1. Data controller
The data controller is Perspective Analytics SAS, 2 rue du General de Gaulle, 44290 Guemene-Penfao, France. For privacy inquiries, contact .
Data Protection Officer. Perspective Analytics SAS has not appointed a Data Protection Officer, as none of the criteria of Article 37 GDPR are met. All data protection inquiries, including requests under Articles 15 to 22 GDPR, are handled by the privacy contact above.
2. Data we collect
Account data
When you register, we collect your company name, contact name, email address, and password (hashed with Argon2id). Before activating a paid Plan, we also collect a SIRET number, VAT number, or equivalent professional identifier for invoicing. If you enable MFA, we store a TOTP secret encrypted with AES-256-GCM.
Certificate and infrastructure data
We store TLS certificate metadata discovered through public enumeration, local infra scanning, or manual upload. This includes: subject names, issuer details, validity dates, key types, TLS protocol versions, and cipher suites. We do not store private keys.
Usage data
We collect platform activity logs including login events, configuration changes, and alert deliveries. These logs are retained for 6 to 12 months depending on your plan.
3. Legal basis for processing
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to deliver the Service.
- Legitimate interest (Art. 6(1)(f) GDPR): security monitoring, fraud prevention, and product improvement.
- Legal obligation (Art. 6(1)(c) GDPR): tax and accounting requirements.
4. Data sharing
We share data with the following categories of processors. The complete, versioned list is available at /legal/dpa/subprocessors.
- Hosting: OVHcloud SAS (France), for nocert-hosted infrastructure in France and Germany.
- Edge delivery: Cloudflare, Inc. / Cloudflare Ireland Limited, for CDN, WAF, and DDoS protection. Cloudflare processes requests and limited technical metadata but is not used as the application-data system of record.
- Payment: Stripe Payments Europe Ltd. (Ireland) and Stripe, Inc. (USA), for payment processing.
- E-invoicing: Tiime SAS (France), certified French Plateforme Agréée for electronic invoicing under Article 289 bis CGI.
- Business email: Google LLC / Google Ireland Limited (Google Workspace), for inbound and outbound business correspondence, including support communications.
- Cloud infrastructure and transactional email: Amazon Web Services EMEA SARL / Amazon Web Services, Inc. (Amazon EC2, Amazon EKS, and Amazon SES in EU regions), for supporting compute and managed Kubernetes workloads, outbound alerts, notifications, and operational emails.
We do not sell personal data. We do not use personal data for advertising or profiling. We do not use personal data to train, fine-tune, or evaluate artificial intelligence or machine-learning models.
5. International transfers
For nocert-hosted deployments, application data is stored and processed primarily within the European Union, on OVHcloud infrastructure in France and Germany. For self-hosted deployments, the Customer determines the primary hosting location. Certain sub-processors (Stripe, Cloudflare, Google Workspace, and Amazon Web Services) are established outside the EEA or may process limited data outside the EEA. For such transfers, we rely on the EU Standard Contractual Clauses 2021/914 (Module 2 or Module 3 as applicable), the UK Addendum where relevant, and the EU-US Data Privacy Framework certification of the sub-processor where applicable, supported by a Transfer Impact Assessment we maintain on file. Details per sub-processor are available at /legal/dpa/subprocessors.
6. Data retention
- Account data and Customer Data upon termination: upon termination of a nocert-hosted subscription, your account enters a 30-day read-only period during which you can retrieve core inventory information and request a portable copy of Customer Data under Section 16 of the Terms of Service. Customer Data in nocert-controlled production systems is purged within 30 days after this read-only period ends. Backups controlled by nocert are purged within 90 days from the effective date of termination. For self-hosted deployments, the Customer is responsible for data held solely in Customer-controlled infrastructure; copies under nocert's control are purged from production within 30 days after termination and from backups within 90 days after termination.
