Data protection
Privacy policy
Last updated: 30 August 2026
Before going live: the identity of the data controller and the competent supervisory authority depend on the publisher's registered office. The highlighted fields must be filled in.
This is a showcase website. It has no login area, no payment and no profiling. The only occasion on which you send us personal data is the contact form, and you remain free to email us directly instead.
1. Data controller
| Organisation | TO BE COMPLETED: legal name, identical to the legal notice |
|---|---|
| Address | TO BE COMPLETED: registered office address |
| Contact | contact@sunygreen.com |
| Data protection officer | TO BE COMPLETED: name and contact details of the DPO, or "not appointed" if the organisation is not required to have one |
2. Data collected and purpose
We collect nothing beyond what you type into the contact form yourself.
| Name | Required: so that we address you correctly in our reply. |
|---|---|
| Organisation | Optional: to put your enquiry in context (manufacturer, partner, evaluator). |
| Required: this is the address we reply to. | |
| Message | Required: the subject of your enquiry. |
| Date sent | Recorded automatically by the delivery service. |
Single purpose: handling your enquiry and replying to it. This data is never used for marketing, is neither sold nor rented nor passed to third parties for advertising purposes, and feeds no mailing list.
3. Legal basis
Processing is based on your consent, within the meaning of Article 6(1)(a) of the General Data Protection Regulation (GDPR). Consent is obtained through the form's tick box, which is not pre-ticked. You may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out beforehand.
4. Recipients
Your messages are read by the members of the SunyGreen consortium responsible for handling enquiries. No other recipient has access to them.
Processor: message delivery
This website is entirely static and has no application server of its own. Form submission is therefore entrusted to Web3Forms, which turns your input into an email and delivers it to us. Web3Forms acts as a processor within the meaning of Article 28 of the GDPR and does not retain message content after delivery.
Provider's privacy policy: web3forms.com/privacy.
Hosting
The website files are hosted by o2switch on infrastructure located in France. The server's technical logs (IP address, date, page requested) are retained by the host for security and diagnostic purposes, in accordance with its own legal obligations.
No third-party analytics
This website contains no Google Analytics, no Meta Pixel and no other tracker. Typefaces are served from this server rather than from Google Fonts: simply browsing the pages triggers no request to any third-party domain.
5. Transfers outside the European Union
The website organises no transfer of data outside the European Union for the purposes of ordinary browsing. As regards delivery of form messages, the applicable safeguards are those described by Web3Forms. If you would rather avoid any intermediary, write to us directly at contact@sunygreen.com.
6. Retention period
Messages received are kept for three years from the last exchange, the usual period for managing contacts and following up a funded research project. After that they are deleted. You may request earlier erasure.
7. Your rights
Under Articles 15 to 22 of the GDPR, you have the following rights over your data:
- Access: obtain confirmation that it is being processed and receive a copy.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have it deleted.
- Restriction: have its use frozen pending verification.
- Objection: object to its processing.
- Portability: receive it in a machine-readable format.
- Withdrawal of consent: at any time, without justification.
To exercise these rights, write to contact@sunygreen.com. We respond within one month. Proof of identity may be requested where there is reasonable doubt as to the identity of the person making the request.
8. Complaints
If, after contacting us, you consider that your rights have not been respected, you may lodge a complaint with the competent supervisory authority:
TO BE COMPLETED: depending on the publisher's registered office:
• Belgium: Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels,
autoriteprotectiondonnees.be
• France: CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, cnil.fr
Delete the line that does not apply.
9. Security
The website is served exclusively over HTTPS: form data travels encrypted. Being entirely static, it exposes no database, no administration interface and no user account, which reduces the attack surface accordingly.
10. Changes
This policy may be updated, in particular if a new tool is added to the website. The date of the last update appears at the top of this page. In the event of a substantial change, visitors will be informed on this page.