AcuSeminars attaches particular importance to the protection of personal data and to the privacy of its users, clients and participants. This policy explains what data may be collected when using the website and the training programmes offered by AcuSeminars.
This English version is provided for information purposes only. In the event of any discrepancy, the French version (Politique de confidentialité) prevails.
1. Data controller
AERIAL GROUP · a French simplified joint-stock company (société par actions simplifiée, SAS)9 rue Quentin-Bauchart, 75008 Paris · France
E-mail: info@acuseminars.com
2. Data collected
Depending on the services used, AcuSeminars may collect: first and last name, e-mail address, telephone number, declared profession, postal address, information relating to orders and registrations, IP address, and exchanges with the AcuSeminars team.
Bank details are never collected or stored by AcuSeminars. Payment is processed entirely by Stripe: no card number passes through our servers.
The website assistant
The website offers an automated assistant (chat window) that answers questions about programmes, prices, access and procedures. It works as follows:
- the question asked, the excerpts of our documentation that relate to it and, where applicable, the previous turns of the conversation are sent to Anthropic (application programming interface, United States), whose language model writes the reply (section 5);
- a filter screens out, before anything is sent, any question about a person's health (symptom, case, treatment): such questions are not sent to the model and receive a referral reply;
- you may, if you wish, identify yourself with a code sent to your e-mail address in order to get answers about your own file (registrations, access, invoices). The session lasts 30 minutes, and the details of your file are supplied to the model only during that session, to answer you alone;
- questions and replies are written to a log (Cloudflare D1 database, European Union), together with the person's name when they have identified themselves, so that the team can review what the assistant answered and improve the documentation. This log is automatically deleted after 90 days;
- a conversation identifier, unrelated to your identity, is set so that the assistant can follow the thread of an exchange (section 7).
Legal basis: legitimate interest (art. 6-1-f), to inform visitors and to check the quality of the replies given; performance of the contract (art. 6-1-b) for replies about your file after identification.
The internal register of participants
To keep track of registrations and payments, AcuSeminars maintains an internal register that copies, every night, the enrolments and progress recorded by the course platform (Teachable) and the payments, instalment plans and invoices recorded by Stripe. It is hosted in the Cloudflare D1 database (European Union), access is restricted to two named addresses of the team, each with a one-time login code and a 12-hour session, and it is read-only towards the outside: it writes nothing to Teachable or Stripe. The only information added to it is the team's follow-up notes.
Legal basis: performance of the training contract (art. 6-1-b) and the legal obligation to keep accounting records (art. 6-1-c).
3. Clinical cases · health data
Participants in certain programmes may choose to submit the description of a clinical case for educational purposes. As this information may constitute data concerning health within the meaning of Article 9 of the GDPR, it is processed separately and deliberately kept apart from payment.
The arrangement is as follows:
- at registration, only a choice (“I would like to submit a clinical case”) is recorded; no health data is requested at this stage;
- no health data is transmitted to Stripe or linked to the payment;
- after payment, a personal, unguessable link allows the case to be entered in a dedicated form;
- the description is stored in a Cloudflare D1 database hosted in the European Union, separate from the rest of the website;
- it is automatically deleted after 90 days by a scheduled task;
- submission is entirely optional: entering nothing has no consequence for your registration.
Legal basis: your explicit consent (art. 9-2-a of the GDPR), given by voluntarily filling in the form. You may ask for your case to be deleted at any time before the end of the 90 days, at the address given in section 8. We recommend not including anything that would directly identify a patient.
The private space of the DAC programme
Participants in the DAC programme have a private space for supervised practice where they share strictly anonymised clinical cases (photographs of the auricle, description) in order to receive corrections from the teaching team:
- access restricted to the enrolled cohort and the teaching team, by one-time login code;
- each member gives an anonymisation undertaking at first login, and each case submission includes a declaration that the patient's consent has been obtained;
- photographs and texts hosted by Cloudflare (R2 and D1), in the European Union, with a weekly backup copy;
- retention period: 12 months after the last session of the cohort, then automatic deletion of the photographs (backup included) and descriptions;
- earlier deletion possible at any time: by the author from the space, or on request (section 8).
Legal basis: explicit consent (art. 9-2-a of the GDPR).
Cases presented during a Masterclass
Some Masterclasses include the live demonstration of a clinical case, presented by an enrolled practitioner in front of an audience of healthcare professionals, filmed and then offered as a replay, including in paid offers. The patient is present and identifiable: this processing is therefore handled with particular care.