- Trial accounts: trial accounts not converted to a paid Plan follow the regime defined in Section 4 of the Terms of Service (fixed deletion at day D+74, reminder at D+67, backup purge within 90 days from D+74).
- Certificate data: retained while the associated monitoring target is active; deleted upon target removal or on termination under the regime above.
- Audit logs: audit logs in nocert-controlled systems are retained for 6 months (Pro) or 12 months (Business / Custom), then deleted. Retention of logs held solely in self-hosted infrastructure is controlled by the Customer.
- Billing records: retained for 10 years per French accounting law (Article L123-22 Code de commerce); tax supporting documents retained 6 years per Article L102 B Livre des procédures fiscales.
7. Your rights
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Request erasure (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
No automated decision-making. We do not carry out automated individual decision-making, including profiling, within the meaning of Article 22 GDPR. The compliance scores and alerts produced by the Service are informational and do not produce legal or similarly significant effects on you within the meaning of that article.
To exercise these rights, contact . We will respond within one month of receipt of the request, in accordance with Article 12(3) GDPR. You also have the right to lodge a complaint with the CNIL ( www.cnil.fr ).
Post-mortem directives (French residents). Under Article 85 of the French Loi Informatique et Libertés, you may issue instructions on the fate of your personal data after your death. You can transmit these instructions to us directly at or register them with a trusted digital third party certified by CNIL.
8. Security measures
- AES-256-GCM encryption for sensitive fields at the application layer
- TLS 1.2 minimum for customer-facing web/API and Sentinel API connections; TLS 1.3 preferred where supported
- Argon2id password hashing
- Role-based access control with session-based authentication
- Agent communication secured via RFC 9421 HTTP signatures
- Cloudflare WAF and DDoS mitigation at the edge
Personal data breach notification. In the event of a personal data breach affecting personal data for which we act as controller (in particular account, billing, and audit-log data), we will notify the CNIL within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will additionally notify you without undue delay, in accordance with Article 34 GDPR. For personal data processed on behalf of a customer (in which case we act as processor), notification follows the path defined in Section 7 of our Data Processing Agreement (notification to the customer within 48 hours; the customer, as controller, then handles any onward notification to the supervisory authority and data subjects).
9. Cookies
The nocert.io platform uses strictly necessary cookies for authentication (session cookies). These cookies are HttpOnly, Secure, and SameSite=Strict. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
The platform is fronted by Cloudflare for edge delivery and bot
protection. Cloudflare may set strictly necessary technical cookies, in
particular __cf_bm (bot-management cookie, lifespan up to
30 minutes) and, when a security challenge is presented,
cf_clearance (challenge-result cookie). These cookies are
used solely to distinguish legitimate visitors from bots and to record
the result of a security challenge. They are exempt from prior consent
under CNIL guidance because they are strictly necessary to provide a
service expressly requested by the user.
10. Anonymised aggregates and threat intelligence
We may derive anonymised and aggregated statistics from Customer Data collected through the Service (for example: distributions of cipher suites, TLS protocol adoption rates, post-quantum readiness across sectors, certificate authority market share). Before any such use, we run and document a re-identification risk assessment following the CNIL and former Article 29 Working Party methodology (singling-out, linkability, inference).
Where the resulting data still constitutes personal data after anonymisation, we act as an independent data controller for that processing, separately from our role as processor under the Data Processing Agreement.
- Purposes: product improvement; publication of sectoral threat-intelligence insights and TLS ecosystem research.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely the legitimate interest of nocert and of the security community in understanding the TLS ecosystem and improving the Service.
- Recipients: nocert internal teams; readers of any published threat-intelligence report.
- Retention: aggregated statistics may be retained indefinitely as they no longer identify individuals.
- Right to object: you may object to this processing at any time by contacting , in accordance with Article 21 GDPR.
We do not use personal data, whether raw or aggregated, to train, fine-tune, or evaluate artificial intelligence or machine-learning models.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.