Skip to content

Privacy Policy for Hyperion Consulting

Last updated: August 20th, 2026

Quick Navigation

1Website Publisher Information
2Data Controller
3Information Collection and Use
4Data Retention
5Data Recipients & Processors
6International Data Transfers
7Your Rights
8Data Security
9Cookie Policy
10Automated Decision-Making & Profiling
10.bisAI Systems & EU AI Act Transparency
10.terData Protection Impact Assessment
11Children's Privacy
12Links to Other Sites
13Changes to This Privacy Policy
14Contact Us

1. Website Publisher Information

Website Publisher:

Hyperion Consulting (SASU)

SIRET: 94804171000013

TVA: FR73948041710

126 Avenue du General Leclerc, 92100 Boulogne-Billancourt, France

contact@hyperion-consulting.io

Director: Mohammed Cherifi

Website Host:

OVHcloud

2 rue Kellermann, 59100 Roubaix, France

Data Centers: France

www.ovhcloud.com

AI Service Provider:

Mistral AI

15 Rue des Halles, 75001 Paris, France

www.mistral.ai

2. Data Controller

For the purposes of the General Data Protection Regulation (GDPR), the data controller is:

Hyperion Consulting

Email: contact@hyperion-consulting.io

Data Protection Contact

Given the size and nature of our operations, the appointment of a Data Protection Officer (DPO) is not mandatory under Article 37 of the GDPR. However, for all data protection inquiries, you may contact:

dpo@hyperion-consulting.io

A Record of Processing Activities (ROPA), as required by Article 30 of the GDPR, is maintained internally and is available upon request to the supervisory authority.

3. Information Collection and Use

3.1 Types of Data Collected

We collect several categories of information:

Personal Data

Information that can directly or indirectly identify you:

  • Identity data: First name, last name
  • Contact data: Email address, phone number (if provided)
  • Technical data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform
  • Usage data: Information about how you use our website and services
  • Marketing and communications data: Your preferences in receiving marketing from us
  • Enquiry journey context: A bounded public landing path, non-identifying campaign labels, referrer origin, selected call to action and diagnostic outcome may be held in memory and attached when you submit an enquiry under the form privacy consent. After analytics consent, the same context may also be stored for the current browser tab. Likely personal or opaque identifiers are filtered first.

Cookies and Similar Technologies

We use cookies and similar tracking technologies. See Section 9 for detailed information.

3.2 Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: When you have given clear consent for us to process your personal data for specific purposes
  • Contract: Processing necessary for the performance of a contract to which you are party
  • Legal obligations: Processing necessary for compliance with legal obligations
  • Legitimate interests: Processing necessary for our legitimate interests or those of third parties, provided those interests are not overridden by your rights and interests

3.3 Purpose of Data Collection

We use your personal data for the following purposes:

  • To provide and maintain our Service
  • To manage your account and provide customer support
  • To notify you about changes to our Service
  • To send you marketing communications (with your consent)
  • To analyse and improve our Service
  • To comply with legal obligations
  • To detect, prevent, and address technical issues
  • To protect our rights and property

3.4 Mandatory vs Optional Data

When collecting data, we will indicate whether providing certain information is:

  • Mandatory: Required to provide our services (marked with an asterisk *)
  • Optional: Additional information that helps us improve our services

Consequences of not providing mandatory data: We may not be able to provide certain services to you.

4. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy:

Enquiries and CRM contacts

duration of the relationship plus 2 years, then deleted by the weekly retention sweep

Prospect records (outbound research)

2 years from last activity, then deleted

CRM activity logs

3 months

Lead qualification scores and enrichment

90 days

AI assistant conversations and agent memory

30 days from last activity

Assessment submissions and attachments

with the CRM contact record; attachments are not retained after analysis

Marketing subscriptions

until you withdraw consent, or 2 years after last interaction

Marketplace accounts

for the life of the account; 30 days after deletion request, then permanently purged

Payment records (Stripe/PayPal)

