How we handle your data.
As of 2026-08-08
Last updated: 19 July 2026 · v1.4.0
1. Who we are
Operated by Analytics Legends, an independent SAP analytics editorial platform registered in France. Contact: contact@analyticslegends.ai.
2. What data we collect
If you do not create an account, we do not ask you for identity data. The site is a client-side application. By default no tracking or analytics cookie, no fingerprinting and no advertising pixel is set. An audience-measurement cookie (Google Analytics) is enabled only if you explicitly consent via the consent banner (see below); no advertising cookie is ever used.
Cookieless audience measurement (Plausible). We measure site traffic with Plausible Analytics, an EU-based tool that works without cookies, without persistent identifiers and without cross-site tracking: only aggregate statistics (page views, country, device type, referrer) are produced, and no data that could identify you is retained. This setup falls under the CNIL consent exemption for audience measurement (Art. 82 of the French Data Protection Act): Plausible alone therefore triggers no consent request. Data is hosted in the European Union.
Google Analytics (subject to your consent). We also use Google Analytics 4. In line with the GDPR and CNIL guidance, GA4 runs in Consent Mode v2 with all storage denied by default: until you click "Accept" in the consent banner, no Google cookie is set and only anonymous, cookieless measurement is sent. If you accept, an audience-measurement cookie is set and usage statistics are sent to Google (Google Ireland Ltd.; any transfer outside the EU is governed by the European Commission's Standard Contractual Clauses). You can withdraw consent at any time by clearing your browser storage, or by emailing us at contact@analyticslegends.ai. Advertising signals (ad personalization) are disabled: GA4 is used for audience measurement only.
Local device storage. We use browser localStorage only for functional app state: language and currency preferences, saved searches, bookmarks, application notes, skill self-assessments, crash diagnostics, account-export helpers, and other user-entered drafts. Some values may identify you if you type personal data into them. They stay on your device unless you explicitly submit or sync them, and you can erase them from your profile export/delete tools or browser storage.
If you do create an account, we collect and store in our authentication provider (Supabase):
- your email address,
- a hashed password (we never see or store the plaintext),
- timestamps of account creation, last sign-in, and email confirmation,
- a unique Supabase user ID.
We do not collect your name, address, phone number, or any other personal information unless you explicitly submit it through the Legends Pass subscription on Stripe.
3. Legal basis for processing
Under GDPR art. 6(1)(b), the processing of your email and authentication metadata is necessary to provide the service you signed up for. For the Legends Pass, the legal basis is art. 6(1)(b) and art. 6(1)(c) (compliance with a legal obligation — invoicing).
4. Where your data is stored
Supabase (authentication provider) — Supabase Inc., 970 Toa Payoh North, #07-04 Singapore. GDPR-compliant. Data is stored in the EU region when the project is configured that way.
GitHub (hosting + CDN via GitHub Pages) — GitHub, Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA. GitHub Pages keeps short-lived technical logs (IP, user-agent, path, timestamp); these are retained under GitHub's privacy policy, not analysed by us.
Stripe (payment processor) — Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Card data is PCI-DSS Level 1 at Stripe and never touches our domain.
5. Fonts and assets
Web fonts are self-hosted via @fontsource. No request to Google Fonts. This closes the RGPD gap flagged by the CNIL and the LG München I court (20.01.2022).
6. AI-agent API
The /api/* JSON endpoints expose aggregate platform data intended for AI agents and third-party integrators: opportunity listings, market rate benchmarks, the Academy catalogue, concept indices, and news. CORS is open so LLM agents can consume the feed.
The consultant-matches and opportunity-matches datasets reference consultants by pseudonymous IDs together with first-and-last name, city, seniority band and a stated daily-rate range. They are not public: they have been removed from the /api/* endpoints and are served only to authenticated accounts on the relevant paid plans, through a server function that checks the subscription level on every call. Each entry is derived from the consultant's publicly-visible LinkedIn profile, whose URL we verified at the time of inclusion. Under GDPR our legal basis is legitimate interest (Art. 6(1)(f) RGPD) in operating a professional directory for the SAP analytics consulting market, balanced against a narrow scope (public professional information only — no email, phone, home address, salary history, or any data not already public on LinkedIn). No email addresses, phone numbers, or non-public contact channels are exposed in any /api/* endpoint. Any listed consultant can object, rectify, or request erasure at contact@analyticslegends.ai (see §8); removal is effected within 30 days and in practice within 24-48h on business days. The directory endpoints are disallowed in robots.txt for AI-training crawlers. The headhunter master directory (~9,104 rows) is NOT exposed as a public artefact — it lives only in Supabase behind a Firm-tier RLS policy (public.is_firm() via the v_headhunters_master_json view). Public visitors and free-tier users see the curated 30-row preview at /api/headhunters-preview.json + the aggregate counts at /api/headhunters-stats.json. Raw operator-curation files under /data/private/ remain inaccessible.
