Privacy Policy for Hyperion Consulting
Last updated: August 20th, 2026
Quick Navigation
1. Website Publisher Information
Website Publisher:
Hyperion Consulting (SASU)
SIRET: 94804171000013
TVA: FR73948041710
126 Avenue du General Leclerc, 92100 Boulogne-Billancourt, France
contact@hyperion-consulting.io
Director: Mohammed Cherifi
Website Host:
AI Service Provider:
2. Data Controller
For the purposes of the General Data Protection Regulation (GDPR), the data controller is:
Hyperion Consulting
Data Protection Contact
Given the size and nature of our operations, the appointment of a Data Protection Officer (DPO) is not mandatory under Article 37 of the GDPR. However, for all data protection inquiries, you may contact:
A Record of Processing Activities (ROPA), as required by Article 30 of the GDPR, is maintained internally and is available upon request to the supervisory authority.
3. Information Collection and Use
3.1 Types of Data Collected
We collect several categories of information:
Personal Data
Information that can directly or indirectly identify you:
- Identity data: First name, last name
- Contact data: Email address, phone number (if provided)
- Technical data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform
- Usage data: Information about how you use our website and services
- Marketing and communications data: Your preferences in receiving marketing from us
- Enquiry journey context: A bounded public landing path, non-identifying campaign labels, referrer origin, selected call to action and diagnostic outcome may be held in memory and attached when you submit an enquiry under the form privacy consent. After analytics consent, the same context may also be stored for the current browser tab. Likely personal or opaque identifiers are filtered first.
Cookies and Similar Technologies
We use cookies and similar tracking technologies. See Section 9 for detailed information.
3.2 Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you have given clear consent for us to process your personal data for specific purposes
- Contract: Processing necessary for the performance of a contract to which you are party
- Legal obligations: Processing necessary for compliance with legal obligations
- Legitimate interests: Processing necessary for our legitimate interests or those of third parties, provided those interests are not overridden by your rights and interests
3.3 Purpose of Data Collection
We use your personal data for the following purposes:
- To provide and maintain our Service
- To manage your account and provide customer support
- To notify you about changes to our Service
- To send you marketing communications (with your consent)
- To analyse and improve our Service
- To comply with legal obligations
- To detect, prevent, and address technical issues
- To protect our rights and property
3.4 Mandatory vs Optional Data
When collecting data, we will indicate whether providing certain information is:
- Mandatory: Required to provide our services (marked with an asterisk *)
- Optional: Additional information that helps us improve our services
Consequences of not providing mandatory data: We may not be able to provide certain services to you.
4. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this Privacy Policy:
Enquiries and CRM contacts
duration of the relationship plus 2 years, then deleted by the weekly retention sweep
Prospect records (outbound research)
2 years from last activity, then deleted
CRM activity logs
3 months
Lead qualification scores and enrichment
90 days
AI assistant conversations and agent memory
30 days from last activity
Assessment submissions and attachments
with the CRM contact record; attachments are not retained after analysis
Marketing subscriptions
until you withdraw consent, or 2 years after last interaction
Marketplace accounts
for the life of the account; 30 days after deletion request, then permanently purged
Payment records (Stripe/PayPal)
10 years, as required by French commercial and tax law
Data-subject request records
3 years, as evidence that requests were handled
Compliance register entries
7 days if never completed, 90 days otherwise
Error monitoring and session replay
90 days (Sentry default)
Operational alerts (Slack/Telegram)
retained in those channels per their own settings
Backups
30 days rolling, after which restores are no longer possible
Technical logs
3 months
Cookies and browser storage
see Section 9
5. Data Recipients & Processors
Your personal data may be shared with the following categories of recipients:
- Internal recipients: the founder, who is the sole person with access to personal data. Hyperion Consulting is a solo practice and has no employees.
- Service providers (processors): Third-party companies listed below that process data on our behalf
- Legal authorities: When required by law or legal proceedings
- Business transfers: In case of merger, acquisition, or sale of assets
We use the following sub-processors to operate our services. Where a provider publishes its own data-processing terms, the entry links to them. An entry marked "Not currently enabled" is an integration that exists in the site but is switched off in the environment this policy was published from — it is listed so this table stays complete, rather than being rewritten every time a component is turned on or off.
Mistral AI
AI inference, embeddings, OCR and speech for user-requested tools and bounded internal workflows
📍 Company established in France (Paris, 15 Rue des Halles). This site is currently configured to call Mistral's GLOBAL API endpoint, not its EU-region endpoint. A French provider is not by itself a residency guarantee, so AI processing may take place outside the EEA. See Section 6.