10 years, as required by French commercial and tax law

Data-subject request records

3 years, as evidence that requests were handled

Compliance register entries

7 days if never completed, 90 days otherwise

Error monitoring and session replay

90 days (Sentry default)

Operational alerts (Slack/Telegram)

retained in those channels per their own settings

Backups

30 days rolling, after which restores are no longer possible

Technical logs

3 months

Cookies and browser storage

see Section 9

5. Data Recipients & Processors

Your personal data may be shared with the following categories of recipients:

  • Internal recipients: the founder, who is the sole person with access to personal data. Hyperion Consulting is a solo practice and has no employees.
  • Service providers (processors): Third-party companies listed below that process data on our behalf
  • Legal authorities: When required by law or legal proceedings
  • Business transfers: In case of merger, acquisition, or sale of assets

We use the following sub-processors to operate our services. Where a provider publishes its own data-processing terms, the entry links to them. An entry marked "Not currently enabled" is an integration that exists in the site but is switched off in the environment this policy was published from — it is listed so this table stays complete, rather than being rewritten every time a component is turned on or off.

OVHcloud

Website and application hosting (primary VPS)

📍 France (EU)

DPA / Privacy

Mistral AI

AI inference, embeddings, OCR and speech for user-requested tools and bounded internal workflows

📍 Company established in France (Paris, 15 Rue des Halles). This site is currently configured to call Mistral's GLOBAL API endpoint, not its EU-region endpoint. A French provider is not by itself a residency guarantee, so AI processing may take place outside the EEA. See Section 6.

DPA / Privacy

Resend

Transactional and marketing email delivery

📍 United States (EU Standard Contractual Clauses in place)

DPA / Privacy

Stripe Payments Europe, Ltd.

Not currently enabled

Marketplace subscription payment processing. NOT CURRENTLY ENABLED: no Stripe credentials are configured in the environment this policy is published from, so no marketplace payment is taken and nothing reaches Stripe through us. The integration is retained and this entry describes the processing if it is switched back on. Separately, and unrelated to this, Stripe is loaded by the Calendly booking widget if you choose to load it — see Section 9.4.

📍 Ireland (EU) with transfers to the United States under SCCs

DPA / Privacy

PayPal (Europe) S.à r.l. et Cie, S.C.A.

Not currently enabled

Alternative marketplace payment method. NOT CURRENTLY ENABLED: no PayPal credentials are configured in the environment this policy is published from. The integration is retained and this entry describes the processing if it is switched back on.

📍 Luxembourg (EU)

DPA / Privacy

Sentry (Functional Software, Inc.)

Not currently enabled

Application error monitoring and performance telemetry, including error-triggered session replay with all text masked. NOT CURRENTLY ENABLED: no Sentry DSN is configured in the environment this policy is published from. The integration is retained and this entry describes the processing if it is switched back on.

📍 United States (EU Standard Contractual Clauses in place)

DPA / Privacy

Google Analytics 4 (Google Ireland Ltd.)

Anonymized website analytics with Consent Mode v2. Client-side tracking tag activates only on explicit opt-in. GA4 Data API also used server-side by the admin dashboard for aggregated reporting.

📍 EU data processing, sub-transfers to the United States under SCCs

DPA / Privacy

Cloudflare Web Analytics (Cloudflare, Inc.)

Real-time website performance and traffic analytics (RUM — Real User Monitoring). Cookieless and privacy-friendly: no persistent cookies, no cross-site tracking, no fingerprinting. Collects aggregated page-view and Core Web Vitals metrics.

📍 United States (EU Standard Contractual Clauses in place)

DPA / Privacy

Calendly

Meeting scheduling

📍 United States (SCCs in place)

DPA / Privacy

Upstash (managed Redis)

Session store, rate-limit counters, cache, and short-lived application state — for example a strategic intake form held for 90 days, and Marketplace agent conversation memory held for 30 days.

📍 Upstash's managed cloud service. The application prefers a self-hosted Redis whenever one is configured; none is configured, so the managed service is what is in use. We do not assert an EU processing region for it. See Section 6.

