Privacy policy
How DraftAndQuery collects, uses and protects personal data. Last updated September 4, 2026.
DraftAndQuery is published and operated by MLJ, SASU, a company registered in Paris, France, whose publication director is Jimenez Julien. This policy explains what personal data this website collects, why it is collected, how long it is kept, who processes it, and what you can ask us to do with it. It covers the marketing website at draftandquery.com. Subscribers to the application receive a separate data processing agreement covering manuscript files and submission records stored inside their account.
What the contact form collects
The only place this website collects personal data is the contact form in the request section of the home page. When you submit that form, the following named fields are transmitted and stored: name (your full name), email (your work email address), company (your imprint, agency or pen name), role (your role, chosen from a list), request (whether you want a demo, early access or a quote), size (how many manuscripts you currently have out on submission), message (your free text description of where your tracking breaks down), and consent (the record that you ticked the consent box).
Three hidden fields also travel with the submission: form-name, which identifies which form was used, subject, which labels the notification email, and recipient, which routes the message to jimenezjulien42@gmail.com. A honeypot field named bot-field is present to catch automated spam; it is left empty by human visitors and its content is never used for any other purpose. The technical metadata attached to a form submission by the hosting provider, such as the submission timestamp and the originating IP address, is also recorded.
Why we process this data, and on what legal basis
We use what you send only to answer you: to prepare a demonstration, to price a Small Press account, or to reply to a question. Under the European General Data Protection Regulation, our legal basis is your consent, given explicitly by ticking the consent box, together with our legitimate interest in responding to a business enquiry addressed to us. We do not use your details for cold outreach, we do not add you to a newsletter without a separate request, and we never sell, rent or trade personal data with anyone.
How long submissions are kept
Contact form submissions are retained for twenty four months from the date they are received, so that we can pick up a conversation that resumes after a season of writing. After that period they are deleted from the form store and from the associated mailbox. If you become a subscriber, correspondence relating to your account is kept for the life of the account and for the statutory accounting retention period afterwards. You can ask for earlier deletion at any time and we will act on it within thirty days.
Who processes the data
Form submissions are processed and stored by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, United States, which hosts this website and operates the Netlify Forms service. Notification emails are delivered to a Google mailbox controlled by MLJ, SASU. These two providers act as processors on our behalf under contractual terms that include appropriate safeguards. No other company receives the contents of your message.
Cookies and tracking
This website sets no advertising cookie and runs no third party analytics script. There is no Google Analytics tag, no advertising pixel, no session replay tool and no cross site tracker on any page. Web fonts are loaded from Google Fonts, which receives the request for the font file and the associated IP address in the ordinary course of serving it. Your browser may store standard technical items such as cache entries; these carry no identifier we can read. Because no tracking cookie is set, no cookie banner is shown.
International transfers
MLJ, SASU is established in France. Netlify, Inc. and Google are established in the United States, so submitting the form results in a transfer of personal data outside the European Economic Area. Those transfers rely on the European Commission standard contractual clauses and, where applicable, the EU to US Data Privacy Framework. If you would like a copy of the transfer safeguards that apply to your data, write to us and we will provide the relevant documentation.
Your rights
If you are in the European Economic Area or the United Kingdom, the GDPR gives you the right to access the personal data we hold about you, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to withdraw consent at any time, and to receive your data in a portable format. You also have the right to lodge a complaint with a supervisory authority, which in France is the Commission Nationale de l'Informatique et des Libertes.
If you are a resident of California, Colorado, Connecticut, Utah or Virginia, state privacy law gives you the right to know what personal information has been collected about you, to obtain a copy of it, to request its deletion, to correct inaccuracies, and to opt out of sale or of targeted advertising. We do not sell personal information and we do not conduct targeted advertising, so no opt out is necessary, but the right to know, correct, delete and appeal is honored in full. California residents may also designate an authorized agent to make a request on their behalf. We will not discriminate against anyone for exercising a privacy right.
To exercise any of these rights, write to jimenezjulien42@gmail.com with the email address you used on the form. We respond within thirty days, and we may ask one clarifying question to make sure we are acting on the right record. If we decline a request, we will explain why and how to appeal that decision.
Security
Traffic to this site is served over HTTPS. Form submissions are transmitted encrypted and are stored by our processor with access limited to the publication director. Application data belonging to subscribers, including manuscript files, is encrypted at rest, backed up hourly and retained for thirty days of point in time recovery. Access to production systems requires two factor authentication.
Children's privacy
This service is intended for adults working professionally in writing and publishing. We do not knowingly collect personal data from anyone under sixteen years of age. If you believe a child has submitted information through this site, write to us and we will delete the record promptly.
Changes to this policy
If this policy changes, the revised version will be published on this page with a new last updated date. Material changes affecting people who have already written to us will also be sent by email to the address they used. The current version is dated September 4, 2026.