Privacy Policy
ONG Conseil is committed to protecting your personal data. This policy explains what data we process, why, for how long, and how to exercise your rights under the General Data Protection Regulation (GDPR).
Data controller
The data controller is ONG Conseil, 60 Boulevard de Sébastopol, 75003 Paris, France. For any questions about your data or to exercise your rights: rgpd@ongconseil.org.
Data collected
We process the data entered in our forms and the technical data needed to secure them, measure aggregate traffic and diagnose Content Security Policy (CSP) violations:
- Contact form: first name, last name, email address, organisation and, if you wish, a message.
- Application forms: first name, last name, email address, desired role or field, and your message (motivation, links to CV/portfolio you choose to add).
- Anti-abuse protection: IP address, user agent and normalised email address used to compute SHA-256 hashes in temporary counters. These hashes are pseudonymised, not anonymous. Application logs only record masked versions of the IP and email, together with the timestamp and event metadata.
- CSP reports: when a violation occurs, the browser may automatically send the directive, relevant URLs, source file, line and report disposition. Before logging, only URL origins are retained, without paths, query parameters, fragments or credentials. The IP address is logged only in masked form.
- Edge audience measurement: Cloudflare processes the network and request metadata needed for Zone Analytics, which may include the IP address, requested URL, timestamp and derived country. Its dashboard provides aggregate metrics such as requests, bandwidth and unique visitors. No analytics script or cookie is loaded in your browser.
Fields marked as required are necessary to send and process your request: without them, the form is not submitted. The contact-form message and the desired role or field in a speculative application are optional; the motivation requested in application forms is required.
We do not carry out advertising profiling and never buy or sell data.
Purposes and legal bases
- Responding to a general question or contact request. Legal basis: legitimate interest in answering the request.
- Handling a demo or service request initiated by you. Legal basis: pre-contractual measures.
- Receiving, filing and reviewing your application. Legal basis: pre-contractual measures taken at your request.
- Keeping, for future opportunities, the profile of an unsuccessful candidate whose application is of interest, unless they object. Legal basis: legitimate recruitment interest.
- Ensuring site security and preventing abuse. Legal basis: legitimate interest in protecting the service and its users.
- Understanding aggregate site usage and managing its availability, performance and technical operation. Legal basis: legitimate interest in measuring and improving the service without advertising profiling.
The required form checkbox confirms that you have read this information; it is not the legal basis for processing.
Recipients and processors
Your data is accessible to authorised ONG Conseil staff according to the nature of the request and to the technical providers needed to operate the site:
- Resend: transactional delivery of the complete form fields, closed subject, masked IP and timestamp to the destination mailbox.
- Google Workspace (Google): receipt and retention of requests in the destination mailbox. That mailbox address is not published.
- Cloudflare: hosting, security, function execution, anti-abuse counters in private technical storage, technical logs and Zone Analytics. Like any edge host, Cloudflare receives the network IP address.
Transfers outside the European Union
Cloudflare, Resend and Google may process data outside the European Union. Where required by the GDPR, such transfers are covered, depending on the provider and flow concerned, by an adequacy decision, including the EU-US Data Privacy Framework, and/or by the European Commission's Standard Contractual Clauses incorporated into data processing agreements. To learn which safeguards apply to your request, email rgpd@ongconseil.org.
Retention periods
- Contact data in Google Workspace: up to 12 months after the last exchange.
- Applications: for the duration of the recruitment process. For unsuccessful profiles of interest for future opportunities only: up to 24 months after the last contact, unless the candidate objects or requests erasure.
- Email data and delivery logs at Resend: 30 days on the standard plans used by the service.
- Anti-abuse counters: 60-second windows for the IP and user-agent fingerprint and for the IP alone, and 10-minute windows for the email address; global and per-IP daily counters expire at the next UTC midnight (no more than 24 hours). Expired records are normally purged automatically within 15 minutes, subject to technical incidents; a delayed purge does not extend the control window.
- In-memory CSP-report limiter: 60-second control window; an expired entry may remain in memory until a later request or the instance is destroyed.
- Contact and CSP-report application logs: live-stream viewing only in Cloudflare Pages Functions; that interface does not retain them. Cloudflare's own network logs and metrics follow the windows of its plan.
- Zone Analytics: history is available for the window provided by the active Cloudflare plan; this product- and plan-dependent window is the retention criterion. ONG Conseil has configured no separate analytics export or data warehouse.
- Functional preferences (theme, language and entrance screen): until they are cleared in the browser settings.
- Technical
__Host-csrf_tokencookie: 2 hours; the token copy remains in the tab session until the tab is closed or the token is invalidated.
Your rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and, where its conditions apply, portability. To exercise them, write to rgpd@ongconseil.org. You may also lodge a complaint with the French data protection authority, the CNIL.
Security
We implement appropriate technical and organisational measures: encryption in transit (HTTPS), anti-abuse protection of the forms (CSRF token, rate limiting), data minimisation and masking, and hosting within a secure infrastructure.
Cookies
The details of cookies and local storage are set out in our cookie policy.