Who controls your data?
E-R.I (Expertise Roanne Informatique), 4 rue Jean Jaurès, 42300 Roanne, France, is the controller for processing performed by OnePage Creator. Richard Coste is the data protection contact.
What data do we use?
We process only the information needed to operate the service:
- email address and language preferences used for your account and sign-in links;
- for professional accounts: contact identity, agency or studio details, country and registration number, as well as public company information;
- for projects managed by a professional: client contact details, internal reference, logo and brand guidelines;
- questionnaire answers, technical requests, texts, links and contact details intended for your project;
- photos and files you upload, as well as generated previews, revisions and delivery files;
- billing details, payment status, invoice and order history;
- security data, error logs, IP address and your analytics choice.
Why do we use it and on what basis?
| Purpose | Legal basis |
|---|---|
| Create the account, build the website, manage revisions and deliver files | Contract performance and pre-contractual steps |
| Process payment and issue the invoice | Contract performance and legal accounting obligations |
| Secure the service, prevent abuse and diagnose incidents | E-R.I’s legitimate interest in protecting its service and users |
| Measure traffic with Google Analytics | Your consent, which you may withdraw at any time |
Who receives the data?
Data is available to authorised E-R.I staff and, only where necessary, to our service providers:
- Stripe for payments. OnePage Creator does not store your full card number;
- Pennylane to create and retrieve your invoice;
- the French government company search API to find and verify public SIREN information during professional registration;
- OpenAI and Anthropic to produce requested copy, code, UI/UX direction and visuals. Relevant answers, instructions and project files may be sent to them;
- hosting and email providers for technical operation and messages;
- Google Fonts to load the typefaces used by the interface;
- Google Analytics only after you agree, to measure traffic.
Some providers may process data outside the European Economic Area. Where this occurs, the transfer relies on the applicable legal mechanisms and contractual safeguards stated by the relevant provider.
How long do we keep it?
Account, project and order data is kept during the customer relationship and then for as long as needed for delivery, support and the defence of E-R.I’s rights. Invoices and accounting records are kept for the applicable legal period, generally ten years. Technical logs are retained for a period proportionate to diagnosis and security needs. Data that is no longer needed is deleted or anonymised.
What are your rights?
You may request access, correction, deletion or restriction of your data, object to processing based on legitimate interest, or withdraw your consent. Where the relevant conditions are met, you also have a right to data portability and may give instructions concerning your data after death.
Send your request to contact@e-r-i.fr or by post to E-R.I, 4 rue Jean Jaurès, 42300 Roanne, France. Proof of identity may be requested only where there is reasonable doubt. You may also lodge a complaint with the French data protection authority, the CNIL.
Visit the CNIL website ↗Cookies and traffic measurement
The “onepage_creator_session” session cookie is strictly necessary for sign-in and journey security. It expires when the browser closes. Google Analytics loads only after you agree. Your choice is stored for six months and can be changed at any time using the button below.
Use of artificial intelligence services
OnePage Creator uses creation assistance tools to turn your brief into a visual proposal and a working website. They do not make decisions that produce legal effects concerning you. Do not provide unnecessary sensitive data and make sure you hold the required rights to all supplied text, photos and files.
Security and updates
E-R.I applies technical and organisational measures designed to limit unauthorised access, loss and disclosure, including HTTPS, protected sessions, private project storage, access controls and incident logging. This policy may change to reflect service or regulatory updates; the date above identifies the latest version.