Personal data protection
Read the French version
Version 2.7 — updated 3 September 2026
1. Who is responsible for this processing
Secufor, a simplified joint-stock company registered with the Nanterre Trade and Companies Register under number 931 143 572, with its registered office at 69 rue Louise Michel, 92300 Levallois-Perret, France.
For any question about your data, or to exercise your rights : dpo[at]secufor.net. We answer at that address ; there is no need to go through the contact form.
2. What we collect, and why
The table below is exhaustive for the website. It does not describe what we might do one day, but what the site does today. The Noviscan application is a different object and has its own section: see section 9, which carries its own exhaustiveness.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Username, email address, password — the latter kept as a hash, never in clear text | Creating and managing your account, identifying you | Performance of the contract | For as long as your account exists |
| Password-reset token and its expiry date | Letting you regain access to your account | Performance of the contract | One hour, after which the token stops working |
| Hash of your session token, creation and last-use dates, your browser’s user agent | Keeping you signed in and spotting abnormal use | Legitimate interest (account security) | Thirty days at most, then deleted automatically. A revoked token (sign-out) is kept for a further seven days for incident investigation, then deleted. |
| Sign-in attempts on your account : a salted hash of the IP address (never the address itself), your account identifier where it is known, the kind of event (successful sign-in, failed sign-in, sign-out) and a timestamp | Spotting an attack on your account and telling it apart from a random sweep of addresses, and showing you the date of your last sign-in | Legitimate interest (account security) | Six months from the event, then deleted automatically |
| Plan subscribed to, and licence key, encrypted in the database | Delivering the product you bought and verifying your licence | Performance of the contract | For the duration of the subscription |
| Proof that you accepted the T&Cs : version accepted, timestamp, and any waiver of the right of withdrawal | Establishing what you agreed to, and when | Legitimate interest (evidence) and legal obligation | Five years from the order |
| Proof that the contractual emails were sent : recipient address, type of message, date sent and its outcome | Establishing that the messages promised by the T&Cs were sent to you | Performance of the contract and legal obligation | Five years from the date sent |
| Proof that the contact-form messages were sent : case number, type of message, date sent and its outcome. Your email address does not appear in it : the case number designates it without keeping it | Establishing that your message reached us and that the acknowledgement was sent to you | Legitimate interest (evidence), and performance of our terms of use (art. 17-18) | Five years from the date sent |
| References for your subscription with our payment provider : session, customer and subscription identifiers, the plan subscribed to, the subscription status and the end date of the current period | Linking your account to your subscription, delivering your licence, ending it on cancellation, and retrieving your invoices from our provider | Performance of the contract, and legal obligation as regards accounting records (art. L123-22 of the French Commercial Code) | Ten years — the retention period for the accounting records these references give access to |
| Billing activity log : your account identifier, the kind of action (adding, designating or removing a payment method, creating or cancelling a subscription, a payment, a failed charge, a refund, opening the billing portal), an opaque reference to the subscription, invoice or refund concerned, the amount and currency of the action, and a timestamp. Not your name, not your email address, and no card reference whatsoever | Spotting fraud or a malfunction of our service : an irreversible action that leaves no trace can neither be explained nor disputed | Legitimate interest (fraud prevention and sound operation of the service) | Six months from the action, then deleted automatically |
| Message sent through the contact form : first name, surname, email address and message body | Replying to you | Steps taken at your request (art. 6(1)(b)) | The message reaches us by email and is not stored in the database. It is kept in our mailbox for five years from receipt (art. 2224 of the French Civil Code : the period during which a dispute may arise from your request). |
| Message sent through the Client Area support form (Premium subscribers) : message body, together with your account identifier, username, email address and subscribed plan | Handling your support request and replying to you | Performance of the contract (art. 6(1)(b)) | The message reaches us by email and is not stored in the database. It is kept in our mailbox for five years from receipt (art. 2224 of the French Civil Code : the period during which a dispute may arise from your request). |
