Privacy policy
This policy explains how Cybershen collects, uses, stores and otherwise processes personal data in connection with the website and the services.
Last updated: September 2026
Who we are
The website cybershen.com and the cybersecurity solutions, software, agents, platforms and related services provided under the Cybershen brand are operated by Cybershen, a société par actions simplifiée with share capital of €20,000, registered with the Nanterre Trade and Companies Register under number 912 704 905, with its registered office at 5 rue Robert Lavergne, 92600 Asnières-sur-Seine, France.
Depending on the circumstances, Cybershen acts either as controller, where it determines why and how personal data is processed, or as processor, where it processes personal data on behalf of a customer or partner and on their documented instructions.
We may update this policy to reflect changes in applicable law, our services or our practices. The version published on the website at the time of use applies.
Definitions
Personal data: any information relating to an identified or identifiable natural person.
Processing: any operation performed on personal data, including collection, storage, use, disclosure, restriction and deletion.
Controller: the person or entity that determines the purposes and means of processing.
Processor: the person or entity that processes personal data on behalf of a controller.
Client: an organisation using the services directly or through an authorised Cybershen partner.
User: an individual authorised by a client to access or use the services.
1. Where Cybershen is the controller
Cybershen is the controller for personal data relating to visitors to the website, prospects, customers, partners, account administrators and others with whom it has a direct relationship.
Contact and information requests
We may process your first and last name, company, professional email address, telephone number, organisation size and anything included in your message.
Purpose: answering enquiries, demo requests and other requests. Legal basis: our legitimate interest in answering requests and developing business relationships, or steps taken at your request before entering into a contract. Retention: for the time needed to handle the request and, where appropriate, up to three years after the last interaction.
Marketing and service announcements
We may process your name, professional email address, company and communication preferences.
Purpose: newsletters, product announcements, event and launch information. Legal basis: consent where the law requires it, otherwise our legitimate interest for existing professional relationships. Retention: until consent is withdrawn, an objection is made, or the retention period following the last meaningful interaction expires. You may unsubscribe at any time.
Users and account administration
We may process your name, professional email address, organisation, user and account identifiers, authentication information, IP address, login and access information, role and permissions, and security logs.
Purpose: creating and administering accounts, authenticating users, controlling access, maintaining security and preventing unauthorised access. Legal basis: performance of a contract, steps before a contract, and our legitimate interest in securing the services. Retention: for the duration of the account or contract, then for the period needed to satisfy legal, security and evidentiary requirements.
Customers, partners, billing and support
We may process your name, professional contact details, company and job title, billing and contractual information, correspondence and support requests.
Purpose: managing contracts, subscriptions, billing, support and partner relationships. Legal basis: performance of a contract, legal obligations, and our legitimate interest in managing business relationships. Retention: for the duration of the relationship, then for the periods required by accounting, tax and commercial law or applicable limitation periods.
Website security, logs and fraud prevention
We may process your IP address, device and browser information, access timestamps, technical logs, security events and online identifiers.
Purpose: keeping the website and services secure, available and working, troubleshooting, and preventing fraud or misuse. Legal basis: our legitimate interest in protecting our systems, services, users and customers. Retention: according to our security and log-retention schedules.
Where the data comes from
directly from you
from your employer or organisation
from an authorised Cybershen partner or reseller
through your use of the website or the services
from publicly available professional sources, where the law permits
Who receives it
Authorised Cybershen personnel access personal data where their duties require it.
We may also disclose personal data to service providers acting on our behalf, including hosting, infrastructure, communications, customer relationship management, support, billing and electronic signature providers. Access is limited to what the purpose requires, and providers are bound by confidentiality, security and data-protection obligations.
We may disclose personal data where required by law, regulation, a court order or a competent authority.
Transfers outside the European Economic Area
Where personal data is transferred outside the European Economic Area, we put in place a transfer mechanism required by applicable data-protection law, such as an adequacy decision, the European Commission's standard contractual clauses, or another recognised safeguard.
Your rights
Subject to the conditions and limits set by applicable law, you may ask for access to your personal data, its rectification or its erasure, ask us to restrict processing, object to processing based on legitimate interests on grounds relating to your situation, object to direct marketing at any time, ask for portability where it applies, and withdraw consent at any time where processing is based on consent. Withdrawing consent does not affect processing carried out before.
Write to [email protected]. We may ask for information reasonably needed to confirm your identity before we answer.
You may also lodge a complaint with the competent supervisory authority. In France that is the Commission nationale de l'informatique et des libertés, the CNIL.
Automated decision-making
Our services use automated technologies, including security rules, correlation and functionality assisted by artificial intelligence, to identify vulnerabilities, security events, risks and recommended remediation.
Unless expressly stated otherwise for a particular service, Cybershen does not take decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them, within the meaning of article 22 of the GDPR.
Children
Cybershen provides professional cybersecurity services to organisations. The services are not directed to children, and we do not knowingly offer them to children or collect their personal data through the services.
2. Where Cybershen is the processor
When a client uses the services to monitor, assess, protect or manage its information systems, devices, users or cloud services, Cybershen may process personal data on that client's behalf. The client is then generally the controller and Cybershen the processor. What is processed depends on the services and the features the client enables.
