Data Processing Agreement
Our Article 28 GDPR commitments when we process personal data on your organisation's behalf. Accepted automatically when you create an account — you do not need to negotiate it with us.
Why this exists. When your agent scans your network, what comes back — hostnames, IP addresses, device descriptions — can identify people. For that data your organisation is the controller and we are the processor: you decide what is scanned and why, and we act on your instructions. Article 28 GDPR requires a contract governing that, and this is it. It takes effect when you accept the Terms of Service, so there is nothing to sign.
1. Parties and scope
This agreement is between the customer ("you", the controller) and Robin Caboche, publisher of Netscope ("we", the processor). It applies to all personal data we process on your behalf and forms part of the Terms of Service. Where it conflicts with those terms on data protection, this agreement wins.
2. What we process for you
| Subject matter | Providing network discovery, topology mapping and scan history |
|---|---|
| Duration | For as long as your account exists, plus the deletion period at clause 9 |
| Nature and purpose | Collecting, storing, structuring, displaying and exporting network data at your instruction |
| Categories of data | IP addresses, hostnames, operating system and version details, service and port information, device descriptions you write, network topology and connections, agent identifiers and their host details |
| Categories of data subject | Your personnel, contractors and anyone else whose device is present on the networks you scan |
| Special categories | None. Netscope is not designed for and must not be used to process them. |
3. Our obligations
We will:
- Process only on your documented instructions — your configuration and use of the service are those instructions — including for transfers, unless the law requires otherwise, in which case we tell you first unless that law forbids it;
- tell you if we believe an instruction of yours breaches the GDPR or another data protection law;
- ensure everyone we authorise to process your data is bound by confidentiality;
- implement the security measures at clause 5;
- respect the conditions on sub-processors at clause 4;
- assist you as set out at clauses 6 to 8;
- delete or return your data at the end of the contract, as set out at clause 9;
- make available the information needed to demonstrate compliance with Article 28, and allow the audits at clause 10.
We do not use your network data for our own purposes. Not to develop the product, not to train anything, not to compile statistics about networks. Aggregate service metadata — how many scans an account ran, how long they took, which features were used — is data we process as controller to operate and improve Netscope, and it never includes the contents of what you scanned.
4. Sub-processors
You give us general authorisation to engage sub-processors. The current list is published at netscope.fr/legal/subprocessors.
- We impose on every sub-processor, by contract, data protection obligations no less protective than those in this agreement.
- We remain fully liable to you for a sub-processor's performance of its obligations.
- Before adding or replacing one, we give you at least 30 days' notice by updating that page and emailing account administrators. You may object on reasonable data protection grounds within that period by writing to privacy@netscope.fr. If we cannot resolve your objection, you may terminate without penalty and we will refund any prepaid unused fees.
5. Security
We implement appropriate technical and organisational measures under Article 32, taking account of the state of the art, the cost, and the risk to individuals. In particular:
- encryption in transit (TLS) for all traffic, and encryption at rest for device descriptions;
- passwords hashed with bcrypt at cost 12; API keys, reset tokens and recovery codes stored only as SHA-256 hashes;
- multi-factor authentication available on every account, with authenticator apps, security keys and emailed codes;
- short-lived access tokens with rotating refresh tokens, and automatic revocation of every session for an account when a used token is presented again;
- access control enforced centrally, denying cross-organisation access by default, and covered by an automated test suite that runs on every change;
- re-authentication required for destructive actions rather than a session alone;
- separated environments, least-privilege deployment credentials, automated dependency updates and vulnerability scanning;
- daily backups, taken before every deployment, with a documented restore procedure;
- logging and monitoring of access and security events, retained for six months.
We may update these measures, provided the level of protection does not decrease.
6. Assisting you with data subject requests
The service lets you access, correct, export and delete data yourself, which will usually be enough. Where it is not, we will assist you with appropriate technical and organisational measures. If a data subject contacts us directly about data we hold for you, we will not respond on the substance — we will tell them to contact you, and forward the request to you without undue delay.
7. Breach notification
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and in any case within 48 hours, giving what we know of its nature, the categories and approximate number of records and people affected, the likely consequences, and the measures taken. We will keep you updated as we learn more, and assist you in meeting your own obligations to the supervisory authority and to affected individuals. The duty to notify the authority is yours as controller; ours is to give you what you need to do it in time.
8. Impact assessments
We will provide reasonable assistance with data protection impact assessments and any prior consultation with a supervisory authority, so far as it relates to our processing and to information available only to us.
9. Deletion at the end
When your account is closed, you have 30 days to export your data through the service. After that we delete it from the live service, and it leaves our backups as those backups rotate out on their normal schedule — within six months at the latest. We will confirm deletion in writing on request. Where the law requires us to keep something, we tell you what and why, and we keep only that.
10. Audit
We will make available the information necessary to demonstrate compliance with Article 28, and allow and contribute to audits conducted by you or an auditor you mandate. Audits take place at most once a year unless a supervisory authority requires otherwise or we have suffered a breach affecting your data, on at least 30 days' written notice, during business hours, and without unreasonable disruption. Anything an auditor learns is confidential. We may satisfy an audit request by providing documentation and answering a security questionnaire where that reasonably meets your requirement.
11. International transfers
Your network and account data are stored on OVH SAS's infrastructure in France and are not transferred outside the EEA. Where a sub-processor listed on the sub-processors page is established outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses, incorporated into this agreement by reference, together with any supplementary measures a transfer impact assessment identifies as necessary.
12. Liability and term
The liability provisions of the Terms of Service apply to this agreement. It takes effect when you accept those terms and continues until every piece of data we process for you has been deleted or returned under clause 9.
13. Contact
Questions, objections to a sub-processor, and audit requests: privacy@netscope.fr.