Home / Privacy Policy
LegalPrivacy Policy.
What we collect, why we collect it, who sees it, how long we keep it, and what you can require of us.
The identification details of the controller, the hosting provider and the list of processors must be completed, and this notice reviewed by counsel, before the site is published on its own domain.
Who we are and who is responsible
Eshay Advisory ("we", "us") provides cybersecurity advisory, security engineering and proprietary security software. This notice explains what personal data we process through this website and in the course of a client, prospect or candidate relationship, on what basis, and what you may require of us.
Eshay Advisory is the data controller for the processing described here. Our identification details appear in the legal notice.
Contact for any question or request: privacy@eshay-advisory.com.
What we collect
Data you give us. Name, organisation, role, professional email address and the content of any message sent through the contact form or by email. For candidates, the application materials you choose to send us.
Data collected automatically. Technical server logs necessary to serve and secure the site: IP address, user agent, resource requested, response status and timestamp. Aggregate measurement data only where you have consented to it.
Data we deliberately do not collect. No behavioural profile, no cross-site identifier, no enriched contact record bought from a third party, and no personal data from any source other than you.
Personal data inside a client engagement
During an audit, a penetration test or a monitoring engagement we may encounter personal data belonging to our client — employee identities, log entries, leaked credentials.
In that situation the client is the controller and we act as processor, under a written data processing agreement meeting Article 28 GDPR. We process only on documented instruction, we minimise what we retain, we return or destroy at the end of the engagement, and we never reuse engagement data for our own purposes.
Findings that identify individuals are reported to the client alone, never published, and never used as marketing material.
Why we process it, and on what basis
- Answering your enquiry — our legitimate interest in responding to a professional approach, or steps taken at your request prior to a contract.
- Delivering an engagement — performance of the contract between us.
- Assessing an application — steps taken prior to a contract of employment.
- Operating and securing the site — our legitimate interest in the availability and integrity of our systems.
- Aggregate measurement — your consent, freely withdrawable.
- Meeting legal and accounting obligations — compliance with a legal obligation to which we are subject.
We do not use enquiry, engagement or candidate data for marketing, and we do not carry out automated decision-making or profiling producing legal effects.
Who has access
Internally, access is limited to the people who need it for the purpose concerned, under confidentiality obligations.
Externally, we use only the processors necessary to operate: hosting, email delivery, and — where you have consented — measurement. Each is bound by a contract meeting Article 28 GDPR. The current list is provided on request.
We do not sell, rent or exchange personal data. Disclosure to a public authority occurs only where legally compelled, and we notify you unless prohibited from doing so.
Transfers outside the EEA
Our processing is hosted within the European Economic Area.
This site makes no third-party requests: typefaces, stylesheets and scripts are self-hosted, so simply visiting the site transfers your IP address to no one but us. Where a transfer outside the EEA becomes necessary, it is covered by an adequacy decision or by Standard Contractual Clauses together with a transfer impact assessment.
How long we keep it
- Enquiries — the duration of the exchange, then up to three years from the last contact.
- Client engagement records — the contractual period, then the legal and accounting retention period applicable to professional services.
- Engagement working data — returned or destroyed at the end of the engagement, subject to any evidential retention agreed in writing.
- Applications — two years from the last contact, unless you ask us to delete them sooner.
- Server logs — a short operational period, then deletion.
- Consent records — the period required to demonstrate compliance.
Your rights
You may request access to your data, its rectification or erasure, restriction of or objection to processing, and portability where applicable. You may withdraw consent at any time without affecting processing already carried out. You may also give directions on the fate of your data after your death.
Write to privacy@eshay-advisory.com. We reply within one month, extendable by two months for complex requests, in which case we tell you why. We may ask for proof of identity where there is genuine doubt — never as an obstacle.
Where we act as processor for a client, forward your request to that client; we will support them in answering it.
You have the right to lodge a complaint with a supervisory authority. In France, the CNIL (3 place de Fontenoy, 75007 Paris).
How we protect it
We apply the technical and organisational measures we would expect of a client during an audit: encryption in transit, access control on a need-to-know basis with multi-factor authentication, logging and review, segregation of client engagement data, hardened endpoints, and a documented incident response process that is exercised rather than filed.
In the event of a personal data breach likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and inform you directly where the risk is high.
Security issues affecting us or our products can be reported to security@eshay-advisory.com under the disclosure policy set out in our legal notice.
Cookies
Cookies and equivalent technologies are covered in detail by our Cookie Policy. In short: nothing beyond the strictly necessary is set without your consent, and there are no advertising or cross-site trackers at all.
Changes to this notice
Material changes are published on this page with a new version number and date. Where a change affects the basis on which we rely, we tell you before it takes effect.
Current version 1.0, dated 5 August 2026.