DPA / PrivacyResend
Transactional and marketing email delivery
📍 United States (EU Standard Contractual Clauses in place)
DPA / PrivacyStripe Payments Europe, Ltd.
Not currently enabledMarketplace subscription payment processing. NOT CURRENTLY ENABLED: no Stripe credentials are configured in the environment this policy is published from, so no marketplace payment is taken and nothing reaches Stripe through us. The integration is retained and this entry describes the processing if it is switched back on. Separately, and unrelated to this, Stripe is loaded by the Calendly booking widget if you choose to load it — see Section 9.4.
📍 Ireland (EU) with transfers to the United States under SCCs
DPA / PrivacyPayPal (Europe) S.à r.l. et Cie, S.C.A.
Not currently enabledAlternative marketplace payment method. NOT CURRENTLY ENABLED: no PayPal credentials are configured in the environment this policy is published from. The integration is retained and this entry describes the processing if it is switched back on.
📍 Luxembourg (EU)
DPA / PrivacySentry (Functional Software, Inc.)
Not currently enabledApplication error monitoring and performance telemetry, including error-triggered session replay with all text masked. NOT CURRENTLY ENABLED: no Sentry DSN is configured in the environment this policy is published from. The integration is retained and this entry describes the processing if it is switched back on.
📍 United States (EU Standard Contractual Clauses in place)
DPA / PrivacyGoogle Analytics 4 (Google Ireland Ltd.)
Anonymized website analytics with Consent Mode v2. Client-side tracking tag activates only on explicit opt-in. GA4 Data API also used server-side by the admin dashboard for aggregated reporting.
📍 EU data processing, sub-transfers to the United States under SCCs
DPA / PrivacyCloudflare Web Analytics (Cloudflare, Inc.)
Real-time website performance and traffic analytics (RUM — Real User Monitoring). Cookieless and privacy-friendly: no persistent cookies, no cross-site tracking, no fingerprinting. Collects aggregated page-view and Core Web Vitals metrics.
📍 United States (EU Standard Contractual Clauses in place)
DPA / PrivacyUpstash (managed Redis)
Session store, rate-limit counters, cache, and short-lived application state — for example a strategic intake form held for 90 days, and Marketplace agent conversation memory held for 30 days.
📍 Upstash's managed cloud service. The application prefers a self-hosted Redis whenever one is configured; none is configured, so the managed service is what is in use. We do not assert an EU processing region for it. See Section 6.
DPA / PrivacyCloudflare, Inc. (R2 Object Storage)
Object storage for product-delivery assets and off-site backups
📍 European Union (EU-jurisdiction bucket); Cloudflare is a US-headquartered company — transfers covered by EU Standard Contractual Clauses
DPA / PrivacyTwenty CRM (self-hosted)
Customer-relationship records for enquiries, leads and assessment submissions. Self-hosted on our own OVHcloud infrastructure in France — the software vendor has no access.
📍 France (EU) — our own infrastructure
DPA / PrivacySlack (Salesforce)
Internal operational alerts to the founder. Visitor page alerts carry page, referrer, user agent, truncated IP address, country, device and browser. Enquiry, assessment and booking alerts additionally carry identity and qualification data: your name, e-mail address, company, the lead score and the signals behind it, the suggested next action, and — where they apply — your assessment result or your booking details. The free text of your enquiry is deliberately NOT forwarded to this channel; it stays in the CRM and in the operator's mailbox.
📍 United States (SCCs / DPF)
DPA / PrivacyTelegram
Internal operational alerts to the founder's own device. Receives the same identity and qualification data as Slack — name, e-mail address, company, source, lead score and signals — plus, for a small number of system-generated notices, a short summary line. The free text of your enquiry is deliberately NOT forwarded to this channel.
📍 Outside the EEA — see Section 6
DPA / PrivacyCloudflare, Inc. (CDN & WAF)
Serves and protects every request to this site. Necessarily processes connection metadata including your IP address. This is infrastructure, not analytics.
📍 Global edge network (SCCs / DPF)
DPA / Privacyn8n (self-hosted)
Workflow automation running on our own infrastructure. Where its intake and lead webhooks are switched on, it receives the e-mail address and source of a gated-resource request, and the full contents of a strategic intake form. Those two webhooks are NOT enabled in the environment this policy is published from; the administrative connection that reads workflow run history — which carries no personal data — is.
