Privacy Policy
Pursuant to Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 and to the French Data Protection Act as amended (loi Informatique et Libertés).
Last updated: 25 May 2026 · Version 1.1 · Version française
1. Identity of the controller
The controller of your personal data is the publisher of the ScanRGPD.fr site (sole trader, SIRET 103 442 430 00015). Full details appear in our legal notices.
- Email: contact@scanrgpd.fr
- GDPR contact point: contact@scanrgpd.fr (subject: “GDPR request”)
- Postal address: as stated in the legal notices
2. Personal data collected
Only the data strictly necessary to provide the service is collected. No data is collected without your knowledge.
2.1. Data collected when ordering an audit
| Category | Specific data | Source |
|---|---|---|
| Identification | Surname, first name, company name, SIRET | Form you complete |
| Contact | Business email, telephone (optional) | Form |
| Activity | Sector, number of employees, tools used, processors | Business context form |
| Website | URL of the audited site, technical data scanned (cookies, headers, forms detected) | You plus the automated scan |
| Payment | Billing email, bank card data (processed by Stripe, never visible to ScanRGPD.fr) | Stripe |
2.2. Data collected on a simple visit to the site (and on the free scan)
| Category | Data | When |
|---|---|---|
| IP address | Stored for 72 hours for security (anti-abuse of the free scan) | On every visit |
| Technical data | Browser type, operating system, page viewed (server logs) | On every visit |
| URL scanned for free | The URL you enter in the free pre-diagnostic | If you use it (not persisted in any database) |
| Audience statistics | Vercel Web Analytics and Umami Analytics (self-hosted in Germany on Vercel plus Neon Postgres Frankfurt), anonymised, aggregated, with no cookie whatsoever in the browser and no persistent identifier. You may object to all measurement by manually adding the disable-analytics=1 cookie on scanrgpd.fr. | On every visit |
What is never collected: no advertising cookie, no tracking pixel, no behavioural analytics tool (no Google Analytics, no Meta Pixel, no Hotjar, no session recording).
3. Purposes and legal bases of processing
Your data is processed for the following purposes, each resting on a specific legal basis:
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Carry out the GDPR audit ordered and deliver the documents | Performance of the contract (Art. 6(1)(b)) |
| Issue invoices and keep accounting records | Legal obligation (Art. 6(1)(c)). French Commercial Code, 10 years |
| Respond to your requests by email | Legitimate interest (Art. 6(1)(f)), communicating with you |
| Detect abuse of the free scan (anti-spam, anti-DDoS) | Legitimate interest (Art. 6(1)(f)), security of the service |
| Improve service quality (anonymised analysis of audits) | Legitimate interest (Art. 6(1)(f)), with data anonymised beforehand |
| Marketing to existing clients (possible upsell) | Legitimate interest (Art. 6(1)(f)), right to object at any time |
What is never done: no use of your data for marketing to third parties, no sale of your data, no sharing for advertising purposes.
4. Retention periods
| Type of data | Retention period |
|---|---|
| Client data (account, audit, generated documents) | 12 months after delivery of the last audit, then archived in an intermediate database for 3 years for evidential purposes, then permanently deleted |
| Invoices and accounting data | 10 years (legal obligation, French Commercial Code) |
| Server logs, IP address | 72 hours for anonymous visits, 12 months for client accounts |
| URL scanned for free (without account creation) | Not persisted in any database, deleted immediately after the scan |
| Prospect data (if you write to us without becoming a client) | 3 years after the last contact |
| Technical cookies | 13 months maximum |
5. Recipients of your data, processors
Your data is accessible only to the publisher of the site and to the technical processors strictly necessary for the service to operate. All of these processors have signed a data processing agreement (DPA) compliant with Article 28 GDPR.
