This Privacy Notice explains how Cyber-Management SAS (“we”, “us”, “our”, “Cyber-Management”) collects, uses, shares, and protects your personal data when you interact with us — for example, when you visit our website, request a consultation, become a client, subscribe to our newsletter, or contact us through any other channel.
It is provided to comply with Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and the French Data Protection Act (Loi n° 78-17 of 6 January 1978, as amended). If you have any question about this notice, contact us using the details in Section 2.
1. About this notice
This notice describes how we — Cyber-Management SAS, a Société par Actions Simplifiée (SAS) having its registered office at 66 avenue des Champs-Élysées, 75008 Paris, France — handle personal data relating to you. We are the “controller” of your personal data, which means we decide why and how it is processed.
This notice applies to:
- Visitors to our website www.cyber-management.com and its French-language version at www.cyber-management.com/fr/.
- Prospective, current, and former clients and the personnel of those client organisations.
- Subscribers to our newsletter or other content updates.
- Suppliers, business partners, subcontractors, and their personnel.
- Anyone who contacts us through any channel — email, contact form, booking page, social media, or in person.
This notice does not cover personal data we handle in the context of an employment relationship; that data is governed by a separate Employee Privacy Notice provided directly to staff. Where we act as a “processor” on behalf of a client — for example, when we handle personal data inside that client’s information system during an engagement — the client’s own privacy notice applies, and our obligations are governed by the Data Processing Agreement signed with that client under Article 28 GDPR.
2. Who we are and how to contact us
Use the following details to reach us about this notice or to exercise any of the rights described in Section 8.
| Controller (legal name) | Cyber-Management SAS |
|---|---|
| Legal form | Société par Actions Simplifiée (SAS) |
| Registered office | 66 avenue des Champs-Élysées, 75008 Paris, France |
| Website | www.cyber-management.com |
| General enquiries | info@cyber-management.com |
| Privacy / Data Protection contact | dpo@cyber-management.com |
| Postal address for privacy enquiries | Cyber-Management SAS — Data Protection Contact — 66 avenue des Champs-Élysées, 75008 Paris, France |
If your enquiry concerns the way we use your personal data, write to dpo@cyber-management.com or to the postal address above. We monitor the privacy mailbox during business days and respond within the timeframes described in Section 8.
We have not formally designated a Data Protection Officer under Article 37 GDPR — we are not legally required to do so given the scale and nature of our processing. We have nevertheless set up a dedicated Data Protection contact channel (dpo@cyber-management.com) to handle all privacy matters.
3. The personal data we collect
We collect and process the following categories of personal data, depending on how you interact with us:
- Identification data — first name, last name, professional title.
- Business contact data — employer name, professional email address, professional phone number, postal address (where relevant for invoicing or contractual delivery).
- Commercial-relationship data — details of your enquiry, the services you are interested in, contracts and engagement letters, correspondence with our team, meeting notes, recordings of consultations only where you have been informed in advance and have consented.
- Billing data — invoices, payment references, payment status, supplier or client account number. We do not collect or store full bank-card numbers — invoices are settled by bank transfer or through a compliant third-party payment service that handles card data on its own infrastructure.
- Marketing-preference data — your subscription status to our newsletter or content updates, and any opt-in or opt-out choices you have recorded.
- Technical data — limited technical information collected by our website host for security and reliability purposes (IP address, browser, operating system, time of access). See Section 10 for details on cookies and similar technologies.
- Audience-measurement data — aggregate statistics about visits to our website (pages viewed, approximate country, referring source, browser family, device type). The data is collected without cookies and without any persistent identifier. See Section 10 for the technical detail and the lawful basis under CNIL guidance.
Special-category data — we do not collect special categories of personal data within the meaning of Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, health data, data concerning sex life or sexual orientation). Please do not include such data in any communication addressed to us.
Children’s data — our services are intended exclusively for professionals acting on behalf of organisations. We do not knowingly collect personal data from children. If you believe a child has provided us with their data, contact us using the details in Section 2 and we will delete it without undue delay.
