1. About This Policy
This Privacy Policy explains how Blue Lion Consultants handles personal data in connection with:
- The Blue Lion Websites public website.
- Business enquiries and reasonable follow-up.
- Sales and customer relationship management.
- Client accounts and services.
- Legal, privacy and accessibility requests.
- Email and telephone communications.
- Invoicing and payment administration.
- Security, fraud prevention and service operation.
- Proportionate business-to-business prospecting.
Blue Lion Websites provides services to businesses and professionals.
2. Data Controller
The controller responsible for the processing described in this policy is:
James André Ferguson — Entrepreneur individuel (EI)
Operating under the registered commercial name Blue Lion Consultants
Blue Lion Websites is a commercial brand operated by Blue Lion Consultants.
Address:
3 Impasse des Castels
81800 Loupiac
France
SIREN: 939 381 497
SIRET: 939 381 497 00014
Privacy requests: Use the secure Your Data Rights form.
General legal contact: legal@bluelionwebsites.com
Telephone: +33 6 08 36 90 91
Blue Lion has not appointed a formal Data Protection Officer.
3. Who This Policy Applies To
This policy may apply to:
- Visitors to
bluelionwebsites.com. - People who submit an enquiry.
- Prospective, current and former business customers.
- Representatives and employees of customer businesses.
- Authorised users of a Blue Lion account or dashboard.
- Suppliers and professional contacts.
- People who submit a privacy, legal or accessibility request.
- Publicly listed business contacts approached in a business-to-business context.
The services are not directed to children.
4. Information Collected Through the Website
Depending on the form used, Blue Lion may collect:
- First name and last name.
- Email address.
- Telephone number.
- Business name.
- Current website address.
- Package or service interest.
- Add-on interest.
- Preferred contact method.
- Message and other information voluntarily entered.
- The form or general submission source.
- Date and time of submission.
Please do not submit health information, identity documents, payment-card details or other highly sensitive information through free-text fields unless Blue Lion has specifically requested it and explained why it is necessary.
The public forms do not accept file uploads.
5. Privacy and Accessibility Requests
The Your Data Rights and Accessibility Report forms may collect:
- Name.
- Email address.
- Optional telephone number.
- Optional business name.
- Type and details of the request.
- A preferred response email, where supplied.
- For accessibility reports, the affected page or feature, device or browser, assistive technology and requested alternative.
A case is created in the restricted Legal & Privacy area of the Blue Lion Master Dashboard.
Cases can be viewed and managed by the authorised Master Administrator. The case record may contain:
- The information submitted.
- A case reference.
- Received date.
- Response deadline.
- Status.
- Internal notes.
- A summary of the response or action taken.
- The date a reply was sent.
- Completion or closure information.
The forms do not accept attachments and do not automatically request identity documents.
Blue Lion may ask for proportionate additional information where there is a genuine need to confirm identity before releasing or changing personal data.
6. Spam and Security Protection
Blue Lion uses Cloudflare Turnstile, honeypot fields and rate limiting to protect public forms from automated abuse.
When Turnstile runs, Cloudflare processes technical browser and device signals and issues a short-lived verification token. The token is validated by the Blue Lion API before the form is accepted.
IP addresses may be processed temporarily by Cloudflare and the rate-limiting system for security and abuse prevention. The Blue Lion Legal & Privacy case record does not permanently store the requester’s IP address or User-Agent.
Turnstile is not used by Blue Lion for advertising or behavioural profiling.
7. Enquiries and Communications
When someone contacts Blue Lion, we may process:
- Emails and replies.
- Telephone numbers and call details.
- Dates and times of communications.
- Conversation history.
- Enquiry and sales status.
- Internal notes.
- Follow-up dates and tasks.
- Quotations, package recommendations and approvals.
- Do-not-contact or objection records.
- Technical delivery, bounce, failure and spam-complaint information.
Blue Lion may respond by email or telephone and may make reasonable follow-up attempts concerning the service requested.
Submitting an enquiry does not subscribe the person to a general newsletter or unrelated mass-marketing list.
Blue Lion does not use invisible open-tracking pixels or tracked links in ordinary Blue Lion enquiry acknowledgements, one-to-one sales emails, privacy replies, accessibility replies or legal replies.
8. Customer and Account Information
When a person becomes a customer or account user, Blue Lion may process:
- Name, role and business details.
- Contact and billing information.
- Package, services and add-ons.
- Website project status and approvals.
- Account role and permissions.
- Login, authentication and security records.
- Support requests and service communications.
- Enquiries and conversations managed through the service.
- Invoices, amounts, payment status and subscription status.
- Technical configuration required to provide the service.
