This page explains which personal data is collected on www.lepl.at, why, how long it is kept and how to exercise your rights (GDPR and the French Data Protection Act).
Last updated: August 2026
Data controller
Laurent LEPLAT, private individual — Lille metropolitan area, France.
For any question about your data: use the contact form on this site or the LinkedIn profile linked in the footer.
Data collected and purposes
The “Message” form collects: first name, last name, email address, phone number (optional), company (optional) and the content of your message (400 characters maximum).
The “Voice message” form collects: first name, last name, phone number and an audio recording of your voice (1 minute maximum), based on your explicit consent to the recording (Article 6.1.a GDPR). You may withdraw this consent at any time by requesting deletion of the message.
This data is used solely to respond to your enquiry in a professional context (legal basis: pre-contractual measures and legitimate interest, Article 6.1.b and f GDPR). It is never sold, shared or used for marketing.
Retention periods
- Written messages: kept for the time needed to handle your request, then no longer than 3 years from the last exchange (CNIL recommendation on prospecting).
- Voice messages: deleted within 2 months of receipt, once your request has been handled.
- IP addresses used for anti-spam rate limiting: kept in volatile server memory for 10 minutes at most, never written to disk.
Processors and transfers outside the European Union
- o2switch (Clermont-Ferrand, France): website hosting, on servers located in France.
- Telegram (United Arab Emirates): forms are delivered through the Telegram API to a private inbox. This non-EU transfer is covered neither by an adequacy decision nor by standard contractual clauses; it relies on the voluntary action of the person submitting the form, after being duly informed (Article 49 GDPR). You can reach me without going through Telegram via the LinkedIn profile linked in the footer.
- Cloudflare (United States): the Turnstile service verifies that you are not a robot, without setting any cookie. This transfer is covered by the EU–US Data Privacy Framework and standard contractual clauses.
Cookies and analytics
This site sets no cookies, runs no analytics and embeds no advertising trackers, so no consent banner is required. The Cloudflare Turnstile anti-bot check works without cookies.
Your rights
You have the right to access, rectify, erase, restrict or object to the processing of your data, the right to data portability and the right to withdraw your consent at any time (in particular for voice messages). To exercise these rights, use the contact form on this site.
If you believe your rights are not being respected, you may lodge a complaint with the CNIL (www.cnil.fr).
Security
The site is served exclusively over HTTPS. Forms are protected against spam (honeypot, rate limiting, anti-bot verification) and messages delivered to Telegram are marked as protected against forwarding.