Privacy policy
This policy describes the processing of personal data carried out by Coroni Security Systems Installation in connection with the use of this website, and the rights you have over your data.
1. Data controller
The data controller, within the meaning of Article 4(7) of the GDPR, is Coroni Security Systems Installation, whose full statutory identifiers appear in the site’s legal notice (mentions légales).
- Registered company name: CORONI
- Address: 128 rue Véron, 94140 Alfortville, France
- Telephone: +33 (0)1 82 01 90 10
- Email: contact@coroni.fr
2. What this site does not do
It is useful to begin with what does not happen, because it determines most of this policy:
- no audience measurement or traffic statistics of any kind;
- no advertising tracker, no profiling, no sale or rental of data;
- no social-network button or widget, no video hosted by a third party;
- no user account, no payment, no online sales;
- no request to any third-party server when a page loads: the typeface is hosted on the site itself rather than loaded from an external service, and the location map is loaded only after an explicit click. Your IP address is therefore disclosed to no third party merely by your reading the site.
3. Data collected
The only data the Publisher collects through this site is the data you voluntarily enter in the contact form:
| Data | Status | Source |
|---|---|---|
| Name | Required, to identify who is asking | Entered by you |
| Email address | Required, so that we can reply | Entered by you |
| Telephone number | Optional | Entered by you |
| Message | Required — the content of your enquiry | Entered by you |
No other data is collected by the site: no advertising identifier, no browsing history, no geolocation, no inferred data. No special-category data within the meaning of Article 9 of the GDPR is requested; please do not include any in your message.
The form is submitted to the site’s own server, hosted by Cloudflare, Inc., which forwards it as an email to the Publisher’s mailbox. No external form service is involved: the message passes through the site’s host and then the Publisher’s email service, provided by Google Ireland Limited (Google Workspace); both act as processors. If that send fails, the site offers to open your own email software with the message pre-filled; that send remains your own action alone.
Independently of the Publisher, the site’s hosting provider may keep technical connection logs including an IP address, for the security of the service and under the retention obligations incumbent on it. Those logs fall under its own responsibility and its own retention periods — Cloudflare, Inc..
4. Purposes and legal bases
| Purpose | Legal basis | Detail |
|---|---|---|
| Replying to an information request sent through the form or by email | Legitimate interest — Article 6(1)(f) GDPR | The legitimate interest consists in answering an enquiry you yourself initiated. |
| Studying a project and preparing a quotation (devis) | Pre-contractual steps — Article 6(1)(b) GDPR | Processing necessary to prepare the works contract under consideration. |
| Keeping a business prospect file and following up the relationship | Legitimate interest — Article 6(1)(f) GDPR | You may object at any time, without giving reasons, under Article 21 GDPR. |
| Performing and monitoring a works contract concluded following the enquiry | Performance of the contract — Article 6(1)(b) GDPR | This processing continues away from the site, in the Publisher’s management tools. |
If a consent tick-box is added to the form, for example for sending commercial information, the legal basis for that purpose becomes consent (Article 6(1)(a) GDPR), freely revocable at any time and without consequence for the handling of your original enquiry.
5. Retention periods
| Situation | Period applied |
|---|---|
| Information request not taken further | Three years from the last contact, in line with the CNIL’s recommendations on business prospecting. |
| Enquiry that led to an unsigned quotation | Three years from the date the quotation was issued. |
| Contractual relationship | The term of the contract, then intermediate archiving for the applicable limitation periods, in particular five years for contractual liability (Article 2224 of the Civil Code) and ten years under the garantie décennale (ten-year construction warranty). |
| Accounting and tax records | Ten years, under Article L123-22 of the Commercial Code. |
These periods have been set and confirmed by the controller, and are applied in practice. — these are proposed reference periods; they are a decision for the controller and must be confirmed, then actually applied.
At the end of those periods the data is deleted or anonymised.
6. Recipients and processors
Your data is intended solely for those people within the company who handle commercial enquiries and the technical study of projects. It is not sold, rented or disclosed for advertising purposes.
- The site’s hosting provider, for storing the site files and its technical logs: Cloudflare, Inc..
- The Publisher’s email provider, which routes and stores incoming messages: Google Ireland Limited (Google Workspace).
- Where applicable, legal advisers and court officers, and administrative or judicial authorities upon a lawful request.