4. Why we use your personal data and our lawful basis
Article 6(1) GDPR requires us to identify a “lawful basis” for every purpose for which we process your personal data. The table below sets out the main processing activities we carry out, the data involved, the lawful basis, and how long we keep the data. The table is consistent with our Records of Processing Activities maintained under Article 30 GDPR.
| Category of personal data | Purpose of processing | Lawful basis (Art. 6 GDPR) | Retention | Source (Art. 13 / 14) |
|---|---|---|---|---|
| Identification, business contact, commercial-relationship data | Respond to your enquiry, prepare and send proposals, hold consultations, and negotiate engagement terms. | Article 6(1)(b) — pre-contractual measures taken at your request; Article 6(1)(f) — our legitimate interest in operating a B2B consulting practice. | Up to 3 years from the last contact if no engagement is signed (CNIL recommended retention for B2B prospect data). | Collected directly from you — Article 13. |
| Identification, business contact, commercial-relationship data | Deliver the consulting services you have engaged us to perform, manage the engagement, communicate during the engagement. | Article 6(1)(b) — performance of the contract you have entered into with us. | Duration of the engagement plus 5 years (general limitation period for contractual claims, Code civil Article 2224). | Collected directly from you — Article 13. |
| Identification, business contact, billing data | Issue invoices, collect payment, manage accounting, comply with accounting and tax obligations. | Article 6(1)(c) — legal obligation (Code de commerce Article L.123-22 and the General Tax Code). | 10 years from the end of the fiscal year (Code de commerce L.123-22). | Collected directly from you — Article 13. |
| Business contact data, marketing-preference data | Send you our newsletter, content updates, or invitations to events you have asked to receive. | Article 6(1)(a) — your consent (B2B prospects); Article 6(1)(f) — our legitimate interest in informing existing clients about similar services, where local law allows. | Until you withdraw consent or unsubscribe, and in any event no longer than 3 years from the last interaction with you. | Collected directly from you — Article 13. |
| Business contact data (name, role, employer, professional email) | Identify and reach out to professionals at organisations likely to be interested in our services. | Article 6(1)(f) — our legitimate interest in B2B business development. We have carried out a balancing test and limit ourselves to professional contact details obtained from public business sources. | Up to 3 years from the last contact, or earlier if you ask us to stop. | Collected from public business registers (e.g., Infogreffe / RCS), public professional networks (e.g., LinkedIn), and B2B data providers — Article 14. |
| Technical data (IP address, browser, time of access) | Operate, secure, and ensure the reliability of our website. | Article 6(1)(f) — our legitimate interest in running a secure and reliable website. | Up to 12 months for raw web-server logs. | Collected automatically when you visit our website — Article 13. |
| Audience-measurement data (aggregate statistics, cookieless) | Measure traffic to our website, understand which pages are useful, identify navigation problems. | Article 6(1)(f) — our legitimate interest in operating an effective website. Exempt from consent under CNIL guidance on audience-measurement statistics that do not allow user tracking. | Up to 6 months at our analytics provider; aggregate statistics may be retained longer for trend analysis. | Collected automatically when you visit our website — Article 13. |
| Any of the categories above, as relevant | Establish, exercise, or defend legal claims (litigation, regulatory enquiries, professional-liability claims). | Article 6(1)(f) — our legitimate interest in defending our legal position. | Duration of the dispute plus the applicable limitation period. | Various — see relevant rows above. |
Where we rely on legitimate interests under Article 6(1)(f), we have carried out a balancing test to confirm that our interests are not overridden by your interests, rights, and freedoms. You can ask us for a summary of the test using the contact details in Section 2.
Where we rely on your consent under Article 6(1)(a), you can withdraw it at any time without giving a reason — withdrawal does not affect the lawfulness of processing carried out before withdrawal. Use the unsubscribe link in any newsletter, or write to dpo@cyber-management.com.
5. Where we obtained your personal data
Most of the personal data we hold about you is collected directly from you — when you visit our website, fill in a form, send us an email, book a consultation, or otherwise interact with us. Article 13 GDPR governs that direct collection.
In some cases we obtain personal data about you from third-party sources — Article 14 GDPR requires us to tell you where the data come from. Specifically:
- Public business registers — we may consult Infogreffe, the Registre du Commerce et des Sociétés, and equivalent EU public registers when we conduct due diligence on a prospective client, supplier, or business partner. We collect company details and the names and roles of legal representatives shown in those registers.
- Professional networks — we may identify professionals at companies that are likely to be interested in our services using publicly available information on professional networks such as LinkedIn. The data we collect is limited to professional contact details (name, role, employer, professional email or messaging handle).
- Referrals — a current or former client or contact may share your professional contact details with us when they introduce you as a potential prospect, partner, or supplier.
- B2B data providers — we use specialist providers that enrich and verify professional contact details (name, role, employer, professional email) to complete and validate the data obtained from the public sources above. These providers act as processors and process your data within the European Economic Area.
Where we have received personal data about you from a source listed above, we provide this Privacy Notice to you within one month of receiving the data, or at the time of first communication with you (whichever is sooner) — as required by Article 14(3) GDPR.
6. Who we share your personal data with
We share your personal data only where it is necessary for the purposes set out in Section 4, and only with the categories of recipient described below. We never sell your personal data, and we do not share it for the recipient’s own marketing without your explicit consent.
