Privacy
What data Webricks collects, why, on what legal basis, for how long, who it is shared with and how to exercise your rights.
Last updated · 19 août 2026
Webricks is established in France and this policy is governed by French law and the GDPR. This English version is provided for information; in the event of any discrepancy, the French version prevails.
1. Data controller
The data controller is Axel Letourneau — Entrepreneur individuel (EI), 12 rue Louise Colet, 06200 Nice, France, reachable at [email protected]. No data protection officer has been appointed, as the nature and volume of processing do not require one.
2. What this site does not do
webricks.co sets no cookies, uses no advertising trackers and embeds no third-party analytics. No consent banner is needed, because there is nothing to consent to.
The contact form sends nothing to a server: it drafts a message and opens it in WhatsApp or your email app. Until you send it yourself, nobody receives it and nothing is recorded.
3. Data processed, purposes and retention
We only process data you send us of your own accord, or data that providing the service makes necessary.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, business, trade, town | Review your enquiry and design a first website | Pre-contractual steps at your request | 3 years if nothing follows |
| Phone, email | Reply to you and follow the project | Pre-contractual steps, then performance of the contract | 3 years after the last exchange |
| Content you send us (text, photos, logos) | Build and maintain your website | Performance of the contract | Term of the contract, then 12 months |
| Billing details, payment history | Issue invoices and keep the accounts | Legal obligation | 10 years (article L123-22 of the French Commercial Code) |
| Your client area credentials | Give you access to your sites, statistics and invoices | Performance of the contract | Term of the contract, then 3 months |
| Server technical logs (IP address, timestamp) | Security, fault diagnosis, abuse prevention | Legitimate interest in securing the service | 12 months |
4. Whether information is required
The information requested to prepare a quote or build a website is necessary to perform the service. Without it, we cannot proceed. Other information is optional and you remain free not to provide it.
None of this data is sold, transferred, rented or used for marketing on behalf of a third party.
5. Recipients and processors
The data is accessible only to Webricks staff working on the project, and to the following providers, bound by confidentiality commitments compliant with article 28 of the GDPR:
- Hosting
- OVH SAS, Hosting of the websites and technical logs. Location : France.
- Payment
- Stripe Payments Europe, Ltd., Payment processing and invoicing. No bank details pass through or are stored on our servers. Location : Ireland, with transfers to Stripe, Inc. (United States).
- Email routing
- Cloudflare, Inc., Delivery of messages sent to the contact address. Location : United States.
- Mailbox
- Apple Distribution International Ltd., Storage of messages received. Location : Ireland.
- Instant messaging
- WhatsApp Ireland Ltd., Message exchanges, if you choose that channel. Location : Ireland, with transfers to Meta Platforms, Inc. (United States).
6. Transfers outside the European Union
The websites we host stay in France, on a dedicated OVH SAS server. No site data leaves the European Union as a result of hosting.
Three providers do however involve transfers to the United States: Stripe for payment, Cloudflare for email routing, and WhatsApp if you choose that channel. These transfers are covered by the European Commission's standard contractual clauses and, where applicable, by these providers' certification under the EU-U.S. Data Privacy Framework. A copy of the applicable safeguards can be requested at [email protected].
You can avoid any transfer linked to instant messaging by using email or the phone instead.
7. Security
Exchanges with the site and the client area are encrypted over HTTPS. Access is personal and limited to those who need it. Regular backups are made. Despite these measures, no system is infallible: in the event of a data breach likely to result in a high risk to your rights, you will be informed in accordance with article 34 of the GDPR.
8. No automated decision-making
No decision producing legal effects concerning you is taken solely on the basis of automated processing. No profiling is carried out.
9. Your rights
Under articles 15 to 22 of the GDPR, you have the right of access, rectification, erasure, restriction, objection and portability regarding your data, as well as the right to set instructions on its fate after your death.
Simply write to [email protected]. The request is handled within one month, extendable by two months if complex. Proof of identity may be requested in the event of reasonable doubt.
Some data cannot be deleted before its statutory retention period expires, in particular accounting records.
10. Complaints
If our response does not satisfy you, you may lodge a complaint with the French data protection authority, Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr.
11. Changes to this policy
This policy may be updated to reflect changes to the service or to regulations. The date of the last update appears at the top of the page. Clients are informed of any substantial change.