Friday, 2 October 2026 | 46.2994° N · 6.5414° E |
Security Dispatch · Vol. XII |

Section IV · Legal Registry · Official Notice

Statutory Notices & Operating Terms

Published by RapidCyberSafe, 51 Route des Rives, 74200 Anthy-sur-Léman, France. Correspondence: [email protected]. Last revised: 2 October 2026.

I

Article One

Privacy Policy

RapidCyberSafe (“the Bureau,” “we,” “us”) is committed to safeguarding personal data processed in the course of delivering cybersecurity consultation, monitoring, incident response, and related professional services. This Privacy Policy explains what information we collect, why we collect it, how long we retain it, and the rights available to individuals under applicable European Union data-protection law, including Regulation (EU) 2016/679 (GDPR).

1.1 Controller. The data controller for personal data collected through our website, inquiry forms, service engagements, and client communications is RapidCyberSafe, 51 Route des Rives, 74200 Anthy-sur-Léman, France. Privacy inquiries may be directed to [email protected].

1.2 Categories of data. We may process identification and contact data (name, business email, telephone number, organization, job title), engagement data (inquiry content, service interests, contract and invoice records), technical data (IP address, browser type, device identifiers, pages viewed, referring URLs), and security telemetry generated when monitoring or responding to incidents on behalf of clients.

1.3 Purposes and legal bases. We process personal data to respond to inquiries and enter into contracts (Art. 6(1)(b) GDPR), to perform professional security services and maintain service quality (Art. 6(1)(b) and 6(1)(c) GDPR as applicable), to secure our website and systems (legitimate interests, Art. 6(1)(f) GDPR), to meet legal, accounting, and regulatory obligations (Art. 6(1)(c) GDPR), and, where required, with consent for optional cookies or marketing communications (Art. 6(1)(a) GDPR).

1.4 Recipients. Personal data may be shared with processors who support hosting, email, payment settlement, and secure collaboration, each bound by appropriate contractual safeguards. We do not sell personal data. Where data is transferred outside the European Economic Area, we rely on standard contractual clauses or other valid transfer mechanisms.

1.5 Retention. Inquiry records are retained for up to twenty-four (24) months unless a contract is signed, in which case client records follow contractual and statutory retention periods. Security monitoring logs are retained according to the engagement’s agreed schedule and our internal security policy. Cookie consent choices persist for the durations described in Section III.

1.6 Rights. Subject to legal limits, data subjects may request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Consent-based processing may be withdrawn at any time without affecting prior lawful processing. Requests may be sent to [email protected]. You also have the right to lodge a complaint with a supervisory authority, including the French data protection authority (CNIL).

1.7 Security. We implement technical and organizational measures appropriate to the risk, including access controls, encryption in transit, logging, and confidentiality obligations for personnel and contractors handling client and inquiry data.

II

Article Two

Terms of Service

These Terms of Service govern access to the RapidCyberSafe website and the engagement of our cybersecurity professional services. By submitting an inquiry, entering a statement of work, or using our website, you agree to these Terms and to any written proposal or contract that references them. Where a signed agreement conflicts with these Terms, the signed agreement prevails.

2.1 Services. RapidCyberSafe provides services that may include threat containment audits, access perimeter design, continuous vulnerability monitoring, incident response retainers, zero-trust architecture blueprints, endpoint hardening, red-team simulations, security awareness briefings, cloud posture reviews, and ransomware containment drills. Scope, deliverables, rates, and turnaround times are confirmed in the applicable engagement document.

2.2 Client responsibilities. Clients shall provide timely access to personnel, systems, documentation, and environments reasonably necessary for service delivery; ensure lawful authority for any system access granted; protect credentials issued under the engagement; and promptly notify RapidCyberSafe of material changes in environment or threat conditions that may affect deliverables.

2.3 Fees and payment. Fees are set out in the proposal or rate ledger applicable to the engagement. Invoices are due within fourteen (14) days unless otherwise stated. Payment may be settled through our secure online payment channel linked from the website. Late payments may accrue statutory interest and may result in suspension of non-critical services until accounts are current.

2.4 Confidentiality. Each party shall protect the other’s non-public information disclosed in connection with an engagement, use it solely for the engagement’s purposes, and not disclose it except to personnel and processors with a need to know who are bound by confidentiality obligations. This duty does not apply to information that is public without breach, independently developed, or required to be disclosed by law.

2.5 Intellectual property. Upon full payment, clients receive the rights to deliverables identified in the engagement as final client materials. RapidCyberSafe retains all rights in its pre-existing tools, templates, methodologies, checklists, and generic frameworks. Nothing in these Terms grants a license to use RapidCyberSafe’s trademarks without prior written consent.

2.6 Limited liability. Except for breaches of confidentiality, infringement, or liability that cannot be limited by law, RapidCyberSafe’s aggregate liability arising out of an engagement shall not exceed the fees paid under that engagement in the twelve (12) months preceding the claim. RapidCyberSafe is not liable for indirect, incidental, special, or consequential damages, or for loss of profit, business interruption, or loss of data, even if advised of the possibility.

