Privacy Policy
Last updated 22 September 2026
This policy explains which personal data Eat The Iceberg processes, why, on which legal basis, who it is shared with, how long it is kept and which rights you can exercise.
1. Data controller
The data controller is Kany Aïcha Diakhaté, sole trader, 10 rue Florence Arthaud, 76100 Rouen, France.
Contact for any question or request about your data: hello@eat-the-iceberg.com.
No data protection officer has been appointed: an appointment is not required given the current activity.
2. Data processed and its source
Data comes from you, either directly (forms) or indirectly (your use of the service).
- Account and sign-in: email address, password encrypted by the authentication system, creation, confirmation and sign-in dates, account state.
- Profile: display name, first and last name if you provide them, professional headline, introduction, photo, professional link, declared specialties, public visibility choice.
- Onboarding: role, experience level, business context, chosen topics and intentions.
- Content: experiments and their files, contributions in the discussion spaces and their images, mentions of other members.
- Personal working space: notes and files in the Experimental Notebook, strictly private.
- Service usage: saved items, collections, follows, membership of themed spaces, notifications and activity.
- Preferences: interface language, choice to receive product guidance emails, marketing consent.
- Moderation and security: reports you submit, moderation decisions, restrictions, technical elements needed to prevent abuse.
- Product feedback: the message sent through the help form, with the originating page, the language and technical display information.
- Terms acceptance: accepted version, date, language displayed, origin of the acceptance.
- Email messages: delivery, open, error and unsubscribe statuses reported by the sending provider.
Mandatory fields are those required to create the account (email address, password, acceptance of the terms) and to complete onboarding. All other fields are optional: leaving them empty only limits some features.
No sensitive data is requested. Do not publish any, whether about yourself or others.
3. Purposes and legal bases
- Creating and managing your account, authenticating you, providing the features of the service — performance of the contract formed by the terms of use.
- Publishing, displaying, translating, classifying and searching content according to your publication choices — performance of the contract.
- Sending emails necessary for your account and its security (confirmation, password reset, address change, security notices) — performance of the contract and legitimate interest in keeping accounts secure.
- Sending product guidance emails about using the service — your explicit choice, which you can withdraw at any time.
- Sending news and marketing communications — consent, which you can withdraw at any time.
- Moderating content, handling reports, preventing and dealing with abuse — legitimate interest in keeping the service safe and reliable, and compliance with the obligations applicable to online services.
- Ensuring technical security, preventing fraud and unauthorised access, keeping the necessary technical traces — legitimate interest in the security of the service.
- Limiting full access to content for signed-out visitors — legitimate interest in protecting the knowledge base built by members.
- Measuring usage in aggregate in order to improve the service, without profiling and without cross-site tracking — legitimate interest, with aggregated data and no identification.
- Handling your product feedback and your data-rights requests — performance of the contract and compliance with legal obligations.
- Keeping minimal evidence of acceptance of the terms to prove the contractual relationship and to establish, exercise or defend legal claims — the controller's legitimate interest.
- Keeping certain experiments internally after account deletion, without identity — legitimate interest described in section 6.
Where processing relies on legitimate interest, a balancing test was carried out: processing is limited to what is necessary, data is minimised, and you can object under the conditions described in section 9.
4. Recipients and processors
Your data is neither sold, rented nor shared for advertising purposes. It is accessible to the publisher and, within the limits of their assignment, to the following technical providers, acting as processors on instruction.
Supabase
Database, authentication and file storage. Processes all account data, content and files. The project's data is hosted in the European Union (the project's European region).
Brevo
Sending account emails, product guidance emails and marketing communications, and managing the associated contact. Processes the email address, the language, profile information used for personalisation, sending preferences and delivery statistics. Company established in France, sending infrastructure in the European Union.
Hostinger
Website hosting. Processes the technical connection data required to deliver the pages.
No advertising tool, no social network and no artificial-intelligence service receives your data.
5. Transfers outside the European Union
The service is configured so that data is processed in the European Union. Some providers may nevertheless rely on support operations from third countries; in that case those transfers are framed by the European Commission's standard contractual clauses and the additional measures put in place by the provider.
You can ask for details about these safeguards at hello@eat-the-iceberg.com.
6. Content kept after an account is deleted
When you delete your account, your published experiments are removed from the public service: they can no longer be viewed and no longer appear in the library, in search or in the sitemap. Their structured content may be kept internally, without your identity (author dissociated).
This content is not anonymous in the legal sense: indirect re-identification cannot be entirely excluded. It is therefore treated as pseudonymised data and protected as such.
Purpose: preserving the consistency and integrity of the collective knowledge base and avoiding broken references and citations made by other members. This processing relies on legitimate interest. No artificial-intelligence model training takes place; such a use would require a prior legal assessment and updated information before any activation.
Likewise, threads other members replied to remain readable without your identity, so that other people's contributions are not erased. You can object to this retention by writing to hello@eat-the-iceberg.com: your request will be assessed against the rights of other members.
7. Retention periods
- Account and associated data: kept for as long as the account exists. Pausing an account deletes nothing.
- Account deletion: carried out after a 7-day cancellation period, then personal data, private files and the contact held by the sending provider are deleted.
- Content kept internally after deletion (dissociated experiments, structurally necessary discussions): kept for as long as the knowledge base is operated, and reviewed in the event of an objection.
- Evidence of terms acceptance: kept for the life of the account and then, solely in minimal dissociated or pseudonymised form, for 5 years after the end of the contractual relationship or permanent account deletion, subject to applicable limitation rules.
- Minimal technical record of deletion: kept to evidence that deletion was carried out, for the same period as above.
- Export archive: only one archive is kept per member; it is replaced on each new request and deleted with the account. The download link expires after 5 minutes.
- Moderation and security records: kept for as long as necessary to handle abuse and to establish or defend a legal claim, then deleted.
- Provider technical logs: kept according to each provider's own policy, which the publisher does not control.
- Email delivery statistics: kept by the sending provider according to its own retention policy.
8. Security
Access to data is enforced at database level: each member reaches only their own data, and private spaces are unreachable by other members. Private files are served only through temporary links. Traffic is encrypted in transit and technical secrets are kept server-side only. A security audit was carried out before the service opened.
9. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent at any time where processing relies on it (withdrawal does not affect messages already sent).
Several rights can be exercised directly from your space: editing your profile, changing your email and language preferences, downloading a copy of your data, pausing your account, deleting your account. These actions remain available from the “Data & privacy” page.
For any other request, write to hello@eat-the-iceberg.com. A reply is provided within one month, extendable if the request is complex.
If you believe your rights are not being respected, you can lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr.
11. Changes to this policy
This policy may change along with the service or applicable regulation. The update date is shown at the top of this page; in the event of a significant change you will be informed through the service or by email.
