Legal information
Privacy policy
This English version is provided for convenience. Only the French version, available at asterale.fr/politique-confidentialite.html, is legally binding.
Updated 6 October 2026
Version 2.0 of 16 September 2026, which replaces version 1.0 of January 2026.
This policy describes how ASTERALE collects, uses, retains and protects the personal data of visitors to its website and of its clients, in accordance with Regulation (EU) 2016/679 (GDPR), French Act no. 78-17 of 6 January 1978 as amended, and the recommendations of the CNIL, the French data protection authority.
1. Controller
ASTERALE, SASU with share capital of €1,000, Créteil Trade and Companies Register no. 921 855 508, 4 allée Django Reinhardt, 94110 Arcueil, France, represented by Mr Sébastien Bailly, President. Contact for any data-related question: sebastien.bailly@asterale.fr or +33 6 28 54 13 74.
Given the size of the firm and the nature of its processing, ASTERALE has not appointed a data protection officer. The President acts personally as point of contact.
2. Data collected
2.1 On the asterale.fr website
| Source | Data | Status |
|---|---|---|
| "Write to the firm" form | Full name, email, telephone, subject, profile, amount to invest, message | Telephone, profile and amount to invest are optional |
| Calendly calendar | First name, surname, email, chosen slot and answers to any booking form questions | On the Calendly website, if you book that way |
| Browsing | Technical logs of the hosting server (IP address, page requested, timestamp, browser), kept by the host for security purposes | No audience measurement tool |
The form is processed by the site's own server and forwarded to the firm by email. No data is entrusted to a third-party form service.
2.2 In the course of the client relationship
Under its know-your-customer and anti-money laundering and counter-terrorist financing (AML/CFT) obligations, ASTERALE collects:
- an identity document;
- proof of address less than three months old;
- evidence of the origin of funds (tax notices, statements, deeds);
- information on the client's wealth, family, tax and professional situation;
- investment objectives and risk tolerance (questionnaire required by MiFID II).
3. Purposes, legal bases and retention periods
| Purpose | Legal basis (Article 6 GDPR) | Retention |
|---|---|---|
| Replying to a contact or appointment request | Pre-contractual measures (6.1.b) | 3 years from last contact |
| Performance of advisory services | Performance of a contract (6.1.b) | Duration of the relationship, then 10 years (limitation period) |
| AML/CFT obligations | Legal obligation (6.1.c) | 5 years after the end of the relationship (Article L. 561-12 of the French Monetary and Financial Code) |
| Accounting obligations | Legal obligation (6.1.c) | 10 years (Article L. 123-22 of the French Commercial Code) |
| Information to existing clients | Legitimate interest (6.1.f), with right to object | Duration of the relationship |
| Marketing to non-clients | Consent (6.1.a) | 3 years from last contact |
No automated decision-making or profiling is carried out.
4. Recipients
Data is disclosed only to the extent strictly necessary, to the following recipients:
- Sébastien Bailly, sole internal staff member;
- technical providers under contract: OVH SAS (website hosting), Microsoft (business email, hosted in the European Union) and Calendly (appointment booking);
- the drafting and analysis assistance tools used by the firm in the course of its engagements, under a processing agreement compliant with Article 28 GDPR, with no training of models on the data entrusted; no decision is automated;
- the insurance companies, asset management companies and institutions with which a subscription is decided, with your express consent;
- the notaries, lawyers and accountants whose work we coordinate, with your consent;
- the competent authorities (AMF, ACPR, TRACFIN, tax administration, judicial authorities), on requisition.
No data is sold, rented or transferred for commercial purposes.
5. Transfers outside the European Union
Calendly LLC (Atlanta, United States) processes the data of appointments booked through the calendar. This transfer relies on the European Commission's standard contractual clauses and on Calendly's certification under the EU-US Data Privacy Framework.
The firm's email is provided by Microsoft and hosted in the European Union. Any access from the United States for support purposes is covered by the standard contractual clauses and the Data Privacy Framework.
The assistance tools mentioned in section 4 may involve a transfer covered by the safeguards of Articles 44 et seq. GDPR.
A copy of the applicable safeguards is available on request.
6. Your rights
Under Articles 15 to 22 GDPR, you have the following rights:
- access;
- rectification;
- erasure, subject to legal retention obligations;
- restriction;
- portability;
- objection, in particular to marketing;
- withdrawal of consent at any time.
You may also give instructions on the fate of your data after your death (Article 85 of the French Data Protection Act).
To exercise these rights, write to sebastien.bailly@asterale.fr or send a letter to the registered office. Proof of identity may be requested where there is doubt. We reply within one month, extendable by two months for complex requests.
7. Cookies and third-party services
The site sets no audience measurement, advertising or behavioural analytics cookies and embeds no script of that kind. No consent banner is therefore required.
The site integrates no third-party service. The "Book a slot" button opens the Calendly calendar on calendly.com, in a new tab; any cookies Calendly then sets are governed by its own policy (calendly.com/privacy). You can also book through the "Write to the firm" form, by email or by telephone.
The site's fonts are served from the site's own server, with no call to a third-party service.
8. Security
ASTERALE applies the following measures:
- HTTPS encryption of the whole site;
- access to the administration area protected by password, and multi-factor authentication on critical services;
- access to data limited to Sébastien Bailly and providers under contract;
- regular backups;
- in the event of a data breach, notification to the CNIL within 72 hours (Article 33 GDPR) and, where applicable, information to the persons concerned.
ASTERALE is also bound by professional secrecy in the course of its regulated activities.
9. Complaints to the CNIL
If, after contacting us, you consider that your rights are not respected, you may refer the matter to the CNIL: www.cnil.fr/fr/plaintes, or CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, telephone +33 1 53 73 22 22.
10. Updates
This policy may change to reflect legal developments or changes in our practices. The version in force is the one published on this page. Version 2.0 of 16 September 2026.
The French version prevails.