1. Data controller
The data controller is Perspective Analytics SAS, 2 rue du Général de Gaulle, 44290 Guémené-Penfao, France. For privacy inquiries, contact .
Data Protection Officer. Perspective Analytics SAS has not appointed a Data Protection Officer, as none of the criteria of Article 37 GDPR are met. All data protection inquiries, including requests under Articles 15 to 22 GDPR, are handled by the privacy contact above.
2. Data we collect
Account data
When you register, we collect your company name, contact name, email address, and password (hashed with Argon2id). Before activating a paid Plan, we also collect a SIRET number, VAT number, or equivalent professional identifier for invoicing. If you enable MFA, we store a TOTP secret encrypted with AES-256-GCM.
Certificate and infrastructure data
We store TLS certificate metadata discovered through public enumeration, local infra scanning, or manual upload. This includes: subject names, issuer details, validity dates, key types, TLS protocol versions, and cipher suites. We do not store private keys.
Usage data
We collect platform activity logs including login events, configuration changes, and alert deliveries. These logs are retained for 12 months on every plan.
Signup handoff data
When you enter a domain on nocert.io, the standard browser launcher carries it to the nocert application in a URL fragment, which is handled by the application and is not sent as part of the HTTP request URL. The no-script fallback opens generic signup without transferring the domain. After the application loads, it validates the domain in a bounded, same-origin JSON request used for handoff reporting. The daily acquisition-counter table records only a global handoff count, without a visitor, device, session, account, organisation, IP-address, or user-agent identifier. A short-lived, in-memory per-IP rate limit separately protects the unauthenticated reporting endpoint from abuse. When nocert's separately controlled domain-alert feature is enabled, the canonical domain may also be sent to nocert's private operations channel hosted by Discord as an unverified, user-supplied handoff, unless your browser sends the Global Privacy Control signal. The domain is not stored in the daily acquisition-counter table. This feature defaults to disabled and will not be enabled until the advance-notice period in Section 11 has elapsed and the message-deletion control described below is operational.
3. Legal basis for processing
- Contract performance (Art. 6(1)(b) GDPR): processing necessary to deliver the Service.
- Legitimate interest (Art. 6(1)(f) GDPR): security monitoring, fraud prevention, product improvement, and limited internal awareness of requested signup handoffs.
- Pre-contractual steps (Art. 6(1)(b) GDPR): opening the signup flow requested after a domain is submitted.
- Legal obligation (Art. 6(1)(c) GDPR): tax and accounting requirements.
4. Data sharing
We share Customer Personal Data with the following categories of processors. The complete, versioned list under the Data Processing Agreement is available at /legal/dpa/subprocessors.
- Hosting: OVHcloud SAS (France), for nocert-hosted infrastructure in France and Germany.
- Edge delivery: Cloudflare, Inc. / Cloudflare Ireland Limited, for CDN, WAF, and DDoS protection. Cloudflare processes requests and limited technical metadata but is not used as the application-data system of record.
- Payment: Stripe Payments Europe Ltd. (Ireland) and Stripe, Inc. (USA), for payment processing.
- E-invoicing: Tiime SAS (France), certified French Plateforme Agréée for electronic invoicing under Article 289 bis CGI.
- Business email: Google LLC / Google Ireland Limited (Google Workspace), for inbound and outbound business correspondence, including support communications.
- Cloud infrastructure and transactional email: Amazon Web Services EMEA SARL / Amazon Web Services, Inc. (Amazon EC2, Amazon EKS, and Amazon SES in EU regions), for supporting compute and managed Kubernetes workloads, outbound alerts, notifications, and operational emails.
Separately, when nocert acts as controller for account and pre-contractual acquisition operations, limited data may be disclosed to Discord Netherlands B.V. / Discord Inc. (EEA/USA) as a controller-side recipient and service provider for private operational messaging. Messages may contain account-contact and organisation details; subscription, billing, quota, and other controller-side service-operation signals; global identifier-free acquisition volumes; or, only when the separately controlled feature is enabled, the submitted handoff domain. A handoff notification itself contains no email address, cookie, session identifier, IP address, or user-agent value from that request. Generic service-operation alerts exclude Customer Data such as monitored domains, certificate details, Sentinel hostnames or labels, and customer infrastructure metadata. Discord is not represented as a sub-processor processing Customer Personal Data under the DPA and therefore does not appear in the linked sub-processor register.
We do not sell personal data. We do not use personal data for advertising or profiling. We do not use personal data to train, fine-tune, or evaluate artificial intelligence or machine-learning models.
5. International transfers
For nocert-hosted deployments, application data is stored and processed primarily within the European Union, on OVHcloud infrastructure in France and Germany. For self-hosted deployments, the Customer determines the primary hosting location. Certain sub-processors (Stripe, Cloudflare, Google Workspace, and Amazon Web Services) are established outside the EEA or may process limited data outside the EEA. For such transfers, we rely on the EU Standard Contractual Clauses 2021/914 (Module 2 or Module 3 as applicable), the UK Addendum where relevant, and the EU-US Data Privacy Framework certification of the sub-processor where applicable, supported by a Transfer Impact Assessment we maintain on file. Details per sub-processor are available at /legal/dpa/subprocessors.
Discord may process limited controller-side operational-message data in the United States. For that separate disclosure, applicable safeguards include Discord's EU-US Data Privacy Framework participation and Standard Contractual Clauses as described in its privacy policy.
