Last updated: June 2026
This policy details our transparent approach to the collection, processing, and protection of your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Data Controller
Xavier MINALI Consulting
Registered office: Colomiers, France
Contact: Contact Form
2. Personal Data Collected and Processing Purposes
A. Primary Contact Form
Data collected:
- Identification data: First name, surname, job title
- Contact details: Professional email address, telephone number
- Professional data: Company name, industry sector
- Request data: Message content, specific project details, identified needs
Processing purposes: Processing inquiry requests, proposing digital transformation services tailored to organizational requirements.
Legal basis: Legitimate interest of the data controller (Article 6.1.f GDPR)
Retention period: 36 months from last contact or until consent withdrawal
B. RESONANCE™ Diagnostic Assessment
Data collected:
- Complete identification data (name, surname, position, company)
- Professional coordinates (email, telephone, postal address)
- Organizational information (headcount, turnover, sector)
- Assessment data (questionnaire responses, organizational challenges)
- Digital maturity data (evaluation of existing processes)
Processing purposes: Generation of personalized digital transformation diagnostics, development of targeted strategic recommendations.
Legal basis: Explicit consent of the data subject (Article 6.1.a GDPR)
Retention period: 60 months to enable long-term transformation tracking
C. Tracking Technologies (Cookies and Tracers)
Categories of cookies deployed:
| Category | Purpose | Retention Period | Deactivation |
|---|---|---|---|
| Strictly Necessary Cookies | Technical website functionality, session security | User session | Non-modifiable |
| Analytics Cookies | Audience analysis, user experience optimization | 24 months maximum | Via consent banner |
| Marketing Cookies | Content personalization, performance measurement | 12 months maximum | Via consent banner |
Consent management: Technical solution compliant with ePrivacy directive for prior consent collection
3. Processing Purposes and Data Usage
Your personal data is exclusively processed for the following purposes:
- Commercial inquiry management: Analysis and response to your requests
- Recommendation personalization: Adaptation of our advice to your organizational context
- Commercial communication: Information about our resources and services (on explicit opt-in)
- Continuous improvement: Anonymized statistical analysis for service optimization
- Legal obligations: Compliance with accounting, fiscal, and regulatory requirements
Confidentiality commitment: No personal data is transferred, sold, or shared with third parties for commercial purposes. All data is protected by enhanced cybersecurity measures.
4. Data Recipients and Transfers
A. Authorized Processors
Your data may be transmitted to the following technical service providers:
- Web hosting: SiteGround (European Union) - ISO 27001 certified secure infrastructure
- Professional messaging: Google Workspace - GDPR-compliant data processing agreement
- Analytics tools: Google Analytics (anonymized data) - Privacy-compliant configuration
B. Protection Guarantees
- Data processing agreements compliant with Article 28 GDPR
- Transfers exclusively to European Union or adequately protected countries
- Data encryption in transit (TLS 1.3) and at rest (AES-256)
- Regular security audits of service providers
5. Data Subject Rights (GDPR)
In accordance with GDPR, you have the following rights regarding your personal data:
| Right | Description | Exercise Procedures | Response Time |
|---|---|---|---|
| Right of Access | Obtain confirmation of processing and copy of your data | Written request with identity verification | 30 days maximum |
| Right to Rectification | Correct or complete inaccurate data | Reasoned request | Immediate processing |
| Right to Erasure | Data deletion ("right to be forgotten") | Justified request under Article 17 GDPR | 30 days maximum |
| Right to Portability | Retrieve your data in structured format | For data collected with consent | 30 days maximum |
| Right to Object | Refuse certain processing activities | Legitimate grounds relating to your situation | Immediate effect |
| Right to Restriction | Temporarily suspend processing | Conditions provided in Article 18 GDPR | 30 days maximum |
Exercise of rights: Secure contact form with identity verification
6. Data Security and Retention
A. Technical and Organizational Security Measures
- Enhanced encryption: SSL/TLS certificate with A+ rating (SSLLabs)
- Access control: Mandatory multi-factor authentication
- Secure backups: AES-256 encryption, geographically distributed retention
- Continuous monitoring: Real-time intrusion detection
- Staff training: GDPR awareness and security best practices
B. Data Retention Periods
| Data Category | Retention Period | Justification |
|---|---|---|
| Unconverted prospects | 36 months after last contact | Reasonable commercial follow-up period |
| Active client data | 10 years after relationship end | Accounting and fiscal obligations |
| Analytics cookies | According to user settings | Duration chosen during consent |
| Technical logs | 12 months maximum | IT security and debugging |
7. Advanced Cookie Management
Our website uses a cookie management solution compliant with CNIL requirements and the ePrivacy directive.
A. Strictly Necessary Cookies (Always Active)
- User session identifiers
- CSRF (Cross-Site Request Forgery) security tokens
- Language and accessibility preferences
- Shopping cart and contact processes
B. Optional Cookies (Subject to Consent)
Analytics Cookies:
- Google Analytics 4 (privacy-compliant configuration)
- Anonymized audience measurements
- User experience optimization
Marketing Cookies:
- Content personalization based on your interests
- Campaign effectiveness measurement
- Advertising retargeting (with explicit consent)
C. Settings and Consent Withdrawal
You can modify your cookie preferences at any time via the "Cookie Management" link available in the page footer. Withdrawal of your consent does not affect the lawfulness of processing based on consent before such withdrawal.
8. Contact and Complaints
A. Data Protection Officer (DPO)
Xavier MINALI (Internal delegate)
Function: Data protection officer
Contact: Dedicated contact form
B. Competent Supervisory Authority
In case of unresolved disputes regarding the processing of your personal data:
Commission Nationale de l'Informatique et des Libertés (CNIL)
Address: 3 Place de Fontenoy, 75007 Paris, France
Website: www.cnil.fr
Telephone: +33 1 53 73 22 22
9. Privacy Policy Modifications
This privacy policy may be amended to account for:
- Changes in European and French regulations
- New services or features offered
- Improvement of our data protection practices
- Recommendations from supervisory authorities
Notification procedure: Any substantial change will be communicated by email to data subjects with 30 days advance notice before implementation. Minor modifications will be signaled by updating the revision date.
10. International Data Transfers
In the event of data transfers to countries outside the European Union, we undertake to:
- Verify adequate level of protection recognized by the European Commission
- Implement appropriate safeguards (EU Standard Contractual Clauses)
- Obtain your explicit consent if necessary
- Transparently inform you of such transfers
Privacy-Related Inquiries Contact
For any questions regarding this privacy policy, the exercise of your GDPR rights, or our data protection practices, please contact us via our secure contact form.
We undertake to respond promptly and transparently to all inquiries.
This privacy policy applies to all personal data processing activities of xavierminali.com, including the website, electronic communications, consulting services, and any commercial interaction.
