Last updated: 26 July 2026
CB Systems (Céleste Bellier) attaches great importance to the protection of personal data, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act. This policy explains what data we process, in what capacity, why, with whom, and what your rights are. It supplements our terms of sale and our legal notice.
1. Data controller
Céleste Bellier, micro-business, SIREN 102 895 836, 9 Rue Fiol, 69003 Lyon. Contact: contact@cb-systems.fr.
2. Our two roles: controller or processor
Depending on the processing, CB Systems acts in two different capacities:
Data controller: for the data we collect and use on our own behalf: site visitors, contact and appointment requests, sales prospecting, management of our customers, shop orders.
Processor: when we process personal data on behalf of our clients, as part of the automations and tools we set up for them (loyalty programme, review collection, forms on their site, follow-ups with their own customers). In that case, our client is the controller, we act on their instructions, and a processing agreement compliant with Article 28 of the GDPR governs the relationship (see section 12).
3. Data collected
Site, contact and appointments. Surname, first name, email, phone, company (if you give them), plus the slot, the format and the subject of the meeting, and the history of your requests and cancellations.
Shop. Order and delivery information (name, address, email). Payment is handled by our secure payment provider: we do not keep your card details.
Business prospecting (between professionals). Business contact details (business name, sector, area, public phone number and address, Google rating and reviews), collected from public sources and mapping services, in order to offer them our services.
Browsing. IP address, browser type, pages visited and traffic source, see section 11.
On behalf of our clients (processor). Depending on the tool put in place, the data of our clients' end customers: for example, for a loyalty programme, first name, surname, email, phone, date of birth, visit history and consent; or the messages received through the form on their site. This data belongs to our client and is processed according to their instructions.
4. Purposes
Answering your requests; organising, reminding and managing appointments; carrying out services and delivering orders; keeping our customer and prospect records; running our sales prospecting; meeting our accounting and legal obligations; securing and improving the site. And, as a processor, running the automations agreed with our clients (loyalty, reviews, follow-ups, forms) on their behalf.
5. Legal bases
Depending on the case: your consent (forms, marketing communications); the performance of a contract (services, orders); a legal obligation (invoicing); our legitimate interest (site security, business-to-business prospecting, with a right to object). For processing carried out as a processor, the legal basis is determined by our client, the controller.
6. Retention periods
Prospects: 3 years from the last contact. Clients: 10 years after the end of the contractual relationship (accounting obligations). Shop orders: according to our legal obligations. Server logs: 12 months. Audience measurement: a period limited to that purpose. Data processed on behalf of a client: kept for the duration of the contract binding us to that client, then returned or deleted according to their instructions.
7. Recipients and processors
Your data is never sold. We use technical processors, strictly to the extent necessary for the purposes described:
· Hostinger: hosting for the site, our automations and our databases, on servers located in the European Union;
· our automation platform n8n, self-hosted on our EU servers;
· Google (Ireland / LLC): calendar, email, mapping and business profile services, and search ranking measurement, depending on the services concerned;
· an SMS sending provider (Twilio), when SMS messages are planned;
· our secure payment provider, for shop orders;
· productivity tools (Notion, for example) and, for support tasks (writing, sorting, summarising), artificial intelligence models supplied by specialist providers, with the minimum data necessary and a contractual ban on reusing it for their own purposes, in particular to train their models.
8. Transfers outside the European Union
We favour hosting and processing within the European Union. Some providers (Google, Twilio or AI suppliers, for example) may involve a transfer of data outside the EU; this is then covered by the safeguards set out in the GDPR (adequacy decision or standard contractual clauses).
9. Prospecting, communications and unsubscribing
Marketing communications are only sent with your consent, or within the permitted framework of business-to-business prospecting. You can object at any time, through the unsubscribe link in every message or by writing to contact@cb-systems.fr. The loyalty programmes we run on behalf of our clients rest on the consent of the individuals concerned and always include an unsubscribe link.
10. Your rights
You have a right of access, rectification, erasure, restriction, objection and portability, as well as the right to set instructions on what happens to your data after your death. To exercise them, write to contact@cb-systems.fr: we reply within one month (extendable by two months if the request is complex). Where we process your data on behalf of one of our clients, we pass your request on to that client, who is the controller and with whom you may also exercise it directly. In the event of a dispute, you may refer the matter to the CNIL.
11. Audience measurement and cookies
The site sets no cookies. Traffic is measured by a minimal in-house system: a session marker kept in your browser's storage (sessionStorage, cleared when the tab is closed) and the sending, to our own tools hosted on our server, of a visit event containing the page viewed, the referring site, any campaign parameters (UTM), the device category (mobile, tablet or computer) and whether or not the session is new. No IP address, no identifier and no data allowing you to be identified are recorded by this system; no profile is built; nothing is passed to third parties or cross-referenced between sites. We use no advertising trackers. This cookie-free system, limited to internal and anonymous audience measurement, falls under the consent exemption set out in the CNIL guidelines.
12. Processing on behalf of our clients
When we set up a tool for a client that processes personal data (loyalty, reviews, forms, follow-ups), we sign a data processing agreement compliant with Article 28 of the GDPR with them, setting out the purposes, the duration, the security measures, the use of any sub-processors and what happens to the data at the end of the contract (returned in a usable format or deleted). Our clients can request a copy at contact@cb-systems.fr. Each client warrants that it has a legal basis for the data it entrusts to us and that it has informed the individuals concerned.
13. Data security
We put in place appropriate technical and organisational measures: hosting in the European Union, restricted and authenticated access, data partitioned by client, databases not publicly exposed, regular encrypted backups, and a firewall. In the event of a data breach likely to create a risk to your rights, we notify the individuals and authorities concerned under the conditions set out by the GDPR.
14. Contact
For any question about this policy or about your data: contact@cb-systems.fr.