johlem.net Privacy — 2026

Overview

johlem.net is the personal and consulting hub of Johnny Lemarquis, an independent cybersecurity consultant based in Luxembourg. It is a static website with no products, no user accounts, no analytics, and no tracking. This policy explains what data is processed, why, and your rights under the GDPR.

Data Controller: JOHLEM.net
Jurisdiction: Luxembourg (EU / GDPR)

What This Policy Covers

  • Data the web server processes when you visit the site
  • Data received when you send an email to @johlem.net
  • Data retained if you engage me for consulting work
  • Your legal rights and how to exercise them

Data Collection

What Data Is Collected

The following categories of personal data may be processed:

  • Visitor data (automatic): IP address, browser type, operating system, pages visited, referrer, timestamps
  • Email correspondence: your name, your email address, message content, mail metadata (timestamps, headers)
  • Engagement details (if applicable): professional contact details, notes on the engagement, contractual documents

How Data Is Collected

Data collection methods and legal bases
Collection Method Data Type Legal Basis
Web server logs (automatic) IP address, browser, request metadata Legitimate interest (Art. 6(1)(f) GDPR)
Email correspondence Name, email, message content, metadata Legitimate interest / contract (Art. 6(1)(b)(f))
Engagement contracting Professional contact, notes, signed documents Contract performance (Art. 6(1)(b))

No analytics platform (Google Analytics, Matomo, etc.) is deployed. No tracking pixels, no advertising scripts, no cookies beyond those strictly necessary for site operation.

Why Data Is Collected

  • To operate, secure, and debug the website (server logs)
  • To reply to your inquiry or message
  • To fulfil consulting engagements you initiate
  • To comply with Luxembourg legal and tax retention obligations

Data Processing

Legal Bases

Personal data is processed only on a lawful basis. The relevant bases under GDPR and Luxembourg law are:

  • Contract performance (Art. 6(1)(b)): to fulfil a consulting engagement you've initiated
  • Legitimate interest (Art. 6(1)(f)): server log security, replying to your email, business correspondence
  • Legal obligation (Art. 6(1)(c)): retention required by Luxembourg commercial and tax law

Consent is not used as a lawful basis on this site — there are no newsletter signups, no cookie banners, no opt-in flows.

Special Categories of Data

Special categories of personal data (health information, racial origin, political beliefs, religious affiliation, etc.) are not intentionally collected. If you provide such information in an email, it will be deleted unless retention is required by law.

Automated Decision-Making

No automated decision-making, profiling, or AI-based processing is performed on visitor or correspondent data.

Data Retention

Personal data is retained only as long as necessary to fulfil its purpose, subject to legal obligations under Luxembourg and EU law.

Data retention periods
Data Type Retention Period Reason
Server logs 30 days, then purged Security / abuse prevention
Email correspondence (no engagement) 12 months from last contact Operational continuity
Email correspondence (active or past engagement) Engagement duration + 7 years Luxembourg legal requirement
Contractual documents 10 years Luxembourg commercial law

After the retention period, data is securely deleted using cryptographic erasure or secure overwrite where applicable.

Data Sharing

With Whom Data Is Shared

Your data is not sold, rented, or shared for marketing or commercial purposes. Limited and necessary sharing may occur with:

  • Hosting and email infrastructure providers: see Processors below
  • Legal or regulatory authorities: when required by applicable Luxembourg law (court order, regulatory request)

International Data Transfers

One processor (Infomaniak) is located in Switzerland, outside the European Economic Area. Switzerland holds an EU adequacy decision under GDPR Article 45, which provides a lawful basis for the transfer without additional safeguards. No other transfers outside the EEA occur.

Processors

The processors used are:

  • Hosting: Infomaniak (Switzerland)
  • Email: tuta.com (Germany)

The list above is the complete set of processors used. It will be updated here if it changes.

Your Rights

Your Legal Rights (GDPR & Luxembourg Law)

You have the following rights regarding your personal data:

  • Right to Access: obtain a copy of personal data held about you
  • Right to Rectification: request that inaccurate or incomplete data be corrected
  • Right to Erasure: request deletion ("right to be forgotten"), subject to overriding legal obligations
  • Right to Restriction: limit how your data is processed
  • Right to Portability: receive your data in a structured, machine-readable format
  • Right to Object: object to processing based on legitimate interest

How to Exercise Your Rights

To exercise any of these rights, email hi@johlem.net. Include:

  • Your full name and email address
  • The specific right you are exercising
  • Enough context to identify the data (e.g. the email thread, the date of contact)

Requests are acknowledged within 72 hours and fulfilled within 30 days, as required by Art. 12 GDPR. Identity verification may be requested for high-risk requests.

Right to Lodge a Complaint

If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Luxembourg supervisory authority (see Contact).

Security

How Data Is Protected

As a cybersecurity professional, appropriate technical and organisational measures are applied:

  • Encryption in transit: HTTPS / TLS for all web traffic; opportunistic TLS for mail
  • Email authentication: SPF, DKIM, DMARC
  • Encrypted storage: LUKS2 with Argon2id key derivation on devices that hold operational data
  • Hardened server configuration: minimal attack surface, access control, monitoring
  • Multi-factor authentication: on all administrative access (hosting panel, email, accounts that touch operational data)
  • Regular security reviews: periodic configuration audit and patching

Limitations

No system is perfectly secure. Email in particular can transit servers outside my control. Avoid sending highly sensitive material (passwords, secret keys, credentials) over unencrypted email; use end-to-end encryption (PGP) for that.

Data Breach Notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, affected individuals will be notified, and the CNPD informed within 72 hours, as required by Art. 33 GDPR.

Contact

Controller

Email

hi@johlem.net

Response Time

Acknowledgement within 72 hours; full response within 30 days (Art. 12 GDPR).

Supervisory Authority

You have the right to lodge a complaint with the Luxembourg supervisory authority:

Commission Nationale pour la Protection des Données (CNPD)

15, boulevard du Jazz
L-4370 Belvaux
Luxembourg
cnpd.public.lu
Phone: +352 26 10 60 1

Changes to This Policy

This policy may be updated periodically to reflect changes in practice, technology, or legal requirements. The "Last updated" date at the top of the page reflects the most recent revision. Material changes will be communicated via this page.

Continued use of johlem.net after an update constitutes acceptance of the revised policy.

Last updated: June 21, 2026