Privacy Policy
In short: this website intentionally collects nothing. No cookies, no trackers, no analytics, no share buttons, no third-party services. You have no account, no profile, and nothing to configure.
This policy describes, in accordance with Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and the amended French Act n° 78-17 of 6 January 1978 (Informatique et Libertés), how Zektyc processes personal data.
1. Data controller
The data controller is Zektyc, France. For any question relating to your personal data: riric65@protonmail.com.
2. Data we process
2.1 No active collection
The website has no accounts, no forms, no newsletter, no social media buttons and no analytics services. We do not ask for, record or intentionally use any data about you.
2.2 Technical connection logs
Like any server, the infrastructure hosting the website automatically generates technical logs for security purposes (prevention and handling of attacks, abuse and attempts to overwhelm the service). These logs may contain:
- the IP address of the connection;
- the date and time of the request;
- the requested resource;
- the browser type (user agent).
These logs are retained for a maximum of fourteen (14) days and then automatically deleted. They are neither sold, nor shared, nor used for profiling. Their legal basis is the data controller's legitimate interest in securing its service (Article 6.1(f) GDPR). The IP addresses in these logs are not cross-referenced with any other source.
2.3 Exchange data (contact)
If you contact us by e-mail, Signal or Discord, the information you choose to share (e-mail address, identifier, message content) is used solely to respond to your request. It is not used for marketing, is not shared with third parties and is not retained beyond the time needed for the exchange. By messaging us, you freely choose to provide us with this data (Article 6.1(a) GDPR).
2.4 Data processed in memory
To protect the website from abuse, a per-IP request counter is kept in the server's random-access memory (RAM), with a maximum window of a few minutes. This data is never written to persistent storage, is never consulted individually and disappears when the server restarts.
2.5 Vulnerability reports (responsible disclosure)
If you report a vulnerability to us, in accordance with Section 6 of the Terms of Service, the information you send us (technical details, proof of concept, screenshots, any contact details) is processed solely for the purpose of assessing, fixing and verifying the fix of the reported vulnerability. It is not shared with third parties, is not used for any other purpose and is deleted once the fix is confirmed, in accordance with Section 6.
2.6 Verification of an authority or a request
When a person claims to act on behalf of a public authority and requests the disclosure of information, in accordance with Section 7 of the Terms of Service, the documents provided to justify their identity and the scope of their powers (official documents, references) constitute personal data processed temporarily. This processing is based on a legal obligation or on the controller's legitimate interest in verifying the merits of the request. The documents are retained solely for the duration of the verification, then deleted; they are never used for any other purpose.
3. Cookies
The website uses no cookies, first- or third-party, no tracking technologies (including canvas or device fingerprinting) and no local storage (localStorage, sessionStorage, IndexedDB). No consent banner is therefore required under Directive 2002/58/EC (ePrivacy) and the GDPR.
4. Recipients and sub-processors
We do not share, sell or transmit your data to any third party, advertising network or analytics provider. The website is hosted on our own infrastructure, in France, without recourse to any third-party hosting sub-processor.
Our e-mail service is provided by Proton Mail (Proton AG, Switzerland), which acts as a technical sub-processor within the meaning of Article 28 GDPR for the transmission and hosting of the messages you send us. This relationship is governed by a GDPR-compliant processing agreement; Proton processes these messages solely for the purpose of providing the service, uses them for no other purpose and does not share them.
Exchanges made via Signal and Discord transit through the servers of their respective providers (Signal Messenger, LLC and Discord Inc.), which process the messages solely for the purpose of transmitting them; Signal encrypts messages end to end, which Discord does not.
5. Transfers outside the European Union
The website is hosted in France. Data processed by the website itself is not transferred outside the European Union or the European Economic Area (Articles 44 et seq. GDPR), and the website uses no external platform or CDN likely to process data.
Regarding the e-mail contact channel: Proton Mail is operated from Switzerland, a country benefiting from an adequacy decision of the European Commission under Article 45 GDPR. The e-mail messages you send us are therefore subject to a transfer to a third country accompanied by appropriate safeguards recognised by the European Commission.
Regarding Signal and Discord: their servers may be located outside the European Union (including the United States). Signal implements end-to-end encryption, so that the content of messages is never accessible to any third party; this encryption limits the real risk of this transfer despite the absence of an applicable adequacy decision. As Discord does not encrypt messages end to end, avoid exchanging sensitive data there.
6. Retention periods
- Technical logs: 14 days maximum, automatic deletion;
- In-memory protection counters: a few minutes, never persisted;
- Exchange data (contact): for the duration needed to handle your request;
- Vulnerability reports: until confirmation that the vulnerability has been fixed, then deletion within a courtesy period of thirty (30) days;
- Documents for the verification of an authority: for the duration of the verification, then deletion.
7. Security
The website is protected by the following technical measures:
- end-to-end encrypted connection (HTTPS / TLS);
- restrictive security headers (CSP, nosniff, clickjacking, HSTS, permissions);
- rate limiting and blocking of abusive behaviour;
- restriction of HTTP methods and sensitive paths;
- data minimisation and limited retention.
8. Your rights
In accordance with Articles 15 to 22 GDPR, you have the following rights:
- right of access;
- right to rectification;
- right to erasure (“right to be forgotten”);
- right to restriction of processing;
- right to data portability;
- right to object.
You may exercise these rights at any time by contacting us at: riric65@protonmail.com. We respond within a maximum of one month, in accordance with Article 12 GDPR.
You also have the right to lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or via cnil.fr.
9. Minors
The website is not specifically directed at minors and implements no mechanism targeting them. We intentionally collect no data from minors.
10. Changes to this policy
We may amend this policy to reflect technical or legal changes. The applicable version is the one online; the date of the last update appears at the top of the page.
11. Contact
For any question about this policy, your rights, or to exercise any of them: riric65@protonmail.com.
Version française de référence : Politique de confidentialité (FR).