Data protection

Privacy policy

Version2.0 — Juillet 2026
FrameworkRGPD (UE 2016/679)
ControllerSAIME3i
Contents
Article 01

Data controller

SAIME3i, a consulting and strategic intelligence firm, determines the purposes and means of the processing described in this policy.

Registration: N° 47036025 — RAKEZ — Address: VUNE2844, Compass Building - Al Hulaila. Al Hulaila Industrial Zone - FZ, Ras Al Khaima, UAE
Contact: contact@saime3i.com

No data protection officer has been appointed, the nature and volume of processing not requiring such appointment. Any question concerning personal data is handled directly by the firm’s founder and receives a written response.

A register of processing activities is maintained and available upon reasoned request.

Article 02

Our principles

Our profession consists in establishing what is verifiable and distinguishing what is not. That requirement applies to our own handling of data.

  • Open sources only. We employ no non-public collection method, no intrusion, no unauthorised access, no surveillance of individuals.
  • Minimisation. We collect only what is necessary to the purpose pursued, and seek no special category data.
  • No resale, no marketing. Your data is neither sold, rented, transferred, nor used for prospecting.
  • No tracking. Our website sets no advertising cookie and uses no audience measurement tool.
  • No automated decision-making. Our conclusions result from human analysis. No automated profiling produces effects concerning any person.
We never reach a conclusion about a person. Our verdicts bear on assertions, with their sources and their limits.
Article 03

If you are a prospect or client

This processing concerns persons who contact us, correspond with us, or entrust us with an engagement.

Data processed

  • Identity, role, organisation
  • Professional contact details
  • Content of exchanges and description of the request
  • Information provided in the course of an engagement
  • Billing data

Purposes and legal bases

PurposeLegal basis
Handling an incoming request and conducting the scoping callPre-contractual measures at your request
Issuing a proposal and performing the engagementPerformance of the contract
Invoicing, accounting, recoveryLegal obligation and performance of the contract
Traceability of work and defence in the event of challengeLegitimate interest

We use your data for no marketing purpose. Should we send you a publication, it is only following your explicit request, and every message includes a means of unsubscribing.

Article 04

If you are subject to a verification

This section concerns you if an organisation engaged us to verify an entity of which you are a director, partner, agent or legal representative. Your data is then processed without having been collected from you.

What we process

  • Your identity and roles, in your professional capacity alone
  • Your corporate offices and declared shareholding links
  • Public mentions concerning you in the press and official publications
  • Your entries in public registers
  • Published decisions concerning you as representative of an entity

Where this data comes from

From publicly accessible sources, exclusively. Commercial registers, official publications, institutional transparency portals, the press, public communications of the entity concerned.

We carry out no collection from you, from a private third party, or by any non-public means. We access no protected data. We do not monitor you.

What we never process

  • No special category data — origin, political opinions, beliefs, health, sexual life, trade union membership
  • No data concerning your private life unconnected to your professional capacity
  • No data concerning your relatives

Should such data appear incidentally in a public source, it is neither used nor reported in our work.

Why we do it — legal basis

This processing rests on legitimate interest: our client’s interest in assessing a risk before committing contractually or financially, and our own in carrying on our activity. That basis requires a balancing exercise, which we have conducted and summarise here.

Balancing exercise

Necessity. An organisation about to contract cannot assess an entity’s reliability without considering the persons who direct and bind it.

Proportionality. Processing is confined to public sources, seeks no special category data, bears on your professional capacity alone, is limited in time to the engagement, and its results are communicated to the commissioning party alone.

Reasonable expectations. A director may reasonably expect that their offices, mandates and public professional record will be consulted by a partner about to contract with their organisation.

Safeguards. Our verdicts bear on assertions and never on persons. Every deliverable states what could not be established, and expressly specifies that such a statement constitutes neither an accusation nor a denial. Every source is traced and dated.

Who receives this data

The commissioning party alone. No third party, no resale, no pooling between engagements. Where applicable, an affiliated analyst or correspondent working on the engagement, bound by equivalent confidentiality obligations.

For how long

The duration of the engagement plus three years. That period allows us to substantiate every element of our conclusions should they be challenged — which is a safeguard for you as much as for our client. Thereafter, data is deleted.

Your rights in this situation

You hold the rights listed in Article 9, and in particular a right to object, exercisable at any time on grounds relating to your particular situation.

