Privacy Policy

Last updated: March 2026

1. Introduction

EJB SAS (“we,” “us,” or “our”), a French société par actions simplifiée registered under SIREN 993 526 326, operates the website www.legalzone.com (the “Site”). This Privacy Policy describes how we collect, use, store, and protect your personal data when you visit and interact with the Site.

We are committed to protecting your privacy in accordance with the European Union General Data Protection Regulation (GDPR — Regulation (EU) 2016/679), the French Loi Informatique et Libertés (Loi n° 78-17), and all applicable data protection laws.

By using the Site, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Site.

2. Data Controller

The data controller responsible for processing your personal data is:

EJB SAS
5 rue des Scandinaves
77700 Serris, France
SIREN: 993 526 326
Email: contact@legalzone.com

For any questions or requests regarding your personal data, contact us at the email address above.

3. Personal Data We Collect

We collect different types of personal data depending on how you interact with the Site.

3.1 Data You Provide Voluntarily

When you contact us, subscribe to a newsletter, or submit a form on the Site, you may provide:

Contact information: name, email address, phone number (optional)
Message content: the text of your inquiry, feedback, or request
Professional information: company name, job title (if provided voluntarily)

3.2 Data Collected Automatically

When you visit the Site, we automatically collect certain technical data through cookies and similar technologies:

Device information: browser type and version, operating system, screen resolution
Connection data: IP address, internet service provider, approximate geographic location (city/country level)
Usage data: pages visited, time spent on each page, referring website, date and time of access, clicks and navigation patterns
Cookie identifiers: unique identifiers stored by cookies and similar tracking technologies

3.3 Data We Do Not Collect

We do not knowingly collect sensitive personal data (also known as “special categories” under the GDPR), including racial or ethnic origin, political opinions, religious beliefs, health data, sexual orientation, or biometric data. We do not collect financial information such as credit card numbers or bank account details through the Site.

4. How We Use Your Data

We process your personal data for the following purposes and legal bases:

To respond to your inquiries (Legal basis: legitimate interest)
When you contact us via email or contact form, we use your information to respond to your request and manage our communication with you.

To improve the Site (Legal basis: legitimate interest)
We analyze usage data to understand how visitors interact with the Site, identify technical issues, improve content and navigation, and optimize performance.

To measure audience and traffic (Legal basis: consent)
We use analytics tools to measure Site traffic, page views, visitor demographics, and content performance. Analytics cookies are only placed after you provide consent via our cookie banner.

To send newsletters and updates (Legal basis: consent)
If you subscribe to our newsletter, we use your email address to send periodic updates about new guides, templates, and resources. You can unsubscribe at any time using the link in each email.

To comply with legal obligations (Legal basis: legal obligation)
We may process your data when required by law, court order, or regulatory authority.

5. Cookies and Tracking Technologies

5.1 What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They allow the site to remember your preferences, analyze usage, and deliver relevant content. Some cookies are essential for the Site to function; others are used for analytics and marketing purposes.

5.2 Types of Cookies We Use

Strictly necessary cookies (no consent required)
These cookies are essential for the Site to function properly. They enable core features such as page navigation, security, and form submission. They do not collect personal data for marketing purposes.

Analytics cookies (consent required)
We use analytics tools (such as Google Analytics or similar services) to measure site traffic, understand user behavior, and improve content. These cookies collect anonymized or pseudonymized data about your visit. They are only activated after you provide consent via our cookie banner.

Advertising and affiliate cookies (consent required)
When you click on affiliate links (such as links to business formation services), third-party providers may place cookies to track referrals and attribute conversions. These cookies are governed by the respective third party’s privacy policy. They are only activated after you provide consent.

5.3 Managing Cookies

When you first visit the Site, a cookie consent banner allows you to accept or refuse non-essential cookies. You can modify your preferences at any time by clicking the “Cookie Settings” link in the footer of the Site.

You can also configure your browser to block or delete cookies. Please note that disabling certain cookies may affect the functionality of the Site. Here are links to manage cookies in major browsers:

Google Chrome
Mozilla Firefox
Apple Safari
Microsoft Edge

5.4 Cookie Retention Periods

Strictly necessary cookies expire at the end of your browsing session or within 13 months, in accordance with CNIL recommendations. Analytics cookies are retained for a maximum of 13 months. Consent records are retained for a maximum of 13 months before re-consent is requested.

