Article One
Privacy Policy
RapidCyberSafe (“the Bureau,” “we,” “us”) is committed to safeguarding personal data processed in the course of delivering cybersecurity consultation, monitoring, incident response, and related professional services. This Privacy Policy explains what information we collect, why we collect it, how long we retain it, and the rights available to individuals under applicable European Union data-protection law, including Regulation (EU) 2016/679 (GDPR).
1.1 Controller. The data controller for personal data collected through our website, inquiry forms, service engagements, and client communications is RapidCyberSafe, 51 Route des Rives, 74200 Anthy-sur-Léman, France. Privacy inquiries may be directed to [email protected].
1.2 Categories of data. We may process identification and contact data (name, business email, telephone number, organization, job title), engagement data (inquiry content, service interests, contract and invoice records), technical data (IP address, browser type, device identifiers, pages viewed, referring URLs), and security telemetry generated when monitoring or responding to incidents on behalf of clients.
1.3 Purposes and legal bases. We process personal data to respond to inquiries and enter into contracts (Art. 6(1)(b) GDPR), to perform professional security services and maintain service quality (Art. 6(1)(b) and 6(1)(c) GDPR as applicable), to secure our website and systems (legitimate interests, Art. 6(1)(f) GDPR), to meet legal, accounting, and regulatory obligations (Art. 6(1)(c) GDPR), and, where required, with consent for optional cookies or marketing communications (Art. 6(1)(a) GDPR).
1.4 Recipients. Personal data may be shared with processors who support hosting, email, payment settlement, and secure collaboration, each bound by appropriate contractual safeguards. We do not sell personal data. Where data is transferred outside the European Economic Area, we rely on standard contractual clauses or other valid transfer mechanisms.
1.5 Retention. Inquiry records are retained for up to twenty-four (24) months unless a contract is signed, in which case client records follow contractual and statutory retention periods. Security monitoring logs are retained according to the engagement’s agreed schedule and our internal security policy. Cookie consent choices persist for the durations described in Section III.
1.6 Rights. Subject to legal limits, data subjects may request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. Consent-based processing may be withdrawn at any time without affecting prior lawful processing. Requests may be sent to [email protected]. You also have the right to lodge a complaint with a supervisory authority, including the French data protection authority (CNIL).
1.7 Security. We implement technical and organizational measures appropriate to the risk, including access controls, encryption in transit, logging, and confidentiality obligations for personnel and contractors handling client and inquiry data.