Passwords are not stored in readable form.
9. Payment Information
Payments are not entered directly into the public Blue Lion website.
Blue Lion may issue an invoice or payment request through Stripe after a project has been approved or where a recurring service is due.
Stripe may process:
- Customer and billing details.
- Payment method and full card information.
- Transaction and fraud-prevention information.
- Invoice, payment, refund, failure or dispute information.
Blue Lion may receive limited transaction information such as payment status, amount, date, currency and a payment reference. Blue Lion does not receive or store full card numbers or card-security codes.
Stripe’s own privacy information applies to its hosted payment pages.
10. Publicly Available Business Information
For proportionate business-to-business sales activity, Blue Lion may collect professional information from publicly available sources, including:
- Business websites.
- Search engines.
- Public business directories.
- Google Business Profiles and similar listings.
- Public social-media business pages.
- Public company or professional registers.
This may include:
- Business name and category.
- Public business address and service area.
- Public business telephone number or email.
- Website and social-media addresses.
- Publicly named owner or representative.
- Opening hours and other public business information.
- Notes about the business’s public online presence.
Blue Lion does not intentionally collect private personal profiles, special-category data or information unrelated to a legitimate business purpose.
11. How Personal Data Is Used
Blue Lion may use personal data to:
- Respond to enquiries.
- Discuss requirements.
- Recommend an appropriate service.
- Prepare quotations and proposals.
- Build, revise, publish and support websites.
- Create and administer accounts.
- Provide dashboards and purchased modules.
- Send transactional and service-related messages.
- Manage customer relationships and reasonable follow-up.
- Receive and answer privacy, legal and accessibility requests.
- Record objections and prevent unwanted contact.
- Issue invoices and administer payments.
- Protect accounts, forms and systems.
- Detect spam, abuse, fraud and unauthorised access.
- Maintain necessary security and administrative records.
- Comply with accounting, tax, regulatory and legal obligations.
- Establish, exercise or defend legal claims.
- Conduct proportionate business-to-business outreach.
- Improve internal operations and service quality.
Blue Lion does not sell personal data.
12. Legal Bases
Depending on the situation, Blue Lion relies on:
Steps before entering a contract
To answer an enquiry, discuss requirements, prepare a quotation or take other steps requested before a service agreement is formed.
Performance of a contract
To provide agreed website, hosting, dashboard, support and related services.
Legal obligation
To comply with tax, accounting, invoicing, data-protection and other legal requirements.
Legitimate interests
For interests such as:
- Managing enquiries and customer relationships.
- Making reasonable business follow-up.
- Protecting forms, systems and accounts.
- Preventing fraud, spam and abuse.
- Maintaining service and security records.
- Recovering unpaid amounts.
- Defending legal claims.
- Conducting relevant business-to-business outreach.
- Improving internal operations.
Blue Lion considers whether those interests are proportionate and whether the processing would unduly affect the person concerned.
Consent
Where consent is legally required, including before using optional analytics or marketing trackers.
No optional website analytics or marketing tracker is active at the date of this policy.
13. Who Receives Personal Data
Personal data may be accessible to:
- James André Ferguson.
- An authorised Blue Lion administrator.
- An authorised sales agent where a lead has been assigned and access is necessary.
- Cloudflare, which provides website delivery, security, Workers, database and storage infrastructure.
- Postmark, which provides transactional and service-email delivery.
- Stripe, which provides invoice and payment services.
- Professional advisers such as accountants, insurers or lawyers where necessary.
- Public authorities, regulators, courts or law-enforcement bodies where disclosure is legally required.
- A lawful successor to the business, subject to appropriate safeguards.
Access is limited according to operational need and account permissions.
14. Email Delivery
Blue Lion uses Postmark to deliver transactional and service-related email, including:
- Enquiry acknowledgements.
- Enquiry notifications.
- One-to-one replies.
- Privacy and accessibility acknowledgements.
- Legal, privacy and accessibility replies.
- Account and service notifications.
Postmark may process email addresses, message content, subject lines, headers and technical delivery information needed to deliver and protect the email service.
Blue Lion keeps operational delivery information where needed to identify failures, bounces, blocks, spam complaints and suppression requirements.
Blue Lion open and link-click tracking is disabled for the ordinary communications described in this policy.
15. International Processing
Cloudflare, Postmark, Stripe and other providers may operate internationally, including from the United States.
Where personal data is transferred outside the European Economic Area, Blue Lion relies on an appropriate transfer mechanism where required, such as:
- An adequacy decision.
- European Commission Standard Contractual Clauses.
- A provider Data Processing Addendum.
- Additional contractual, technical or organisational safeguards.
