Privacy Policy
This policy explains how FittingMe.ai processes data from website visitors, prospects, press contacts, and users of public demos.
Controller and contact
For fittingme.ai, contact requests, commercial conversations, and public demos, FittingMe.ai acts as controller. For privacy requests, email privacy@fittingme.ai or use the contact page.
Data we collect
We may process information you send voluntarily, such as name, business email address, company, message, demo request, and meeting preferences. The site may also process limited technical data: page viewed, language, page type, clicked outbound-link domain, cookie-consent state, and analytics events if you accept them.
Purposes and legal bases
- Responding to requests and arranging demos: legitimate interest or pre-contractual steps.
- Maintaining security, diagnosing incidents, and preventing abuse: legitimate interest.
- Measuring website audience with Google Analytics 4 only after consent: consent.
- Storing cookie preferences: legal obligation and legitimate interest for consent evidence.
Demos and widget
Demo pages use public test configurations. Do not send sensitive personal data, real customer data, or production images into a non-contracted demo. Processing for a merchant integration is documented in the customer agreement and DPA.
Recipients and subprocessors
Data may be accessed by authorized FittingMe.ai team members and providers needed for website operation, hosting, security, audience measurement, or appointment booking when you choose to open a third-party service. Subprocessor categories are described on the Subprocessors page.
Retention
- Contact requests and sales conversations: up to 3 years after the last active exchange.
- Cookie preferences: up to 6 months unless withdrawn earlier.
- Consented analytics events: according to documented GA4 configuration and no longer than needed for aggregate site measurement.
- Technical and security logs: a short period proportionate to diagnostics, security, and applicable obligations.
Your rights
Depending on your situation, you may request access, rectification, erasure, restriction, objection, portability where applicable, or withdraw analytics consent at any time from cookie preferences. You may also lodge a complaint with the CNIL or your local supervisory authority.
Cookies, GPC, and consent withdrawal
Google Analytics is loaded only after consent. If your browser sends a Global Privacy Control signal, we treat it as a refusal of audience measurement. You can reopen cookie preferences from the control displayed on the site.
Transfers outside the EEA
Some providers may process data outside the EEA. When required, we use appropriate transfer mechanisms, such as standard contractual clauses or provider-specific contractual safeguards.
Last updated: 3 June 2026.