GiscardLabs
    ExperimentsMethodGamesConsulting
    Start a project

    Legal

    Privacy Policy

    Version 2026-09-03-b · Effective 3 September 2026

    1. Who we are

    This website, GiscardLabs, is operated by Giscard Consulting By Mounir Lakhdari (Giscard Consulting), the data controller responsible for your personal data.

    46a, Rue Maximilien, L-6463 Echternach, Luxembourg
    Trade & Companies Register (RCS Luxembourg): A43893
    Contact: m@giscard.consulting

    2. What this policy covers

    This policy explains what personal data we collect through this website, why we collect it, the legal bases we rely on, how long we keep it, who it may be shared with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Luxembourg data protection law.

    3. What we collect

    We keep data collection to a minimum. Specifically:

    • Enquiry details you send us. When you complete a contact form, we collect your name, email address, an optional company name, an optional phone number, and the message you write. The phone number field is entirely optional; you are never required to provide one.
    • Proof of consent. When you submit a form we record that you gave consent, the exact consent wording shown to you, the version of this policy in force, and the time of submission.
    • Meeting Ledger delivery details. If you ask us to email a Meeting Ledger entry, we keep the email address you provide, your delivery consent, the consent wording, the policy version, and the time of submission. The meeting content you paste and the generated entry are processed transiently and are not stored in our database, application logs, admin dashboard, or exports.
    • An optional follow-up opt-in. Beneath the delivery consent there is a second, separate checkbox, unticked by default, asking whether we may email you occasionally about the Meeting Ledger and related experiments. It is entirely optional: leaving it unticked has no effect on your entry being sent. If you tick it, we record that decision, the exact opt-in wording shown to you, and the policy version in force. If you leave it unticked, we record only that you did not opt in, and your address is used for that one delivery and nothing else.
    • Anonymous usage analytics. We record aggregate, cookieless counts of page views and form interactions to understand what is useful. These contain no name, no email, no IP address, and nothing that identifies you.
    • Technical request data. Like any web server, ours processes your IP address momentarily to deliver pages and to protect against abuse. We do not store it alongside your enquiry.

    4. Why we use it and our legal basis

    • To respond to your enquiry and take steps at your request before any engagement — legal basis: your consent (Art. 6(1)(a) GDPR) and, where relevant, steps prior to entering a contract (Art. 6(1)(b) GDPR).
    • To keep the site secure and working (transient request handling, anti-abuse rate limiting) — legal basis: our legitimate interests (Art. 6(1)(f) GDPR).
    • To create and email a Meeting Ledger entry at your request — legal basis: your consent (Art. 6(1)(a) GDPR). Delivery consent applies only to that entry and does not subscribe you to marketing.
    • To email you occasionally about the Meeting Ledger and related experiments — legal basis: your consent (Art. 6(1)(a) GDPR), given separately through the optional opt-in checkbox described in section 3. This consent is never bundled with delivery: it is unticked by default, and the entry is sent whether or not you tick it. You can withdraw it at any time by emailing us at m@giscard.consulting, and we will delete the record. Withdrawal does not affect processing carried out before it.

    You are free not to provide your details, but we then cannot reply to your enquiry.

    5. Cookies and tracking

    One strictly necessary cookie is set when you visit this site. It is placed by our hosting platform, Replit, Inc., and the infrastructure it runs on — not by us — and it is used purely for load balancing: to keep your requests on the same server while you browse. You will see it in your browser as GAESA, and it lasts about 30 days from your visit, so it stays after you close the tab. It holds an opaque technical value only: no name, no email, no IP address, nothing that identifies you, and it is never used for tracking, advertising, or profiling.

    We do not use advertising or third-party tracking cookies, and we do not build profiles of visitors. Our analytics are cookieless and aggregate. If you sign in to the private admin area, one additional strictly necessary cookie keeps you signed in; it is not set for ordinary visitors.

    Loading a page of this site also makes no request to any third-party server. Everything a page needs — the typefaces, the images, the scripts and the stylesheets — is served from this domain, so simply visiting does not disclose your IP address or your browsing to anyone else. Third parties are involved only when you actively submit something, and only as set out in section 7.

    Because every cookie in use is strictly necessary to deliver the site, you will not see a cookie consent banner — there is nothing non-essential to consent to.

    6. How long we keep it

    We keep enquiry details only as long as needed to handle your request and for a reasonable period afterwards. We routinely delete enquiries older than 24 months, unless a longer period is required to meet a legal obligation or to establish, exercise, or defend legal claims. Aggregate analytics contain no personal data and may be kept indefinitely. Meeting Ledger email addresses and consent records follow the same 24-month period, whether or not you gave the optional follow-up opt-in — opting in does not keep your address any longer. GiscardLabs does not retain the pasted meeting content or generated entry after processing and delivery.

    7. Who we share it with

    We do not sell your personal data. We share it only with service providers who help us run this website, acting as our processors under contract:

    • Hosting & database: Replit, Inc., which hosts the website and the database where enquiries are stored, together with the cloud infrastructure it runs on — that infrastructure is what places the GAESA load-balancing cookie described in section 5.
    • Transactional email: Resend, Inc. (resend.com), which delivers operator notification emails when a new enquiry is received. Enquiry details (name, email, company, message) are transmitted to Resend's servers for this purpose. If you request Meeting Ledger delivery, your email address and generated entry are sent to Resend so the email can be delivered. Resend is based in the United States; data transfers are covered by Standard Contractual Clauses.
    • AI processing: OpenAI, L.L.C. (openai.com), which receives the meeting content you paste to classify it into the six Meeting Ledger areas. We use the API without asking OpenAI to store application state. OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the customer explicitly opts in. Under OpenAI's standard data controls, abuse-monitoring logs may contain prompts and responses and are retained for up to 30 days, unless longer retention is required by law or reasonably necessary to protect its services or third parties. This account does not use OpenAI's approval-gated Zero Data Retention setting. OpenAI is based in the United States; data transfers are covered by Standard Contractual Clauses.

    We may also disclose data where required by law or to protect our legal rights.

    8. International transfers

    Depending on configuration, data may be processed on servers located outside the EEA, including in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

    9. Your rights

    Subject to the conditions in the GDPR, you have the right to request access to your data; to have it corrected or erased; to restrict or object to its processing; to data portability; and to withdraw your consent at any time (which does not affect processing carried out before withdrawal).

    To exercise any of these rights, email us at m@giscard.consulting. We will respond within the time limits set by law.

    You also have the right to lodge a complaint with the supervisory authority, the Commission nationale pour la protection des données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux, Luxembourg.

    10. How we protect your data

    We apply appropriate technical and organisational measures, including encryption of data in transit (HTTPS), access controls on stored data, and the principle of collecting only what we need.

    11. Children

    This website is not directed at children, and we do not knowingly collect personal data from anyone under 16.

    12. Changes to this policy

    We may update this policy from time to time. Material changes are reflected in a new version number and effective date at the top of this page. This is version 2026-09-03-b.

    What changed in this version: section 5 now names the one strictly necessary cookie you receive, GAESA, states how long it lasts and what it is for. Earlier versions did not mention it. Nothing else about what we collect, why, or how long we keep it has changed.

    GiscardLabs

    The experiments studio of Giscard Consulting.

    PrivacyLegal notice
    Luxembourg · Field Notes Vol. 01