Legal
Privacy policy.
The short version: no cookies, no trackers, no audience measurement. We only process what you send us yourself.
This is a translation. The French version is the one that binds.
Why there is no cookie banner
Because this site sets no cookie. Not for measurement, not for advertising, not for sessions. Consent is required for reading or writing on your device beyond what the service strictly needs, and we write exactly one thing: your light or dark preference, in your browser’s local storage, because you clicked the button that changes it. It never leaves your machine and serves nothing else.
A banner that asks permission for nothing mostly teaches people to click without reading the ones that ask for real. The day an audience measurement tool is added, this page and that decision both have to be reopened.
The forms are protected by Turnstile, Cloudflare’s anti-robot challenge. It was chosen precisely because it sets no tracking cookie and builds no advertising profile: it looks at how the browser behaves during the submission, and at nothing beyond that. That is what lets this site keep a public form and still have no banner.
What we collect
The only personal data we process is what you send us yourself in a form: name, company, email address and the content of your message. No field is filled in without your knowledge, none is inferred from your browsing.
What becomes of your message, in full. It is sent to a function hosted on our own domain, which checks the anti-robot challenge and then hands it to Resend, our sending provider, which turns it into an email to our inbox. It is written to no database, no file, no queue, and it appears in no application log: all we keep of the operation is whether it succeeded or failed. Past that moment your message exists only in our mailbox, where it lives like any other email we receive.
Our host, Cloudflare, keeps technical connection logs including IP addresses, to keep the service secure and available. We have no access to them and derive no statistics from them. Your IP address is also passed to the anti-robot challenge at the moment you submit, for that check alone.
Transfers outside the European Union
Three processing operations leave the Union, all three towards companies under United States law which adhere to the Data Privacy Framework and cover those transfers with the European Commission’s standard contractual clauses.
The technical logs and the anti-robot challenge of our host, Cloudflare. The routing of your message by our sending provider, Resend, which handles it for the time of the delivery and is not meant to keep it beyond. And the email itself, whose routing then depends on our mail provider.
None of these transfers concerns data collected without your knowledge: two are technical checks any public site runs, the third is a message you wrote and sent deliberately.
What we do with it
Answer you, and nothing else. This data is neither sold, nor rented, nor passed to third parties. It is kept for the duration of the commercial relationship, then for at most three years after the last contact. The legal basis is the legitimate interest in answering a request you initiated.
Site search
Search runs entirely in your browser. On first use it downloads the site index, then queries that index locally. No search query is sent or recorded anywhere.
Your rights
Under the GDPR you have a right of access, rectification, erasure, restriction and objection over your data. An email to contact@apim.one is enough, and we answer within thirty days. You may also complain to the French supervisory authority, the CNIL, cnil.fr, or to the authority of the country you live in.
Data controller
APIM One, a company being registered, represented by Azzeddine Daghoui. Contact: contact@apim.one. The full details are in the legal notice.