Privacy Policy

GDPR compliance — Site cisapp.eu and Platform app.cisapp.eu

Version 1.0.0 · Last updated on 12 August 2026

Privacy Policy

This Privacy Policy (the “Policy”) describes how CISAPP SAS processes personal data collected through the website www.cisapp.eu and the software platform app.cisapp.eu. It is drafted in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the “GDPR”) and French Law No. 78-17 of 6 January 1978 as amended (the “French Data Protection Act”). The French version published on the Site shall prevail in case of discrepancy.

1. Identity and contact details of the controller

The controller of personal data collected via the Site and, where applicable, via the Platform for processing carried out for its own account is:

  • CISAPP SAS, a French société par actions simplifiée with share capital of 6,000 euros, registered office at 28 rue Descartes, 59000 Lille, France, registered with the Lille Métropole Trade and Companies Register under number 108 189 325 (intra-Community VAT number FR70108189325).
  • Legal representative: Mr. Alexis Soto, as representative of QUANTUM OPERATION GROUP, Chief Executive Officer (Directeur général).
  • General contact email: hello@cisapp.eu.
  • Email dedicated to data protection: privacy@cisapp.eu.
  • Data Protection Officer (DPO): CISAPP SAS has not appointed a Data Protection Officer. Requests relating to data protection may be sent to privacy@cisapp.eu.

2. CISAPP's various roles

Depending on the context, CISAPP SAS acts in several capacities within the meaning of the GDPR:

  • As controller in respect of personal data collected via the Site (visitors, prospects, contact forms) and personal data of its own employees, contractors and suppliers.
  • As processor in respect of personal data entered, imported or generated in the Platform by the Customer's authorised users (employees, contractors, supplier contacts identified by the Customer). The terms of this processing are governed by the Data Processing Agreement (DPA) annexed to the contractual terms.
  • Company data relating to suppliers (corporate name, sector, size, aggregated risk indicators) entered or produced in the Platform may be pooled between Customers under the conditions set out in the contractual terms. Such pooling relates exclusively to data concerning legal entities and excludes any personal data.

3. Data collected and purposes

CISAPP SAS only collects data strictly necessary for the purposes described below.

3.1 Site visitors

When you visit the Site, CISAPP SAS may collect the following data:

  • Contact or demo request form data: business email address, and, where applicable, name, position, company and message entered.
  • Audience-measurement data: page viewed, referring source, browser type and screen resolution, country, all strictly anonymised through our self-hosted analytics tool (Plausible Analytics) without collecting any individual identifier or unmasked IP address.
  • Technical connection data: server logs retained for security purposes, including truncated IP address, date and time of request, requested URL and response code.

Purposes of the processing:

PurposeLegal basisData concernedRetention
Responding to contact and demo requestsPre-contractual measures (Art. 6.1.b GDPR)Business contact details, message3 years from last contact
Sending commercial information on similar products by electronic meansLegitimate interest of CISAPP SAS in promoting its services to professional prospects (Art. 6.1.f GDPR)Business email address3 years from last contact or objection
Measuring Site audienceLegitimate interest of CISAPP SAS in understanding the use of its Site without infringing visitors' privacy (Art. 6.1.f GDPR)Anonymised audience data13 months maximum
Ensuring Site security and retaining technical evidenceLegal security obligation (Art. 6.1.c GDPR) and legitimate interest (Art. 6.1.f GDPR)Technical logs12 months maximum

3.2 Platform users

Data processed in the context of the Customer's authorised users' use of the Platform (employees, contractors, contacts identified by the Customer) is processed by CISAPP SAS as a processor, on behalf of and according to the documented instructions of the Customer (controller).

Categories of data processed include in particular:

  • User account identification data: name, position, business email address, hashed password, internal unique identifier, preferred language.
  • Navigation and usage data: actions performed, modules accessed, time-stamp of connections, IP address.
  • Supplier management data: names, positions and business contact details of contacts identified by the Customer at its suppliers.
  • Documents and files uploaded by the Customer or its suppliers: contracts, certifications, attestations, completed questionnaires, which may contain personal data depending on the Customer's choices.

Purposes, retention periods and recipients of such data are defined by the Customer and specified in the Data Processing Agreement (DPA).

3.3 Business contacts identified at suppliers

When the Customer enters into the Platform the business contact details of contacts at its suppliers (for instance to send them an evaluation questionnaire), such persons are informed of the collection and processing of their data in the first communication addressed to them via the Platform. This information includes the identity of the Customer (controller), the purpose, their rights and the contact details to exercise them.

CISAPP SAS uses such data solely to provide the service to the Customer and does not process it for its own purposes.

4. Recipients of the data

Personal data collected by CISAPP SAS as a controller is shared only with the following recipients, and only insofar as strictly necessary for the purpose pursued:

  • CISAPP SAS's authorised staff (commercial, marketing, support, security and compliance teams), strictly within the scope of their duties.
  • CISAPP SAS's technical processors listed in section 5.
  • Administrative or judicial authorities, where required by law.

CISAPP SAS does not sell, rent or otherwise transfer personal data to third parties for commercial purposes.

