Privacy & data protection

Privacy notice

This notice explains, in plain language, what REX processes when you visit this company website or send a business enquiry, why it is needed, how long it is kept and how to exercise your rights.

Last updated

At a glance

No
advertising or behavioural tracking
Never
sold or rented personal data
3 years max.
enquiry record after the last contact
Direct
email channel for your data rights

01 / Responsibility

Who is responsible for your data

REX determines how personal data is used on this website and is therefore the data controller for the processing described below.

Data controller
REX, société par actions simplifiée (SAS) au capital de 3 000 €, immatriculée au registre du commerce et des sociétés de Toulouse
Company registration
SIREN 940 816 507 · SIRET 940 816 507 00013
Tax and activity identifiers
TVA FR84 940 816 507 · APE 46.90Z
Registered office
13 bis avenue de Francazal, 31270 Villeneuve-Tolosane, France
Privacy contact
Use this address for questions or to exercise your rights: rex31fr@hotmail.com

This notice covers the public pages under rex31.com/site and the contact form on those pages. Services, demonstrations and third-party websites reached through a link have their own data practices and are not covered by this notice.

02 / Processing record

What we process, and why

We limit processing to the operations needed to serve the site, protect it and respond to a request you choose to send.

Website delivery and security

Serve pages, diagnose failures and protect the service against abuse.

Data
IP address, date and time, requested path, response status and standard request metadata generated by the web server.
Legal basis
REX's legitimate interest in providing a reliable and secure website (GDPR Article 6(1)(f)).
Retention
Web-server access logs rotate daily and are deleted after 14 days.

Business enquiry

Review your request, reply and, where relevant, prepare a proposal or other pre-contractual steps requested by you.

Data
Name, email address, message, selected language, submission reference and time; company or organisation only if you choose to provide it.
Legal basis
Steps at your request before entering a contract (Article 6(1)(b)); for general non-contractual messages, REX's legitimate interest in answering them (Article 6(1)(f)).
Retention
Up to 3 years after your last active contact if no contract is concluded, then deletion or anonymisation.

Receipt and email delivery

Send you a confirmation and route your enquiry to the authorised REX mailbox.

Data
Email address, name, enquiry content, submission reference and delivery metadata.
Legal basis
The same pre-contractual or legitimate-interest basis as the enquiry to which the email relates.
Retention
The delivery provider retains message and log data for 30 days on the plan in use. The REX mailbox copy follows the enquiry retention above.

Contact-form abuse prevention

Limit automated or excessive submissions without profiling visitors.

Data
IP address, one-time request identifier and form start time. The hidden anti-spam field is expected to remain empty.
Legal basis
REX's legitimate interest in protecting the form and email service (Article 6(1)(f)).
Retention
The IP address remains only in application memory for 1 hour; the request identifier and reference for no more than 24 hours. The contact endpoint does not write an access log.

If an enquiry leads to a contract, the information needed for the client relationship is moved into the relevant business records and kept for the applicable contractual, accounting or legal periods. You will be informed if a new use requires additional information.

03 / Data minimisation

Only ask for what the conversation needs

The contact form distinguishes information needed to answer you from useful but optional context.

  • Name, email address and message are required. Without them, REX cannot identify your request, reply or understand what is needed.
  • Company or organisation is optional. Leaving it blank does not prevent submission.
  • The form is not used to subscribe you to marketing and does not create an account or visitor profile.
  • Information is collected directly from you; the website does not enrich it from data brokers or social networks.

Please do not send sensitive data

Do not include passwords, payment-card details, health data, government identifiers or confidential third-party records in the free-text field. If a later project requires protected material, REX will agree a suitable transfer channel separately.

04 / Access boundary

Who receives the information

Access is limited to people and providers that need the information for the stated purpose.

Authorised REX recipient

The business mailbox used to review and answer the enquiry. Contact submissions are not copied to a separate personal inbox.

OVHcloud

Hosts the website and contact service on the production VPS. Standard web-server logs are retained for 14 days.

Resend

Transmits the internal notification and your confirmation email. It processes the email address, content and delivery metadata as REX's email service provider.