- the practitioner submits the case from their space: the patient's first name and e-mail address, the clinical reason anonymised at entry and, where applicable, photographs of the auricle, hosted by Cloudflare (R2, European Union) and served only to the administrators of the scheme, within a session;
- the practitioner gives an undertaking on their own behalf (they appear on camera) but can never consent on behalf of their patient: the address provided is used solely to send the patient their own consent form, via a personal, single-use link valid for 45 days;
- the patient reads the full text of the consent and decides on six separate authorisations (presence of an audience, discussion of their health, recording, replay distribution including paid, promotional excerpts, display of their first name), may ask for their face to be blurred and may write a reservation. The case is scheduled only if consent is complete;
- to evidence this consent, the following are recorded: the signed name, date of birth and postal address declared by the patient, the exact version of the text they read, and the IP address and browser at the time of signature. For a minor, the signature of both holders of parental authority is required;
- the patient may withdraw consent at any time, for the future, through the withdrawal link attached to their confirmation (valid for five years) or on simple request (section 8): their sequence is then removed from current offers;
- the case and its photographs are kept for five years after the session, the replay exploitation period stated to the patient, then automatically deleted. The proof of consent (the signature data above) is kept for five years after the end of that exploitation, then deleted.
Legal basis: the patient's explicit consent (art. 9-2-a of the GDPR), given by the patient personally. Retention of the proof is based on the obligation to demonstrate that consent (art. 7-1 of the GDPR).
Mentoring cases
Former students of the DAC programme have access to a mentoring space, with a monthly videoconference session, where they submit anonymised clinical cases to be discussed by the lead instructor:
- access by one-time login code, restricted to former students and the supervising team;
- each submission (title, description, photographs of the auricle, miscellaneous questions) includes a declaration that the patient's consent has been obtained and that the case has been anonymised;
- unlike the cohort space, a case is visible only to its author, the lead instructor and the administrators: other students see it only when it is presented during a session;
- texts hosted in the Cloudflare D1 database, photographs and session recordings in a private Cloudflare R2 storage space (European Union), served only within a session;
- retention period: 3 years after the session to which the case was attached, then automatic deletion. Earlier deletion on request (section 8).
Legal basis: explicit consent (art. 9-2-a of the GDPR).
The entry form of the DAC programme
Before accessing the course content, each participant submits a two-part entry form, required by the French national quality standard (Qualiopi): a positioning assessment on the announced prerequisites, in the form of four statements to be qualified (true, false, I don't know yet), together with free-text fields, and a needs analysis (profession, clinical situations encountered, skills sought):
- the answers are recorded, with your name and the date, in the Cloudflare D1 database hosted in the European Union;
- they are consulted by the teaching team (instructor, tutors, administrators) to adapt the support provided, and by the team only;
- the result of the positioning assessment has no bearing on anything: neither access, nor validation, nor the certificate;
- the needs analysis remains editable by you at any time during the programme;
- these forms may be presented, by name, to the certification body during a Qualiopi audit, and to a funding body for the file it funds.
Legal basis: performance of the training contract (art. 6-1-b) and legal obligation (art. 6-1-c); Article L6316-1 of the French Labour Code and the national quality standard require the training provider to document positioning at entry and the needs analysis.
The form includes an optional box allowing you to report a disability or a need for adjustments, and to describe it. This information is health data: it is entered only if you decide to, it is passed on without delay to our disability officer to arrange the adjustments, and you can remove it yourself by unticking the box. Legal basis: your explicit consent (art. 9-2-a of the GDPR). Reporting nothing has no consequence for your registration or the support you receive.
4. Use of data and legal bases
Each purpose rests on a distinct legal basis:
- Managing registrations, payments and access to programmes: performance of the contract (art. 6-1-b).
- Registering you for the live sessions of a programme that includes them, and sending you your personal access link: performance of the contract (art. 6-1-b), see section 5.
- Providing educational follow-up and the relationship with participants, including keeping the internal register of participants: performance of the contract (art. 6-1-b).
- Issuing invoices and keeping accounting records: legal obligation (art. 6-1-c).
- Sending the newsletter: consent, obtained by double opt-in and revocable at any time (art. 6-1-a).
- Answering requests sent through the contact form: legitimate interest (art. 6-1-f).
- Informing visitors through the website assistant and checking the quality of its replies: legitimate interest (art. 6-1-f), see section 2.
- Protecting the website against automated submissions and abuse: legitimate interest (art. 6-1-f).
- Processing voluntarily submitted clinical cases, including cases presented during a Masterclass and mentoring cases: explicit consent (art. 9-2-a), see section 3.
Users may unsubscribe from communications at any time using the link included in every e-mail. AcuSeminars does not sell or rent its users' personal data. No automated decision-making or profiling is carried out: the website assistant provides information, it decides nothing.
5. Recipients and processors
Data is processed by AcuSeminars and by the following processors, each for a specific purpose:
- Stripe Payments Europe, Ltd. (Ireland), payment processing and invoicing. Possible transfers outside the EU covered by standard contractual clauses.
- Brevo (Sendinblue SAS, France), e-mail sending, list management and the newsletter.
