Privacy policy

What is collected when you visit geoany.xyz or book an audit, why, for how long, and how to have it deleted.

Updated 27 September 2026

Who is responsible

Geoany, reachable at [email protected]. Geoany is the only person with access to the data.

What is collected

When you book an audit on call.geoany.xyz: first name, last name, email address and phone number, the chosen slot, and the source code of the visit (the site button or link that brought you). Your details are saved at the first step of the form, before you pick a slot, so we can get back to you if the booking stops halfway.

When you visit geoany.xyz: first-party audience measurement records pages viewed, buttons clicked, sections reached, scrolling and reading time, linked to a random visitor ID. Your IP address is never stored: only an encrypted fingerprint that changes every day is used to filter duplicates.

When you write to us by email or WhatsApp: the content of your messages and your contact details.

Nothing is guessed, bought or collected elsewhere.

What it is used for

To organise and hold the audit you asked for: confirm the appointment, send the video link, remind you the day before, and contact you once if no slot was ever picked.

To understand what works on the site: which pages are read, which buttons lead to an audit. These figures are only used to improve geoany.xyz.

Nothing else: no resale, no advertising, no newsletter sign-up without an explicit request.

Legal basis

Booking an audit is a pre-contractual step you request (Article 6(1)(b) GDPR). Following up on an unfinished form and audience measurement rely on the legitimate interest in improving the service and resuming a conversation you started (Article 6(1)(f)); just say so and they stop.

Who else sees it

Four technical providers, each for a single task:

OVH SAS (Roubaix, France) hosts the booking and measurement server; this data stays in France. Cloudflare, Inc. (USA) hosts the site's pages and routes traffic. Resend, Inc. (USA) sends the confirmation email and its calendar invite. Telegram (Telegram FZ-LLC, UAE) carries the notification telling Geoany a booking was made.

Transfers outside the European Union are covered by the European Commission's standard contractual clauses. No other recipient, no data broker, no ad network.

How long

Details left for an audit: three years from the last exchange, as recommended by the CNIL, then deleted. Audience measurement data: 25 months at most, automatically deleted every night beyond that. A deletion request is honoured before these periods, no questions asked.

Cookies and local storage

No advertising cookies, no third-party cookies, no external analytics tool. Only three items:

_vs, on geoany.xyz, 13 months: the random ID used for audience measurement. It holds no name or address and is only read by geoany.xyz.

at, on geoany.xyz subdomains, 6 months: the code of the link or button that brought you to the booking page, to know which one actually leads to an audit. It holds only that code.

Browser local storage: the light or dark theme and the chosen language. These preferences never leave your device.

This measurement is strictly limited to geoany.xyz statistics, with no cross-site tracking or combination with other data, which puts it under the consent exemption set by the CNIL: that is why no banner is shown. To opt out, block cookies in your browser (browsing and booking still work) or write to [email protected].

Your rights

Access, rectification, erasure, restriction, objection and portability are exercised by a simple email to [email protected], answered within one month. If you disagree, you can file a complaint with the CNIL (cnil.fr, 3 place de Fontenoy, 75007 Paris, France).

Security

All exchanges use HTTPS end to end, the data lives on a server in France accessible only to Geoany, and no account or password is created on your side.