📍 France (EU) — our own infrastructure at n8n.hyperion-consulting.io. The software vendor has no access.
SerpAPI
Search-engine result retrieval for outbound business research and competitor monitoring. Queries name organisations, and can name individuals at organisations we research for outbound contact. It is NOT on any visitor or enquiry path: nothing you submit to this website is sent to SerpAPI.
📍 United States
LinkedIn (Microsoft)
Not currently enabledTwo separate uses. (1) Company look-up during lead qualification: when you request a gated resource we take the first label of your e-mail address's company domain — "example" from "example.com" — and ask LinkedIn's organisation directory about it. Your e-mail address, your name and your message are never sent, and free e-mail providers are skipped entirely. (2) Publishing and measuring our own posts from our own LinkedIn page, which involves no visitor data at all. Use (1) is NOT enabled in the environment this policy is published from.
📍 United States / Ireland
DPA / PrivacyOpenAI (via the Codex command-line tool)
Not currently enabledDrafting English long-form articles for our own insights corpus. It is reachable only from the content-authoring pipeline: a build-time rule forbids every other module in the codebase from importing it, so visitor, enquiry and customer data cannot reach it. It is off unless explicitly switched on, and it is NOT switched on in the environment this policy is published from. It runs against the founder's personal ChatGPT subscription rather than a business agreement, which means there is no data-processing agreement with OpenAI behind it — that is acceptable only for as long as no personal data is sent to it, which the build-time rule is there to guarantee.
📍 United States
We do not sell, trade, or rent your personal information to any third party. We do not engage in cross-context behavioural advertising.
6. International Data Transfers
Your information, including Personal Data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ.
If we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions
- Your explicit consent
Recipients that involve a transfer outside the EEA include: Resend (e-mail delivery), Sentry (error monitoring — not currently enabled), Google Analytics 4 (anonymised analytics, see Section 9.4), Calendly (scheduling), Cloudflare, Inc. (R2 object storage, Web Analytics and the CDN/WAF), Slack and Telegram (internal operational alerts), Upstash (session and rate-limit store), SerpAPI (outbound research only — never your data), LinkedIn (company look-up — not currently enabled) and OpenAI (article drafting — not currently enabled, and fenced off from personal data). In addition, although Mistral AI is established in France, this site is configured to use its global API endpoint, so AI processing may also take place outside the EEA.
Where we rely on Standard Contractual Clauses we do so through the data-processing terms each provider publishes, linked in Section 5, pursuant to Art. 46(2)(c) GDPR and, where applicable, the UK International Data Transfer Agreement.
We will not claim a safeguard we cannot show you. For the following recipients we have not yet verified that a specific transfer mechanism is concluded and in force, and we say so rather than assert one: Mistral AI in respect of its global API endpoint, Telegram, LinkedIn, SerpAPI and OpenAI. That verification is in progress. If it matters to your decision to contact us, ask us at dpo@hyperion-consulting.io first.
You have the right to obtain information about these safeguards by contacting us.
7. Your Rights
Under GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15)
Obtain confirmation whether we process your data and access to it
Right to rectification (Art. 16)
Correct inaccurate or incomplete data
Right to erasure (Art. 17, 'right to be forgotten')
Request deletion of your data under certain circumstances
Right to restriction of processing (Art. 18)
Request limitation of processing under certain circumstances
Right to data portability (Art. 20)
Receive your data in a structured, commonly used, machine-readable format
Right to object (Art. 21)
Object to processing based on legitimate interests or for direct marketing
Right to withdraw consent (Art. 7.3)
Where processing is based on consent, you can withdraw it at any time without affecting prior lawfulness
Right not to be subject to automated decision-making (Art. 22)
Including profiling that produces legal or similarly significant effects
Right to compensation (Art. 82)
Claim material or non-material damages for infringements of GDPR
Right to lodge a complaint (Art. 77)
File a complaint directly with the French supervisory authority (CNIL) — details below
To exercise these rights, submit a request through our Data Subject Request form at /data-subject-request, or contact us at: dpo@hyperion-consulting.io. We may need to verify your identity before processing your request. Verification will be proportionate to the sensitivity of the data involved.
You also have the right to lodge a complaint with the supervisory authority:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
Tel: +33 (0)1 53 73 22 22
8. Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit and at rest
- Regular security assessments
- Access controls and authentication measures
- Ongoing data-protection training maintained by the founder, who is the only person with access
However, no method of transmission over the Internet or electronic storage is 100% secure.
