Aller au contenu principal
ScanRGPD
ARGUS ENGINE v2.8
PricingBlogFAQScan my website →
FREN

Privacy Policy

Pursuant to Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 and to the French Data Protection Act as amended (loi Informatique et Libertés).

Last updated: 25 May 2026 · Version 1.1 · Version française

Our commitmentScanRGPD.fr provides a GDPR audit service. It would be incoherent for us not to be beyond reproach ourselves. This policy sets out concretely what we do with your data, without empty formulas or forgotten placeholders.

1. Identity of the controller

The controller of your personal data is the publisher of the ScanRGPD.fr site (sole trader, SIRET 103 442 430 00015). Full details appear in our legal notices.

  • Email: contact@scanrgpd.fr
  • GDPR contact point: contact@scanrgpd.fr (subject: “GDPR request”)
  • Postal address: as stated in the legal notices

2. Personal data collected

Only the data strictly necessary to provide the service is collected. No data is collected without your knowledge.

2.1. Data collected when ordering an audit

CategorySpecific dataSource
IdentificationSurname, first name, company name, SIRETForm you complete
ContactBusiness email, telephone (optional)Form
ActivitySector, number of employees, tools used, processorsBusiness context form
WebsiteURL of the audited site, technical data scanned (cookies, headers, forms detected)You plus the automated scan
PaymentBilling email, bank card data (processed by Stripe, never visible to ScanRGPD.fr)Stripe

2.2. Data collected on a simple visit to the site (and on the free scan)

CategoryDataWhen
IP addressStored for 72 hours for security (anti-abuse of the free scan)On every visit
Technical dataBrowser type, operating system, page viewed (server logs)On every visit
URL scanned for freeThe URL you enter in the free pre-diagnosticIf you use it (not persisted in any database)
Audience statisticsVercel Web Analytics and Umami Analytics (self-hosted in Germany on Vercel plus Neon Postgres Frankfurt), anonymised, aggregated, with no cookie whatsoever in the browser and no persistent identifier. You may object to all measurement by manually adding the disable-analytics=1 cookie on scanrgpd.fr.On every visit

What is never collected: no advertising cookie, no tracking pixel, no behavioural analytics tool (no Google Analytics, no Meta Pixel, no Hotjar, no session recording).

3. Purposes and legal bases of processing

Your data is processed for the following purposes, each resting on a specific legal basis:

PurposeLegal basis (Art. 6 GDPR)
Carry out the GDPR audit ordered and deliver the documentsPerformance of the contract (Art. 6(1)(b))
Issue invoices and keep accounting recordsLegal obligation (Art. 6(1)(c)). French Commercial Code, 10 years
Respond to your requests by emailLegitimate interest (Art. 6(1)(f)), communicating with you
Detect abuse of the free scan (anti-spam, anti-DDoS)Legitimate interest (Art. 6(1)(f)), security of the service
Improve service quality (anonymised analysis of audits)Legitimate interest (Art. 6(1)(f)), with data anonymised beforehand
Marketing to existing clients (possible upsell)Legitimate interest (Art. 6(1)(f)), right to object at any time

What is never done: no use of your data for marketing to third parties, no sale of your data, no sharing for advertising purposes.

4. Retention periods

Type of dataRetention period
Client data (account, audit, generated documents)12 months after delivery of the last audit, then archived in an intermediate database for 3 years for evidential purposes, then permanently deleted
Invoices and accounting data10 years (legal obligation, French Commercial Code)
Server logs, IP address72 hours for anonymous visits, 12 months for client accounts
URL scanned for free (without account creation)Not persisted in any database, deleted immediately after the scan
Prospect data (if you write to us without becoming a client)3 years after the last contact
Technical cookies13 months maximum

5. Recipients of your data, processors

Your data is accessible only to the publisher of the site and to the technical processors strictly necessary for the service to operate. All of these processors have signed a data processing agreement (DPA) compliant with Article 28 GDPR.

ProcessorRoleData locationDPA
Vercel Inc.Website hosting (frontend)Frankfurt, Germany (EU)✓ Signed
Supabase Inc.Database and storage of auditsParis, France (eu-west-3)✓ Signed
Anthropic PBCAutomatic report generation (Claude AI), primary providerUnited States (DPF certified), data not used for training✓ Signed (Zero Data Retention)
Mistral AIReport generation, fallback processor, activated only if access to the primary provider is unavailable (reversibility, see Terms of Sale Art. 12.2)European Union (France)✓ Mistral processing terms (EU)
Stripe Payments Europe LtdPayment processingIreland (EU), with US activity for fraud (DPF certified)✓ Signed
ResendSending transactional emailsUSA (DPF certified)✓ Signed
Neon, Inc.PostgreSQL database hosting Umami Analytics (self-hosted). Stores only anonymised audience statistics (page views, referrers, UTM events). No client data, no cookie, no persistent identifier.Frankfurt, Germany (AWS eu-central-1)Terms available at neon.tech/dpa
Upstash, Inc.Distributed Redis counter for anti-abuse rate limiting (limiting the number of requests per IP address on the free pre-diagnostic, checkout and account creation). No audit data and no client identity passes through it, only the source IP address associated with a numeric counter.AWS eu-west-1 servers (Ireland, EU) · retention: 1 hour maximum (Redis TTL applied to each counter key).Processor terms available at upstash.com/trust
Regarding Anthropic's AI (Claude)The integration with the Claude API is configured in “Zero Data Retention” mode. Anthropic retains no data sent beyond the time strictly necessary to process the request (a few seconds). Your information is never used to train AI models.