- Cloudflare: website hosting, anti-abuse protection (Turnstile), databases and storage (D1 and R2, located in the European Union) for clinical cases, the assistant log and the internal register. Possible transfers outside the EU covered by standard contractual clauses.
- Teachable (United States), hosting of the course platform and access to content. Transfers covered by standard contractual clauses.
- Genesis Digital LLC, publisher of WebinarJam (United States), hosting of live sessions (question-and-answer sessions of the DAC programme, webinars, mentoring sessions). For each purchaser of a programme that includes a live session, first name, last name and e-mail address are transmitted to it in order to create your personal link to the live room and the replay, and to record your attendance. Transfers covered by standard contractual clauses.
- Anthropic, PBC (United States), provider of the language model that writes the website assistant's replies. Only the text of the question, the relevant documentation excerpts and, after identification by code, the details of your file needed for the reply are transmitted to it. Questions about a person's health are screened out before anything is sent. Transfers covered by standard contractual clauses.
- Vimeo (United States), playback of videos embedded in the website, in “do not track” mode. Transfers covered by standard contractual clauses.
These providers only have access to the data needed for their task and are bound by confidentiality and security commitments. The transfers to the United States mentioned above rely on the standard contractual clauses adopted by the European Commission, supplemented where applicable by the provider's certification under the EU-U.S. Data Privacy Framework. Data may also be communicated to a funding body (employer, OPCO, training insurance fund) at your request, when funding is sought.
6. Retention periods
- Prospects (contact request without registration): 3 years from the last exchange.
- Participants and clients: duration of the relationship, then retention of accounting records and training documents for the applicable statutory period.
- Internal register of participants: the copies of enrolments and payments are resynchronised every night and follow the retention period of the source data; the register's access log is deleted after 400 days.
- Entry forms of the DAC programme (positioning, needs analysis, teaching summary): 3 years after the end of the session, a period that covers the Qualiopi certification cycle and any audit by a funding body, then deletion. An adjustment linked to a disability is deleted on simple request, without waiting for that term.
- Newsletter: until consent is withdrawn, then retention of proof of unsubscription.
- Clinical cases submitted after a registration: 90 days, with automatic deletion.
- Cases in the private space of the DAC programme: 12 months after the last session of the cohort, then automatic deletion.
- Cases presented during a Masterclass (description, photographs): 5 years after the session, then automatic deletion. Patients' consents (signature data): 5 years after the end of exploitation, then deletion.
- Mentoring cases (description, photographs, questions): 3 years after the session to which the case is attached, then automatic deletion.
- Website assistant log (questions and replies): 90 days, with automatic deletion. Identification session: 30 minutes.
- Technical logs and anti-abuse data: short period, limited to the security of the service. One-time login codes: 10 minutes.
7. Cookies and trackers
The website uses no audience-measurement tool and no advertising cookie. No consent banner is therefore necessary.
Only strictly necessary mechanisms, or mechanisms triggered by your own action, are used:
- Cloudflare Turnstile: on forms that trigger a sending or a write operation (contact, newsletter, conference registration, quote request, testimonial submission, resending access details from “My access”, opening the “My invoices” space, first message to the website assistant), to tell a human from a bot. A security mechanism, with no advertising profiling.
- Session cookies, set only after you log in with a code, essential to recognise you from one page to the next and deleted at their term:
espace_session(DAC private space, 60 days),mentorat_session(mentoring space, 180 days),registre_session(internal register, team only, 12 hours),acu_certif(certificate download, 12 hours),chat_session(website assistant after identification, 30 minutes). The assistant also setschat_fil(conversation number, 2 hours) andchat_humain(remembers that the Turnstile check has been passed, 12 hours). A login link received by e-mail places your address in a 10-minute pre-fill cookie, which opens no session by itself. - Vimeo: only if you play an embedded video. Players are loaded in “do not track” mode.
- Stripe: on the payment page, hosted by Stripe.
- Browser local storage: one-off memorisation of a display setting within a single visit, and of the parameters of the campaign that brought you to the website (utm), attached to the registration form to know which advertisement produced which registration. Cleared when the tab is closed, with no transmission to a third party and no cross-site tracking.
Should audience measurement be introduced in the future, this page would be updated and consent collected accordingly.
8. Your rights
In accordance with the GDPR and the French Data Protection Act, you have the rights of access, rectification, erasure, restriction, objection and portability of your data, the right to withdraw your consent at any time where processing is based on it, and the right to set post-mortem instructions regarding the fate of your data (art. 85 of the French Data Protection Act). These rights may also be exercised by a patient whose case was presented during a Masterclass, whether or not they have an account with AcuSeminars.
AcuSeminars has not appointed a data protection officer; requests are handled by the data controller. To exercise these rights: info@acuseminars.com. You also have the right to lodge a complaint with the French data-protection authority, the CNIL (www.cnil.fr).
See also: Legal notice · Terms of sale