DPA / Privacy

Cloudflare, Inc. (R2 Object Storage)

Object storage for product-delivery assets and off-site backups

📍 European Union (EU-jurisdiction bucket); Cloudflare is a US-headquartered company — transfers covered by EU Standard Contractual Clauses

DPA / Privacy

Twenty CRM (self-hosted)

Customer-relationship records for enquiries, leads and assessment submissions. Self-hosted on our own OVHcloud infrastructure in France — the software vendor has no access.

📍 France (EU) — our own infrastructure

DPA / Privacy

Slack (Salesforce)

Internal operational alerts to the founder. Visitor page alerts carry page, referrer, user agent, truncated IP address, country, device and browser. Enquiry, assessment and booking alerts additionally carry identity and qualification data: your name, e-mail address, company, the lead score and the signals behind it, the suggested next action, and — where they apply — your assessment result or your booking details. The free text of your enquiry is deliberately NOT forwarded to this channel; it stays in the CRM and in the operator's mailbox.

📍 United States (SCCs / DPF)

DPA / Privacy

Telegram

Internal operational alerts to the founder's own device. Receives the same identity and qualification data as Slack — name, e-mail address, company, source, lead score and signals — plus, for a small number of system-generated notices, a short summary line. The free text of your enquiry is deliberately NOT forwarded to this channel.

📍 Outside the EEA — see Section 6

DPA / Privacy

Cloudflare, Inc. (CDN & WAF)

Serves and protects every request to this site. Necessarily processes connection metadata including your IP address. This is infrastructure, not analytics.

📍 Global edge network (SCCs / DPF)

DPA / Privacy

n8n (self-hosted)

Workflow automation running on our own infrastructure. Where its intake and lead webhooks are switched on, it receives the e-mail address and source of a gated-resource request, and the full contents of a strategic intake form. Those two webhooks are NOT enabled in the environment this policy is published from; the administrative connection that reads workflow run history — which carries no personal data — is.

📍 France (EU) — our own infrastructure at n8n.hyperion-consulting.io. The software vendor has no access.

SerpAPI

Search-engine result retrieval for outbound business research and competitor monitoring. Queries name organisations, and can name individuals at organisations we research for outbound contact. It is NOT on any visitor or enquiry path: nothing you submit to this website is sent to SerpAPI.

📍 United States

LinkedIn (Microsoft)

Not currently enabled

Two separate uses. (1) Company look-up during lead qualification: when you request a gated resource we take the first label of your e-mail address's company domain — "example" from "example.com" — and ask LinkedIn's organisation directory about it. Your e-mail address, your name and your message are never sent, and free e-mail providers are skipped entirely. (2) Publishing and measuring our own posts from our own LinkedIn page, which involves no visitor data at all. Use (1) is NOT enabled in the environment this policy is published from.

📍 United States / Ireland

DPA / Privacy

OpenAI (via the Codex command-line tool)

Not currently enabled

Drafting English long-form articles for our own insights corpus. It is reachable only from the content-authoring pipeline: a build-time rule forbids every other module in the codebase from importing it, so visitor, enquiry and customer data cannot reach it. It is off unless explicitly switched on, and it is NOT switched on in the environment this policy is published from. It runs against the founder's personal ChatGPT subscription rather than a business agreement, which means there is no data-processing agreement with OpenAI behind it — that is acceptable only for as long as no personal data is sent to it, which the build-time rule is there to guarantee.

📍 United States

We do not sell, trade, or rent your personal information to any third party. We do not engage in cross-context behavioural advertising.

6. International Data Transfers

Your information, including Personal Data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.

If we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Standard contractual clauses approved by the European Commission
  • Adequacy decisions
  • Your explicit consent

Recipients that involve a transfer outside the EEA include: Resend (e-mail delivery), Sentry (error monitoring — not currently enabled), Google Analytics 4 (anonymised analytics, see Section 9.4), Calendly (scheduling), Cloudflare, Inc. (R2 object storage, Web Analytics and the CDN/WAF), Slack and Telegram (internal operational alerts), Upstash (session and rate-limit store), SerpAPI (outbound research only — never your data), LinkedIn (company look-up — not currently enabled) and OpenAI (article drafting — not currently enabled, and fenced off from personal data). In addition, although Mistral AI is established in France, this site is configured to use its global API endpoint, so AI processing may also take place outside the EEA.

