Legal Notice
Publisher
This website (stratos.club) is published by:
- Company name
- LMsquare
- Legal form
- SAS with share capital of €2,000
- Registered office
- 25 rue de Ponthieu, 75008 Paris, France
- Registration
- 920 593 787 R.C.S. Paris
- SIRET
- 920 593 787 00012
- contact@stratos.club
Hosting
This website is hosted by:
- Host
- OVH SAS
- Address
- 2 rue Kellermann, 59100 Roubaix, France
- Registration
- R.C.S. Lille Métropole 424 761 419
- Website
- ovhcloud.com
The website is built with Webflow.
Intellectual Property
All content on this website, including text, graphics, logos, and the overall structure, is the property of LMsquare or its partners and is protected by intellectual property law. Any reproduction, distribution, or use without prior written authorisation is prohibited.
Privacy Policy
We process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act (Loi Informatique et Libertés).
1.What We Collect and Why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Contact form data (name, email, company, message) | Respond to enquiries, qualify a prospect | Legitimate interest / pre-contractual steps | 3 years from last contact |
| Client and prospect business data | Manage the commercial relationship | Contract / legitimate interest | Duration of the relationship plus legal archiving obligations |
| Navigation and measurement data | Audience measurement, site performance | Consent (non-exempt cookies) / legitimate interest (exempt measurement) | 13 months maximum for identifiers |
We collect only what is necessary for the stated purpose (data minimisation). Fields required to process a request are indicated; the rest is optional.
2.Recipients
Personal data is accessed by our authorised staff and by service providers acting on our instructions as processors (hosting, email, analytics, CRM, automation). These providers are bound by contract to process data only as instructed and to secure it.
Current categories of processors include: hosting (OVH), website platform and forms (Webflow), email and productivity (Google Workspace), CRM (HubSpot), tag management and audience measurement (Google Tag Manager, Google Analytics), consent management (Cookiebot), advertising and campaign measurement (Google Ads, LinkedIn), translation (Weglot), and form collection (Tally). A current list is available on request.
We do not sell personal data.
3.International Transfers
Some of our processors are established outside the European Union (notably in the United States). Where this is the case, transfers are governed by appropriate safeguards under the GDPR: an EU adequacy decision (including the EU–US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses. Details are available on request.
4.Your Rights
Under the GDPR you have the right to: access your data; have it corrected; have it erased; restrict its processing; object to processing; data portability; and, where processing is based on consent, withdraw that consent at any time.
To exercise these rights, contactcontact@stratos.club. We may ask for proof of identity. We respond within one month.
You also have the right to lodge a complaint with the French supervisory authority, the CNIL (Commission Nationale de l'Informatique et des Libertés), 3 Place de Fontenoy, 75007 Paris,cnil.fr.
5.Automated Decisions
We do not carry out automated decision-making producing legal or similarly significant effects on individuals through this website. Our approach to AI is set out in the Responsible AI section below.
6.Security
We apply technical and organisational measures appropriate to the risk (encrypted transport, access control, provider vetting). No system is perfectly secure; we work to protect data and to react promptly to any incident.
7.Updates
This policy may change to reflect legal or operational developments. The date at the top of the page indicates the latest version.
Responsible AI
Stratos uses and builds AI as an accelerator of its work, not as a substitute for human judgement. Our practices are governed by an internal AI Governance Charter aligned with the EU AI Act (Regulation (EU) 2024/1689) and the GDPR. We commit publicly to the following:
- Human oversight. No decision affecting a person's rights is fully automated. Qualified human review applies before deployment in sensitive contexts, and results can be contested and corrected.
- Transparency. We document how AI is used in our client work, and we inform users when they interact with an AI system.
- Data protection. We do not send confidential, sensitive, or client data to non-contracted AI tools. Personal data processed through AI follows the GDPR.
- Fairness. We assess our AI systems for bias and decline to deploy AI with demonstrated discriminatory effects.
- Security and robustness. AI systems are tested for security and reliability, and cybersecurity is built into our AI projects.
- Digital sovereignty. For clients with sovereignty or heightened security requirements, we favour EU-hosted or sovereign solutions and document where data is processed.
- Proportionate, responsible use. We choose the model suited to the task rather than the most powerful by default, mindful of environmental impact.
We do not develop or deploy AI systems that are prohibited under the EU AI Act.
Our detailed internal governance framework is available to clients and partners on request where a project requires it.