A request to object or to erase is examined case by case. It may be refused where retention remains necessary for the establishment, exercise or defence of legal claims — in particular where our conclusions are subject to challenge. Any refusal is set out in writing with reasons.

We are unable to disclose our client’s identity, that information being covered by professional confidentiality and by our contractual undertakings.

Article 05

Website visitors

Our website sets no cookie for audience measurement, tracking or advertising. We employ no behavioural analysis tool.

The only data processed is that which you voluntarily enter in the scoping form: name and organisation, email address, nature of the need, description of your situation, and your consent.

Our host retains technical logs — IP address, timestamp, request type — for security and operational reasons. These logs are not used for analytical purposes and are purged according to the host’s schedule.

Article 06

Recipients and processors

Your data is neither sold, rented, nor transferred to third parties for commercial purposes.

It may be processed by the following technical providers, acting on our instructions and bound by contract:

ProviderRole
Vercel Inc. (440 N Barranca Avenue #4133, Covina, CA 91723, USA)Website hosting and technical logs
n8n — the firm's own infrastructure, hosted on its own serverRouting and processing of requests submitted via the contact form
Cloudflare, Inc.Routing of incoming email to the firm's mailbox

Affiliated analysts and correspondents. Some engagements require an analyst or local correspondent. Each is bound by a contract containing confidentiality and data protection obligations equivalent to our own, together with a declaration of interests.

Authorities. Your data may be communicated to competent authorities where the law so requires.

Article 07

Transfers outside the European Union

Some of our technical providers, as well as some of our local correspondents, are established outside the European Union. Transfers of data may therefore occur.

Such transfers are governed by the appropriate safeguards provided for under applicable regulation — in particular the standard contractual clauses adopted by the European Commission, or any other recognised mechanism.

You may obtain details of the safeguards implemented upon request to contact@saime3i.com.

Article 08

Retention periods

DataPeriod
Request not pursued3 years from last contact
Client relationshipDuration of the relationship, then 3 years
Deliverables, sources consulted and working papersDuration of the engagement, then 3 years
Data concerning verified third partiesDuration of the engagement, then 3 years
Accounting and billing recordsApplicable statutory period
Host technical logsPer the host’s schedule
Why three years

Our conclusions are valid as at a date, within a scope and with determined sources. Retaining these elements allows us to substantiate every assertion in a deliverable should it be challenged — by our client, by a third party, by an auditor or by a court.

Premature deletion would deprive all parties of that possibility. This retention is therefore a safeguard, not a convenience.

Beyond these periods, or upon an admissible request, data is securely deleted.

Article 09

Your rights

Access

Obtain confirmation that processing concerns you, and a copy of the data held.

Rectification

Have inaccurate data corrected or incomplete data completed.

Erasure

Request deletion of your data, in the cases provided for by regulation.

Restriction

Request suspension of processing in certain circumstances.

Objection

Object, on grounds relating to your particular situation, to processing based on legitimate interest.

Portability

Receive the data you provided to us, in a structured, machine-readable format.

To exercise these rights: contact@saime3i.com. We respond within one month, extendable by two months for complex requests, of which you would be informed.

We may request proof of identity where the request leaves reasonable doubt as to the identity of the requester.

Limits. A right may be restricted where retention remains necessary to comply with a legal obligation, or for the establishment, exercise or defence of legal claims. Any refusal, whole or partial, is set out in writing with reasons.

Article 10

Security

  • Encryption of data in transit and of storage media
  • Strong authentication across all professional accounts
  • Access limited to the founder, save contractual engagement of an affiliate on a specific mandate
  • Strict compartmentalisation of files: no information flows between engagements
  • Prior anonymisation of third-party data before any processing involving an external automated system, identifiers being restored outside those systems
  • Encrypted backup with periodic restoration testing
  • Secure deletion upon expiry of retention periods

In the event of a data breach likely to result in a risk to your rights and freedoms, we inform the competent authority and, where the risk is high, the persons concerned, within the regulatory time limits.

Article 11

Contact and complaints

For any question concerning this policy or the exercise of your rights: contact@saime3i.com. Every request receives a written response.

If you consider that the processing of your data does not comply with applicable regulation, you have the right to lodge a complaint with a supervisory authority — in France, the Commission nationale de l’informatique et des libertés, whose website is accessible at cnil.fr.

Version 2.0 — July 2026. Any change gives rise to a numbered and dated version.