WMG-STUDIO

Privacy policy

Privacy Policy

This policy explains what personal data is collected on the wmg-studio.com website, why, on what legal basis, with whom it is shared, how long it is retained and what your rights are. It is written in clear language, in accordance with Article 12 of the GDPR.

Last updated: 5 September 2026.

1. Data controller

The controller of your data is Farhat Werfelli, operating under the trade name WMG-STUDIO, a sole trader (entreprise individuelle), whose contact details appear in the Legal Notice.

  • Contact for any question regarding your data: contact@wmg-studio.com

Given the nature and volume of the processing carried out, the appointment of a Data Protection Officer (DPO) is not mandatory; no DPO has been appointed.

2. What data, why and on what legal basis?

We only collect the data necessary for each purpose (data minimisation principle). No sensitive data (health, opinions, etc.) is requested.

a) Quote request / contact form

  • Data: name, e-mail address, type of project, message; budget is optional.
  • Purpose: to respond to your request and, where appropriate, prepare a proposal.
  • Legal basis: steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).

b) Online appointment booking (Cal.com)

  • Data: name, e-mail address, subject, time slot and time zone.
  • Purpose: to arrange a discussion about a project.
  • Legal basis: steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).
  • Processor: the booking tool is provided by Cal.com, acting as a data processor on our behalf, with data hosted within the European Union. The confirmed appointment appears in the WMG-STUDIO professional calendar.

c) Account and access to online training courses

  • Data: e-mail address, login credentials and progress data (courses taken, steps completed, trophies).
  • Purpose: to create and manage your account, give you access to the courses and record your progress.
  • Legal basis: performance of the service you sign up for by creating an account (Article 6(1)(b) GDPR).

f) Publication on clients’ social media accounts (social media management service)

  • Data: client’s social media account(s) (e.g. TikTok) and associated access tokens (OAuth); video, visual, and text content provided or approved by the client for publication; publication statistics linked to the account.
  • Purpose: to publish and manage content on behalf of our clients, as part of the mandate entrusted to WMG-STUDIO.
  • Legal basis: performance of the contract concluded with the client (Article 6(1)(b) GDPR).
  • Service provider: TikTok, via its official “Content Posting API,” within the scope of the access granted by the client themselves (an OAuth authorisation which the client may revoke at any time).

g) Verification of partner venues’ Google Business listings (Events Platform)

  • Purpose: when a venue signs up on the Events Platform, it may connect its Google Business Profile account so that WMG-STUDIO can automatically verify that it genuinely owns or manages the declared establishment (prevention of fraudulent registrations).
  • Data accessed: through the OAuth authorisation granted by the venue (scope business.manage), WMG-STUDIO has read-only access to the information of its Google Business Profile account(s) and listing(s) — account identifier, listing name, address, verification status. No change is made to the venue’s Google listing at this stage.
  • Legal basis: performance of the contract concluded with the venue (Article 6(1)(b) GDPR) — necessary to activate its account on the Events Platform.
  • Retention: the authorisation token (access/refresh token) is kept for as long as the venue’s account is active; it can be revoked at any time by the venue (Google, “Third-party apps” section of its Google account) and is deleted from our systems upon revocation or deletion of the venue’s account.
  • Recipients: this data is never passed on to any third party; it is used strictly internally for verification.
  • Rights: identical to those described for the other processing operations (see the “Your rights” section).

d) Website audience measurement (in-house statistics)

  • What we do: we measure website traffic (page views, visit sources) using a tool developed in-house and hosted on our own server.
  • No cookies or trackers: this measurement places no cookies on your device. Your IP address is not retained: at the time of the visit it is used solely to compute an anonymous technical identifier that is regenerated each day (a daily-salted hash), which does not allow you to be re-identified or tracked from one website to another.
  • Purpose: to produce anonymous traffic statistics, for our own use only. No data is shared with any third party, and no advertising profiling is carried out.
  • Legal basis: our legitimate interest in understanding the audience of our website (Article 6(1)(f) GDPR), balanced by the anonymisation of the data and your right to object.
  • This audience measurement falls under the consent exemption provided for anonymous statistics; this is why the website does not display a cookie banner. You may nonetheless object to it (see the “Your rights” section).

e) Strictly necessary cookies

The website may set technical cookies that are essential to its operation (for example: keeping your session open when you are logged in to your account, remembering your language). These cookies are exempt from consent because they are strictly necessary for the service you request. The website uses no Google Analytics, no advertising cookies and no social-network trackers.

3. Who receives your data?

Your data is intended solely for WMG-STUDIO (Farhat Werfelli). It is never sold or rented. The only parties involved, acting as data processors on our instructions, are:

  • Hostinger International Ltd — hosting of the website and data;
  • Cal.com — appointment booking tool (data hosted within the European Union).
  • TikTok Technology Limited (Ireland) and, depending on TikTok’s processing structure, TikTok Inc. (United States) — the destination platform for content published on behalf of the client (social media management service). WMG-STUDIO only accesses the rights explicitly authorised by the client via OAuth and does not retain the client’s TikTok account credentials beyond what is necessary to provide the service.

4. Transfers outside the European Union

Our providers are configured to host data within the European Union. In principle, no data is transferred outside the EU. Should a transfer take place, it would be covered by the appropriate safeguards provided for by the GDPR (the European Commission’s standard contractual clauses).

The TikTok publishing service involves a transfer of data to TikTok Technology Limited (Ireland/United Kingdom) and, depending on the processing involved, to TikTok Inc. (United States). This transfer is governed by the European Commission’s Standard Contractual Clauses.

5. How long do we keep your data?

  • Quote or appointment requests with no follow-up (prospects): 3 years from our last contact, then deletion.
  • Clients: for the duration of the relationship, then archiving of contractual and accounting documents (invoices) for 10 years in accordance with our legal obligations.
  • Training account: as long as your account is active; deleted at your request, or after an extended period of inactivity.
  • Audience statistics: raw data kept for a maximum of 25 months; aggregated and anonymous statistics may be kept beyond this period.
  • Client’s social media management mandate: data related to the mandate is retained for the duration of the mandate, then deleted or revoked (access tokens) within 30 days of the end of the contract, unless a legal obligation requires otherwise.

6. Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights over your data: the right of access, rectification, erasure, restriction, objection and portability.

To exercise these rights, write to contact@wmg-studio.com, specifying your request. We may ask you to prove your identity. We respond within a maximum of one month.

If, after contacting us, you consider that your rights are not being respected, you may lodge a complaint with the CNIL (the French data protection authority): www.cnil.fr.

7. Security

We implement reasonable technical and organisational measures to protect your data against loss, unauthorised access or disclosure.

8. Changes

This policy may be updated to reflect legal or technical developments. The date of the latest update appears at the top of this page.