Where we rely on Standard Contractual Clauses we do so through the data-processing terms each provider publishes, linked in Section 5, pursuant to Art. 46(2)(c) GDPR and, where applicable, the UK International Data Transfer Agreement.

We will not claim a safeguard we cannot show you. For the following recipients we have not yet verified that a specific transfer mechanism is concluded and in force, and we say so rather than assert one: Mistral AI in respect of its global API endpoint, Telegram, LinkedIn, SerpAPI and OpenAI. That verification is in progress. If it matters to your decision to contact us, ask us at dpo@hyperion-consulting.io first.

You have the right to obtain information about these safeguards by contacting us.

7. Your Rights

Under GDPR, you have the following rights regarding your personal data:

Right of access (Art. 15)

Obtain confirmation whether we process your data and access to it

Right to rectification (Art. 16)

Correct inaccurate or incomplete data

Right to erasure (Art. 17, 'right to be forgotten')

Request deletion of your data under certain circumstances

Right to restriction of processing (Art. 18)

Request limitation of processing under certain circumstances

Right to data portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format

Right to object (Art. 21)

Object to processing based on legitimate interests or for direct marketing

Right to withdraw consent (Art. 7.3)

Where processing is based on consent, you can withdraw it at any time without affecting prior lawfulness

Right not to be subject to automated decision-making (Art. 22)

Including profiling that produces legal or similarly significant effects

Right to compensation (Art. 82)

Claim material or non-material damages for infringements of GDPR

Right to lodge a complaint (Art. 77)

File a complaint directly with the French supervisory authority (CNIL) — details below

To exercise these rights, submit a request through our Data Subject Request form at /data-subject-request, or contact us at: dpo@hyperion-consulting.io. We may need to verify your identity before processing your request. Verification will be proportionate to the sensitivity of the data involved.

You also have the right to lodge a complaint with the supervisory authority:

Commission Nationale de l'Informatique et des Libertés (CNIL)

3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07

Tel: +33 (0)1 53 73 22 22

www.cnil.fr

8. Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments
  • Access controls and authentication measures
  • Ongoing data-protection training maintained by the founder, who is the only person with access

However, no method of transmission over the Internet or electronic storage is 100% secure.

9. Cookie Policy

9.1 What Are Cookies

Cookies are small text files placed on your device when you visit our website. We use the following types of cookies:

Essential cookies

Necessary for the website to function

Analytical cookies

Help us understand how visitors use our website

Functional cookies

Remember your preferences

Marketing cookies

Used to deliver relevant advertisements

9.2 Consent

We will request your consent before placing non-essential cookies on your device. You can withdraw consent at any time through your browser settings or our cookie management tool.

9.3 Third-Party Cookies

Some of our pages may contain content from third-party services (e.g., Google Analytics) which may set their own cookies. We do not control these cookies.

9.4 Cookie Inventory

Below is the complete list of cookies and browser-storage entries this site uses. Entries marked as local storage are not cookies; third-party entries appear only after you actively load the feature that sets them.

