Privacy Policy

Last updated: December 2025

Introduction

CyberScore, published by Patrick Astoul (Individual Entrepreneur), is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.

Data Controller

Company name: CyberScore - Patrick Astoul

Legal form: Individual Entrepreneur

SIRET: 84506850100012

Address: 90 avenue de Choisy, 75013 PARIS, France

Email: patrick@cybersco.re

Personal Data Collected

1. Registration Data

  • First and last name
  • Email address
  • Organization name (optional)

2. Billing Data

  • Billing address
  • Payment information (processed by Stripe, not stored by CyberScore)

3. Service Usage Data

  • Scanned domains
  • Security scan results
  • Scan history
  • Generated PDF reports

4. Technical Data

  • IP address
  • Browser type
  • Pages visited
  • Connection timestamps

Processing Purposes

Your data is collected to:

  • Provide CyberScore security scanning services
  • Manage your account and subscription
  • Track usage according to your plan
  • Improve service quality
  • Comply with legal obligations
  • Communicate about service updates

Legal Basis for Processing

  • Contract performance: to provide scanning services
  • Legitimate interest: for service improvement and security
  • Legal obligation: for billing and accounting
  • Consent: for optional features

Retention Period

Account data: Subscription duration + 3 years

Billing data: 10 years (legal obligation)

Scan history: Subscription duration + 1 year

PDF reports: Subscription duration + 1 year

Usage data: Maximum 2 years

Technical data: Maximum 1 year

Your Rights

Under GDPR, you have the following rights:

  • Right of access: view your personal data
  • Right to rectification: correct inaccurate data
  • Right to erasure: delete your data
  • Right to object: oppose data processing
  • Right to portability: retrieve your data in a structured format
  • Right to restriction: limit data processing

To exercise your rights, contact us at: patrick@cybersco.re

Data Security

CyberScore implements the following security measures:

  • HTTPS/TLS encryption: all communications are encrypted in transit
  • Password encryption: passwords are encrypted with bcrypt hashing (one-way, salted)
  • Secure authentication: JWT tokens with expiration
  • Restricted access: only authorized administrators access data
  • Access monitoring: audit logs for sensitive operations
  • Secure backups: daily encrypted backups
  • Data isolation: Docker containerization

Note: Scan results (DNS records, SSL certificates, HTTP headers) are stored unencrypted as they represent publicly available information. Only passwords and authentication tokens are encrypted.

Data Sharing

Your data may be shared with:

  • Stripe: for payment processing (PCI-DSS compliant)
  • Hostinger International Ltd: for hosting (servers in France)
  • Competent authorities: in case of legal obligation

⚠️ Your data is never sold to third parties.

International Data Transfers

Some data may be transferred outside the European Union (notably to the United States for Stripe). These transfers are governed by Standard Contractual Clauses (SCC) approved by the European Commission.

Cookies

CyberScore uses cookies to:

  • Maintain your login session
  • Remember your preferences
  • Analyze site usage

You can disable cookies in your browser settings, but this may affect service functionality.

Minors

CyberScore is not intended for persons under 18 years old. If you are under 18, please do not use this service.

Filing a Complaint (EU Residents)

If you believe your rights are not being respected, you can file a complaint with the CNIL (French Data Protection Authority):

Website: www.cnil.fr

Address: 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07, France

Phone: +33 1 53 73 22 22

California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

1. Right to Know

You can request information about the personal data we collect, use, and share. This information is detailed in the sections above.

2. Right to Delete

You can request deletion of your personal data. Contact us at privacy@cybersco.re to exercise this right.

3. Right to Opt-Out of Sale

✓ We do NOT sell your personal information to third parties.

4. Right to Non-Discrimination

We will not discriminate against you for exercising your CCPA rights. You will receive the same service quality regardless.

To exercise your CCPA rights:

Contact us at privacy@cybersco.re with "CCPA Request" in the subject line.
We will respond within 45 days as required by California law.

Last updated: December 2025

Contact

For any questions regarding this privacy policy, contact us:

Email: patrick@cybersco.re

Mail: CyberScore - Patrick Astoul - 90 avenue de Choisy, 75013 PARIS, France