Analytics Legends The knowledge platform for SAP Analytics
Privacy policy · GDPR

How we handle your data.

As of

Last updated: 22 September 2026 · v2.2.0

1. Who we are

The data controller is CM CONSULTING — a French EURL with share capital of €5,000, registered office 929 Chemin de la Thomassine, 04100 Manosque, France · SIREN 508 603 206 · intra-EU VAT FR18508603206 — which publishes the Analytics Legends editorial platform. No data protection officer has been appointed: the processing meets none of the three mandatory-appointment cases in GDPR art. 37. Contact: contact@analyticslegends.ai.

2. What data we collect

If you do not create an account, we do not ask you for identity data. The site is a client-side application. No tracking or audience-measurement cookie, no fingerprinting and no advertising pixel is set — neither by default nor after any acceptance. The site therefore shows no consent banner, because it has nothing to ask consent for: Google Analytics, and the banner that existed only for it, were removed on 8 August 2026.

Cookieless audience measurement (Plausible). We measure site traffic with Plausible Analytics, an EU-based tool that works without cookies, without persistent identifiers and without cross-site tracking: only aggregate statistics (page views, country, device type, referrer) are produced, and no data that could identify you is retained. This setup falls under the CNIL consent exemption for audience measurement (Art. 82 of the French Data Protection Act): Plausible alone therefore triggers no consent request. Data is hosted in the European Union.

First-party audience measurement. In addition, our own collection point (a Cloudflare Worker we operate) receives, for each page view, the path visited, the host of the referring site, the country, region and city derived from the request, the device type, browser, operating system, language and screen width. It writes nothing on your device — no cookie, no storage — and does not keep your IP address: it derives a salted digest from it whose salt changes every night, so that two days cannot be linked. "Do Not Track" and "Global Privacy Control" signals are honoured. Legal basis: legitimate interest (GDPR art. 6(1)(f)) in measuring site traffic; this measurement is not tracking and feeds no profile.

Local device storage. We use browser localStorage only for functional app state: language and currency preferences, saved searches, bookmarks, application notes, skill self-assessments, crash diagnostics, account-export helpers, and other user-entered drafts. Some values may identify you if you type personal data into them. They stay on your device unless you explicitly submit or sync them, and you can erase them from your profile export/delete tools or browser storage.

If you do create an account, we collect and store in our authentication provider (Supabase):

If you sign in via Google, LinkedIn or Apple, the provider passes us an identifier, your email address (for Apple, possibly a "Hide My Email" relay address) and the name attached to the account; we receive neither your contacts nor your activity there. What you then add yourself to your profile — first and last name, headline, company, city and country, phone, LinkedIn URL, photo, CV, skills, seniority, languages, rate floor, availability, preferences — is stored in the same project and readable only by you, except the items you choose to publish (§ 6). Using the account also produces data: applications, messages, saved searches and favourites, interview-studio sessions, questions asked of the concierge (§ 4), API keys and call counters, timestamped consents and cancellation requests (contractual evidence) and, for a subscriber, the Stripe customer identifier. The mobile apps read and write the same record as the website; they embed no advertising SDK and no push notification.

3. Legal basis for processing

Contract (GDPR art. 6(1)(b)): your account, profile, applications, messages, sessions and subscriptions — everything needed to provide the service you asked for. Legal obligation (art. 6(1)(c)): billing metadata and the evidence of consent at checkout, kept with the invoice. Consent (art. 6(1)(a)): publishing your availability to firms, revealing your identity, the newsletter, a testimonial — each withdrawable at any time, without effect on the rest. Legitimate interest (art. 6(1)(f)): audience measurement, security and abuse logs, the professional directory and the prospecting described in § 6 and § 6 bis, after balancing against your rights; you may object at any time.

4. Where your data is stored

Supabase (authentication, database and server functions) — Supabase Inc., 970 Toa Payoh North, #07-04 Singapore. The project is hosted in the European Union: region eu-north-1 (Stockholm, Sweden), verified on 2 September 2026. Transfers to Supabase Inc. are governed by the European Commission's Standard Contractual Clauses.

Google, LinkedIn and Apple (identity providers, only if you choose one of them to sign in) — Google — Gordon House, Barrow Street, Dublin 4, Ireland; LinkedIn Ireland Unlimited Company, Dublin; Apple Distribution International Ltd., Cork. Each learns that you sign in to Analytics Legends and passes us the identity described in § 2; they act as controllers of their own processing, under their own policy.

GitHub (origin hosting via GitHub Pages) — GitHub, Inc., 88 Colin P Kelly Jr Street, San Francisco, CA 94107, USA. GitHub Pages keeps short-lived technical logs (IP, user-agent, path, timestamp); these are retained under GitHub's privacy policy, not analysed by us. Transfers outside the EU are governed by the EU-US Data Privacy Framework and the Standard Contractual Clauses.

Stripe (payment processor) — Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin, Ireland. Card data is PCI-DSS Level 1 at Stripe and never touches our domain.