5. Processors and data transfers

CISAPP SAS relies on technical providers to host and operate the Site and the Platform. As at the date of last update of this Policy, the processors used are:

ProcessorAddressCountryService
OVH SAS2 rue Kellermann, 59100 RoubaixFrance (EU)Infrastructure hosting, backups, network services
Scaleway SAS8 rue de la Ville l'Evêque, 75008 ParisFrance (EU)Complementary infrastructure hosting, backups, transactional email delivery
Crisp IM SAS2 Boulevard de Launay, 44100 NantesFrance (EU)Live chat for visitor and user support
Google Ireland Limited (Google Workspace)Gordon House, Barrow Street, Dublin 4Ireland (EU)Business email and internal document storage

Applicable safeguards: OVH SAS and Scaleway SAS are certified ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018, and operate data centres with HDS and SecNumCloud qualifications depending on the offering; Crisp IM SAS is GDPR-compliant with all hosting in the European Union; Google Ireland Limited is certified ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and SOC 2 Type II.

As at the date of last update of this Policy, all CISAPP SAS processors are established within the European Union. For processors belonging to international groups (in particular Google Ireland Limited, part of the Google group), the Standard Contractual Clauses adopted by the European Commission are implemented to govern any potential intra-group onward transfer, in accordance with Articles 44 to 49 of the GDPR and the recommendations of the European Data Protection Board.

Should CISAPP SAS engage a new processor established outside the European Union, the transfer would be carried out only on the basis of an adequacy decision of the European Commission, the Standard Contractual Clauses adopted by the Commission, or any other mechanism provided for by Articles 44 et seq. of the GDPR. The up-to-date list of processors is maintained and may be communicated upon request to privacy@cisapp.eu.

6. Retention periods

CISAPP SAS retains personal data for the period strictly necessary to achieve the purposes described in section 3. Beyond such period, data is deleted or anonymised.

For data processed in the Platform on behalf of a Customer, retention periods are defined contractually and, in the absence of contrary instructions, data is deleted no later than ninety (90) days after the end of the contractual relationship, subject to any legal retention obligations.

Legal retention obligations (notably accounting, tax or evidentiary) prevail over the above periods. Affected data is then archived under conditions ensuring its security and the limitation of access.

7. Rights of data subjects

Pursuant to Articles 15 to 22 of the GDPR, you have the following rights:

  • Right of access to your personal data and information about its processing.
  • Right to rectification of inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) in the cases provided for by the GDPR.
  • Right to restriction of processing in the cases provided for by the GDPR.
  • Right to object to processing based on legitimate interest, and in all circumstances for direct marketing purposes.
  • Right to data portability of the data you have provided, in a structured, commonly used format.
  • Right to issue directives relating to the fate of your data after your death (French specific right).
  • Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal, for processing based on consent.

To exercise these rights, you may send a request to privacy@cisapp.eu, accompanied, where there is reasonable doubt, by any element enabling your identity to be verified. CISAPP SAS will use its best efforts to respond within one (1) month of receipt of the request, extendable by two (2) additional months in case of complex or numerous requests.

Where data is processed by CISAPP SAS as a processor on behalf of a Customer, CISAPP SAS will forward your request to the relevant Customer, who is the controller and is responsible for responding to it.

You are also entitled to lodge a complaint with the French Data Protection Authority (Commission Nationale de l'Informatique et des Libertés — CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr, or with the supervisory authority of your habitual residence.

8. Cookies and other trackers

The Site does not use any cookie or tracker requiring prior consent within the meaning of Article 82 of the French Data Protection Act.

Site audience measurement is provided by a self-hosted instance of Plausible Analytics, configured to respect visitors' privacy: no individual identification, no unmasked IP address, no cross-correlation with other processing. Pursuant to the position of the French Data Protection Authority, such use falls within the consent exemption.

Cookies strictly necessary for the operation of the Platform (for instance session cookies, authentication cookies, CSRF cookies) may be set when using the Platform. Such cookies are essential to the provision of the service and are not subject to prior consent.

No advertising, profiling or third-party audience-measurement cookie is set.

9. Data security

CISAPP SAS implements appropriate technical and organisational measures to safeguard the security, integrity, availability and confidentiality of the data processed. These measures are described in detail in the Security Annex made available to Customers.

Key measures include in particular: encryption of data in transit (TLS) and at rest, access control through individual credentials and strong passwords, available multi-factor authentication, environment segregation, access logging, encrypted backups, hosting in ISO/IEC 27001-certified data centres located in the European Union.

In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, CISAPP SAS notifies the supervisory authority within 72 hours and informs the data subjects under the conditions provided for by the GDPR.

10. Changes to the Policy

CISAPP SAS may amend this Policy to reflect legal, regulatory, case-law, technical or operational developments. The applicable version is the one published on the Site at the time of your visit. The date of last update appears at the bottom of this Policy.

In case of material amendment, Customers will be informed by any appropriate means at least thirty (30) days before the entry into force of the amendments.

11. Contact

For any question relating to this Policy or to the processing of your personal data, you may contact CISAPP SAS:

  • by email: privacy@cisapp.eu
  • by post: to the attention of the data protection contact, CISAPP SAS, 28 rue Descartes, 59000 Lille, France.

Last update: 12 August 2026. Version: 1.0.0.