Further information about applicable safeguards may be requested through the Your Data Rights page.
16. Retention
Blue Lion does not intend to keep personal data indefinitely.
Unsuccessful website enquiries
Enquiries that do not become an active customer relationship are normally reviewed after 12 months from submission or the last meaningful incoming contact.
The current process is a manual review supported by a read-only retention report. Records may be deleted, anonymised, restricted or retained for longer where there remains a genuine business, contractual, security or legal reason.
An unanswered outgoing follow-up from Blue Lion does not indefinitely restart the period.
Publicly sourced business prospects
Publicly sourced business contact information is normally retained for no longer than three years from collection or the last meaningful incoming contact, unless an objection is received earlier or a longer period is justified by an active relationship or legal reason.
Active customers
Operational customer and account information is retained for the duration of the active customer relationship.
Former customers
Ordinary customer-relationship and support information is normally reviewed within three years after the relationship ends or the last meaningful contact.
Information may be retained separately for longer where needed for accounting, contractual evidence, debt recovery, security or legal claims.
Invoices and accounting records
Invoices and supporting accounting records may be retained for ten years where required by French accounting law.
Do-not-contact records
Where someone objects to further contact, Blue Lion may retain a minimal suppression record so that the person is not contacted again.
Legal & Privacy cases
A minimal case record may be retained for as long as reasonably necessary to demonstrate that the request was received and handled, subject to periodic review and applicable legal limitation periods.
Security and technical records
Security and technical records are retained only for as long as reasonably necessary for system operation, investigation, fraud prevention or legal claims.
Deletion is not always immediate or absolute. Some information may need to remain where required by law, needed to protect rights, connected with another person or necessary to honour a do-not-contact request.
17. Data Processed for Blue Lion Customers
Some Blue Lion services allow a customer to receive and manage information submitted through that customer’s own website.
In that situation:
- The Blue Lion customer will normally decide why and how the information is used and will generally act as controller.
- Blue Lion will normally process the information on the customer’s behalf as processor.
The customer is responsible for its own privacy notice and lawful instructions.
Detailed controller–processor obligations may be set out in the applicable service agreement and Data Processing Agreement.
A person seeking rights concerning information controlled by a Blue Lion customer should normally contact that customer first. Blue Lion will assist where required and appropriately instructed.
18. Security
Blue Lion uses technical and organisational measures intended to protect personal data, including where applicable:
- HTTPS encryption in transit.
- Cloudflare network and application protection.
- Restricted administrative access.
- Role-based permissions.
- Password hashing.
- Two-factor authentication.
- Session and login protections.
- Rate limiting and form-abuse protection.
- Security and administrative records.
- Private handling of credentials and secrets.
- Pre-migration recovery safeguards.
No website or information system can be guaranteed completely secure.
19. Your Rights
Depending on the processing and applicable law, you may have the right to:
- Receive information about processing.
- Access your personal data.
- Correct inaccurate or incomplete information.
- Request deletion.
- Request restriction.
- Object to processing based on legitimate interests.
- Object to sales or marketing contact.
- Receive certain information in a portable format.
- Withdraw consent where processing depends on consent.
- Lodge a complaint with a supervisory authority.
These rights are not absolute. Blue Lion may need to retain limited information for accounting, contractual evidence, security, legal claims or suppression purposes.
20. Exercising Your Rights
Submit a request through:
Please provide enough information for Blue Lion to understand the request and identify the relevant records.
Blue Lion may request proportionate additional information where there is reasonable doubt about identity.
Blue Lion aims to respond without undue delay and normally within one month. Where legally permitted and genuinely necessary because a request is complex or numerous, that period may be extended, and the requester will be informed.
Requests are normally handled free of charge. A reasonable fee may apply, or a request may be refused, only where permitted by law, including where a request is manifestly unfounded or excessive.
21. Complaints
Blue Lion encourages people to raise concerns through the Your Data Rights page so they can be investigated.
You also have the right to lodge a complaint with:
Commission nationale de l’informatique et des libertés — CNIL
22. Cookies and Analytics
The public website does not currently use optional analytics, advertising or marketing trackers.
Further information is available in the Cookie & Tracking Notice.
If optional analytics or marketing technology is introduced later, this policy and the Cookie & Tracking Notice will be updated and consent will be obtained where required before the technology is activated.
23. Automated Decision-Making
Blue Lion does not make decisions producing legal or similarly significant effects solely through automated processing.
Internal prioritisation may be used to help organise work, but it does not automatically determine legal rights or whether a person may purchase a service.
24. Changes to This Policy
This policy may be updated when services, providers, technology, retention practices or legal requirements change.
The current version will be published on this page with an updated date.
---
