Last updated: April 10th, 2026
Hyperion Consulting (SASU)
SIRET: 94804171000013
TVA: FR73948041710
126 Avenue du General Leclerc, 92100 Boulogne-Billancourt, France
contact@hyperion-consulting.io
Director: Mohammed Cherifi
For the purposes of the General Data Protection Regulation (GDPR), the data controller is:
Hyperion Consulting
Given the size and nature of our operations, the appointment of a Data Protection Officer (DPO) is not mandatory under Article 37 of the GDPR. However, for all data protection inquiries, you may contact:
A Record of Processing Activities (ROPA), as required by Article 30 of the GDPR, is maintained internally and is available upon request to the supervisory authority.
We collect several categories of information:
Information that can directly or indirectly identify you:
We use cookies and similar tracking technologies. See Section 9 for detailed information.
We process your personal data based on the following legal grounds:
We use your personal data for the following purposes:
When collecting data, we will indicate whether providing certain information is:
Consequences of not providing mandatory data: We may not be able to provide certain services to you.
We retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy:
Enquiries and CRM contacts
duration of the relationship plus 2 years, then deleted by the weekly retention sweep
Prospect records (outbound research)
2 years from last activity, then deleted
CRM activity logs
3 months
Lead qualification scores and enrichment
90 days
AI assistant conversations and agent memory
30 days from last activity
Assessment submissions and attachments
with the CRM contact record; attachments are not retained after analysis
Marketing subscriptions
until you withdraw consent, or 2 years after last interaction
Marketplace accounts
for the life of the account; 30 days after deletion request, then permanently purged
Payment records (Stripe/PayPal)
10 years, as required by French commercial and tax law
Data-subject request records
3 years, as evidence that requests were handled
Compliance register entries
7 days if never completed, 90 days otherwise
Error monitoring and session replay
90 days (Sentry default)
Operational alerts (Slack/Telegram)
retained in those channels per their own settings
Backups
30 days rolling, after which restores are no longer possible
Technical logs
3 months
Cookies and browser storage
see Section 9
Your personal data may be shared with the following categories of recipients:
We use the following sub-processors to operate our services. Each is bound by a Data Processing Agreement (DPA) compliant with GDPR Article 28:
Mistral AI
Large-language-model inference for chatbot and AI Readiness Assessment
📍 France (EU)
DPA / PrivacyResend
Transactional and marketing email delivery
📍 United States (EU Standard Contractual Clauses in place)
DPA / PrivacyStripe Payments Europe, Ltd.
Marketplace subscription payment processing
📍 Ireland (EU) with transfers to the United States under SCCs
DPA / PrivacyPayPal (Europe) S.à r.l. et Cie, S.C.A.
Alternative marketplace payment method
📍 Luxembourg (EU)
DPA / PrivacySentry (Functional Software, Inc.)
Application error monitoring and performance telemetry
📍 United States (EU Standard Contractual Clauses in place)
DPA / PrivacyGoogle Analytics 4 (Google Ireland Ltd.)
Anonymized website analytics with Consent Mode v2. Client-side tracking tag activates only on explicit opt-in. GA4 Data API also used server-side by the admin dashboard for aggregated reporting.
📍 EU data processing, sub-transfers to the United States under SCCs
DPA / PrivacyCloudflare Web Analytics (Cloudflare, Inc.)
Real-time website performance and traffic analytics (RUM — Real User Monitoring). Cookieless and privacy-friendly: no persistent cookies, no cross-site tracking, no fingerprinting. Collects aggregated page-view and Core Web Vitals metrics.
📍 United States (EU Standard Contractual Clauses in place)
DPA / PrivacyUpstash / local Redis
Session store, rate-limit counters, cache
📍 Self-hosted in France (EU) on the OVHcloud VPS
DPA / PrivacyCloudflare, Inc. (R2 Object Storage)
Object storage for product-delivery assets and off-site backups
📍 European Union (EU-jurisdiction bucket); Cloudflare is a US-headquartered company — transfers covered by EU Standard Contractual Clauses
DPA / PrivacyTwenty CRM (self-hosted)
Customer-relationship records for enquiries, leads and assessment submissions. Self-hosted on our own OVHcloud infrastructure in France — the software vendor has no access.
