Privacy Policy
What personal data Netscope processes, on what legal basis, for how long, who else can see it, and what you can require of us.
Who is responsible
The controller for the data described in this policy is Robin Caboche, publisher of Netscope. Contact: privacy@netscope.fr. Full publisher and host details are on the Legal Notice.
We have not designated a Data Protection Officer, and are not required to: we are not a public authority, and we do not carry out large-scale systematic monitoring of individuals or process special categories of data. privacy@netscope.fr is a contact point that a person reads, not a formal DPO designation.
We wear two hats, and the difference matters. For your account we are the controller: we decide why the data exists. For the network data your agent collects, topology, hosts, scan results, we are a processor: your organisation decides what is scanned and why, and we act on your instructions. The rules for that half are in the Data Processing Agreement, and this policy covers the first half.
What we process, and why we are allowed to
Every purpose below has a legal basis under Article 6 GDPR. Where the basis is legitimate interest, you have an unconditional right to object, see “Your rights”.
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account | Email address, first and last name, password hash, avatar, language and theme | Performance of a contract |
| Confirming your address, resetting a password, changing an email | Hashed one-time tokens and codes, the time the last email was sent | Performance of a contract |
| Two-factor authentication | Encrypted authenticator secret, security-key credential identifiers, hashed recovery codes | Contract, and our obligation to keep the service secure (Art. 32) |
| Keeping you signed in, and showing you your sessions | Session records with the IP address and browser used to sign in | Legitimate interest, account security |
| Blocking brute-force sign-in attempts | Failed attempt counts and lockout times | Legitimate interest, fraud and abuse prevention |
| Signing in with Google, GitHub or Microsoft, if you choose to | The provider, your account identifier there, and your verified email address | Performance of a contract |
| Answering a message you send us | Name, email address, message, and an anti-bot verification result | Legitimate interest, replying to you |
| Sending you product news, if you asked for it | Email address, and the record of when and how you consented | Consent, withdrawable at any time |
| Measuring how the website is used | Page, referrer, country, and a daily signature that is not linked to you | Legitimate interest, understanding what the site is for |
| Keeping the service running and secure | Server and application logs, which include IP addresses | Legitimate interest, network and information security, which Recital 49 names explicitly |
What we do not do
- We do not sell, rent or share your personal data, and we do not disclose it to third parties for their own marketing.
- We make no automated decisions producing legal or similarly significant effects, and we do not profile you.
- We do not track you across other websites, and we run no advertising technology.
- We do not read the contents of your network data to develop our product. Aggregate metadata about how the service is used, how many scans, how long they took, which features were used — is covered by the Data Processing Agreement; the contents are not.
Providing your data
An email address and a password (or a linked sign-in provider) are necessary to create an account: without them there is no account to create. Everything else, your name, avatar, language, theme, is optional and can be left empty or removed.
How long we keep it
| Data | Retention |
|---|---|
| Your account | Until you delete it, or 30 days after closure |
| An account with no sign-in for 24 months | We warn you by email, then delete it |
| Sessions and trusted devices | Until they expire, plus 30 days |
| One-time codes and verification tokens | 15 minutes to 24 hours |
| Network topology and scan results | 12 months by default, or whatever your organisation configures |
| Server and security logs | 6 months |
| Website audience measurement | 25 months at most |
| Messages you send us | 12 months after the exchange ends |
| Newsletter subscription | Until you unsubscribe. We keep the fact that you unsubscribed indefinitely, so that we can honour it. |
| Invoices and accounting records | 10 years, required by French commercial law |
Backups are kept on a rolling basis for disaster recovery. When you delete something it goes from the live service immediately and from backups as those backups rotate out, rather than instantly.