CookiePurposeTypeDurationProvider
hyperion_cookie_consentStores your cookie consent choices. This is LOCAL STORAGE, not a cookie.Necessary · Local storagePersistent (until you clear it)Hyperion Consulting
hyperion:first-touch:v1After analytics consent, session storage keeps a bounded public landing path, non-identifying campaign labels, referrer origin, selected call to action and diagnostic outcome. It excludes ad click IDs and full referrer URLs. If you submit an enquiry, the same bounded context is attached under your form privacy consent.Analytics · Session storageCurrent browser tab; removed when analytics consent is withdrawnHyperion Consulting
hyperion_booking_embed_consentRemembers that you chose to load the third-party booking calendar on /book.Necessary · Local storagePersistent (until you clear it)Hyperion Consulting
hyperion_lead_accessRecords that you have been granted access to a gated resource, so you are not asked for your email again.Necessary · Local storagePersistent (until you clear it)Hyperion Consulting
hyperion_store_cartKeeps the contents of your store basket between visits.Necessary · Local storagePersistent (until you clear it)Hyperion Consulting
hyperion_ai_act_register_idLinks your browser to the EU AI Act compliance register you created.Necessary · Local storagePersistent (until you clear it)Hyperion Consulting
hyperion_sticky_cta_dismissed / hyperion-ambient-dismiss-*Remembers prompts you dismissed, so they stay dismissed.Functional · Local storagePersistent (until you clear it)Hyperion Consulting
hyperion-jarvis-*Keeps your assistant conversation, session id and preferences in your browser.Functional · Local storagePersistent (until you clear it)Hyperion Consulting
admin_tokenAuthentication for the admin dashboard.Necessary2 hoursHyperion Consulting
marketplace_sessionAuthenticated session for the Marketplace area (JWT).Necessary24 hoursHyperion Consulting
portal_sessionAuthenticated session for the client portal (JWT).Necessary7 daysHyperion Consulting
ventures_access / ventures_pendingVenture-room access and pending approval state.Necessary30 days / 7 daysHyperion Consulting
lead_access / compliance_dossier_accessServer-side access to gated resources and the claimed compliance dossier.Necessary1 yearHyperion Consulting
hyperion-jarvis-subjectSigned pseudonymous identity used to restore your JARVIS conversation context.Necessary30 daysHyperion Consulting
linkedin_oauth_stateShort-lived anti-forgery state for a LinkedIn connection request.Necessary10 minutesHyperion Consulting
NEXT_LOCALEStores your preferred language.Functional1 yearHyperion Consulting
_ga, _ga_*Google Analytics 4. Set ONLY after you grant analytics consent — the tag is not requested at all before that.Analytics2 years / 24 hoursGoogle
sentryReplaySessionSentry session replay. Runs ONLY with analytics consent, and is stopped and cleared if you withdraw it. Error monitoring itself runs without replay.Analytics · Local storageBrowser tab sessionSentry
__cf_bm, _cfuvid (Calendly)Set by Calendly ONLY after you click to load the booking calendar. Nothing is contacted before that.Third-partySessionCalendly
m (Stripe)Set by Stripe, which the Calendly widget loads. Appears only once you have loaded the booking calendar.Third-partyUp to ~400 days (set by Stripe)Stripe
(no cookie set)Cloudflare Web Analytics — cookieless, aggregated page metrics only, no cross-site tracking. Cloudflare also serves the site as our CDN and WAF.AnalyticsNo persistent cookieCloudflare, Inc.

9.5 Withdrawing Cookie Consent

You can withdraw or modify your cookie consent at any time by clicking the 'Cookie Settings' link in the footer of any page. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

10. Automated Decision-Making & Profiling

We do not use automated decision-making that produces legal effects or similarly significantly affects you.

Lead qualification combines deterministic rules with AI-assisted scoring. When you submit the contact form, the score is calculated by deterministic rules alone: no AI model and no third-party look-up is involved. When you request a gated resource by e-mail, we additionally look up publicly available information about your organisation — a LinkedIn look-up on the company domain in your e-mail address, and a web search about that organisation carried out through Mistral — and pass that context to Mistral AI to estimate seniority, fit and a suggested next action. This is profiling within the meaning of Art. 4(4) GDPR. It is used only to prioritise and prepare a human reply: no decision producing legal or similarly significant effects is automated, and a person decides whether and how we respond. Legal basis: our legitimate interest in prioritising enquiries (Art. 6(1)(f)). Scores are retained for 90 days. You may object at any time at dpo@hyperion-consulting.io.

10.bis AI Systems & EU AI Act Transparency

In accordance with Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), we inform you that the following AI systems are in use on this website:

Hyperion AI Assistant (site chatbot)

Answers questions about our services and content using retrieval-augmented generation

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: The interface clearly indicates you are interacting with an AI system, not a human.

