← Back to home

Privacy Policy

Last updated: May 11, 2026.

1. Data controller

The controller of personal data collected via www.iarankgeo.fr and the IA RANK GEO service is:

  • SAS CONCILIUM (brand CONCILIUM DIGITAL)
  • 7-14 Cité Griset, 75011 Paris, France · RCS Paris 812 371 516
  • Legal representative and Data Protection contact: Thomas Kolbé
  • GDPR contact: iarankgeo@concilium.digital

2. Data we collect

Depending on how you use the service, the following categories of data may be collected:

  • Account: email address (used for magic-link sign-in and product notifications).
  • Licenses: WordPress site URL, plugin version, WordPress version, PHP version.
  • Pro billing: name, billing address, company name, EU VAT (where applicable), payment method (card processed by Stripe · CONCILIUM stores no card details).
  • AI usage logs: token volume consumed, call type (meta, FAQ, facts, Quick Answer, rewriter, image-alt…), timestamp. No article content is retained after processing.
  • Visibility test: analyzed domain, requester email (with explicit consent), aggregated result.
  • Technical data: IP address, user-agent, anonymized application access logs.

3. Purposes and legal basis

PurposeLegal basis (GDPR art. 6)
Provide the service (Lite/Pro plugin, dashboard)Contract performance (6.1.b)
Issue and retain invoicesLegal obligation (6.1.c · French Commercial Code)
Daily license verificationContract performance (6.1.b)
Service security and fraud preventionLegitimate interest (6.1.f)
Product notifications (updates, quota alerts)Contract performance (6.1.b)
Newsletter / marketing contentExplicit consent (6.1.a)

No automated processing produces legal effects or significantly impacts data subjects within the meaning of GDPR article 22.

4. Retention periods

  • Account: as long as the subscription is active + 12 months after termination.
  • Invoices and accounting data: 10 years (legal obligation).
  • AI usage logs: rolling 12 months.
  • Technical logs (IP, user-agent): 12 months maximum.
  • Visibility test leads: 24 months or until deletion request.
  • Session cookies: session duration, deleted on logout.

5. Hosting and subprocessors

All subprocessors are located within the European Union and bound by a data processing agreement compliant with GDPR article 28.

SubprocessorRoleLocation
ScalingoApplication hosting + PostgreSQL databaseStrasbourg / Paris, France
Mistral AIAI generation (meta, FAQ, facts, Quick Answer, etc.)Paris, France
StripePayment (PCI DSS Level 1) and subscription portalDublin, Ireland
ResendTransactional emails (magic link, invoices, alerts)Frankfurt, Germany
ScalewayObject storage (Pro plugin ZIPs)Paris, France
Google Analytics 4Anonymized usage analytics (truncated IP)EU (Google Ireland)

No personal data is transferred outside the European Union, with the exception of Google Analytics, configured with IP anonymization and Standard Contractual Clauses validated by the European Commission.

6. Your WordPress article content

When the Pro plugin runs an optimization (Quick Answer, FAQ, key facts, rewriter, image-alt), the article content is transmitted to Mistral AI only for the duration of the call. CONCILIUM does not store any copy of the content after processing. The generated outputs are returned to the plugin, which saves them in the user's WordPress database (post_meta).

Article content is never used to train AI models. Mistral AI is bound by a Data Processing Agreement that explicitly excludes retraining on customer data.

7. Security

  • End-to-end TLS 1.3 encryption for all communications.
  • Passwords: none stored · magic link single-use authentication.
  • Encryption at rest for sensitive data (license keys, API tokens).
  • Automatic daily PostgreSQL backups (Scalingo).
  • Error monitoring via Sentry (anonymized payloads).
  • Data access restricted to authorized personnel on a least-privilege basis.

8. Your rights

In accordance with articles 15 to 22 of the GDPR and the French Data Protection Act, you may at any time exercise the following rights:

  • right of access to your data;
  • right of rectification of inaccurate or incomplete data;
  • right to erasure (the « right to be forgotten »);
  • right to restriction of processing;
  • right to object to processing based on legitimate interest;
  • right to data portability (JSON export on request);
  • right to set post-mortem directives for your data.

To exercise these rights: iarankgeo@concilium.digital. CONCILIUM commits to responding within a maximum of 30 days.

If you disagree with our response, you can file a complaint with the French Data Protection Authority (CNIL): 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 · +33 1 53 73 22 22 · www.cnil.fr.

9. Cookies and trackers

The site uses only:

  • Session cookies strictly necessary for authentication;
  • Anonymized audience measurement cookies via Google Analytics 4 (truncated IP, CNIL-exempt configuration).

No advertising cookies or third-party marketing trackers are placed without your prior explicit consent.

10. Incident notification

In the event of a data breach posing a risk to your rights and freedoms, CONCILIUM commits to notifying the CNIL within 72 hours and informing you as soon as possible, in accordance with GDPR articles 33 and 34.

11. Changes

This privacy policy may be amended to reflect changes in the service or applicable regulations. Substantial modifications are notified by email to users with an active account.