Privacy Policy
GDPR compliance — Site cisapp.eu and Platform app.cisapp.eu
Version 1.0.0 · Last updated on 12 August 2026
Privacy Policy
This Privacy Policy (the “Policy”) describes how CISAPP SAS processes personal data collected through the website www.cisapp.eu and the software platform app.cisapp.eu. It is drafted in accordance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (the “GDPR”) and French Law No. 78-17 of 6 January 1978 as amended (the “French Data Protection Act”). The French version published on the Site shall prevail in case of discrepancy.
1. Identity and contact details of the controller
The controller of personal data collected via the Site and, where applicable, via the Platform for processing carried out for its own account is:
- CISAPP SAS, a French société par actions simplifiée with share capital of 6,000 euros, registered office at 28 rue Descartes, 59000 Lille, France, registered with the Lille Métropole Trade and Companies Register under number 108 189 325 (intra-Community VAT number FR70108189325).
- Legal representative: Mr. Alexis Soto, as representative of QUANTUM OPERATION GROUP, Chief Executive Officer (Directeur général).
- General contact email: hello@cisapp.eu.
- Email dedicated to data protection: privacy@cisapp.eu.
- Data Protection Officer (DPO): CISAPP SAS has not appointed a Data Protection Officer. Requests relating to data protection may be sent to privacy@cisapp.eu.
2. CISAPP's various roles
Depending on the context, CISAPP SAS acts in several capacities within the meaning of the GDPR:
- As controller in respect of personal data collected via the Site (visitors, prospects, contact forms) and personal data of its own employees, contractors and suppliers.
- As processor in respect of personal data entered, imported or generated in the Platform by the Customer's authorised users (employees, contractors, supplier contacts identified by the Customer). The terms of this processing are governed by the Data Processing Agreement (DPA) annexed to the contractual terms.
- Company data relating to suppliers (corporate name, sector, size, aggregated risk indicators) entered or produced in the Platform may be pooled between Customers under the conditions set out in the contractual terms. Such pooling relates exclusively to data concerning legal entities and excludes any personal data.
3. Data collected and purposes
CISAPP SAS only collects data strictly necessary for the purposes described below.
3.1 Site visitors
When you visit the Site, CISAPP SAS may collect the following data:
- Contact or demo request form data: business email address, and, where applicable, name, position, company and message entered.
- Audience-measurement data: page viewed, referring source, browser type and screen resolution, country, all strictly anonymised through our self-hosted analytics tool (Plausible Analytics) without collecting any individual identifier or unmasked IP address.
- Technical connection data: server logs retained for security purposes, including truncated IP address, date and time of request, requested URL and response code.
Purposes of the processing:
| Purpose | Legal basis | Data concerned | Retention |
|---|---|---|---|
| Responding to contact and demo requests | Pre-contractual measures (Art. 6.1.b GDPR) | Business contact details, message | 3 years from last contact |
| Sending commercial information on similar products by electronic means | Legitimate interest of CISAPP SAS in promoting its services to professional prospects (Art. 6.1.f GDPR) | Business email address | 3 years from last contact or objection |
| Measuring Site audience | Legitimate interest of CISAPP SAS in understanding the use of its Site without infringing visitors' privacy (Art. 6.1.f GDPR) | Anonymised audience data | 13 months maximum |
| Ensuring Site security and retaining technical evidence | Legal security obligation (Art. 6.1.c GDPR) and legitimate interest (Art. 6.1.f GDPR) | Technical logs | 12 months maximum |
3.2 Platform users
Data processed in the context of the Customer's authorised users' use of the Platform (employees, contractors, contacts identified by the Customer) is processed by CISAPP SAS as a processor, on behalf of and according to the documented instructions of the Customer (controller).
Categories of data processed include in particular:
- User account identification data: name, position, business email address, hashed password, internal unique identifier, preferred language.
- Navigation and usage data: actions performed, modules accessed, time-stamp of connections, IP address.
- Supplier management data: names, positions and business contact details of contacts identified by the Customer at its suppliers.
- Documents and files uploaded by the Customer or its suppliers: contracts, certifications, attestations, completed questionnaires, which may contain personal data depending on the Customer's choices.
Purposes, retention periods and recipients of such data are defined by the Customer and specified in the Data Processing Agreement (DPA).
3.3 Business contacts identified at suppliers
When the Customer enters into the Platform the business contact details of contacts at its suppliers (for instance to send them an evaluation questionnaire), such persons are informed of the collection and processing of their data in the first communication addressed to them via the Platform. This information includes the identity of the Customer (controller), the purpose, their rights and the contact details to exercise them.
CISAPP SAS uses such data solely to provide the service to the Customer and does not process it for its own purposes.
4. Recipients of the data
Personal data collected by CISAPP SAS as a controller is shared only with the following recipients, and only insofar as strictly necessary for the purpose pursued:
- CISAPP SAS's authorised staff (commercial, marketing, support, security and compliance teams), strictly within the scope of their duties.
- CISAPP SAS's technical processors listed in section 5.
- Administrative or judicial authorities, where required by law.
CISAPP SAS does not sell, rent or otherwise transfer personal data to third parties for commercial purposes.
