Privacy notice · GDPR · last updated 11 July 2026

How this site handles your data.

ezelman.com exists to be read by senior risk executives, not to harvest their data. This notice states, in plain terms, what the site collects, which providers touch it, on what legal basis, for how long, and the rights you hold under the GDPR. It is written against the site’s actual source — every tag and form named below is one that really runs, and no analytics or advertising tag loads before you consent.

01 · Data controllerWho is responsible for your data.

The data controller for ezelman.com is Ezelman SASU, a French société par actions simplifiée unipersonnelle registered in Paris, France, trading as Ezelman — the financial-risk advisory boutique whose work this site describes. SIRET and Kbis extract are supplied on request, as on the procurement page. For anything in this notice — a question, an objection, a rights request — write to contact@ezelman.com. Requests are read and answered by the firm directly.

02 · What is collectedThree channels, described exactly.

Analytics — Google Analytics 4. GA4 (measurement ID G-DC0TT52NCP) loads only after you accept analytics in the consent banner (section 07), with IP anonymisation switched on in the site’s configuration. It records the pages you visit, approximate location derived from a truncated IP address, browser and device type, and interaction events fired when you click specific calls to action — booking a call, downloading a paper. It is used to understand what senior readers actually read, nothing more.

Advertising measurement — LinkedIn Insight Tag. LinkedIn’s Insight Tag (partner ID 536180358) also loads only after you accept in the consent banner. If you are a LinkedIn member, LinkedIn can match your visit to your member profile to measure the firm’s LinkedIn campaigns and to build retargeting audiences. Ezelman sees aggregated campaign data only, never your identity.

Forms — handled by Netlify. The site is hosted on Netlify, which also processes every form submission. The forms that exist, with their actual fields: the contact form (full name, email address, company / institution, subject, message); the newsletter signup that appears on most pages (email address only); and the gated-download request forms for papers such as the Regulatory Thesis 2026–2030 (first name, last name, work email, organisation, role, and an explicit consent tick-box). Submissions land in the site’s Netlify form inbox and are read by the firm.

And in the background. Netlify, as host, keeps standard server logs (IP address, requested URL, timestamp) for security and operations. Page typography is served by Google Fonts, so your browser requests font files from Google’s servers, which discloses your IP address to Google. “Book a call” links lead to calendly.com — anything you enter there is governed by Calendly’s own privacy notice, not this one.

What the site does not do: no advertising networks beyond the LinkedIn tag, no sale or sharing of personal data for third-party marketing, no profiling beyond the analytics described above.

  • Answering enquiries and providing requested papers. Contact-form and download-form data is used to respond and to deliver what you asked for. Legal basis: Article 6(1)(b) GDPR — steps taken at your request prior to a contract — and, for follow-up, Article 6(1)(f), the firm’s legitimate interest in continuing a conversation you started.
  • The regulatory briefing. Newsletter addresses are used for the briefing and nothing else. Legal basis: consent, Article 6(1)(a) — withdrawable at any time via unsubscribe or a one-line email.
  • Readership analytics and campaign measurement. GA4 and LinkedIn Insight Tag data. Legal basis: consent, Article 6(1)(a) GDPR, given via the consent banner before either tag loads — and withdrawable at any time via the Cookie preferences link in the footer of this page (section 07).
  • Security and operations. Server logs. Legal basis: Article 6(1)(f) — keeping the site available and abuse off it.

04 · RetentionHow long, in plain terms.

Form submissions and email correspondence. Kept for one year from the last exchange, then deleted — unless the conversation has become a client relationship, in which case engagement records are governed by the engagement terms.

Newsletter addresses. Kept until you unsubscribe, then removed promptly.

GA4 event data. Event-level analytics data is retained for 14 months, the property’s configured retention setting and the maximum GA4 permits. Aggregated reporting persists beyond that window but does not identify you.

LinkedIn Insight Tag data. Held by LinkedIn in pseudonymised form on LinkedIn’s published schedule: LinkedIn states that members’ direct identifiers are removed within seven days and the remaining pseudonymised data deleted within 180 days.

Server logs. Retained by Netlify for a short operational window under its own policy.

05 · ProcessorsWho touches the data, and where it goes.

Four external providers process data in connection with this site. Each link is the provider’s own privacy notice.

Transfers outside the EEA. These providers are US-headquartered or route data to US infrastructure. Transfers rely on the EU–US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses otherwise; each provider’s certification status was checked as part of the counsel review noted in section 08.

06 · Your rightsWhat you can require of the firm.

Under the GDPR you can, at any time and free of charge, require:

  • Access — a copy of the personal data the firm holds about you (Article 15).
  • Rectification — correction of inaccurate data (Article 16).
  • Erasure — deletion where there is no continuing ground to hold the data (Article 17).
  • Restriction — a freeze on processing while a dispute is resolved (Article 18).
  • Portability — the data you provided, in a machine-readable format (Article 20).
  • Objection — to processing based on legitimate interest, and absolutely to any direct marketing (Article 21).
  • Withdrawal of consent — for the newsletter or anything else consent-based, with effect for the future (Article 7(3)).

To exercise any of these, email contact@ezelman.com. You also have the right to lodge a complaint with the supervisory authority of your member state — in France, the CNIL (cnil.fr).

07 · Cookies & consentNothing loads until you choose.

The consent banner. On your first visit, a banner offers two choices: Accept analytics or Decline. No analytics or advertising tag — neither GA4 nor the LinkedIn Insight Tag — loads until you accept. If you decline, nothing loads and no analytics cookie is set. Your choice is stored locally in your browser (a single ez-consent entry in local storage — it never leaves your device) so the banner does not reappear on every page.

What is set if you accept. GA4 sets first-party cookies (_ga and a _ga_* container cookie) to recognise returning browsers, and the LinkedIn Insight Tag sets LinkedIn cookies used for member matching and campaign attribution.

Changing your mind. Use the Cookie preferences link in the footer of this page — or the button below — to clear your stored choice and re-open the banner at any time. You can also clear cookies in your browser settings, block Google Analytics across all sites with Google’s opt-out browser add-on, and opt out of LinkedIn retargeting via LinkedIn’s guest and member controls.

08 · StatusWhere this notice stands.

Last updated: 11 July 2026. This notice describes the trackers and forms actually running on ezelman.com at that date — it was written against the site’s source, not from a template. When a tag, form or provider is added or removed, this page is edited the same day and the date above moves.

Reviewed and adopted 11 July 2026. The counsel review is complete: the registered legal identity (section 01), fixed retention periods (section 04) and the consent mechanism (section 07) are as stated above.

A question about your data?

Access, correction, erasure or any other request under this notice: one email, answered by the firm, not a ticketing system.

This notice was prepared by the firm, reviewed by counsel, and adopted on 11 July 2026. It reflects the trackers, consent mechanism and forms actually running on ezelman.com at that date.
Follow Ezelman on LinkedIn — Regulatory insights read by 2,000+ risk professionals across Europe & the GCC Follow →