9. Cookie Policy
9.1 What Are Cookies
Cookies are small text files placed on your device when you visit our website. We use the following types of cookies:
Essential cookies
Necessary for the website to function
Analytical cookies
Help us understand how visitors use our website
Functional cookies
Remember your preferences
Marketing cookies
Used to deliver relevant advertisements
9.2 Consent
We will request your consent before placing non-essential cookies on your device. You can withdraw consent at any time through your browser settings or our cookie management tool.
9.3 Third-Party Cookies
Some of our pages may contain content from third-party services (e.g., Google Analytics) which may set their own cookies. We do not control these cookies.
9.4 Cookie Inventory
Below is the complete list of cookies and browser-storage entries this site uses. Entries marked as local storage are not cookies; third-party entries appear only after you actively load the feature that sets them.
| Cookie | Purpose | Type | Duration | Provider |
|---|---|---|---|---|
| hyperion_cookie_consent | Stores your cookie consent choices. This is LOCAL STORAGE, not a cookie. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion:first-touch:v1 | After analytics consent, session storage keeps a bounded public landing path, non-identifying campaign labels, referrer origin, selected call to action and diagnostic outcome. It excludes ad click IDs and full referrer URLs. If you submit an enquiry, the same bounded context is attached under your form privacy consent. | Analytics · Session storage | Current browser tab; removed when analytics consent is withdrawn | Hyperion Consulting |
| hyperion_booking_embed_consent | Remembers that you chose to load the third-party booking calendar on /book. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_lead_access | Records that you have been granted access to a gated resource, so you are not asked for your email again. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_store_cart | Keeps the contents of your store basket between visits. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_ai_act_register_id | Links your browser to the EU AI Act compliance register you created. | Necessary · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion_sticky_cta_dismissed / hyperion-ambient-dismiss-* | Remembers prompts you dismissed, so they stay dismissed. | Functional · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| hyperion-jarvis-* | Keeps your assistant conversation, session id and preferences in your browser. | Functional · Local storage | Persistent (until you clear it) | Hyperion Consulting |
| admin_token | Authentication for the admin dashboard. | Necessary | 2 hours | Hyperion Consulting |
| marketplace_session | Authenticated session for the Marketplace area (JWT). | Necessary | 24 hours | Hyperion Consulting |
| portal_session | Authenticated session for the client portal (JWT). | Necessary | 7 days | Hyperion Consulting |
| ventures_access / ventures_pending | Venture-room access and pending approval state. | Necessary | 30 days / 7 days | Hyperion Consulting |
| lead_access / compliance_dossier_access | Server-side access to gated resources and the claimed compliance dossier. | Necessary | 1 year | Hyperion Consulting |
| hyperion-jarvis-subject | Signed pseudonymous identity used to restore your JARVIS conversation context. | Necessary | 30 days | Hyperion Consulting |
| linkedin_oauth_state | Short-lived anti-forgery state for a LinkedIn connection request. | Necessary | 10 minutes | Hyperion Consulting |
| NEXT_LOCALE | Stores your preferred language. | Functional | 1 year | Hyperion Consulting |
| _ga, _ga_* | Google Analytics 4. Set ONLY after you grant analytics consent — the tag is not requested at all before that. | Analytics | 2 years / 24 hours | |
| sentryReplaySession | Sentry session replay. Runs ONLY with analytics consent, and is stopped and cleared if you withdraw it. Error monitoring itself runs without replay. | Analytics · Local storage | Browser tab session | Sentry |
| __cf_bm, _cfuvid (Calendly) | Set by Calendly ONLY after you click to load the booking calendar. Nothing is contacted before that. | Third-party | Session | Calendly |
| m (Stripe) | Set by Stripe, which the Calendly widget loads. Appears only once you have loaded the booking calendar. | Third-party | Up to ~400 days (set by Stripe) | Stripe |
| (no cookie set) | Cloudflare Web Analytics — cookieless, aggregated page metrics only, no cross-site tracking. Cloudflare also serves the site as our CDN and WAF. | Analytics | No persistent cookie | Cloudflare, Inc. |
9.5 Withdrawing Cookie Consent
You can withdraw or modify your cookie consent at any time by clicking the 'Cookie Settings' link in the footer of any page. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
10. Automated Decision-Making & Profiling
We do not use automated decision-making that produces legal effects or similarly significantly affects you.
