

If you consider that your rights have not been respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 Place de Fontenoy, 75007 Paris, France — www.cnil.fr.

8. Cookie management

The cookiefort.com website uses CookieFort's own consent management technology. Strictly necessary technical cookies are placed automatically to ensure the site functions correctly and to remember your consent choices.

You may change your preferences at any time via the permanent link available on the site: Cookie settings. For further details on the cookies used and your choices, please refer to our cookie policy.