Your rights: You may at any time request to speak with a human via contact@hyperion-consulting.io. Outputs are not used for automated decision-making.

JARVIS Decision Navigator

Routes a product or system decision you describe to the smallest engagement that fits, or to an honest no-fit result, and drafts a cited brief

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: Identified as an AI assistant before you can type anything. It recommends; it does not decide, price or contract. Giving contact details and booking a call are a separate, consented step.

Your rights: You can use it without giving any contact details. Internal alerts about its use carry bounded metadata only, never your free text.

AI site search

Answers a question typed into the site search box from this site's published content, and lists the pages the answer came from

Model: Mistral small models (provider: Mistral AI — see Section 5)

Disclosure: The answer is labelled as AI-generated and shows its sources. Your query is sent to the provider to produce it, and answers are cached so the same question is not sent twice.

Your rights: Ordinary keyword search works without it. No output is used to make any decision about you.

AI Readiness Assessment

Generates a personalised AI maturity score and recommendations from your quiz answers

Model: Deterministic scoring logic combined with optional Mistral-generated recommendations (provider: Mistral AI — see Section 5)

Disclosure: Results are for informational purposes only, do not constitute professional advice, and do not produce legal or similarly significant effects.

Your rights: You may request deletion of your results and associated personal data under Article 17 GDPR.

EU AI Act risk classifier

Suggests an indicative risk tier, and the articles that would apply, for a system you describe

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: Labelled as indicative and not legal advice. The description you type is sent to the provider to produce the classification.

Your rights: A human decides what to do with the result. You may request deletion of a register entry you created under Article 17 GDPR.

Use-case generator

Drafts candidate AI use cases from a business context you describe

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: The output is a draft for you to choose from, not a finding about you. The context you type is sent to the provider and is not stored beyond the session.

Your rights: Using the tool is entirely optional and requires no contact details.

Marketplace AI agents

Configurable AI agents that registered Marketplace users converse with to produce work for their own projects

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: Every agent is labelled as an AI agent. Your messages, the agent's replies, and any project context you attach are sent to the provider to produce each reply.

Your rights: Conversation memory is held for 30 days from your last activity. You can delete your account and its data from the Marketplace account area, or by writing to dpo@hyperion-consulting.io.

Lead qualification and scoring

Scores an enquiry or a gated-resource request so that a human can prioritise a reply. This is profiling — Section 10 describes it in full.

Model: The contact form is scored by deterministic rules only, with no AI and no third-party look-up. On the gated-resource path we additionally use Mistral models, a Mistral web search about the organisation, and a LinkedIn company look-up (see Section 5).

Disclosure: Disclosed at the point of collection. No decision producing legal or similarly significant effects is automated: a person decides whether and how we reply.

Your rights: Legal basis is our legitimate interest in prioritising enquiries (Art. 6(1)(f)). Scores are kept for 90 days. You may object at any time at dpo@hyperion-consulting.io.

Outbound prospect research and scoring

Researches and tiers organisations we may approach, from publicly available professional information

Model: Mistral models, plus public search results retrieved through SerpAPI and publicly available LinkedIn information (see Section 5)

Disclosure: Where the information was not obtained from you, Article 14 GDPR applies and we give that notice on first contact.

Your rights: An objection is honoured immediately and the record suppressed. Write to dpo@hyperion-consulting.io.

Proposal drafting

Drafts a proposal outline from an enquiry so that a human has something to work from

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: Nothing drafted this way is sent to you without human review.

Your rights: The draft is kept with the enquiry record. You may request access or deletion under Articles 15 and 17 GDPR.

AI-assisted content generation

Blog articles, research digests, and tool guides may be drafted with AI assistance and pass automated verification against their cited sources before publication

Model: Mistral models in all languages. For English long-form drafting only, the OpenAI Codex command-line tool may also be used; that option is switched off by default, and a build-time rule prevents any visitor, enquiry or customer data from reaching it (see Section 5).