Lead qualification combines deterministic rules with AI-assisted scoring. When you submit the contact form, the score is calculated by deterministic rules alone: no AI model and no third-party look-up is involved. When you request a gated resource by e-mail, we additionally look up publicly available information about your organisation — a LinkedIn look-up on the company domain in your e-mail address, and a web search about that organisation carried out through Mistral — and pass that context to Mistral AI to estimate seniority, fit and a suggested next action. This is profiling within the meaning of Art. 4(4) GDPR. It is used only to prioritise and prepare a human reply: no decision producing legal or similarly significant effects is automated, and a person decides whether and how we respond. Legal basis: our legitimate interest in prioritising enquiries (Art. 6(1)(f)). Scores are retained for 90 days. You may object at any time at dpo@hyperion-consulting.io.
10.bis AI Systems & EU AI Act Transparency
In accordance with Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), we inform you that the following AI systems are in use on this website:
Hyperion AI Assistant (site chatbot)
Answers questions about our services and content using retrieval-augmented generation
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: The interface clearly indicates you are interacting with an AI system, not a human.
Your rights: You may at any time request to speak with a human via contact@hyperion-consulting.io. Outputs are not used for automated decision-making.
JARVIS Decision Navigator
Routes a product or system decision you describe to the smallest engagement that fits, or to an honest no-fit result, and drafts a cited brief
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: Identified as an AI assistant before you can type anything. It recommends; it does not decide, price or contract. Giving contact details and booking a call are a separate, consented step.
Your rights: You can use it without giving any contact details. Internal alerts about its use carry bounded metadata only, never your free text.
AI site search
Answers a question typed into the site search box from this site's published content, and lists the pages the answer came from
Model: Mistral small models (provider: Mistral AI — see Section 5)
Disclosure: The answer is labelled as AI-generated and shows its sources. Your query is sent to the provider to produce it, and answers are cached so the same question is not sent twice.
Your rights: Ordinary keyword search works without it. No output is used to make any decision about you.
AI Readiness Assessment
Generates a personalised AI maturity score and recommendations from your quiz answers
Model: Deterministic scoring logic combined with optional Mistral-generated recommendations (provider: Mistral AI — see Section 5)
Disclosure: Results are for informational purposes only, do not constitute professional advice, and do not produce legal or similarly significant effects.
Your rights: You may request deletion of your results and associated personal data under Article 17 GDPR.
EU AI Act risk classifier
Suggests an indicative risk tier, and the articles that would apply, for a system you describe
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: Labelled as indicative and not legal advice. The description you type is sent to the provider to produce the classification.
Your rights: A human decides what to do with the result. You may request deletion of a register entry you created under Article 17 GDPR.
Use-case generator
Drafts candidate AI use cases from a business context you describe
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: The output is a draft for you to choose from, not a finding about you. The context you type is sent to the provider and is not stored beyond the session.
Your rights: Using the tool is entirely optional and requires no contact details.
Marketplace AI agents
Configurable AI agents that registered Marketplace users converse with to produce work for their own projects
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: Every agent is labelled as an AI agent. Your messages, the agent's replies, and any project context you attach are sent to the provider to produce each reply.
Your rights: Conversation memory is held for 30 days from your last activity. You can delete your account and its data from the Marketplace account area, or by writing to dpo@hyperion-consulting.io.
Lead qualification and scoring
Scores an enquiry or a gated-resource request so that a human can prioritise a reply. This is profiling — Section 10 describes it in full.
Model: The contact form is scored by deterministic rules only, with no AI and no third-party look-up. On the gated-resource path we additionally use Mistral models, a Mistral web search about the organisation, and a LinkedIn company look-up (see Section 5).
Disclosure: Disclosed at the point of collection. No decision producing legal or similarly significant effects is automated: a person decides whether and how we reply.
Your rights: Legal basis is our legitimate interest in prioritising enquiries (Art. 6(1)(f)). Scores are kept for 90 days. You may object at any time at dpo@hyperion-consulting.io.
Outbound prospect research and scoring
Researches and tiers organisations we may approach, from publicly available professional information
Model: Mistral models, plus public search results retrieved through SerpAPI and publicly available LinkedIn information (see Section 5)
Disclosure: Where the information was not obtained from you, Article 14 GDPR applies and we give that notice on first contact.
Your rights: An objection is honoured immediately and the record suppressed. Write to dpo@hyperion-consulting.io.
Proposal drafting
Drafts a proposal outline from an enquiry so that a human has something to work from
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: Nothing drafted this way is sent to you without human review.
