Website Privacy and Cookie Policy

Last updated: July 13th, 2026

This Privacy and Cookie Policy explains how EXEO collects, uses, shares and protects personal data when you visit our website, contact us, or receive our communications. It also explains your rights and how to exercise them.

1. Who is responsible for your data

The data controller for personal data processed through this website is:

SAS EXEO, a simplified joint-stock company registered in France.

  • Registered office: 111 avenue Victor Hugo, 75016 Paris, France
  • SIREN: 892 079 567 (RCS Paris)
  • Intra-EU VAT: FR80 892 079 567
  • Privacy contact: privacy [at] exeo [dot] net

EXEO operates internationally through affiliated entities, including EXEO SAL (Lebanon) and our operations in the Middle East (United Arab Emirates). Where these entities process personal data collected through this website on behalf of SAS EXEO, they act as processors or, where relevant, joint controllers. International data flows are covered in Section 8.

2. Scope of this Policy

This Policy applies to personal data processed when you browse exeo.net, submit a form, subscribe to our communications, or interact with content we send you by email. It does not cover services governed by a separate agreement, where the applicable data protection terms are set out in that agreement.

3. Personal data we collect

3.1 Data you provide

When you complete a form or contact us, we may collect your first and last name, email address, phone number, company, and the content of your message or request.

3.2 Data collected automatically

When you use the website, we may collect your IP address, browser type and version, operating system, the pages you view, referral source, and the date, time and duration of your visit. This data is collected through cookies and similar technologies, as described in Section 6, and, where required, only with your consent.

4. Why we use your data and on what legal basis

We process personal data only where we have a legal basis under the GDPR.

Purpose Legal basis
Providing, operating and securing the website Legitimate interest
Responding to your contact requests and quotes Pre-contractual steps / performance of a contract
Managing the client relationship and contracts Performance of a contract
Sending marketing emails and newsletters Consent, or legitimate interest for existing clients on similar services (soft opt-in), with an opt-out in every message
Measuring audience and website usage Consent (via cookies)
Email delivery and open/click measurement (pixels) Consent for marketing emails; exemption for transactional emails and strict deliverability (see 6.4)
Complying with legal and accounting obligations Legal obligation
Establishing, exercising or defending legal claims Legitimate interest

5. Recipients and third-party services

We share personal data only with the categories of recipients needed to deliver the purposes above: our authorised staff and affiliated entities, and service providers acting as processors under contract.

Service Provider Purpose
Google Analytics Google Ireland Ltd Website audience measurement
Microsoft Clarity Microsoft Corporation Website usage analytics
Leadfeeder Dealfront / Liidio Oy Identifying business visitors by IP
Outfunnel Outfunnel OÜ Marketing and email engagement tracking
Mailchimp Intuit / Rocket Science Group LLC Email marketing delivery
Vimeo Vimeo Inc. Embedded video
Cloudflare Turnstile Cloudflare, Inc. Bot protection on forms (replaces reCAPTCHA)
Microsoft Advertising Microsoft Corporation Advertising measurement (MUID, ANONCHK)

We may also disclose personal data where required by law or a valid request from a public authority, or in connection with a merger, acquisition or transfer of assets, in which case we will inform you beforehand.

6. Cookies and similar technologies

6.1 What we use

A cookie is a small file stored on your device when you visit a website. We also use similar technologies such as pixels, tags and local storage.

  • Strictly necessary: required for the site to function and to remember your consent choices. No consent required.
  • Analytics and performance: Google Analytics, Microsoft Clarity, Leadfeeder. Consent required.
  • Advertising: Microsoft Advertising. Consent required.
  • Functional: remember preferences such as language. Consent required unless strictly necessary for a feature you requested.

6.2 Your choices

Non-essential cookies are only placed after you give consent through our consent banner. You can accept all, refuse all, or choose by category, and you can change or withdraw your choice at any time through the “Revisit consent” link. Refusing is as easy as accepting, and refusal does not prevent you from using the site.

6.3 Cookie lifetime

Consent to cookies is stored for 6 months, after which we will ask again. Cookies we set have a maximum lifetime of 13 months, and information collected through them is kept for no longer than 25 months.

6.4 Tracking pixels in our emails

Our emails may contain tracking pixels (small invisible images) that tell us whether an email was opened and which links were clicked. We follow the CNIL recommendation of 12 March 2026 on email tracking pixels:

  • Marketing emails: we place tracking pixels only with your prior consent, given when you subscribe. You can withdraw consent at any time using the unsubscribe link or by contacting us.
  • Transactional emails: emails tied to a service you requested (account alerts, order confirmations and invoices, shipping notices, password resets, security alerts and breach notifications) may contain a pixel without separate consent.
  • Deliverability: we may measure, at an individual level, whether messages are opened solely to detect inactive recipients and remove them from our lists, limited to the data strictly necessary for that purpose.

7. Sharing your data

We share your personal data with our authorised staff, our affiliated entities, and our processors, in each case limited to what is necessary. We do not sell your personal data. Where affiliated entities or processors are located outside the European Economic Area, the safeguards in Section 8 apply.

8. International data transfers

Some recipients, including EXEO SAL (Lebanon) and EXEO Middle-East & Africa FZ-LLC (United Arab Emirates), as well as certain service providers, are located outside the European Economic Area in countries that do not benefit from a European Commission adequacy decision. For these transfers we rely on the European Commission’s Standard Contractual Clauses, which are in place with the relevant EXEO entities and providers, together with a transfer impact assessment and additional technical and organisational measures where needed. You can request a copy of the relevant safeguards by contacting us.

9. How long we keep your data

We keep personal data only as long as necessary for the purposes described in this Policy, then delete or anonymise it. Indicative retention periods:

Data Retention
Prospect and marketing contacts 3 years from your last contact with us
Client contractual data Duration of the contract, then archived for applicable limitation periods (5 years commercial, 10 years accounting)
Contact-form messages 1 year after the exchange closes, if no relationship follows
Cookie consent records 6 months
Data collected through cookies 25 months maximum
Email engagement / inactivity Recipients removed from lists after a defined period without opening our emails

10. Your rights

Subject to the conditions set by the GDPR and the French Data Protection Act, you have the right to:

  • access the personal data we hold about you and obtain a copy;
  • have inaccurate or incomplete data corrected;
  • have your data erased in the cases provided by law;
  • restrict or object to processing, including objecting to direct marketing at any time;
  • receive your data in a portable format and, where technically possible, have it transmitted to another controller;
  • withdraw your consent at any time, without affecting processing carried out before withdrawal;
  • give instructions on the fate of your data after your death (directives post-mortem).

To exercise these rights, contact us at privacy [at] exeo [dot] net. We may ask you to confirm your identity, and we will reply within one month.

If you believe your rights have not been respected, you can lodge a complaint with the CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr.

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss or alteration. As a managed services and cybersecurity provider, EXEO maintains a certified security management system, including ISO 27001, ISO 27017, ISO 27701 and SOC 2 Type II. No method of transmission or storage is completely secure, but we work to keep our safeguards aligned with recognised standards.

12. Children

This website is intended for a professional audience and is not directed at children. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it.

13. Changes to this Policy

We may update this Policy to reflect changes in our practices or the law. We will post the updated version on this page and change the “Last updated” date. For significant changes, we will provide a more prominent notice.

14. Contact

For any question about this Policy or about how we handle your personal data, contact us at privacy [at] exeo [dot] net.

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent

Paris. Beirut. Dubai.