Cloudflare (CDN and proxy in front of the domain) — Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. Cloudflare sees the IP address and headers of each request for as long as it takes to route it and filter abuse; we derive no analytics from it. Transfers governed by the Standard Contractual Clauses.

Plausible (cookieless audience measurement) — Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Data hosted in the European Union, no transfer outside the EU.

Brevo (transactional email and newsletter delivery) — Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France. Receives the recipient's email address and the message content. Data hosted in the European Union.

Anthropic (the platform's "concierge" assistant) — Anthropic PBC, 548 Market Street, San Francisco, CA 94104, USA. The concierge is an artificial-intelligence system: when you ask it a question, its text is sent to the Claude API to produce the answer, together with your account identifier and your tier. Anthropic acts as a processor, does not use this data to train its models, and transfers are governed by the standard contractual clauses. We log every question and answer with your identifier for 18 months (§ 7). Do not write personal or confidential data into the concierge: as with any assistant, what you type there leaves the platform.

If you live outside the European Economic Area. What you give us leaves your country: it is hosted in the European Union (Sweden, see Supabase above) and, for the purposes described in this section, reaches the providers named above in the United States (GitHub, Cloudflare, Anthropic) and Supabase Inc. (Singapore); Stripe Payments Europe may itself transfer payment data to Stripe, Inc. (United States) under its own policy. The instruments cited above are those of EU law; we have not put in place any transfer instrument specific to the law of your country (for example the ANPD standard clauses in Brazil). If your law requires one, or requires your consent to this transfer, write to us at contact@analyticslegends.ai.

5. Fonts and assets

Web fonts are self-hosted via @fontsource. No request to Google Fonts. This closes the RGPD gap flagged by the CNIL and the LG München I court (20.01.2022).

6. AI-agent API

The /api/* JSON endpoints expose aggregate platform data intended for AI agents and third-party integrators: opportunity listings, market rate benchmarks, the Academy catalogue, concept indices, and news. CORS is open so LLM agents can consume the feed.

The consultant-matches and opportunity-matches datasets — the matching between consultant records and opportunities — are not public: they are served only to the paying accounts concerned, by a server function that checks the tier on every call, and in a pseudonymised form (record label, country, skills, seniority, day-rate band). No name, email, phone or LinkedIn URL appears in them; an identity is delivered only through the consent described below. No /api/* endpoint exposes contact details. The master headhunter directory (~9,332 rows) remains reserved to the Firm tier behind a server-side policy; visitors see only a curated preview and aggregates.

SAP-analytics stakeholder directory. We maintain a pseudonymised directory of SAP-analytics stakeholders (consultants, architects, partners, decision-makers) derived from the operator's professional LinkedIn network. What the directory shows is pseudonymised per GDPR Art. 4(5) — which means it is still personal data: initials, company, position and a coarse signal tier. Behind it, the operator keeps privately, in a part of the database that is served to no account and through no API: the full name, the LinkedIn profile URL, the date of the LinkedIn connection, the history of messages exchanged with the operator, working notes and, for some entries, a professional email address (found published, or inferred from the company's address format). None of this is ever exposed on the site, in the API or to a subscriber. The full directory never reaches the Pages origin: it lives under data/private/ and will be accessible only through an authenticated Supabase edge function gated by the Firm-tier JWT. The aggregate counterpart at /api/stakeholders-stats.json exposes only counts by archetype, tier and top employers — no individual rows, no PII. Legal basis: Art. 6(1)(f) legitimate interest, with the same narrow scope and removal process as above. Any listed individual can object, rectify, or request erasure at contact@analyticslegends.ai.

Opt-in to the pool and to introductions. From your signed-in area (website or app), you declare your availability and tick, if you wish, the box that allows subscribing firms to propose an introduction. This processing rests on your consent (GDPR art. 6(1)(a)); every grant and every withdrawal is logged with the version of the text you read. The default is off; you withdraw consent by unticking the box, withdrawing your availability, or writing to us at contact@analyticslegends.ai. An accepted introduction request triggers a notification email that carries neither the firm's name nor its message.

Identity reveal to firms — self-serve explicit consent. When you post your availability ("Open to work") from your signed-in area, your card is anonymous by default: only a free-text label, country, stack, mode and a rate floor are visible to subscribed firms (Firm Pass) — no name, no email, no LinkedIn URL. Through a separate checkbox, off by default, you may authorise Firm Pass subscribers to see the name and LinkedIn URL you enter yourself at that time. Legal basis: GDPR Art. 6(1)(a) — explicit consent. This consent is tightly scoped: (i) your identity is never included in the directory feed; it is delivered only on an explicit Firm Pass subscriber request, enforced server-side (public.is_firm()); (ii) it auto-expires with your availability (60 days); (iii) it is revocable at any time by unchecking the box or deleting your availability. We never use the pseudonymised directory described above for this purpose: only people who explicitly consented through this mechanism have their identity revealed. Firm Pass subscribers may be established outside the European Economic Area, including in countries the European Commission has not recognised as providing adequate protection: your card, and your identity if you tick the second box, can then be read by a firm in such a country. We do not currently restrict introductions or identity reveal by the firm's country.