6. Data retention
- Account data and Customer Data upon termination: upon termination of a nocert-hosted subscription, your account enters a 60-day read-only period during which you can retrieve core inventory information and request a portable copy of Customer Data under Section 16 of the Terms of Service. Customer Data in nocert-controlled production systems is deleted at the end of that read-only period, and a reminder email is sent 7 days beforehand. Backups controlled by nocert are purged within 30 days from that deletion. For self-hosted deployments, the Customer is responsible for data held solely in Customer-controlled infrastructure; copies under nocert's control follow the same timeline.
- Trial and Free Plan accounts: an account not converted to a paid Plan continues on the Free Plan under Section 4 of the Terms of Service: monitoring continues within the Free Plan allowances and no data is deleted on a schedule. Deletion occurs on the account holder’s request or upon termination, following the regime in Section 16 of the Terms (deletion from production, then from backups within 30 days).
- Certificate data: retained while the associated monitoring target is active; deleted upon target removal or on termination under the regime above.
- Audit logs: audit logs in nocert-controlled systems are retained for 12 months, on every plan, then deleted. Retention of logs held solely in self-hosted infrastructure is controlled by the Customer.
- Billing records: retained for 10 years per French accounting law (Article L123-22 Code de commerce); tax supporting documents retained 6 years per Article L102 B Livre des procédures fiscales.
- Aggregate acquisition counters: daily global counts are retained for up to 13 months and then deleted automatically. They contain no submitted domain or visitor identifier.
nocert does not keep a database copy of a submitted handoff domain. When such a handoff alert is sent, nocert stores only the Discord message identifier, the non-secret webhook identifier needed to target deletion, and lifecycle metadata. It schedules the visible message for deletion no later than 30 days after delivery. No webhook token or domain is stored in that lifecycle table. Access to that channel is restricted to nocert operators. Discord may retain residual backup copies under its own documented retention practices after the visible message is deleted.
7. Your rights
Under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Request erasure (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing (Art. 21)
No automated decision-making. We do not carry out automated individual decision-making, including profiling, within the meaning of Article 22 GDPR. The compliance scores and alerts produced by the Service are informational and do not produce legal or similarly significant effects on you within the meaning of that article.
To exercise these rights, contact . We will respond within one month of receipt of the request, in accordance with Article 12(3) GDPR. You also have the right to lodge a complaint with the CNIL ( www.cnil.fr ).
Post-mortem directives (French residents). Under Article 85 of the French Loi Informatique et Libertés, you may issue instructions on the fate of your personal data after your death. You can transmit these instructions to us directly at or register them with a trusted digital third party certified by CNIL.
8. Security measures
- AES-256-GCM encryption for sensitive fields at the application layer
- TLS 1.2 minimum for customer-facing web/API and Sentinel API connections; TLS 1.3 preferred where supported
- Argon2id password hashing
- Role-based access control with session-based authentication
- Agent communication secured via RFC 9421 HTTP signatures
- Cloudflare WAF and DDoS mitigation at the edge
Personal data breach notification. In the event of a personal data breach affecting personal data for which we act as controller (in particular account, billing, and audit-log data), we will notify the CNIL within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will additionally notify you without undue delay, in accordance with Article 34 GDPR. For personal data processed on behalf of a customer (in which case we act as processor), notification follows the path defined in Section 7 of our Data Processing Agreement (notification to the customer within 48 hours; the customer, as controller, then handles any onward notification to the supervisory authority and data subjects).
9. Cookies
The nocert.io platform uses strictly necessary cookies for authentication (session cookies). These cookies are HttpOnly, Secure, and SameSite=Strict. We do not use tracking cookies, analytics cookies, or third-party advertising cookies.
The signup-handoff counter is server-side and aggregate-only. It does not set or read a cookie, local-storage value, session-storage value, or visitor identifier. When Global Privacy Control is enabled, the aggregate count is still recorded but the domain is not sent to the Discord operations channel.
The platform is fronted by Cloudflare for edge delivery and bot protection. Cloudflare may set strictly necessary technical cookies, in particular __cf_bm (bot-management cookie, lifespan up to 30 minutes) and, when a security challenge is presented,
cf_clearance (challenge-result cookie). These cookies are used solely to distinguish legitimate visitors from bots and to record the result of a security challenge. They are exempt from prior consent under CNIL guidance because they are strictly necessary to provide a service expressly requested by the user.
10. Anonymised aggregates and threat intelligence
We may derive anonymised and aggregated statistics from Customer Data collected through the Service (for example: distributions of cipher suites, TLS protocol adoption rates, post-quantum readiness across sectors, certificate authority market share). Before any such use, we run and document a re-identification risk assessment following the CNIL and former Article 29 Working Party methodology (singling-out, linkability, inference).
Where the resulting data still constitutes personal data after anonymisation, we act as an independent data controller for that processing, separately from our role as processor under the Data Processing Agreement.
- Purposes: product improvement; publication of sectoral threat-intelligence insights and TLS ecosystem research.
- Legal basis: legitimate interest (Article 6(1)(f) GDPR), namely the legitimate interest of nocert and of the security community in understanding the TLS ecosystem and improving the Service.
- Recipients: nocert internal teams; readers of any published threat-intelligence report.
- Retention: aggregated statistics may be retained indefinitely as they no longer identify individuals.
- Right to object: you may object to this processing at any time by contacting , in accordance with Article 21 GDPR.
We do not use personal data, whether raw or aggregated, to train, fine-tune, or evaluate artificial intelligence or machine-learning models.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.