2.7 No guarantee of zero risk. Security advisory, monitoring, and simulation services reduce risk; they do not eliminate it. Clients remain responsible for implementing recommended controls and for their own operational decisions. Findings and recommendations are based on information available at the time of assessment.

2.8 Governing law. These Terms and any disputes relating to them are governed by French law, without regard to conflict-of-law principles. The courts of Annecy, France, shall have exclusive jurisdiction, subject to mandatory consumer protections that may apply.

III

Article Three

Cookie Policy

This Cookie Policy describes how RapidCyberSafe uses cookies and similar technologies on rapidcybersafe.com and related inquiry surfaces. It should be read together with our Privacy Policy. “Cookies” includes small text files stored on your device, as well as comparable local storage mechanisms used for session continuity and preference recording.

3.1 Essential cookies. We use essential storage required to operate the site’s security and preference features, including remembering your cookie-consent choice and maintaining basic session integrity. These are strictly necessary to provide the service you request and do not require consent under applicable EU rules.

3.2 Functional preferences. Where you accept optional notices, we may store a preference flag in your browser’s local storage so the consent banner is not re-displayed on every visit. You may clear this through your browser settings at any time, which will re-prompt the banner on your next visit.

3.3 Analytics and embedded content. Embedded map frames and similar third-party content providers may set their own cookies when such content loads. Payment settlement pages are operated by our payment processor and are governed by that processor’s own cookie and privacy notices once you are redirected there.

3.4 Managing cookies. Most browsers allow you to block, delete, or limit cookies through privacy settings. Blocking essential storage may prevent the site from remembering your consent choice or from functioning as intended. For detailed browser guidance, consult your browser provider’s documentation.

3.5 Updates. We may update this Cookie Policy as our practices or legal requirements change. The “last revised” date at the top of this page indicates the current version. Questions regarding cookies and privacy can be sent to [email protected] at RapidCyberSafe, 51 Route des Rives, 74200 Anthy-sur-Léman, France.

IV

Article Four

Refund & Reimbursement Policy

RapidCyberSafe issues professional security deliverables that are scheduled, staffed, and often privileged-access dependent. This Refund & Reimbursement Policy explains when fees may be refunded, when they are non-refundable, and how clients may request a review of billing outcomes. It supplements—not replaces—the signed engagement terms for any specific contract.

4.1 Request channel. Refund and credit requests must be directed to [email protected] from the email associated with the engagement, identifying the invoice number, amount paid, and a concise rationale. Requests are reviewed by our finance desk within ten (10) business days of receipt.

4.2 Deliverable-based fees. Fixed-fee deliverables that have not yet been started—such as scheduled audits, briefings, or simulation exercises—may be cancelled without charge up to five (5) business days before the agreed kickoff date. Cancellations inside five (5) business days may be subject to a partial retention of the fee to cover reserved specialist capacity, typically not exceeding fifty percent (50%) of the engagement fee.

4.3 Retainers and subscriptions. Incident response retainers and continuous vulnerability monitoring subscriptions are billed for the access, monitoring, and reserved capacity they provide. Fees for a completed billing period are non-refundable once monitoring or on-call coverage has been in effect. Where you cancel mid-period, service continues through the end of the paid period unless RapidCyberSafe agrees otherwise in writing.

4.4 Failure to deliver. If RapidCyberSafe is unable to deliver a contracted final deliverable for reasons within our control and not caused by client-side delay, missing access, or material scope change, we will, at our election, re-perform the deliverable within a reasonable time or issue a pro-rata refund for the undelivered portion of the fee.

4.5 Client-caused delay and scope change. Fees remain payable where work is delayed or aborted due to unavailable systems, withdrawn access, late responses, or requested scope expansions. Additional out-of-scope work is quoted before execution and is not subject to automatic refund.

4.6 Payment method. Approved refunds are returned via the original payment method (including the secure payment channel used at checkout) unless another method is agreed in writing. Processing times depend on banks and payment processors and typically require five (5) to fifteen (15) business days after approval.

4.7 Statutory rights. Nothing in this policy limits non-waivable consumer rights under applicable law. Where mandatory legal refund rights apply and cannot be excluded, those rights govern. For questions about billing outcomes, contact RapidCyberSafe at 51 Route des Rives, 74200 Anthy-sur-Léman, France, or [email protected].

Closing notice. If any provision of these legal notices is found unenforceable, the remaining provisions continue in full force. These notices are published in English for the international clients and partners of RapidCyberSafe. A French-language version is available upon request to [email protected].

Registered operator: RapidCyberSafe
Address: 51 Route des Rives, 74200 Anthy-sur-Léman, France
Email: [email protected]
Telephone: +33 62 71 59 341
Document control: Legal Registry · RCS-LEGAL-2026 · Rev. 2026-10-02