Privacy policy
Data controller
The data controller is KOLOSALTech, a French SASU registered with the Trade and Companies Register of Rennes under number 106 103 047 (RCS Rennes 106 103 047), with its registered office at 3 Rue de Robien, 35000 Rennes, France, for the personal data collected on this site as part of the commercial relationship and quote requests.
Contact for any question regarding personal data: contact@kolosaltech.com. (No Data Protection Officer is required given the size and activity of the company.)
Data collected
Via the contact form: name, organization, country, email, phone, type of need and message. Data collected solely to respond to your request.
Callback requests collect a name, phone number, optional company, preferred time and optional message. Equipment-list requests collect a name, email, optional company, message and the transmitted file.
The sales assistant remains a local demonstration: no entered text, AI API call or conversation storage is involved.
Purpose and legal basis
Response to your commercial requests, qualification of the need, issuing of quotes, order tracking and post-delivery support.
Legal bases for processing (art. 6 GDPR):
- Pre-contractual measures and performance of the contract (art. 6.1.b): handling quote requests, orders and support.
- Legitimate interest (art. 6.1.f): commercial relationship, measured B2B prospecting and site security.
- Legal obligation (art. 6.1.c): retention of accounting and invoicing records.
- Consent (art. 6.1.a): newsletter subscription and audience measurement subject to the cookie banner.
Retention period
Prospect data is kept for 3 years after the last contact. Client data is kept for the duration of the commercial relationship and then 5 years for accounting and legal purposes.
The site does not retain equipment-list files permanently. They are checked in memory and attached to an internal email. Resend and the destination mailbox retention periods still need validation before production.
Your rights
In accordance with the GDPR: right of access, rectification, erasure, objection and portability. To exercise these rights:
Cookies & trackers
This site uses a limited number of cookies/trackers, in accordance with the CNIL guidelines:
- Functional cookies (no consent required):
kolosal-quote-cart(localStorage): multi-product quote cart — stored until deleted by the user or the browser
- Subject to your consent:
- Audience measurement (Vercel Analytics): anonymized, no personal data collected, no profiling — enabled only after acceptance.
- Conversion events: event name, language, placement and generic catalog identifiers only; no name, email, phone, message or filename is sent.
kolosal-ab-hero-cta(cookie): A/B variant for CTA display, anonymous, duration 30 days — set only after acceptance.
- No third-party advertising tracking cookies (Google Ads, Facebook Pixel, etc.)
Functional local storage includes the quote cart and form drafts, which are automatically deleted after seven days. The banner choice is stored inkt-consent-v1.
You can change your choice at any time with the button below, or block cookies in your browser settings.
Hosting and processors
List of processors with access to your data:
- Vercel Inc. (web hosting and consented analytics) — USA + international CDN
- Resend, Inc. (transactional email sending) — EU + USA
- Airtable, Inc. (lightweight CRM) — USA
- Stripe Payments Europe Ltd. (online payments) — Ireland/EU — PCI-DSS
- Hostinger International Ltd. (DNS and professional email management) — EU
- Slack, Discord or an automation platform (lead notification) — only if an optional webhook is enabled after contractual review
Contracts, DPAs, effective processing regions and retention periods for these services must be checked by the data controller before production.
International transfers
Some data may transit through servers located outside the EU (mainly the United States). Applicable contractual safeguards, Standard Contractual Clauses and certifications must be verified before each processor is enabled.
Security
Technical measures implemented:
- HTTPS (TLS 1.3) across the entire site
- Rate limiting on API endpoints (anti-spam, anti-abuse)
- HTTP security headers (X-Frame-Options, CSP, etc.)
- Anti-bot honeypot on all forms
- No user password stored on the site side (delegated auth)
- Encryption of secrets via Vercel Secrets
CNIL complaint
If you believe your rights are not being respected, you can lodge a complaint with the CNIL.