5. Processors and data transfers
CISAPP SAS relies on technical providers to host and operate the Site and the Platform. As at the date of last update of this Policy, the processors used are:
| Processor | Address | Country | Service |
|---|---|---|---|
| OVH SAS | 2 rue Kellermann, 59100 Roubaix | France (EU) | Infrastructure hosting, backups, network services |
| Scaleway SAS | 8 rue de la Ville l'Evêque, 75008 Paris | France (EU) | Complementary infrastructure hosting, backups, transactional email delivery |
| Crisp IM SAS | 2 Boulevard de Launay, 44100 Nantes | France (EU) | Live chat for visitor and user support |
| Google Ireland Limited (Google Workspace) | Gordon House, Barrow Street, Dublin 4 | Ireland (EU) | Business email and internal document storage |
Applicable safeguards: OVH SAS and Scaleway SAS are certified ISO/IEC 27001, ISO/IEC 27017 and ISO/IEC 27018, and operate data centres with HDS and SecNumCloud qualifications depending on the offering; Crisp IM SAS is GDPR-compliant with all hosting in the European Union; Google Ireland Limited is certified ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and SOC 2 Type II.
As at the date of last update of this Policy, all CISAPP SAS processors are established within the European Union. For processors belonging to international groups (in particular Google Ireland Limited, part of the Google group), the Standard Contractual Clauses adopted by the European Commission are implemented to govern any potential intra-group onward transfer, in accordance with Articles 44 to 49 of the GDPR and the recommendations of the European Data Protection Board.
Should CISAPP SAS engage a new processor established outside the European Union, the transfer would be carried out only on the basis of an adequacy decision of the European Commission, the Standard Contractual Clauses adopted by the Commission, or any other mechanism provided for by Articles 44 et seq. of the GDPR. The up-to-date list of processors is maintained and may be communicated upon request to privacy@cisapp.eu.
6. Retention periods
CISAPP SAS retains personal data for the period strictly necessary to achieve the purposes described in section 3. Beyond such period, data is deleted or anonymised.
For data processed in the Platform on behalf of a Customer, retention periods are defined contractually and, in the absence of contrary instructions, data is deleted no later than ninety (90) days after the end of the contractual relationship, subject to any legal retention obligations.
Legal retention obligations (notably accounting, tax or evidentiary) prevail over the above periods. Affected data is then archived under conditions ensuring its security and the limitation of access.
7. Rights of data subjects
Pursuant to Articles 15 to 22 of the GDPR, you have the following rights:
- Right of access to your personal data and information about its processing.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”) in the cases provided for by the GDPR.
- Right to restriction of processing in the cases provided for by the GDPR.
- Right to object to processing based on legitimate interest, and in all circumstances for direct marketing purposes.
- Right to data portability of the data you have provided, in a structured, commonly used format.
- Right to issue directives relating to the fate of your data after your death (French specific right).
- Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal, for processing based on consent.
To exercise these rights, you may send a request to privacy@cisapp.eu, accompanied, where there is reasonable doubt, by any element enabling your identity to be verified. CISAPP SAS will use its best efforts to respond within one (1) month of receipt of the request, extendable by two (2) additional months in case of complex or numerous requests.
Where data is processed by CISAPP SAS as a processor on behalf of a Customer, CISAPP SAS will forward your request to the relevant Customer, who is the controller and is responsible for responding to it.
You are also entitled to lodge a complaint with the French Data Protection Authority (Commission Nationale de l'Informatique et des Libertés — CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr, or with the supervisory authority of your habitual residence.
8. Cookies and other trackers
The Site does not use any cookie or tracker requiring prior consent within the meaning of Article 82 of the French Data Protection Act.
Site audience measurement is provided by a self-hosted instance of Plausible Analytics, configured to respect visitors' privacy: no individual identification, no unmasked IP address, no cross-correlation with other processing. Pursuant to the position of the French Data Protection Authority, such use falls within the consent exemption.
Cookies strictly necessary for the operation of the Platform (for instance session cookies, authentication cookies, CSRF cookies) may be set when using the Platform. Such cookies are essential to the provision of the service and are not subject to prior consent.
No advertising, profiling or third-party audience-measurement cookie is set.
9. Data security
CISAPP SAS implements appropriate technical and organisational measures to safeguard the security, integrity, availability and confidentiality of the data processed. These measures are described in detail in the Security Annex made available to Customers.
Key measures include in particular: encryption of data in transit (TLS) and at rest, access control through individual credentials and strong passwords, available multi-factor authentication, environment segregation, access logging, encrypted backups, hosting in ISO/IEC 27001-certified data centres located in the European Union.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, CISAPP SAS notifies the supervisory authority within 72 hours and informs the data subjects under the conditions provided for by the GDPR.
10. Changes to the Policy
CISAPP SAS may amend this Policy to reflect legal, regulatory, case-law, technical or operational developments. The applicable version is the one published on the Site at the time of your visit. The date of last update appears at the bottom of this Policy.
In case of material amendment, Customers will be informed by any appropriate means at least thirty (30) days before the entry into force of the amendments.
11. Contact
For any question relating to this Policy or to the processing of your personal data, you may contact CISAPP SAS:
- by email: privacy@cisapp.eu
- by post: to the attention of the data protection contact, CISAPP SAS, 28 rue Descartes, 59000 Lille, France.
Last update: 12 August 2026. Version: 1.0.0.