Disclosure: Articles containing AI-generated content are labelled as such. Automatically published articles pass automated source-verification checks; they are not individually reviewed by a human editor before publication.

Your rights: You may report inaccurate AI-generated content to contact@hyperion-consulting.io.

Attachment text extraction (contact and assessment forms)

Reads a brief or deck you choose to attach and returns a short summary so you do not have to retype it

Model: Mistral OCR followed by one Mistral summarisation call (provider: Mistral AI — see Section 5)

Disclosure: This is stated at the point of collection, before you choose a file. The file is sent to the provider for text extraction and is not stored by us: it is held in memory for the call only. Only the text you choose to send is kept, as part of your enquiry.

Your rights: Attaching a file is optional and the form works without it. You can edit or remove the extracted summary before sending, and request deletion of your enquiry under Article 17 GDPR.

AI Lab public demonstrations

Let you try model behaviour yourself — vision, document OCR, speech, prompt injection and evaluation — so the practice's technical claims can be judged rather than taken on trust

Model: Mistral models, including vision, OCR and speech (provider: Mistral AI — see Section 5)

Disclosure: Each demonstration is labelled as an AI demonstration and is illustrative only. Whatever you supply is sent to the provider for processing and is not stored by us.

Your rights: Every demonstration is optional and starts only when you run it. No output is used to make any decision about you.

JARVIS industrial demonstrations (plant audit, defect inspection, maintenance logs)

Show how a vision or tabular model reads an industrial scene, a part photograph or a maintenance log, as a worked example of the practice's method

Model: Mistral models, including vision (provider: Mistral AI — see Section 5)

Disclosure: Labelled as a demonstration and not a professional assessment. The photograph or file you supply is sent to the provider for processing and is not stored by us.

Your rights: Every demonstration is optional and starts only when you run it. No output is used to make any decision about you.

Homepage campaign personalisation

Rewrites a page headline to match the marketing campaign you arrived from

Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)

Disclosure: It uses only the campaign labels in the link you followed and the audience of the page — no personal data is sent. It is BUILT BUT NOT CURRENTLY IN USE: no page on this site mounts it today. It is listed so that this register is complete rather than merely current.

Your rights: Nothing about you is sent to the provider, and no output is used to make any decision about you.

We do not engage in any of the AI practices prohibited under Article 5 of the AI Act (social scoring, emotion recognition in workplace, biometric categorization, subliminal manipulation, exploitation of vulnerabilities, untargeted facial scraping, real-time remote biometric identification).

The AI systems operated on this website do not fall within the high-risk categories listed in Annex III of the AI Act.

In accordance with Article 4 of the AI Act, the founder — the only person operating these AI systems — maintains a sufficient level of AI literacy, kept current through direct engineering work on the systems themselves.

This list and the system-by-system register on our AI Transparency page describe the same systems, in the same order. If they ever disagree, treat the disagreement itself as a defect and tell us at dpo@hyperion-consulting.io.

10.ter Data Protection Impact Assessment

We have reviewed our processing activities against Article 35 GDPR criteria. No processing activity currently triggers a mandatory DPIA (we do not process special categories of data at scale, do not engage in systematic profiling with legal effects, and do not conduct large-scale monitoring of public areas). We maintain this assessment under review and will perform DPIAs for any new processing likely to result in a high risk to data subjects.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.

In accordance with Article 8 of the GDPR and Article 45 of the French Data Protection Act (Loi Informatique et Libertés), the age of digital consent in France is set at 15. For users under 15 residing in France, the consent of a parent or guardian is required for any information society service directly offered to the child.

12. Links to Other Sites

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.

13. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending you an email notification (for significant changes)

You are advised to review this Privacy Policy periodically. Continued use of our Service after changes constitutes acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:

Mail

126 Avenue du General Leclerc

92100 Boulogne-Billancourt, France

Response time: We will respond to your requests within one month of receipt, as required by GDPR.

This Privacy Policy is governed by French law and complies with the General Data Protection Regulation (EU) 2016/679.

Privacy Policy — GDPR Data Protection