Fallback plan (reversibility): in order to guarantee continuity of service should Anthropic become unavailable (outage, regulatory suspension, export controls), generation may automatically switch to a European sovereign model (Mistral AI, France). In that case, the data remains processed within the European Union, with no transfer outside the EU.

6. Transfers outside the European Union

Some processors (Anthropic, Stripe for the fraud component, Resend) are headquartered in the United States. These transfers are governed by:

  • The EU-US Data Privacy Framework (DPF), adopted by adequacy decision of the European Commission on 10 July 2023
  • Standard Contractual Clauses (SCCs) of the European Commission, signed with each processor
  • Supplementary technical measures: TLS 1.3 encryption in transit, AES-256 at rest, minimal retention configurations

7. Security of your data

Appropriate technical and organisational measures are implemented to protect your data:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Strong authentication on all administrator accounts (2FA)
  • Access to data strictly limited to persons with a justified need
  • Encrypted and redundant backups (Paris, France)
  • Automatic security updates
  • Deliverable download links: signed URLs with short expiry (24 hours)
  • Breach notification procedure within 72 hours (Art. 33 GDPR)

8. Your rights

In accordance with Articles 15 to 22 GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15). Obtain confirmation that your data is processed and obtain a copy of it
  • Right to rectification (Art. 16). Correct inaccurate or incomplete data
  • Right to erasure (Art. 17). Request deletion of your data (“right to be forgotten”), subject to legal obligations (in particular invoices retained for 10 years)
  • Right to restriction of processing (Art. 18). Temporarily freeze processing in certain cases
  • Right to data portability (Art. 20). Receive your data in a structured, machine-readable format
  • Right to object (Art. 21). Object to processing based on legitimate interest (in particular marketing)
  • Right to give post-mortem instructions (Article 85 of the French Data Protection Act)
  • Right to withdraw your consent at any time, where processing is based on consent

How to exercise your rights

To exercise these rights:

  • Email: contact@scanrgpd.fr (subject: “GDPR request”)
  • Post: 25 chemin des Cornets, 69700 Givors, France (marked “GDPR request”)

Response within 72 hours for simple requests, and within a maximum of one month for complex requests (extendable by a further two months where necessary, in accordance with Article 12(3) GDPR).

For security reasons, verification of your identity may be requested (only in case of doubt, in accordance with Article 12(6) GDPR).

9. Complaint to the CNIL

If, after contacting us, you consider that your rights are not being respected, you have the right to lodge a complaint with the CNIL, the French data protection authority (Commission Nationale de l'Informatique et des Libertés):

  • Website: www.cnil.fr/fr/plaintes
  • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Telephone: +33 1 53 73 22 22

If you are resident in another EU or EEA country, you may also lodge a complaint with your own national supervisory authority.

10. Cookies and trackers

The use of cookies on this site is detailed on our dedicated cookie management page.

In short: only technical cookies strictly necessary for the site to function (session, security) are used. No third-party cookie, no advertising cookie and no behavioural analytics cookie is placed. No consent is therefore required for these cookies (Art. 82 of the French Data Protection Act, exemption for strictly necessary cookies).

11. Minors

The service is aimed exclusively at businesses and professionals. No data relating to minors is knowingly collected. If you are a minor, please do not use this service without the agreement of a legal representative.

12. Amendments to this policy

This policy may be amended to reflect changes in the service or in the regulations. The date of the last update is shown at the top of this document. In the event of a substantial change, clients will be informed by email.

13. Contact

For any question concerning this policy:

  • Email: contact@scanrgpd.fr

14. Language

This policy is published in French and in English so that data subjects receive the information in a language they understand, as required by Article 12(1) GDPR.

The processing described is identical in both versions. Where a difference of interpretation arises in a contractual context, the French version prevails, without this depriving any data subject of the information provided to them in English.

© 2026 ScanRGPD.fr · SIRET 103 442 430 00015 · Legal notices · Privacy policy · Terms of sale · Cookies