Mailbox operators

Microsoft operates the REX receiving mailbox; the provider of the email address you supply necessarily receives the confirmation sent to you.

Transfers outside the European Economic Area

Resend states that customer email and log data is stored in the United States. Its Data Processing Addendum incorporates the European Commission's Standard Contractual Clauses and also describes the EU–US Data Privacy Framework. Email providers may process data internationally under their own applicable safeguards. You can ask REX for information about the safeguards relevant to your request.

Read Resend's Data Processing Addendum (opens in a new tab)

REX does not sell, rent or disclose contact-form data to data brokers, advertising networks or social platforms. It is not reused for newsletters or unsolicited marketing.

05 / Browser storage

No advertising cookies or analytics

The company site currently uses no audience analytics, advertising pixels, cross-site identifiers or social-media tracking widgets.

Language preference

The site writes one first-party local-storage value named “rex-locale” containing only the selected interface language (en, fr or zh). It is used solely to keep the expected language and remains on your device until you clear browser storage. It is not sent with page requests, combined with another identifier or used to follow browsing behaviour.

What is not present

  • No advertising, retargeting or behavioural profiling
  • No Google Analytics, Tag Manager, Meta Pixel or equivalent tool
  • No third-party cookie or embedded social feed
  • No automated decision-making based on website activity

Because the only browser storage is an interface-language preference that is necessary for the feature requested by the visitor, no consent banner is displayed. If a tool requiring consent is introduced later, it must remain disabled until a valid choice mechanism and this notice are updated.

06 / Safeguards

Controls matched to a small contact service

REX applies technical and organisational measures proportionate to the limited data handled by this site.

  1. 01

    HTTPS protects traffic in transit; strict browser headers restrict scripts, framing, referrers and sensitive device permissions.

  2. 02

    The contact service does not use a customer database. It creates a protected temporary text file only for the email send, then deletes it automatically.

  3. 03

    Message bodies are excluded from application and Mailato audit logs; the contact endpoint's Nginx access log is disabled.

  4. 04

    Origin checks, payload limits, a hidden anti-spam field, minimum form age, per-IP throttling and a global daily limit reduce automated abuse.

  5. 05

    The service runs under a dedicated unprivileged system account with restricted filesystem, device, kernel and process access.

  6. 06

    Only the business recipient needed to answer the request receives the internal message.

No internet transmission or storage system can be guaranteed absolutely secure. If a personal-data breach is likely to create a risk for individuals, REX will assess it and make the notifications required by applicable law.

07 / Individual control

You remain in control of your data

Subject to the conditions in the GDPR, you may exercise the following rights without charge.

Access

Ask whether REX processes your personal data and receive a copy.

Rectification

Correct information that is inaccurate or incomplete.

Erasure

Request deletion when the information is no longer needed or another legal ground applies.

Restriction

Ask REX to freeze certain uses while an issue is examined.

Objection

Object, for reasons relating to your situation, to processing based on legitimate interest.

Portability

Receive data you supplied in a structured, commonly used format where the legal conditions apply.

How to exercise a right

Email rex31fr@hotmail.com with the subject “Data protection request”. Describe the request and the email address or submission reference involved. Do not attach identity documents unless REX asks for proportionate proof because there is reasonable doubt about identity.

REX will respond without undue delay and normally within one month. That period may be extended by up to two further months for a complex or numerous request; if so, you will be told within the first month and given the reason.

Right to complain

If you believe your rights have not been respected after contacting REX, you may lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), the French supervisory authority.

Contact or lodge a complaint with the CNIL (opens in a new tab)

08 / Version

A notice that follows the actual service

This notice is reviewed when the contact workflow, hosting, email provider, browser storage or legal requirements change. Material changes will be dated on this page and, where required, brought to affected people’s attention before the new processing begins.

Current version: 31 August 2026. This is the first full version replacing the former one-sentence contact-form alert.

This notice is structured around Articles 12 and 13 of the General Data Protection Regulation and the transparency guidance published by the CNIL.

Read the GDPR on EUR-Lex (opens in a new tab)