| Processor | Role | Data location | DPA |
|---|---|---|---|
| Vercel Inc. | Website hosting (frontend) | Frankfurt, Germany (EU) | ✓ Signed |
| Supabase Inc. | Database and storage of audits | Paris, France (eu-west-3) | ✓ Signed |
| Anthropic PBC | Automatic report generation (Claude AI), primary provider | United States (DPF certified), data not used for training | ✓ Signed (Zero Data Retention) |
| Mistral AI | Report generation, fallback processor, activated only if access to the primary provider is unavailable (reversibility, see Terms of Sale Art. 12.2) | European Union (France) | ✓ Mistral processing terms (EU) |
| Stripe Payments Europe Ltd | Payment processing | Ireland (EU), with US activity for fraud (DPF certified) | ✓ Signed |
| Resend | Sending transactional emails | USA (DPF certified) | ✓ Signed |
| Neon, Inc. | PostgreSQL database hosting Umami Analytics (self-hosted). Stores only anonymised audience statistics (page views, referrers, UTM events). No client data, no cookie, no persistent identifier. | Frankfurt, Germany (AWS eu-central-1) | Terms available at neon.tech/dpa |
| Upstash, Inc. | Distributed Redis counter for anti-abuse rate limiting (limiting the number of requests per IP address on the free pre-diagnostic, checkout and account creation). No audit data and no client identity passes through it, only the source IP address associated with a numeric counter. | AWS eu-west-1 servers (Ireland, EU) · retention: 1 hour maximum (Redis TTL applied to each counter key). | Processor terms available at upstash.com/trust |
Fallback plan (reversibility): in order to guarantee continuity of service should Anthropic become unavailable (outage, regulatory suspension, export controls), generation may automatically switch to a European sovereign model (Mistral AI, France). In that case, the data remains processed within the European Union, with no transfer outside the EU.
6. Transfers outside the European Union
Some processors (Anthropic, Stripe for the fraud component, Resend) are headquartered in the United States. These transfers are governed by:
- The EU-US Data Privacy Framework (DPF), adopted by adequacy decision of the European Commission on 10 July 2023
- Standard Contractual Clauses (SCCs) of the European Commission, signed with each processor
- Supplementary technical measures: TLS 1.3 encryption in transit, AES-256 at rest, minimal retention configurations
7. Security of your data
Appropriate technical and organisational measures are implemented to protect your data:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Strong authentication on all administrator accounts (2FA)
- Access to data strictly limited to persons with a justified need
- Encrypted and redundant backups (Paris, France)
- Automatic security updates
- Deliverable download links: signed URLs with short expiry (24 hours)
- Breach notification procedure within 72 hours (Art. 33 GDPR)
8. Your rights
In accordance with Articles 15 to 22 GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15). Obtain confirmation that your data is processed and obtain a copy of it
- Right to rectification (Art. 16). Correct inaccurate or incomplete data
- Right to erasure (Art. 17). Request deletion of your data (“right to be forgotten”), subject to legal obligations (in particular invoices retained for 10 years)
- Right to restriction of processing (Art. 18). Temporarily freeze processing in certain cases
- Right to data portability (Art. 20). Receive your data in a structured, machine-readable format
- Right to object (Art. 21). Object to processing based on legitimate interest (in particular marketing)
- Right to give post-mortem instructions (Article 85 of the French Data Protection Act)
- Right to withdraw your consent at any time, where processing is based on consent
How to exercise your rights
To exercise these rights:
- Email: contact@scanrgpd.fr (subject: “GDPR request”)
- Post: 25 chemin des Cornets, 69700 Givors, France (marked “GDPR request”)
Response within 72 hours for simple requests, and within a maximum of one month for complex requests (extendable by a further two months where necessary, in accordance with Article 12(3) GDPR).
For security reasons, verification of your identity may be requested (only in case of doubt, in accordance with Article 12(6) GDPR).
9. Complaint to the CNIL
If, after contacting us, you consider that your rights are not being respected, you have the right to lodge a complaint with the CNIL, the French data protection authority (Commission Nationale de l'Informatique et des Libertés):
- Website: www.cnil.fr/fr/plaintes
- Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
- Telephone: +33 1 53 73 22 22
If you are resident in another EU or EEA country, you may also lodge a complaint with your own national supervisory authority.
10. Cookies and trackers
The use of cookies on this site is detailed on our dedicated cookie management page.
In short: only technical cookies strictly necessary for the site to function (session, security) are used. No third-party cookie, no advertising cookie and no behavioural analytics cookie is placed. No consent is therefore required for these cookies (Art. 82 of the French Data Protection Act, exemption for strictly necessary cookies).
11. Minors
The service is aimed exclusively at businesses and professionals. No data relating to minors is knowingly collected. If you are a minor, please do not use this service without the agreement of a legal representative.
12. Amendments to this policy
This policy may be amended to reflect changes in the service or in the regulations. The date of the last update is shown at the top of this document. In the event of a substantial change, clients will be informed by email.
13. Contact
For any question concerning this policy:
- Email: contact@scanrgpd.fr
14. Language
This policy is published in French and in English so that data subjects receive the information in a language they understand, as required by Article 12(1) GDPR.
The processing described is identical in both versions. Where a difference of interpretation arises in a contractual context, the French version prevails, without this depriving any data subject of the information provided to them in English.