6. Data Sharing and Third Parties

6.1 Service Providers

We may share your personal data with trusted third-party service providers who assist us in operating the Site:

Hosting provider: WPX.net (Jeanie Network SRL, Bulgaria) — hosts the Site and stores data on secure servers
Analytics provider: Google Analytics or equivalent — processes anonymized usage data
Email service provider: used to manage newsletter subscriptions and email communications
Contact form provider: processes contact form submissions

These providers act as data processors under our instructions and are contractually bound to protect your data in accordance with GDPR requirements.

6.2 Affiliate Partners

When you click on affiliate links on the Site, you may be redirected to third-party websites (such as business formation services). These third parties have their own privacy policies, and we encourage you to review them before providing personal information. EJB SAS does not share your personal data directly with affiliate partners — tracking is handled through cookies and referral URLs.

6.3 Legal Requirements

We may disclose your personal data if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, prevent fraud, or ensure the safety of our users.

6.4 No Sale of Data

We do not sell, rent, or trade your personal data to third parties for marketing or any other purposes.

7. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States (e.g., Google Analytics servers). When such transfers occur, we ensure that appropriate safeguards are in place:

Adequacy decisions: transfers to countries recognized by the European Commission as providing adequate data protection.
Standard Contractual Clauses (SCCs): EU-approved contractual frameworks binding the receiving party to protect your data.
EU-US Data Privacy Framework: for transfers to certified US organizations under the DPF.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy:

Contact form submissions: retained for 3 years from the last communication, unless you request deletion sooner.
Newsletter subscriptions: retained until you unsubscribe. After unsubscription, your email is deleted within 30 days.
Analytics data: retained for a maximum of 26 months (in accordance with CNIL recommendations).
Cookie consent records: retained for 13 months before re-consent is requested.
Server logs: retained for 12 months for security and performance purposes.

9. Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR and French data protection law:

Right of access (Article 15): You have the right to obtain confirmation of whether we process your personal data and to receive a copy of that data.
Right to rectification (Article 16): You have the right to request correction of inaccurate personal data or completion of incomplete data.
Right to erasure (Article 17): You have the right to request deletion of your personal data when it is no longer necessary for the purpose for which it was collected, or when you withdraw consent.
Right to restriction (Article 18): You have the right to request restriction of processing in certain circumstances (e.g., while we verify the accuracy of your data).
Right to data portability (Article 20): You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
Right to object (Article 21): You have the right to object to processing based on legitimate interest, including profiling. You also have the right to object to direct marketing at any time.
Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
Right to lodge a complaint: You have the right to lodge a complaint with the French data protection authority (CNIL) or any other competent supervisory authority.

How to Exercise Your Rights

To exercise any of these rights, contact us at:

Email: contact@legalzone.com
Mail: EJB SAS — Data Protection, 5 rue des Scandinaves, 77700 Serris, France

We will respond to your request within one month of receipt, in accordance with GDPR Article 12. This period may be extended by two additional months for complex requests, in which case we will notify you of the extension and the reasons for the delay.

To verify your identity, we may ask for additional information before processing your request.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

• SSL/TLS encryption for all data transmitted between your browser and our servers
• Secure hosting with a reputable provider (WPX.net) using enterprise-grade infrastructure
• Access controls limiting data access to authorized personnel only
• Regular software updates and security patches
• Two-factor authentication for administrative access
• Regular security audits and monitoring

While we take reasonable steps to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

11. Children’s Privacy

LegalZone.com is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at contact@legalzone.com.

12. Links to Third-Party Websites

The Site contains links to third-party websites. This Privacy Policy applies only to LegalZone.com. We are not responsible for the privacy practices of third-party websites. We encourage you to review the privacy policies of any website you visit through links on our Site.

13. CNIL — French Data Protection Authority

If you are unsatisfied with our response to a data protection request, or if you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL):

CNIL
3 Place de Fontenoy, TSA 80715
75334 Paris Cedex 07, France
Website: www.cnil.fr
Online complaint: www.cnil.fr/fr/plaintes

14. California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

Right to know: You may request information about the categories of personal data we collect, the purposes of collection, and the categories of third parties with whom we share data.
Right to delete: You may request deletion of personal data we have collected about you.
Right to opt-out of sale: We do not sell personal data. There is no need to opt out.
Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise CCPA rights, contact us at contact@legalzone.com.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Changes will be posted on this page with an updated “Last updated” date. We encourage you to review this Policy periodically. Continued use of the Site after changes constitutes acceptance of the updated Policy.

For material changes that significantly affect how we process your personal data, we will make reasonable efforts to notify you (e.g., through a notice on the Site or an email to registered users).

16. Contact

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us at:

EJB SAS
5 rue des Scandinaves
77700 Serris, France
Email: contact@legalzone.com

icon 4 206 utilisateurs ce mois-ci
J
Jacques
vient de demander un devis