Data protection

Privacy policy

Last updated: 30 August 2026

Before going live: the identity of the data controller and the competent supervisory authority depend on the publisher's registered office. The highlighted fields must be filled in.

This is a showcase website. It has no login area, no payment and no profiling. The only occasion on which you send us personal data is the contact form, and you remain free to email us directly instead.

1. Data controller

Organisation TO BE COMPLETED: legal name, identical to the legal notice
Address TO BE COMPLETED: registered office address
Contact contact@sunygreen.com
Data protection officer TO BE COMPLETED: name and contact details of the DPO, or "not appointed" if the organisation is not required to have one

2. Data collected and purpose

We collect nothing beyond what you type into the contact form yourself.

Name Required: so that we address you correctly in our reply.
Organisation Optional: to put your enquiry in context (manufacturer, partner, evaluator).
Email Required: this is the address we reply to.
Message Required: the subject of your enquiry.
Date sent Recorded automatically by the delivery service.

Single purpose: handling your enquiry and replying to it. This data is never used for marketing, is neither sold nor rented nor passed to third parties for advertising purposes, and feeds no mailing list.

3. Legal basis

Processing is based on your consent, within the meaning of Article 6(1)(a) of the General Data Protection Regulation (GDPR). Consent is obtained through the form's tick box, which is not pre-ticked. You may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out beforehand.

4. Recipients

Your messages are read by the members of the SunyGreen consortium responsible for handling enquiries. No other recipient has access to them.

Processor: message delivery

This website is entirely static and has no application server of its own. Form submission is therefore entrusted to Web3Forms, which turns your input into an email and delivers it to us. Web3Forms acts as a processor within the meaning of Article 28 of the GDPR and does not retain message content after delivery.

Provider's privacy policy: web3forms.com/privacy.

Hosting

The website files are hosted by o2switch on infrastructure located in France. The server's technical logs (IP address, date, page requested) are retained by the host for security and diagnostic purposes, in accordance with its own legal obligations.

No third-party analytics

This website contains no Google Analytics, no Meta Pixel and no other tracker. Typefaces are served from this server rather than from Google Fonts: simply browsing the pages triggers no request to any third-party domain.

5. Transfers outside the European Union

The website organises no transfer of data outside the European Union for the purposes of ordinary browsing. As regards delivery of form messages, the applicable safeguards are those described by Web3Forms. If you would rather avoid any intermediary, write to us directly at contact@sunygreen.com.

6. Retention period

Messages received are kept for three years from the last exchange, the usual period for managing contacts and following up a funded research project. After that they are deleted. You may request earlier erasure.

7. Your rights

Under Articles 15 to 22 of the GDPR, you have the following rights over your data:

  • Access: obtain confirmation that it is being processed and receive a copy.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: have it deleted.
  • Restriction: have its use frozen pending verification.
  • Objection: object to its processing.
  • Portability: receive it in a machine-readable format.
  • Withdrawal of consent: at any time, without justification.

To exercise these rights, write to contact@sunygreen.com. We respond within one month. Proof of identity may be requested where there is reasonable doubt as to the identity of the person making the request.

8. Complaints

If, after contacting us, you consider that your rights have not been respected, you may lodge a complaint with the competent supervisory authority:

TO BE COMPLETED: depending on the publisher's registered office:
• Belgium: Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels, autoriteprotectiondonnees.be
• France: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr
Delete the line that does not apply.

9. Security

The website is served exclusively over HTTPS: form data travels encrypted. Being entirely static, it exposes no database, no administration interface and no user account, which reduces the attack surface accordingly.

10. Changes

This policy may be updated, in particular if a new tool is added to the website. The date of the last update appears at the top of this page. In the event of a substantial change, visitors will be informed on this page.