What is processed
Depending on the services subscribed to and configured by the client, we may process information relating to employees, contractors, administrators, users, customers or other people whose accounts, devices or activity form part of the client's authorised security perimeter.
names and professional email addresses
usernames and account identifiers
IP addresses and network identifiers
device identifiers and characteristics
operating system and software information
device security configuration and posture
vulnerability and patch information
authentication and access events
security events, alerts and logs
network and connection metadata
domain, address or web-security information where web protection is enabled
Microsoft 365, Google Workspace or other supported cloud service configuration and security information
information about externally exposed assets, domains and services
governance, security assessment and remediation information
other technical security data submitted to or generated by the services
What it is used for
Depending on the features the client configures, processing may serve to assess cybersecurity posture, detect vulnerabilities and configuration weaknesses, monitor and protect endpoints and workstations, identify and reduce external attack surfaces, detect potentially malicious activity, secure web access and network connections, analyse the security configuration of supported cloud and collaboration platforms, generate alerts, reports, scores and remediation recommendations, support governance, compliance and evidence requirements, authenticate and authorise access to protected resources, support investigations and incident response, and provide and maintain the services.
Cybershen does not determine the client's own purposes. The client is responsible for configuring and using the services in compliance with applicable law.
Artificial intelligence and automated analysis
Some services use automated analysis or functionality assisted by artificial intelligence to correlate security information, identify risks, prioritise findings, generate recommendations or assist users.
Where personal data is processed through these functions while Cybershen acts as processor, that processing is carried out on the client's behalf and for the purpose of providing the service.
How long
Cybershen processes personal data on the client's behalf for the duration of the services, and afterwards only for the period needed to return, delete or secure the data under the applicable contract, the client's documented instructions and legal obligations. Specific technical logs or backups may be kept for limited additional periods where security, integrity, disaster recovery or compliance require it.
Our obligations as processor
process personal data only on the client's documented instructions, unless applicable law requires otherwise
ensure that authorised persons are bound by appropriate confidentiality obligations
implement appropriate technical and organisational security measures
assist the client, given the nature of the processing, in answering requests from data subjects where reasonably possible
assist the client with security, breach, impact assessment and regulatory consultation obligations
make available the information reasonably needed to demonstrate compliance
delete or return personal data at the end of the services, as the contract and the law require
Sub-processors
Cybershen may engage third-party providers to process personal data on a client's behalf where the services require it, including infrastructure, hosting and communications providers. We require them to give data-protection and security commitments appropriate to the processing and consistent with our own obligations.
Where the law or the contract requires it, we inform clients of additions or changes to relevant sub-processors and give an opportunity to object under the applicable agreement.
What the client is responsible for
having an appropriate legal basis for the processing carried out through the services
using and configuring the services in compliance with applicable law
giving the required privacy information to data subjects
obtaining any required consents
issuing lawful, documented instructions to Cybershen
answering data subject requests
deciding retention periods and security settings for its own processing
Requests from individuals
Where Cybershen acts as processor, requests should be addressed to the client, which is the controller. If we receive such a request directly, we forward it to the client where appropriate, or tell the individual to address the controller. We assist the client in answering, as the law and the agreement require.
Personal data breaches
If Cybershen becomes aware of a breach affecting personal data processed on a client's behalf, we notify the client without undue delay, as the law and our contractual commitments require, and provide the information reasonably available to us so the client can assess the incident and meet its own notification obligations. The client decides whether a supervisory authority or the individuals concerned must be notified, unless the law provides otherwise.
Records, documentation and audits
Cybershen keeps records of the categories of processing carried out on behalf of clients where article 30 of the GDPR or other applicable law requires it.
We make available the information reasonably needed to demonstrate compliance with our obligations as processor and support audits to the extent the law and the agreement require. Audit arrangements may be subject to reasonable conditions that protect the security, confidentiality, availability and integrity of our systems and those of other clients.
End of processing
When the services end, Cybershen deletes or returns the personal data processed on the client's behalf, as the agreement and the client's instructions provide, unless the law requires it to be kept. Where immediate deletion from backups or segregated systems is not reasonably possible, we continue to protect that data and prevent further processing except as needed for deletion, restoration, security or legal compliance.
3. Security
Cybershen applies technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
confidentiality obligations for employees and contractors
security and data-protection awareness and training
identity and access management
strong authentication
least privilege and role-based access
secure configuration of workstations and infrastructure
protection of data in transit and, where appropriate, at rest
logging and security monitoring
vulnerability management and security updates
backup and recovery
physical and environmental protection of the relevant infrastructure
security incident management
periodic review and improvement of controls
No system is perfect
No information system can be guaranteed completely secure. We therefore review and improve our controls regularly, according to the nature of the services, the risks and developments in cybersecurity practice. More detail may be set out in the applicable contract, the data processing agreement, our security documentation or the Trust Center.
4. Changes to this policy
We may change this policy to reflect changes in our services, our processing, the law or our practices. Where appropriate, material changes are announced on the website, in the services or through another suitable channel.
5. Contact
For any question about this policy, our processing of personal data or the exercise of your rights, write to the Data Protection Officer at [email protected].
Cybershen, 5 rue Robert Lavergne, 92600 Asnières-sur-Seine, France.