Categories of recipient:
- Internal recipients — the personnel of Cyber-Management who need access to your personal data to perform their duties (consulting delivery, business development, finance, support functions). Access is governed by role-based permissions and confidentiality undertakings.
- Subcontractors and service providers acting on our behalf and under our written instructions, under an agreement compliant with Article 28 GDPR. The main categories include cloud hosting and infrastructure, audience-measurement (cookieless web analytics), professional email, customer-relationship and marketing platforms, accounting and invoicing platforms, electronic-signature services, B2B data enrichment and verification services, and document-collaboration tools.
- Professional advisers — our auditors, lawyers, insurers, and external accountants, bound by professional secrecy or contractual confidentiality.
- Independent associate consultants — where we engage a qualified independent consultant to support an engagement, that consultant is bound by a written confidentiality and data-protection agreement and operates under our instructions.
- Regulators and public authorities — where we are required to disclose your data by law (in particular tax, social-security, supervisory, or judicial authorities).
- Business successors — in the event of a merger, acquisition, or business transfer involving Cyber-Management, your data may be transferred to the successor entity under appropriate confidentiality arrangements. We will inform you in advance of any such transfer.
A current list of our principal subcontractors is available on request through dpo@cyber-management.com — we maintain it under Article 30 GDPR.
7. International transfers of your personal data
We have selected our subcontractors so that your personal data is stored and processed within the European Economic Area (EEA). We do not currently transfer your personal data outside the EEA.
If we engage a subcontractor in the future that processes your personal data outside the EEA, we will update this notice and ensure that an appropriate safeguard from Chapter V of the GDPR is in place before any such transfer. The applicable safeguards are:
- Adequacy decisions — transfers to countries the European Commission has formally recognised as providing an adequate level of protection (Article 45 GDPR).
- Standard Contractual Clauses (SCCs) — transfers to countries without an adequacy decision, using the Commission-approved SCCs (Decision (EU) 2021/914), supplemented where necessary by a Transfer Impact Assessment and additional technical, contractual, or organisational measures (Article 46 GDPR).
- EU–US Data Privacy Framework — transfers to certified United States organisations under the Adequacy Decision of 10 July 2023.
- Other Article 46 mechanisms — Binding Corporate Rules or approved certification mechanisms, where applicable.
A copy of the safeguards in place for any specific transfer will be made available on request through dpo@cyber-management.com.
8. Your rights under the GDPR
You have the following rights in relation to your personal data. We respond to a valid request within one month of receipt — extendable by two further months for complex or numerous requests, in which case we will tell you within one month and explain why.
| Right (GDPR Article) | What it means for you | How to invoke it |
|---|---|---|
| Access — Article 15 | Ask for confirmation that we process personal data about you, and a copy of that data, together with information about the processing. | Email dpo@cyber-management.com. |
| Rectification — Article 16 | Ask us to correct inaccurate personal data and complete data that is incomplete, where relevant to the purpose. | Email dpo@cyber-management.com. |
| Erasure (“right to be forgotten”) — Article 17 | Ask us to delete your personal data where one of the grounds in Article 17(1) applies — for example, the data is no longer necessary, you withdraw consent, or you object to processing based on legitimate interests. | Email dpo@cyber-management.com. |
| Restriction — Article 18 | Ask us to limit processing of your data — for example, while we verify the accuracy of contested data or while we consider your objection. | Email dpo@cyber-management.com. |
| Portability — Article 20 | Receive the personal data you have provided to us, in a structured, commonly used, machine-readable format, and ask us to transmit it to another controller, where technically feasible. | Email dpo@cyber-management.com. |
| Object — Article 21 | Object to processing based on legitimate interests (Article 6(1)(f)) on grounds relating to your particular situation. You may always object to direct-marketing processing without giving any reason. | Email dpo@cyber-management.com; for marketing, also use the unsubscribe link in any newsletter. |
| Withdraw consent — Article 7(3) | Where we rely on your consent (Article 6(1)(a)), withdraw it at any time, without giving a reason. Withdrawal does not affect lawfulness of processing carried out before withdrawal. | Use the unsubscribe link in any newsletter; for other consent-based processing, email dpo@cyber-management.com. |
| Post-mortem instructions — Article 85 of the French Data Protection Act | Define directives on how your personal data should be handled after your death (general directives registered with a certified third party, or specific directives sent to us). | Email dpo@cyber-management.com. |
| Lodge a complaint — Article 77 | Lodge a complaint with a supervisory authority — in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. | See Section 9 for the contact details of our lead supervisory authority. |
To help us respond, please tell us your full name, the email address associated with your data, and a clear description of what you want. We may ask for proof of identity if your request reaches us through a channel where your identity is not already authenticated.