The form is not connected to any external form service: it is handled by the site’s host and then delivered to the Publisher’s email service, both named above. If an external collection endpoint is configured later — a form service, a transactional messaging platform or a customer-relationship tool — the chosen provider will become a processor within the meaning of Article 28 GDPR: it must be covered by a compliant data-processing agreement and then named in this policy before going live.
7. Transfers outside the European Union
The site is hosted by Cloudflare, Inc., a company established in the United States, operating a global network. A transfer of technical connection data outside the European Union is therefore possible. In its privacy policy, Cloudflare states that it relies on its certification under the EU-U.S. Data Privacy Framework and, failing that, on the European Commission’s standard contractual clauses. No other transfer takes place: the site calls no third-party service on load and contains no analytics or advertising tooling. A copy of the safeguards relied on may be requested at the contact address given in the legal notice.
The Publisher’s email is provided by Google Workspace. The contact form’s message is carried by the site’s host, then received and retained by the Publisher’s email service. The processing terms and the safeguards covering transfers outside the European Union are those of the Google data processing agreement applicable to the Publisher.
If you ask for the location map to be displayed, your IP address is disclosed to the mapping service called at that moment, outside the Publisher’s control. This is detailed in the cookie policy.
8. Data security
The site is static: it has no database and no online administration area, which reduces its exposure accordingly. Pages are served over HTTPS.
The Publisher implements appropriate measures within the meaning of Article 32 GDPR: access restricted to authorised staff, minimisation of the data requested, and deletion of enquiries that have become moot at the end of the periods stated above.
9. Your rights
Under Articles 15 to 22 GDPR, you have the following rights over your data:
- right of access: to obtain confirmation that your data is processed and to receive a copy of it (Article 15);
- right to rectification: to have inaccurate or incomplete data corrected (Article 16);
- right to erasure: to obtain deletion of your data in the cases provided for (Article 17);
- right to restriction of processing, in particular while a challenge is being verified (Article 18);
- right to object, in particular to commercial prospecting, which is acted upon unconditionally (Article 21);
- right to portability of the data you provided, in a structured, machine-readable format (Article 20);
- right to withdraw your consent at any time, where processing is based on it;
- right to give directions as to what happens to your data after your death (Article 85 of French Law no. 78-17 of 6 January 1978 as amended).
No automated decision-making and no profiling within the meaning of Article 22 GDPR is carried out on this site.
10. How to exercise your rights
You may exercise your rights by email to contact@coroni.fr or by post to Coroni Security Systems Installation, 128 rue Véron, 94140 Alfortville, France, stating the right you are invoking.
You will receive a reply within one month of receipt of the request. That period may be extended by two months where the request is complex or where several requests are made, in which case you will be informed within the first month (Article 12(3) GDPR).
Proof of identity is requested only where there is reasonable doubt as to the identity of the person making the request, and is limited to what is strictly necessary.
11. Data protection officer
No data protection officer has been appointed: the Publisher falls into none of the cases of mandatory designation set out in Article 37 GDPR. Requests concerning personal data are handled at the contact address given in the legal notice.
Appointing an officer is mandatory under Article 37 GDPR only in specific cases — in particular large-scale systematic monitoring or large-scale processing of special-category data — which do not appear to be met by the processing described here. It remains optional and has not been presumed.
12. Data breaches
In the event of a data breach likely to create a risk to your rights and freedoms, the Publisher will notify the CNIL within seventy-two hours in accordance with Article 33 GDPR, and will inform you directly where the risk is high, in accordance with Article 34.
13. Complaint to the CNIL
If, having contacted us, you consider that your rights have not been respected, you may lodge a complaint with the French supervisory authority:
- Commission nationale de l’informatique et des libertés (CNIL) — the French data protection authority
- 3 Place de Fontenoy, 75007 Paris, France
- Telephone: +33 (0)1 53 73 22 22
- Website: www.cnil.fr
If you live in another Member State of the European Union, you may also contact the supervisory authority of your country of residence or of the place of the alleged infringement (Article 77 GDPR).
14. Changes to this policy
This policy is updated whenever the processing changes, in particular if a collection endpoint is added for the form, if an audience-measurement tool is introduced or if a new processor is engaged. The date of last update appears at the head and foot of this document.
Status and last update of this document
Last updated: 3 September 2026. This document is a template drafted solely from verified information: it must be completed, then reviewed and approved by a lawyer admitted to the French bar (avocat) before publication.