📍 France (EU) — our own infrastructure
DPA / PrivacySlack (Salesforce)
Internal operational alerts. Receives page, referrer, user agent, truncated IP, country, device and browser for visitor and lead notifications.
📍 United States (SCCs / DPF)
DPA / PrivacyTelegram
Internal operational alerts (error and lead notifications) to the founder’s own device.
📍 Outside the EEA (SCCs)
DPA / PrivacyCloudflare, Inc. (CDN & WAF)
Serves and protects every request to this site. Necessarily processes connection metadata including your IP address. This is infrastructure, not analytics.
📍 Global edge network (SCCs / DPF)
DPA / PrivacyWe do not sell, trade, or rent your personal information to any third party. We do not engage in cross-context behavioural advertising.
Your information, including Personal Data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
If we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
You have the right to obtain information about these safeguards by contacting us.
Under GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15)
Obtain confirmation whether we process your data and access to it
Right to rectification (Art. 16)
Correct inaccurate or incomplete data
Right to erasure (Art. 17, 'right to be forgotten')
Request deletion of your data under certain circumstances
Right to restriction of processing (Art. 18)
Request limitation of processing under certain circumstances
Right to data portability (Art. 20)
Receive your data in a structured, commonly used, machine-readable format
Right to object (Art. 21)
Object to processing based on legitimate interests or for direct marketing
Right to withdraw consent (Art. 7.3)
Where processing is based on consent, you can withdraw it at any time without affecting prior lawfulness
Right not to be subject to automated decision-making (Art. 22)
Including profiling that produces legal or similarly significant effects
Right to compensation (Art. 82)
Claim material or non-material damages for infringements of GDPR
Right to lodge a complaint (Art. 77)
File a complaint directly with the French supervisory authority (CNIL) — details below
To exercise these rights, submit a request through our Data Subject Request form at /data-subject-request, or contact us at: dpo@hyperion-consulting.io. We may need to verify your identity before processing your request. Verification will be proportionate to the sensitivity of the data involved.
You also have the right to lodge a complaint with the supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
Tel: +33 (0)1 53 73 22 22
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
However, no method of transmission over the Internet or electronic storage is 100% secure.
Cookies are small text files placed on your device when you visit our website. We use the following types of cookies:
Essential cookies
Necessary for the website to function
Analytical cookies
Help us understand how visitors use our website
Functional cookies
Remember your preferences
Marketing cookies
Used to deliver relevant advertisements
We will request your consent before placing non-essential cookies on your device. You can withdraw consent at any time through your browser settings or our cookie management tool.
Some of our pages may contain content from third-party services (e.g., Google Analytics) which may set their own cookies. We do not control these cookies.
Below is the complete list of cookies and browser-storage entries this site uses. Entries marked as local storage are not cookies; third-party entries appear only after you actively load the feature that sets them.
| Cookie | Purpose | Type | Duration | Provider |
|---|---|---|---|---|
| hyperion_cookie_consent | Stores your cookie consent choices. This is LOCAL STORAGE, not a cookie. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_booking_embed_consent | Remembers that you chose to load the third-party booking calendar on /book. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_lead_access | Records that you have been granted access to a gated resource, so you are not asked for your email again. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_store_cart | Keeps the contents of your store basket between visits. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_ai_act_register_id | Links your browser to the EU AI Act compliance register you created. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_sticky_cta_dismissed / hyperion-ambient-dismiss-* | Remembers prompts you dismissed, so they stay dismissed. | Functional · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion-jarvis-* | Keeps your assistant conversation, session id and preferences in your browser. | Functional · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| admin_token | Authentication for the admin dashboard. | Necessary | 2 hours | Hyperion Consulting |
| marketplace_session | Authenticated session for the Marketplace area (JWT). | Necessary | 24 hours | Hyperion Consulting |
| portal_session | Authenticated session for the client portal (JWT). | Necessary | 7 days | Hyperion Consulting |
| NEXT_LOCALE | Stores your preferred language. | Functional | 1 year | Hyperion Consulting |
| _ga, _ga_* | Google Analytics 4. Set ONLY after you grant analytics consent — the tag is not requested at all before that. | Analytics | 2 years / 24 hours | |
| sentryReplaySession | Sentry session replay. Runs ONLY with analytics consent, and is stopped and cleared if you withdraw it. Error monitoring itself runs without replay. | Analytics · Local storage | Browser tab session | Sentry |
| __cf_bm, _cfuvid (Calendly) | Set by Calendly ONLY after you click to load the booking calendar. Nothing is contacted before that. | Third-party | Session | Calendly |
| m (Stripe) | Set by Stripe, which the Calendly widget loads. Appears only once you have loaded the booking calendar. | Third-party | Up to ~400 days (set by Stripe) | Stripe |
| (no cookie set) | Cloudflare Web Analytics — cookieless, aggregated page metrics only, no cross-site tracking. Cloudflare also serves the site as our CDN and WAF. | Analytics | No persistent cookie | Cloudflare, Inc. |
You can withdraw or modify your cookie consent at any time by clicking the 'Cookie Settings' link in the footer of any page. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
We do not use automated decision-making that produces legal effects or similarly significantly affects you.