Exercising your rights is free of charge. We may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive (Article 12(5) GDPR) — in which case we will explain why in writing.
9. Right to lodge a complaint with a supervisory authority
You can lodge a complaint with a supervisory authority if you consider that our processing infringes the GDPR. We hope you will contact us first so we can address your concern, but you do not have to.
Our lead supervisory authority is:
| Authority | Commission Nationale de l’Informatique et des Libertés (CNIL) — France |
|---|---|
| Postal address | 3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07 — France |
| Telephone | +33 (0)1 53 73 22 22 |
| Online complaint | https://www.cnil.fr/fr/plaintes |
You may also lodge a complaint with the supervisory authority of the EU member state where you live, where you work, or where the alleged infringement took place — Article 77(1) GDPR.
10. Cookies and similar technologies
Our website does not set cookies on your device, does not use any persistent identifier, does not fingerprint your browser, and does not run advertising trackers, retargeting, or social-media tracking. The only data we collect about your visit is the cookieless audience measurement described below.
We use Cloudflare Web Analytics, the audience-measurement tool built into our infrastructure host. When you load a page, your browser fetches a small measurement script from static.cloudflareinsights.com (loaded under our Content Security Policy) which sends one anonymous request per page view to Cloudflare. The request includes the page URL, your browser family, device type, viewport size, the referring page, and your approximate country derived from your IP. No cookie is set, no identifier is stored on your device, and the metadata cannot be combined to single you out across visits or sessions.
Under the French data-protection authority's guidance onaudience-measurement tools that do not require consent(CNIL guidance on cookies and other trackers, applying Article 82 of the Loi Informatique et Libertés), this audience measurement is exempt from prior consent because it is strictly limited to producing anonymous statistics for our own use, no data is shared with third parties for re-use, and no profile is built about you. We rely on it under Article 6(1)(f) GDPR (legitimate interest in operating an effective website).
Your browser may still record limited technical information needed to load the website (such as your IP address and browser type) — see Section 3 for what we collect and Section 4 for why.
If we introduce any cookies or similar persistent technologies in the future — or move to an audience-measurement tool that does not qualify for the CNIL consent exemption — we will update this notice and, where the law requires it, ask for your consent through a cookie banner before activating them.
11. Automated decision-making and profiling
We do not take decisions based solely on automated processing — including profiling — that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR.
Any decision we take that materially affects you (for example, whether to accept an engagement, scope a project, or recommend a course of action) is taken by a human consultant exercising professional judgement.
12. How we protect your personal data
We take appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access — as required by Article 32 GDPR. The measures are proportionate to the risk and to the state of the art, and include in particular:
- Access control — role-based access, least-privilege provisioning, mandatory authentication, multi-factor authentication for administrative and privileged access.
- Encryption — data in transit (TLS 1.2 or above), data at rest where the underlying technology supports it, encrypted backups.
- Network and infrastructure security — segmentation, hardened configurations, intrusion detection, vulnerability management on our endpoints and on the platforms we operate.
- Logging and monitoring — security events are logged and reviewed; suspicious activity triggers an incident-response process.
- Personnel — written confidentiality undertakings, security awareness, and skills maintained through ongoing professional development (CISSP, PECB ISO 27001 Lead Auditor, and equivalent credentials).
- Subcontractors — written agreements compliant with Article 28 GDPR, with security commitments aligned to the sensitivity of the data handled.
- Incident response — a documented procedure to identify, contain, investigate, and notify personal-data breaches in line with Articles 33 and 34 GDPR. We will inform you of a breach without undue delay where it is likely to result in a high risk to your rights and freedoms.
13. Changes to this notice
We review this notice at least once a year and whenever there is a material change to the personal data we process or how we process it. The “Last updated” date at the top of the notice reflects the date of the last revision.
When the change is significant — for example, a new purpose of processing, a new lawful basis, or a new category of recipient — we will draw your attention to it through a prominent notice on our website, by email where we have a relationship with you, or both. Continued use of our services after a change implies that you have read the updated notice.
14. Contact us about your personal data
Any question about this notice, any request relating to your personal data, or any concern about how we are handling it — write to us at:
| Privacy / Data Protection contact | dpo@cyber-management.com |
|---|---|
| Postal address | Cyber-Management SAS — Data Protection Contact — 66 avenue des Champs-Élysées, 75008 Paris, France |
| General enquiries | info@cyber-management.com |
We acknowledge requests within five business days and respond substantively within one month — extendable to three months for complex or numerous requests, in which case we will tell you within the first month.
— End of Privacy Notice — Version 1.2 — 22 July 2026 —