Privacy Policy
Last updated: 06/08/2026.
​
Rogue Media respects your privacy. This policy explains what personal data we collect through this website, why we collect it, who has access to it, how long we keep it, and what rights you have over it.
It is written in accordance with Regulation (EU) 2016/679 (GDPR / RGPD) and the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978, as amended).
1. WHO IS RESPONSIBLE FOR YOUR DATA
The data controller for this website is:
Tiphaine Stucki, entrepreneur individuel, trading under the name Rogue Media SIREN: 890 320 625 APE/NAF code: 7022Z -- Conseil pour les affaires et autres conseils de gestion, registered at Les Clayes-sous-Bois, France
​
Contact for all privacy matters: privacy@werogue.io
Â
We are not required to appoint a Data Protection Officer under Article 37 GDPR, and have not done so. All requests should be sent to the address above.
2. WHAT DATA WE COLLECT
2.1 Data you give us through the contact form
When you submit the contact form, we collect:
-
Your name to address you correctly in our reply (required);
-
Your company to understand the context of your enquiry (required);
-
Your email address to reply to you (required);
-
Your message to understand what you are asking (required).
​
Please do not include special category data (Article 9 GDPR) in your message -- data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. We do not need it and do not want to hold it.
2.2 Data collected automatically
Technical data. Our hosting platform records standard server data when you visit: your IP address, the date and time of your request, the pages you requested, your browser type and operating system, and the page that referred you. This is necessary to deliver the site to you and to keep it secure.
​
Audience measurement. Subject to your consent, we use Wix Analytics to understand how the site is used -- how many people visit, which pages they read, roughly where in the world they are, and whether they arrived from a search engine, a social platform, or a direct link. This is aggregated statistical information. We use it to improve the site, not to identify you.
2.3 What we do not do
This website does not:
-
Operate a newsletter or mailing list
-
Use advertising or retargeting pixels
-
Sell, rent, or trade your data to anyone
-
Carry out automated decision-making or profiling within the meaning of Article 22 GDPR
3. Why we process your data, and on what legal basis
Purpose and legal basis attached:
-
Replying to your enquiry and discussing a possible collaboration --Â 6(1)(b) steps taken at your request prior to entering into a contract;
-
Keeping a record of business enquiries and managing our commercial pipeline --Â 6(1)(f)Â our legitimate interest in developing our business;
-
Delivering the website and keeping it available, functional and secure --Â 6(1)(f) our legitimate interest in the integrity of our website;
-
Audience measurement and site improvement --Â 6(1)(a) your consent, given through the cookie banner;
-
Complying with our accounting and tax obligations --Â 6(1)(c) compliance with a legal obligation.
​
Where we rely on legitimate interest, we have weighed our interest in operating a business website against your rights and freedoms, and consider that the limited, non-sensitive nature of the data involved does not override them. You may object at any time -- see Section 7.
​
Where we rely on consent, you may withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
4. Who has access to your data
Your data is accessed by the data controller and by the persons working with her under her authority within Rogue Media, and by the technical service providers listed below. We do not share your personal data with any third party for their own purposes.
4.1 Our processors
Wix.com Ltd.
Role:Â Website hosting, contact form processing and storage, audience measurement
Location:Â Israel, with sub-processors in the EU and the United States
Safeguard:Â Israel benefits from a European Commission adequacy decision (Decision 2011/61/EU). For onward transfers to the United States, Wix's Data Processing Addendum incorporates the EU Standard Contractual Clauses (Decision 2021/914).
​
Google Workspace.
Role:Â Receiving and storing contact form notifications in our inbox
Location:Â Israel, with sub-processors in the EU and the United States
Safeguard:Â Israel benefits from a European Commission adequacy decision (Decision 2011/61/EU). For onward transfers to the United States, Wix's Data Processing Addendum incorporates the EU Standard Contractual Clauses (Decision 2021/914).
​
Wix acts on our documented instructions under a data processing agreement meeting the requirements of Article 28 GDPR. Wix's own privacy practices are described at wix.com/about/privacy.
​
You may request a copy of the safeguards applying to any transfer outside the European Economic Area by writing to privacy@werogue.io.
4.2 Legal disclosure
We may disclose your data where legally obliged to do so -- for example in response to a valid order from a court or a competent public authority. We will not disclose data on the basis of an informal request.
5. How long we keep your data
Data and retention:
-
Contact form enquiries where no commercial relationship follows --Â 3 years from our last contact with you, in line with CNIL guidance on prospect data;
-
Contact form enquiries leading to a commercial relationship --Â For the duration of the relationship, then for the applicable statutory limitation periods -- up to 10 years for accounting records under Article L123-22 of the French Commercial Code;
-
Server and technical logs --Â 12 months maximum, in line with CNIL recommendations
-
Audience measurement data --Â 13 months maximum for the cookies themselves; 25 months maximum for the resulting statistics, in line with CNIL recommendations.
​
At the end of the applicable period, data is deleted or irreversibly anonymised.
6. Security
We take appropriate technical and organisational measures to protect your data:
-
Encryption in transit -- the whole site is served over HTTPS with a valid TLS certificate
-
Access control -- access to contact submissions is restricted, protected by strong unique credentials and two-factor authentication
-
Data minimisation -- we collect only what is needed to answer your enquiry
-
Vendor selection -- we use an established platform that contractually commits to GDPR-compliant security standards
​
No system is perfectly secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the CNIL within 72 hours as required by Article 33 GDPR, and will notify you directly where the breach is likely to result in a high risk to you.
7. Your rights
Under the GDPR you have the right to:
-
Access (Art. 15) -- obtain confirmation of whether we process your data, and a copy of it
-
Rectification (Art. 16) -- have inaccurate data corrected and incomplete data completed
-
Erasure (Art. 17) -- have your data deleted where one of the grounds in Article 17 applies
-
Restriction (Art. 18) -- have processing limited in certain circumstances
-
Portability (Art. 20) -- receive your data in a structured, commonly used, machine-readable format
-
Object (Art. 21) -- object at any time to processing based on our legitimate interest, on grounds relating to your particular situation
-
Withdraw consent (Art. 7(3)) -- withdraw your consent to audience measurement at any time, via the cookie settings link in the footer
-
Give post-mortem directives -- under Article 85 of the French Data Protection Act, you may give instructions on the storage, erasure and disclosure of your data after your death
​
How to exercise them
​
Write to privacy@werogue.io. We will respond within one month of receiving your request, as required by Article 12(3) GDPR. For complex requests this may be extended by two further months, in which case we will tell you within the first month and explain why.
​
We may ask for information to confirm your identity, but only where we have reasonable doubts about who is making the request. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
​
Complaints
Â
If you believe we have not handled your data lawfully, you may lodge a complaint with the French supervisory authority:
Â
Commission Nationale de l'Informatique et des Libertés (CNIL) 3 Place de Fontenoy -- TSA 80715 75334 Paris Cedex 07, France Tel: +33 (0)1 53 73 22 22 -- www.cnil.fr
You may also complain to the supervisory authority of the EU Member State where you live or work.