Privacy Policy
Personal Data Protection — Last updated: March 2026
Privacy Policy & Personal Data Protection
SecureOps ("SecureOps", "we") places the highest importance on the protection of personal data and the respect of its users' privacy. This Privacy Policy informs you about how your data is collected, used, protected, shared and the rights you have, in accordance with:
- Regulation (EU) 2016/679 (GDPR)
- French Data Protection Act No. 78-17 as amended
- CNIL recommendations
1. Data controller
SecureOps — https://secureops.fr
Email: pierreglerant@gmail.com
For any question or to exercise your rights: contact us by email or via the contact form — Subject: GDPR Request.
2. What data do we collect?
We only collect data strictly necessary for the purposes described below.
2.1 Data you provide directly
A. Contact form
- Name and first name
- Email address
- Subject and message content
This data is used solely to process your request.
B. Newsletter
- Email address
You can unsubscribe at any time via the unsubscribe link in each email.
C. User account creation
- Identity (name, first name)
- Email address
- Password (bcrypt-hashed, if email/password sign-up)
- Service usage history
D. Scan and analysis data
- URL(s) submitted for security analysis
- Scan results, security scores (/100) and associated recommendations
- Scan history (date, target, result, severity levels)
- Scheduled scan configurations (frequency, targets, options)
- Pages discovered during automated crawls
- API keys (sk_...): name, expiry date, IP restrictions, tags (raw values are never stored — hashed)
This data is directly linked to your account and strictly necessary to provide the security service.
2.2 Data collected automatically
When browsing the site, we anonymously collect certain technical logs to improve our service and understand its usage:
- Pages visited (URL path)
- Referral page (referrer)
- Browser window dimensions (viewport)
- Tab visibility (whether the page is active or in the background)
This data is entirely anonymous: we do not store any IP addresses and do not perform any analytical, advertising or behavioral tracking that could personally identify you.
3. Purposes and legal bases
Purpose
- Responding to messages sent via the contact form
- Managing newsletter subscriptions
- Providing the cybersecurity SaaS service
- Site security (anti-fraud, minimal technical logs)
- Legal, tax and regulatory obligations
GDPR Legal basis
- Legitimate interest (contact, security)
- Consent (newsletter)
- Contract performance (SaaS service)
- Legal obligation (legal/tax management)
4. Data recipients
4.1 Internal recipients
Data accessible only by authorized SecureOps personnel.
4.2 Subcontractors
Currently, SecureOps uses:
- AWS (cloud infrastructure, hosting and identity management via Cognito)
- Cloudflare (DDoS protection, WAF and CDN)
- Cloudflare Turnstile (anti-bot protection for the contact form)
Each subcontractor is bound by a GDPR-compliant contract guaranteeing an adequate level of security.
5. Data retention periods
- Contact form: 12 months after the last exchange
- Newsletter: until unsubscription, immediate deletion after unsubscription
- User account (profile, email, preferences): account lifetime + 12 months after deletion
- Scan data (results, history, scores, scheduled configurations): account lifetime + 12 months after deletion
- API keys: deleted immediately upon revocation or account deletion
- Non-IP technical logs: 0 to 24 hours, no archiving
6. Data security
We implement technical and organizational measures, including:
- Hosting exclusively in EU AWS regions (eu-west / eu-central)
- Communication encryption (HTTPS/TLS 1.2+)
- DDoS protection and WAF via Cloudflare
- Strict limitation of internal access
- Password hashing (bcrypt) — plaintext passwords are never stored
- API key hashing (sk_...) — raw values are never retained
- Identity management via AWS Cognito (email/password authentication, MFA)
- Minimal technical logging (no IP address retention)
- Enhanced authentication available (MFA via app or SMS)
7. Your GDPR rights
You have the following rights:
- Right of access: obtain a copy of your personal data
- Right of rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to restriction: limit the processing of your data
- Right to portability: receive your data in a usable format
- Right to object: object to the processing of your data
To exercise your rights: contact form — Subject: GDPR Request. Complaint possible with the CNIL.
8. Cookies
Currently: no tracking, statistics, advertising or profiling cookies. Only technical cookies may be used for service operation (authentication, session).
Future cookies(audience measurement, personalization, advertising): a CNIL-compliant cookie banner will be deployed before activation.
9. Transfer outside the European Union
All your data is hosted exclusively in EU AWS regions (e.g. eu-west-1, eu-central-1). No data is hosted outside the European Union.
AWS is a US-incorporated company potentially subject to the CLOUD Act. Accordingly, data transfers to AWS are governed by:
- Standard Contractual Clauses (SCC) approved by the European Commission
- AWS Data Processing Agreement (DPA)
- Additional protection measures: encryption in transit (TLS) and at rest, strict access control
10. Policy modifications
SecureOps may modify this policy to account for:
- regulatory changes
- new service features
- addition of subcontractors
- technical developments
In case of major changes, users will be informed.
11. Contact
For any question or request regarding your data, go to the contact form and select GDPR Request as the subject.