6 bis. Data that does not come from you (GDPR art. 14)

Some of the data we process was not collected from the data subject: organisation and opportunity records come from public web pages (company sites, job postings, public registers), and the professional directory entries described in § 6 come from publicly-visible LinkedIn profiles. The categories processed are professional data: for organisations, name, role, country or city and a link to the source; for directory entries, in addition, the person's name, LinkedIn profile URL and connection date, and for some of them a professional email address (see § 6).

GDPR art. 14 requires informing the data subject individually within one month, and at the latest at the first communication. For the directory entries for which we hold no contact channel, that individual notice would require collecting precisely the contact details we do not have: for those entries only, we rely on the disproportionate-effort exception in art. 14(5)(b), and compensate with this public notice, which states the sources, the categories, the legal basis and the retention. For the entries for which we do hold a professional email address, that exception does not apply: the person is owed individual information within one month, and at the latest in the first message we send them, which points to this page and says how to object. Anyone may exercise their rights at the address below at any time; an objection or erasure request is honoured without needing to be justified.

Professional addresses of organisations. To offer the publisher's services and present the platform, we keep professional email addresses published by firms, agencies and companies (generic recruiting or contact addresses, and named addresses published on their website or their postings), with the organisation, the role and the source. Legal basis: legitimate interest (art. 6(1)(f)) in business-to-business prospecting related to the recipient's role. Every message says how to stop receiving them; an address that rejects our messages or asks us to stop is excluded and receives nothing further. These addresses are neither published, nor transferred, nor served by the platform.

Candidates entrusted by a firm. A subscribing firm may enter or import into its seat candidates it follows (name, email, skills, country, seniority). For that data the firm is the controller and we act as processor, on the conditions of § 9 of the Terms; we serve it to no other account and delete it when the seat is closed. If you appear in a firm's pool, contact the firm or us: we pass the request on and help you exercise your rights.

7. Retention

Each category of data has a duration tied to its purpose:

8. Your rights

Under GDPR art. 15–22 you can access your data, rectify it, erase it, receive it in a structured format, restrict its processing or object to it, and withdraw a consent at any time. From your profile, Download my data (JSON) returns everything we hold under your identifier, and rectification is done by editing your fields. For anything else, write to contact@analyticslegends.ai; we answer within 30 days, free of charge, after a reasonable identity check. These rights also apply to the people in the directory (§ 6), to prospecting recipients (§ 6 bis) and to candidates entrusted by a firm, whom we help exercise them with the firm.

Self-serve deletion: sign into your profile on the website, or open the Profile tab in the apps, and use Delete my account. Deletion is immediate and irreversible: a server function erases every row attached to your identifier, then the account itself; only the billing metadata required by tax law remains, anonymised. No email request is needed.

You may lodge a complaint with the CNIL, the controller's supervisory authority, or with the authority of your country of residence (GDPR art. 77) — for instance the BfDI or your Land's authority in Germany, the Datenschutzbehörde in Austria, the ICO in the United Kingdom; in Switzerland, the FDPIC under the FADP. The GDPR applies to this processing because we are established in the European Union; a UK resident additionally benefits from the UK GDPR and the Data Protection Act 2018, and a Swiss resident from the revised Federal Act on Data Protection of 25 September 2020, in force since 1 September 2023. The rights described above — access, rectification, erasure, restriction, objection, portability — are exercised through the same channel, within the same time limits and free of charge, whichever text you invoke.

Outside the European Union, the United Kingdom and Switzerland. The GDPR applies to all our processing, whatever your country, because the controller is established in the European Union. If you live elsewhere, your own law may also give you rights — for example the LGPD (Lei 13.709/2018) in Brazil, PIPEDA and Québec's Law 25 in Canada, the CCPA as amended by the CPRA in California, POPIA in South Africa, the DPDP Act 2023 in India, the PDPA in Singapore, the APPI in Japan, the PIPL in China or the Privacy Act 1988 in Australia. Whichever text you invoke, you exercise the rights described above — access, correction, deletion, portability, objection, withdrawal of consent — through the same channel and with the same self-service tools, free of charge, within 30 days or within the shorter period your law sets (15 days for a full answer under art. 19 of the LGPD). You also keep the right to complain to the authority of your country — in Brazil, the ANPD.

9. Security

HTTPS enforced, strict Content-Security-Policy (separate style-src / style-src-attr in v36), edge CDN. Details in our Security policy.

10. Data-breach notification

If a personal-data breach likely to result in a risk to your rights and freedoms occurs, we notify the CNIL (the French supervisory authority) within 72 hours of becoming aware of it (GDPR Art. 33) and, where the breach is likely to result in a high risk, inform you without undue delay (GDPR Art. 34). We keep an internal register of any breach, its effects and the remedial action taken.

11. Changes

For active accounts, we notify by email before making any material change.