Data protection
Privacy Policy
Last updated: 23 July 2026
1. Purpose of this policy
This policy explains how YMUNIT collects, uses, retains and protects the personal data of visitors to ymunit.com, people who contact the firm and prospective clients requesting information about its services.
2. Data controller
The data controller is:
YMUNIT — SASU with share capital of EUR 50,000
229 rue Saint-Honoré
75001 Paris — France
SIREN : 879 189 330
Contact address: contact@ymunit.com
YMUNIT does not list a data protection officer until a DPO has been formally appointed. Any data-protection request may be submitted through the website contact form.
3. Data that may be collected
Contact form
YMUNIT may collect:
- full name;
- organisation;
- business email address;
- telephone number, where provided;
- nature of the requirement;
- message content;
- page from which the enquiry was submitted;
- date and time of submission;
- technical data required for security and abuse prevention.
The form sends the enquiry to YMUNIT’s contact address through WordPress email functionality. The YMUNIT theme does not store a copy of messages in the WordPress database.
Professional communications
When you communicate with YMUNIT, the firm may retain professional contact details, the content of communications, documents provided and information required to follow up the enquiry or professional relationship.
Technical and security data
The website and its technical providers may process information such as:
- IP address;
- browser type and operating system;
- date, time and pages viewed;
- technical and security logs;
- data required to detect automated or malicious submissions;
- Cloudflare Turnstile verification result;
- language and cookie preferences.
Audience measurement
Where consent-based audience-measurement tools are enabled, they are triggered only after you give consent. The tools used, their purposes and associated data are described in the CookieYes preference centre and Cookie Policy.
4. Purposes and legal bases
| Purpose | Main legal basis | Indicative retention period |
|---|---|---|
| Respond to an enquiry, qualify a requirement and prepare a potential engagement | Pre-contractual measures taken at your request and, depending on the B2B context, YMUNIT’s legitimate interest in responding to professional enquiries | Up to three years from the last active contact where no contractual relationship is established |
| Manage communications, proposals, contracts and client relationships | Performance of pre-contractual measures or a contract; legal obligations | During the relationship, followed by archiving for applicable statutory periods |
| Secure the website and prevent spam, fraud and attacks | YMUNIT’s legitimate interest in protecting its website and communications | Logs are generally retained for between six and twelve months, except in the event of an incident, dispute or specific obligation |
| Manage cookie choices | Legal obligation and legitimate interest in demonstrating compliance with users’ choices | Period indicated in the CookieYes preference centre; you may be asked to renew your choices on expiry or following a material change |
| Measure audience and improve the website | Consent, unless the tool is configured to benefit from a legally applicable exemption | According to the period indicated in the cookie manager; audience-measurement trackers must not be extended indefinitely |
| Defend YMUNIT’s rights and manage claims | Legitimate interest and legal obligations | For the period required to handle the matter, followed by applicable limitation periods |
Retention periods are applied in accordance with the data-minimisation principle. Certain data may be archived to meet a legal obligation, establish evidence or defend a right.
5. Mandatory nature of data
Fields marked as mandatory are required to process the enquiry. Without them, YMUNIT may be unable to respond. Optional fields are used only to facilitate or contextualise the discussion.
6. Recipients
Data is accessible, within the scope of their responsibilities, to authorised personnel within YMUNIT.
It may also be processed by providers acting on YMUNIT’s behalf, particularly for:
- website hosting and maintenance;
- email services and delivery;
- website security and anti-spam measures, including Cloudflare Turnstile;
- cookie-consent management through CookieYes;
- audience measurement, only where enabled in accordance with your choices;
- technical support and backups.
YMUNIT does not sell personal data collected through the website.
7. Transfers outside the European Economic Area
Some technical providers may process data from countries outside the European Economic Area. Where this occurs, YMUNIT ensures that a recognised transfer mechanism is used, such as an adequacy decision or standard contractual clauses, together with supplementary safeguards where required.
YMUNIT maintains information on its providers and their locations in its compliance documentation, data-processing agreements and, for trackers, the CookieYes preference centre.
8. Your rights
Subject to applicable legal conditions, you may exercise:
- your right of access;
- your right to rectification;
- your right to erasure;
- your right to restriction of processing;
- your right to object;
- your right to data portability where applicable;
- your right to withdraw consent at any time for processing based on consent.
To exercise your rights, use the website contact form or send a letter to:
YMUNIT — Data Protection
229 rue Saint-Honoré
75001 Paris — France
Your request must identify you with sufficient precision. Proof of identity will be requested only where there is reasonable doubt about the requester’s identity, and only information necessary for that verification will be sought.
YMUNIT responds within the periods provided by law. You may also lodge a complaint with the French data-protection authority, the Commission nationale de l’informatique et des libertés (CNIL).
9. No automated decision-making
Data collected through the website is not used for a decision based solely on automated processing that produces legal effects or similarly significantly affects an individual.
10. Security
YMUNIT implements technical and organisational measures appropriate to the risks, including HTTPS encryption, access restrictions, permission management, protection against automated submissions, backups and updates to technical components.
No transmission or storage method can, however, be guaranteed to be entirely risk-free.
11. Third-party websites
Links to third-party websites, including LinkedIn, are subject to those third parties’ privacy rules. A simple outbound link does not necessarily place a tracker on the YMUNIT website. However, embedded external content must be blocked before consent where it uses non-essential trackers.
12. Changes to this policy
YMUNIT may amend this policy to reflect legal, technical or functional changes. The update date appears at the top of the page.