Your rights: The draft is kept with the enquiry record. You may request access or deletion under Articles 15 and 17 GDPR.
AI-assisted content generation
Blog articles, research digests, and tool guides may be drafted with AI assistance and pass automated verification against their cited sources before publication
Model: Mistral models in all languages. For English long-form drafting only, the OpenAI Codex command-line tool may also be used; that option is switched off by default, and a build-time rule prevents any visitor, enquiry or customer data from reaching it (see Section 5).
Disclosure: Articles containing AI-generated content are labelled as such. Automatically published articles pass automated source-verification checks; they are not individually reviewed by a human editor before publication.
Your rights: You may report inaccurate AI-generated content to contact@hyperion-consulting.io.
Attachment text extraction (contact and assessment forms)
Reads a brief or deck you choose to attach and returns a short summary so you do not have to retype it
Model: Mistral OCR followed by one Mistral summarisation call (provider: Mistral AI — see Section 5)
Disclosure: This is stated at the point of collection, before you choose a file. The file is sent to the provider for text extraction and is not stored by us: it is held in memory for the call only. Only the text you choose to send is kept, as part of your enquiry.
Your rights: Attaching a file is optional and the form works without it. You can edit or remove the extracted summary before sending, and request deletion of your enquiry under Article 17 GDPR.
AI Lab public demonstrations
Let you try model behaviour yourself — vision, document OCR, speech, prompt injection and evaluation — so the practice's technical claims can be judged rather than taken on trust
Model: Mistral models, including vision, OCR and speech (provider: Mistral AI — see Section 5)
Disclosure: Each demonstration is labelled as an AI demonstration and is illustrative only. Whatever you supply is sent to the provider for processing and is not stored by us.
Your rights: Every demonstration is optional and starts only when you run it. No output is used to make any decision about you.
JARVIS industrial demonstrations (plant audit, defect inspection, maintenance logs)
Show how a vision or tabular model reads an industrial scene, a part photograph or a maintenance log, as a worked example of the practice's method
Model: Mistral models, including vision (provider: Mistral AI — see Section 5)
Disclosure: Labelled as a demonstration and not a professional assessment. The photograph or file you supply is sent to the provider for processing and is not stored by us.
Your rights: Every demonstration is optional and starts only when you run it. No output is used to make any decision about you.
Homepage campaign personalisation
Rewrites a page headline to match the marketing campaign you arrived from
Model: Mistral models (provider: Mistral AI — see Section 5 for where that processing takes place)
Disclosure: It uses only the campaign labels in the link you followed and the audience of the page — no personal data is sent. It is BUILT BUT NOT CURRENTLY IN USE: no page on this site mounts it today. It is listed so that this register is complete rather than merely current.
Your rights: Nothing about you is sent to the provider, and no output is used to make any decision about you.
We do not engage in any of the AI practices prohibited under Article 5 of the AI Act (social scoring, emotion recognition in workplace, biometric categorization, subliminal manipulation, exploitation of vulnerabilities, untargeted facial scraping, real-time remote biometric identification).
The AI systems operated on this website do not fall within the high-risk categories listed in Annex III of the AI Act.
In accordance with Article 4 of the AI Act, the founder — the only person operating these AI systems — maintains a sufficient level of AI literacy, kept current through direct engineering work on the systems themselves.
This list and the system-by-system register on our AI Transparency page describe the same systems, in the same order. If they ever disagree, treat the disagreement itself as a defect and tell us at dpo@hyperion-consulting.io.
10.ter Data Protection Impact Assessment
We have reviewed our processing activities against Article 35 GDPR criteria. No processing activity currently triggers a mandatory DPIA (we do not process special categories of data at scale, do not engage in systematic profiling with legal effects, and do not conduct large-scale monitoring of public areas). We maintain this assessment under review and will perform DPIAs for any new processing likely to result in a high risk to data subjects.
11. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18.
In accordance with Article 8 of the GDPR and Article 45 of the French Data Protection Act (Loi Informatique et Libertés), the age of digital consent in France is set at 15. For users under 15 residing in France, the consent of a parent or guardian is required for any information society service directly offered to the child.
12. Links to Other Sites
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
13. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending you an email notification (for significant changes)
You are advised to review this Privacy Policy periodically. Continued use of our Service after changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
126 Avenue du General Leclerc
92100 Boulogne-Billancourt, France
Response time: We will respond to your requests within one month of receipt, as required by GDPR.
This Privacy Policy is governed by French law and complies with the General Data Protection Regulation (EU) 2016/679.