Privacy Policy

Your privacy matters. This policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable French data protection laws.

1. Introduction

This Privacy Policy applies to the website yassite.com (hereinafter "the Website") operated by Yassine Labhih, sole proprietor and freelance web developer based in France, trading as Yassite.

Data Controller: Yassine Labhih
Email: contact@yassite.com
Website: yassite.com

This policy describes how personal data is collected, processed, stored, and protected when you visit the Website, use the contact form, subscribe to the newsletter, leave blog comments, or book a consultation via Cal.com.

By using this Website, you acknowledge that you have read and understood this Privacy Policy.

2. Data Collected

We collect the following personal data depending on how you interact with the Website:

a) Contact Form

When you submit the contact form, we collect:

  • Full name
  • Email address
  • Phone number
  • Company name
  • Project type
  • Estimated budget
  • Project timeline
  • Message content
  • IP address (collected automatically)
  • User agent / browser information (collected automatically)

b) Newsletter Subscription

When you subscribe to our newsletter, we collect:

  • Email address
  • IP address (collected automatically)
  • Locale / language preference (collected automatically)

c) Blog Comments

When you leave a comment on a blog post, we collect:

  • Name or username
  • Email address
  • Comment content
  • IP address (collected automatically)

d) Appointment Booking (Cal.com)

When you book a consultation through Cal.com, your data (name, email, appointment details) is processed by Cal.com in accordance with their own privacy policy. We receive the booking information to manage your appointment. Please refer to Cal.com's Privacy Policy for details on their data processing practices.

e) Analytics Data

We use Google Analytics 4 (GA4) with IP anonymization enabled. GA4 automatically collects anonymized data about your browsing behaviour, including pages visited, session duration, referral source, device type, and approximate geographic location. No personally identifiable information is collected by analytics.

3. Purpose of Processing

Your personal data is processed for the following purposes:

  • Responding to enquiries: To process and respond to contact form submissions and manage project discussions
  • Newsletter: To send periodic email communications about web development, digital strategy, and relevant industry insights to subscribers who have opted in
  • Blog engagement: To display and manage comments on blog posts and prevent spam
  • Appointment scheduling: To manage consultation bookings made through Cal.com
  • Website analytics: To analyse website traffic and improve user experience using anonymized data
  • Security and fraud prevention: To protect the Website against abuse, spam, and malicious activity using IP addresses and user agent data

4. Legal Basis

In accordance with the GDPR (Article 6), we process your data based on the following legal grounds:

  • Consent (Art. 6(1)(a)): For newsletter subscriptions and the placement of non-essential cookies (Google Analytics). You may withdraw your consent at any time.
  • Legitimate interest (Art. 6(1)(f)): For processing contact form submissions to respond to enquiries, managing blog comments, ensuring website security, and analysing anonymized usage data to improve the Website.
  • Pre-contractual measures (Art. 6(1)(b)): For processing data provided through the contact form or booking system when you enquire about or request services.
  • Legal obligation (Art. 6(1)(c)): When required to comply with applicable laws, including tax and accounting regulations.

5. Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Contact form data: Retained for up to 3 years from the date of submission, or for the duration of the business relationship plus any applicable legal retention period.
  • Newsletter subscriber data: Retained until you unsubscribe. Upon unsubscription, your email is deleted or anonymized within 30 days.
  • Blog comments: Retained for the lifetime of the blog post or until you request deletion.
  • Analytics data: Google Analytics data is retained for 14 months (default GA4 setting) with IP anonymization enabled.
  • Invoicing and accounting data: Retained for 10 years as required by French accounting and tax regulations.

6. Data Recipients

Your personal data may be shared with the following categories of recipients, strictly on a need-to-know basis:

  • Hosting provider: For website hosting and data storage
  • Google (Google Analytics 4): For anonymized website analytics
  • Cal.com: For appointment booking management
  • Email service provider: For sending newsletter communications
  • Accounting and legal advisors: As required for tax compliance and legal obligations

We do not sell, rent, or trade your personal data to any third party for marketing purposes. All third-party service providers are contractually bound to handle your data in accordance with the GDPR.

7. International Transfers

Some of the third-party services we use may process data outside the European Economic Area (EEA). In particular:

  • Google Analytics 4: Google may process anonymized analytics data in the United States. Google operates under the EU-U.S. Data Privacy Framework and implements Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure adequate data protection.
  • Cal.com: Appointment data may be processed outside the EEA. Cal.com adheres to GDPR-compliant data processing standards.

Where personal data is transferred outside the EEA, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses, adequacy decisions, or other mechanisms recognised by the European Commission under Article 46 of the GDPR.

8. Cookies

This Website uses cookies and similar technologies to enhance your browsing experience and collect anonymized analytics data.

Essential Cookies

These cookies are strictly necessary for the Website to function properly (e.g., session management, CSRF protection). They do not require your consent and cannot be disabled.

Analytics Cookies (Google Analytics 4)

We use Google Analytics 4 with the following privacy-preserving measures:

  • IP anonymization is enabled, meaning your full IP address is never stored by Google
  • No advertising features or remarketing are enabled
  • Data is used solely to understand website traffic, popular pages, and user behaviour patterns
  • Data retention is set to 14 months

Analytics cookies are only placed with your prior consent, in accordance with Article 82 of the French Data Protection Act (Loi Informatique et Libertes) and the CNIL guidelines. You can manage your cookie preferences at any time.

You may also opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.

9. Your Rights

Under the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights regarding your personal data:

  • Right of access (Art. 15): You may request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17): You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
  • Right to restriction of processing (Art. 18): You may request that we limit the processing of your data under certain circumstances.
  • Right to data portability (Art. 20): You may request to receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object (Art. 21): You may object to the processing of your personal data based on legitimate interest at any time.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at contact@yassite.com. We will respond to your request within one (1) month, in accordance with GDPR requirements. This period may be extended by two (2) additional months for complex requests.

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the French data protection authority:

  • CNIL (Commission Nationale de l'Informatique et des Libertes)
  • Website: www.cnil.fr

10. Security

We take the security of your personal data seriously and implement appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • SSL/TLS encryption for all data transmitted between your browser and our servers
  • Secure storage of personal data with restricted access
  • Regular security updates and patching of server software and dependencies
  • CSRF protection and input validation on all forms
  • Hashed passwords and secure authentication mechanisms

While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security but will promptly notify you and the relevant supervisory authority in the event of a data breach, in accordance with Articles 33 and 34 of the GDPR.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or the services we offer. When significant changes are made, we will update the "Last updated" date at the bottom of this page.

For substantial changes that affect how your data is processed, we will make reasonable efforts to notify you (e.g., via a notice on the Website or by email to newsletter subscribers). We encourage you to review this page periodically.

12. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, please contact us:

  • Data Controller: Yassine Labhih
  • Email: contact@yassite.com
  • Website: yassite.com

We are committed to resolving any concerns you may have about our data practices and will work with you to reach a fair and prompt resolution.

This Privacy Policy was last updated on February 20, 2026.

I use Analytics cookies to measure performance and improve your experience. This data helps me optimize the site.