| Withdrawal notice sent from the Client Area : email address, subscribed plan, the licence concerned and, if you write one, your message | Handling your withdrawal (refund within fourteen days), then being able to prove it was exercised — this record survives account deletion, because it also evidences what we owe you | Legal obligation (right of withdrawal, art. L221-18 et seq. of the French Consumer Code) and legitimate interest (evidence) | Five years from the notice (art. 2224 of the French Civil Code) |
| Hashes of your IP address and of the email address you entered, at the time of submission — neither is kept in the clear | Preventing bulk automated submissions, which would get our email flagged as spam, and preventing the acknowledgement from being used to flood a third party’s address | Legitimate interest (service security, and protection of third parties) | 48 hours |
| A copy of your request, sent to the email address you entered and carrying a case number — it repeats neither your message nor your name | Leaving you a record of your request and a number to quote. This copy contains no text you typed: were someone to enter your address without your knowledge, they could not use it to write to you | Steps taken at your request (art. 6(1)(b) GDPR) | Not retained: the email is sent, the database keeps nothing of it |
| Server technical logs, including the IP address | Security and fault diagnosis | Legitimate interest | As per our host’s policy, twelve months at most |
What we never receive : your card number, its expiry date and its security code. Your invoices themselves are held by our provider, not by us : we keep only the references needed to retrieve them and — in our billing activity log, for six months — the amount of the action itself. Payment takes place on the pages of our provider Stripe, and those details do not pass through our servers. All we receive is confirmation that a payment has been made.
Periodic signal from the extensions — allowed by the contract, no data received to date
Article 5.3.5 of the terms of use allows an Application to transmit periodically the identifier of the licensed site, the version installed and its activation status, for the sole purposes of verifying the licence and monitoring proper operation.
No Application does so today, and the table above therefore remains exhaustive. We mention it here because a contractual authorisation is not a collection, and the latter must not be discovered after the fact : on the day an Application emits this signal, its description page will say so and the table above will be completed BEFORE it goes live — retention period and legal basis included. The signal will remain disableable without any loss of functionality.
3. What we do not do
It seems just as useful to state what does not happen :
- No advertising, no targeting, no retargeting. We pass nothing to ad networks or advertising platforms.
- No profiling, and no automated decision producing effects concerning you.
- No decision taken by a machine. When you write to us for support, an automated process may prepare a draft reply from your message and send you an acknowledgement. No decision concerning you — refusal, refund, termination — is taken by that means, and any reply that rules on your request is reviewed by a person before it is sent. You are interacting with an artificial-intelligence system when you write to our support.
- No analytics : no Google Analytics, nor any equivalent. See our cookie policy.
- No newsletter, no promotional message. The only automated email we can send you is the one that lets you reset your password, and you are the one who triggers it. If you write to us, we reply — that goes without saying, and it stops there.
- No sale, no rental, no exchange of your data.
- No collection by the plugins. WPOAuth and WPSQL run on your server and send us nothing, apart from the verification of your licence key — which contains no data about your own users.
4. Who else has access
Three providers, each for one precise task :
- Stripe — collecting payments. Stripe gathers payment details directly from you, on its own pages.
- OVHcloud — hosting the site and the database, and delivering the password-reset email. The servers are located in the European Union.
- A professional artificial-intelligence provider — analysing support requests in order to prepare a reply. No data has been sent to it to date : this processing is planned and has not yet begun. On the day it does, that provider will never receive your name, your email address or your account identifier : it will receive only an extract of your request from which those elements have been removed beforehand. The name of this provider is given to you on request, as part of exercising your rights (§6), and it appears in the documentation supplied to our professional and public-sector customers.
Apart from these three providers, your data is disclosed to no one — save for a request from a judicial or administrative authority empowered to make it, with which we are bound to comply.
