Last updated: August 2026
1. Preamble and sovereignty commitment
COOKIEFORT (Simplified joint-stock company with share capital of €5,000, registered with the Paris Trade and Companies Register under number 107 807 554, registered office at 5 rue de la Terrasse, 75017 Paris, France) is committed to protecting your privacy and the security of your personal data when you use the website cookiefort.com, our SaaS platform and our related communications.
This policy describes how we collect, use, store and protect your data, in compliance with the General Data Protection Regulation (GDPR) and applicable French data protection law.
Extraterritorial immunity commitment (US Cloud Act / FISA 702)
CookieFort has designed its infrastructure and contractual framework to limit exposure to extraterritorial requests under United States law, including the CLOUD Act and Section 702 of the Foreign Intelligence Surveillance Act (FISA 702).
- Data sovereignty: production data is hosted within the European Union and/or Switzerland with Infomaniak Network SA, without reliance on US hyperscale cloud providers for the storage of personal data processed on behalf of our customers.
- No transfer to the United States: we do not intentionally transfer personal data to the United States for hosting or primary processing. Where a sub-processor is established outside the EEA, we apply appropriate safeguards in accordance with Chapter V of the GDPR.
2. Data controller and DPO
The data controller for processing described in this policy is:
- Organisation: COOKIEFORT SAS
- SIREN: 107 807 554
- Registered office: 5 rue de la Terrasse, 75017 Paris, France
- Legal representative: Mr Khaled Hamadmad, President
- Data Protection Officer (DPO) contact: cmp@cookiefort.com
3. Processing activities
The table below summarises the main processing activities carried out by CookieFort, the categories of data concerned, the legal basis and retention periods.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Contact or demo request | First name, last name, professional email, company, URL, message | Legitimate interest (prospects) | 3 years from last contact |
| SaaS account and subscription management | Hashed identifiers, email, billing data, logs | Performance of a contract | Duration of the contract + 10 years (accounting records) |
| Payments and invoicing | Card data via Stripe, billing address, transactions | Performance of a contract | Commercial relationship + 10 years |
| Newsletter and communications | Professional email, first name, last name, status | B2B legitimate interest / Consent | Until unsubscribe or 3 years without interaction |
| Security and fraud prevention | Truncated IP addresses, logs, User-Agent | Legitimate interest | 6 rolling months maximum |
| Sovereign audience measurement | Anonymous local session identifier | Legitimate interest / CNIL exemption | 25 months (anonymised statistics) |
4. Sub-processors
Your personal data is never sold or rented. CookieFort uses carefully selected sub-processors, bound by contractual obligations consistent with Article 28 of the GDPR:
- Infomaniak Network SA (Switzerland / European Union) — website and application hosting, data centres located in Switzerland and/or the EU.
- Stripe Payments Europe Ltd — payment processing, certified PCI-DSS Level 1. Card numbers are never stored on CookieFort servers; payment data is handled directly by Stripe.
5. Unsubscribe and email management
You may unsubscribe from marketing emails at any time using the unsubscribe link included in each message, or by sending a request to cmp@cookiefort.com. We will process your request without undue delay.
6. Security measures
CookieFort implements technical and organisational measures appropriate to the risk, including:
- Transport encryption: HTTPS with TLS 1.3 for data in transit.
- Storage encryption: AES-256 encryption at rest for sensitive data.
- Authentication: passwords hashed with Argon2id or BCrypt; access controls and logging on production systems.
7. Your rights and remedies
Under Articles 15 to 21 of the GDPR, you have the right to access, rectify, erase, restrict processing, object and data portability, where applicable. You may also define directives regarding the storage, erasure and communication of your data after your death, in accordance with French law.
To exercise your rights, contact us by email at cmp@cookiefort.com or by post to: COOKIEFORT SAS – DPO, 5 rue de la Terrasse, 75017 Paris, France. We will respond within 30 days of receipt of your request, subject to proof of identity where necessary.
If you consider that your rights have not been respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 Place de Fontenoy, 75007 Paris, France — www.cnil.fr.
8. Cookie management
The cookiefort.com website uses CookieFort's own consent management technology. Strictly necessary technical cookies are placed automatically to ensure the site functions correctly and to remember your consent choices.
You may change your preferences at any time via the permanent link available on the site: Cookie settings. For further details on the cookies used and your choices, please refer to our cookie policy.