Who else can see it
We use a small number of providers to run the service. Each is bound by a contract that permits them to process your data only for us and only for the purpose named. The current list, kept up to date, is on the Sub-processors page.
| Provider | For | Where | Safeguard |
|---|---|---|---|
| OVHcloud SAS | Infrastructure hosting: application servers, databases, backups | France (EU) | No transfer outside the EEA |
| Resend, Inc. | Transactional and service email delivery | United States | Standard Contractual Clauses |
| Cloudflare, Inc. | Turnstile anti-abuse verification on public forms | United States / global network | Standard Contractual Clauses; EU–US Data Privacy Framework |
| Google, GitHub (Microsoft), Microsoft | Optional single sign-on, only if you choose that sign-in method | United States | Independent controllers, not our sub-processors |
We may also disclose data where the law requires it, a court order or a lawful request from an authority. We do not disclose data to authorities voluntarily.
Transfers outside the European Economic Area
Your account and network data are stored in France, on OVH SAS's infrastructure, and are not transferred outside the EEA. Two providers used for email delivery and anti-bot verification are established in the United States; those transfers are covered by the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards at privacy@netscope.fr.
How we protect it
- Passwords are hashed with bcrypt at cost factor 12 and are never stored or logged in clear.
- Password reset tokens, email verification tokens, API keys and recovery codes are stored only as SHA-256 hashes. The usable value exists only in the email or the one screen that shows it.
- Device descriptions inside your topology are encrypted at rest with AES-256 before they reach the database.
- Sessions use short-lived access tokens with rotating refresh tokens, and a reused refresh token revokes every session for that account.
- Two-factor authentication is available with an authenticator app, a security key (WebAuthn) or an emailed code, with single-use recovery codes.
- Destructive actions, deleting your account, changing your password, removing a second factor — require you to prove who you are again, not just to hold a session.
- Access between organisations is denied by default and covered by an automated test suite that runs on every change.
- All traffic is served over TLS. Data is encrypted in transit at all times.
No system is perfectly secure. If we suffer a breach that is likely to result in a risk to your rights, we notify the Commission Nationale de l’Informatique et des Libertés (CNIL) within 72 hours of becoming aware of it, and we notify you directly where the risk is high.
Your rights
Under the GDPR you can require the following of us. Write to privacy@netscope.fr and we will answer within one month, which we may extend by two further months for a complex request, telling you within the first month if we do. There is no charge.
- Access (Art. 15), a copy of the personal data we hold about you.
- Rectification (Art. 16), correction of data that is wrong or incomplete.
- Erasure (Art. 17), deletion of your account and its data. Some records, such as invoices, we are legally required to keep.
- Restriction (Art. 18), a freeze on processing while a dispute is resolved.
- Portability (Art. 20), your data in a structured, machine-readable format. You can export it yourself from your account settings.
- Objection (Art. 21), to any processing we base on legitimate interest. If you object to direct marketing we stop, with no balancing test and no exceptions.
- Withdrawal of consent, at any time, for anything based on consent. It does not affect what was lawful before you withdrew.
- Complaint, to the Commission Nationale de l’Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, https://www.cnil.fr. You do not have to contact us first, though we would rather you did.
If your data reached us through an organisation using Netscope, your employer, for instance — address your request to them. They decide what is collected; we act on their instructions, and we will pass your request on and assist them with it.
If you are in the United States
We are not currently subject to the CCPA or to comparable US state privacy laws, because we fall well below every applicability threshold. We extend the same rights anyway: access, deletion, correction, portability, and no penalty of any kind for exercising them. Specifically: we do not sell your personal information, and we do not share it for cross-context behavioural advertising. We run no advertising technology at all, so a Global Privacy Control signal from your browser has nothing to disable.
Children
Netscope is a professional tool and is not directed at children. We do not knowingly create accounts for anyone under 16. If you believe a child has an account, tell us at privacy@netscope.fr and we will delete it.
Cookies
Everything we store on your device is either strictly necessary or set at your own request, which is why there is no consent banner on this site. The complete inventory is on the Cookie Policy.
Changes to this policy
The version and effective date of this document are at the top of the page. If we change it in a way that affects your rights or what we do with your data, we will email you at least 30 days before it takes effect, and the previous version stays available on request. Fixing a typo is not that, and we will not email you about one.