Lead qualification combines deterministic rules with AI-assisted scoring. When you submit an enquiry we may look up publicly available information about your organisation (including a LinkedIn company lookup and a web search) and pass your submission together with that context to Mistral AI to estimate seniority, fit and a suggested next action. This is profiling within the meaning of Art. 4(4) GDPR. It is used only to prioritise and prepare a human reply: no decision producing legal or similarly significant effects is automated, and a person decides whether and how we respond. Legal basis: our legitimate interest in prioritising enquiries (Art. 6(1)(f)). Scores are retained for 90 days. You may object at any time at dpo@hyperion-consulting.io.
In accordance with Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), we inform you that the following AI systems are in use on this website:
Answers questions about our services and content using retrieval-augmented generation
Model: Mistral Large (provider: Mistral AI, France)
Disclosure: The interface clearly indicates you are interacting with an AI system, not a human.
Your rights: You may at any time request to speak with a human via contact@hyperion-consulting.io. Outputs are not used for automated decision-making.
Generates a personalised AI maturity score and recommendations from your quiz answers
Model: Deterministic scoring logic combined with optional Mistral-generated recommendations
Disclosure: Results are for informational purposes only, do not constitute professional advice, and do not produce legal or similarly significant effects.
Your rights: You may request deletion of your results and associated personal data under Article 17 GDPR.
Blog articles, research digests, and tool guides may be drafted with AI assistance and pass automated verification against their cited sources before publication
Model: Mistral Large (provider: Mistral AI, France)
Disclosure: Articles containing AI-generated content are labelled as such. Automatically published articles pass automated source-verification checks; they are not individually reviewed by a human editor before publication.
Your rights: You may report inaccurate AI-generated content to contact@hyperion-consulting.io.
We do not engage in any of the AI practices prohibited under Article 5 of the AI Act (social scoring, emotion recognition in workplace, biometric categorization, subliminal manipulation, exploitation of vulnerabilities, untargeted facial scraping, real-time remote biometric identification).
The AI systems operated on this website do not fall within the high-risk categories listed in Annex III of the AI Act.
In accordance with Article 4 of the AI Act, the founder — the only person operating these AI systems — maintains a sufficient level of AI literacy, kept current through direct engineering work on the systems themselves.
For a detailed, system-by-system transparency notice, see our AI Transparency page.
We have reviewed our processing activities against Article 35 GDPR criteria. No processing activity currently triggers a mandatory DPIA (we do not process special categories of data at scale, do not engage in systematic profiling with legal effects, and do not conduct large-scale monitoring of public areas). We maintain this assessment under review and will perform DPIAs for any new processing likely to result in a high risk to data subjects.
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.
In accordance with Article 8 of the GDPR and Article 45 of the French Data Protection Act (Loi Informatique et Libertés), the age of digital consent in France is set at 15. For users under 15 residing in France, the consent of a parent or guardian is required for any information society service directly offered to the child.
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
We may update our Privacy Policy from time to time. We will notify you of any material changes by:
You are advised to review this Privacy Policy periodically. Continued use of our Service after changes constitutes acceptance of the updated policy.
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
126 Avenue du General Leclerc
92100 Boulogne-Billancourt, France
Response time: We will respond to your requests within one month of receipt, as required by GDPR.
This Privacy Policy is governed by French law and complies with the General Data Protection Regulation (EU) 2016/679.