5. Where your data is
The data we hold is hosted in the European Union. Stripe, whose group is established in the United States, may process data outside the Union ; such transfers rely on the safeguards provided for in Chapter V of the GDPR and are described in its own privacy policy.
6. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as the right to give directions as to what becomes of your data after your death.
To exercise them, write to dpo[at]secufor.net. We reply within one month. If your request is complex, that period may be extended by two months ; we will tell you so within the first month.
Deleting your account : requested from your Client Area, your licences remain fully functional, on their own terms, while your account stays reactivable : for ten days. If you do not reactivate it within that period, your current subscriptions are cancelled, your valid licences are revoked, and your account, with the personal data it holds, is permanently deleted at the end of those ten days. Some data must nevertheless be kept beyond that point because the law requires it : accounting records (ten years) and proof of your acceptance of the T&Cs (five years). It is then set apart and used for that purpose alone.
If our answer does not satisfy you, you may lodge a complaint with the French data protection authority, the Commission nationale de l’informatique et des libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr. If you reside in another Member State, you may also contact your own supervisory authority.
7. How your data is protected
- The site and the API are served over HTTPS only.
- Passwords are kept as a hash, never in clear text. They cannot be recovered — not even by us.
- Licence keys are encrypted in the database.
- Session tokens are likewise never stored in clear text : the database holds only a hash, so a database leak would not allow anyone to sign in as you.
- Downloading the product is restricted to accounts holding the corresponding subscription.†
† This wording will be strengthened — “requires genuine authentication; knowing an account identifier is not enough” — once session-token verification is deployed, which is under way. We would rather promise less than we are about to deliver than the reverse.
If you find a vulnerability, our reporting procedure is set out on the Security page.
8. Cookies
This site sets no advertising, analytics or social-network cookies. The details are in our cookie policy.
9. The Noviscan application
This section covers the Noviscan mobile application. Sections 1 to 8 above describe the website and the customer account; they do not describe the application, and the application cannot be read into them.
What the publisher receives
Nothing. The data produced by using the application lives on your instance and on your phone. Secufor receives no copy of it and has no means of accessing it.
What lives on your instance
The Noviscan instance is installed and administered by its operator. It holds: face templates — biometric data —, the detection history, the presence log, accounts, sessions and device tokens, the connection log, the audit log, Premium video clips and outgoing notifications. Each has its own retention period, set by the operator of the instance.
What lives on your phone
- a local copy of the media you view, written to the operating system’s cache. ⚠️ It is stored there unencrypted, with no lifetime and no setting in the application: it is purged as the system purges its caches. We write this down rather than leave it unsaid;
- in the phone’s secure store (Keystore on Android, Keychain on iOS): your instance’s address, its identifier and its name, the pairing token, the pinned certificate fingerprint and the certification root. Unpairing erases these;
- your application preferences — language, theme, biometric lock, roaming — which remain after unpairing, like any other setting.
What leaves the phone, and when
On your local network, the application talks directly to your instance. When roaming, the connection is brokered by a relay: the application sends it your instance identifier and the signalling messages needed to establish the link, which carry network addresses (yours and your instance’s). The relay does not see the content exchanged: that content stays encrypted between the application and the instance, and passes through the relay as-is.
What the application does not do
These absences are established by reading the code, not by silence:
- no push notifications, and therefore no APNs or FCM token;
- no telemetry and no crash reporting to any third party;
- no face template on the phone: biometric unlocking is performed by the operating system, and nothing it uses reaches the application;
- no account creation from the application.
This section states technical facts established against the code of the application on 18 August 2026: declared dependencies, Android manifest, writes to the cache and to the secure store — and, as regards the secure store and unpairing, re-established on 29 August 2026, the day the application stopped keeping the instance’s address list after unpairing. The corresponding legal characterisations — who is the controller for data held by an instance, and on what legal basis — are under review by counsel and will be published once settled. We prefer to publish what is established rather than wait to publish everything at once.