SAP-analytics stakeholder directory. We maintain a pseudonymised directory of SAP-analytics stakeholders (consultants, architects, partners, decision-makers) derived from the operator's professional LinkedIn network. The directory is pseudonymised per GDPR Art. 4(5): only initials, company, position and a coarse signal tier are retained — no full name, email, phone, LinkedIn URL, connection date, or message history is ever exposed. The full directory never reaches the Pages origin: it lives under data/private/ and will be accessible only through an authenticated Supabase edge function gated by the Firm-tier JWT. The aggregate counterpart at /api/stakeholders-stats.json exposes only counts by archetype, tier and top employers — no individual rows, no PII. Legal basis: Art. 6(1)(f) legitimate interest, with the same narrow scope and removal process as above. Any listed individual can object, rectify, or request erasure at contact@analyticslegends.ai.
Recruiter-outreach opt-in. Listed consultants may opt in to be contacted by Firm-tier recruiters subscribed to the platform. This is a distinct, narrower processing under GDPR Art. 6(1)(a) explicit consent (not legitimate interest), recorded per-consultant as a boolean openToRecruiters flag on their profile. Default is off; the flag is set only after the consultant explicitly confirms consent by email. Consent can be withdrawn at any time by emailing contact@analyticslegends.ai with subject "Recruiter outreach — opt out"; the flag is cleared within 48 business hours. A visible badge ("📩 Open to recruiter outreach") appears on the consultant card only when the flag is on, so third parties can distinguish consenting from non-consenting profiles.
Identity reveal to firms — self-serve explicit consent. When you post your availability ("Open to work") from your signed-in area, your card is anonymous by default: only a free-text label, country, stack, mode and a rate floor are visible to subscribed firms (Firm Pass) — no name, no email, no LinkedIn URL. Through a separate checkbox, off by default, you may authorise Firm Pass subscribers to see the name and LinkedIn URL you enter yourself at that time. Legal basis: GDPR Art. 6(1)(a) — explicit consent. This consent is tightly scoped: (i) your identity is never included in the directory feed; it is delivered only on an explicit Firm Pass subscriber request, enforced server-side (public.is_firm()); (ii) it auto-expires with your availability (60 days); (iii) it is revocable at any time by unchecking the box or deleting your availability. We never use the pseudonymised directory described above for this purpose: only people who explicitly consented through this mechanism have their identity revealed.
7. Retention
Your account data is retained as long as your account is active. You can request erasure at any time (see below). We retain minimal invoice metadata required by French tax law (10 years) even after account deletion; this is anonymised so it is no longer personal data under GDPR.
8. Your GDPR rights — self-serve deletion (v36)
Under GDPR art. 15–22 you can access, rectify, erase, port, restrict, or object to processing of any personal data we hold. Send requests to contact@analyticslegends.ai. 30-day response.
Self-serve deletion: sign into your profile and use the Delete my account button. If the Supabase delete_self RPC is wired, deletion is immediate; otherwise your browser opens a pre-filled email to request manual processing under the 30-day SLA.
You may also complain to the CNIL.
9. Security
HTTPS enforced, strict Content-Security-Policy (separate style-src / style-src-attr in v36), edge CDN. Details in our Security policy.
10. Data-breach notification
If a personal-data breach likely to result in a risk to your rights and freedoms occurs, we notify the CNIL (the French supervisory authority) within 72 hours of becoming aware of it (GDPR Art. 33) and, where the breach is likely to result in a high risk, inform you without undue delay (GDPR Art. 34). We keep an internal register of any breach, its effects and the remedial action taken.
11. Changes
For active accounts, we notify by email before making any material change.