Skip to content

This policy explains how Cybershen collects, uses, stores and otherwise processes personal data in connection with the website and the services.

Last updated: September 2026

Who we are

The website cybershen.com and the cybersecurity solutions, software, agents, platforms and related services provided under the Cybershen brand are operated by Cybershen, a société par actions simplifiée with share capital of €20,000, registered with the Nanterre Trade and Companies Register under number 912 704 905, with its registered office at 5 rue Robert Lavergne, 92600 Asnières-sur-Seine, France.

Depending on the circumstances, Cybershen acts either as controller, where it determines why and how personal data is processed, or as processor, where it processes personal data on behalf of a customer or partner and on their documented instructions.

We may update this policy to reflect changes in applicable law, our services or our practices. The version published on the website at the time of use applies.

Definitions

  • Personal data: any information relating to an identified or identifiable natural person.

  • Processing: any operation performed on personal data, including collection, storage, use, disclosure, restriction and deletion.

  • Controller: the person or entity that determines the purposes and means of processing.

  • Processor: the person or entity that processes personal data on behalf of a controller.

  • Client: an organisation using the services directly or through an authorised Cybershen partner.

  • User: an individual authorised by a client to access or use the services.

1. Where Cybershen is the controller

Cybershen is the controller for personal data relating to visitors to the website, prospects, customers, partners, account administrators and others with whom it has a direct relationship.

Contact and information requests

We may process your first and last name, company, professional email address, telephone number, organisation size and anything included in your message.

Purpose: answering enquiries, demo requests and other requests. Legal basis: our legitimate interest in answering requests and developing business relationships, or steps taken at your request before entering into a contract. Retention: for the time needed to handle the request and, where appropriate, up to three years after the last interaction.

Marketing and service announcements

We may process your name, professional email address, company and communication preferences.

Purpose: newsletters, product announcements, event and launch information. Legal basis: consent where the law requires it, otherwise our legitimate interest for existing professional relationships. Retention: until consent is withdrawn, an objection is made, or the retention period following the last meaningful interaction expires. You may unsubscribe at any time.

Users and account administration

We may process your name, professional email address, organisation, user and account identifiers, authentication information, IP address, login and access information, role and permissions, and security logs.

Purpose: creating and administering accounts, authenticating users, controlling access, maintaining security and preventing unauthorised access. Legal basis: performance of a contract, steps before a contract, and our legitimate interest in securing the services. Retention: for the duration of the account or contract, then for the period needed to satisfy legal, security and evidentiary requirements.

Customers, partners, billing and support

We may process your name, professional contact details, company and job title, billing and contractual information, correspondence and support requests.

Purpose: managing contracts, subscriptions, billing, support and partner relationships. Legal basis: performance of a contract, legal obligations, and our legitimate interest in managing business relationships. Retention: for the duration of the relationship, then for the periods required by accounting, tax and commercial law or applicable limitation periods.

Website security, logs and fraud prevention

We may process your IP address, device and browser information, access timestamps, technical logs, security events and online identifiers.

Purpose: keeping the website and services secure, available and working, troubleshooting, and preventing fraud or misuse. Legal basis: our legitimate interest in protecting our systems, services, users and customers. Retention: according to our security and log-retention schedules.

Cookies and similar technologies

This website sets one cookie. It is named NEXT_LOCALE and it remembers the language you chose. It is strictly necessary to deliver the site in the language you asked for, so it does not require consent.

We use no advertising cookies and no cross-site tracking. Our audience measurement is Plausible, self-hosted by Cybershen, which sets no cookie and builds no profile of a visitor.

Because the site sets no non-essential cookie, there is no consent banner to accept or refuse. If that ever changes, the site will ask before setting one.

Where the data comes from

  • directly from you

  • from your employer or organisation

  • from an authorised Cybershen partner or reseller

  • through your use of the website or the services

  • from publicly available professional sources, where the law permits

Who receives it

Authorised Cybershen personnel access personal data where their duties require it.

We may also disclose personal data to service providers acting on our behalf, including hosting, infrastructure, communications, customer relationship management, support, billing and electronic signature providers. Access is limited to what the purpose requires, and providers are bound by confidentiality, security and data-protection obligations.

We may disclose personal data where required by law, regulation, a court order or a competent authority.

Transfers outside the European Economic Area

Where personal data is transferred outside the European Economic Area, we put in place a transfer mechanism required by applicable data-protection law, such as an adequacy decision, the European Commission's standard contractual clauses, or another recognised safeguard.

Your rights

Subject to the conditions and limits set by applicable law, you may ask for access to your personal data, its rectification or its erasure, ask us to restrict processing, object to processing based on legitimate interests on grounds relating to your situation, object to direct marketing at any time, ask for portability where it applies, and withdraw consent at any time where processing is based on consent. Withdrawing consent does not affect processing carried out before.

Write to [email protected]. We may ask for information reasonably needed to confirm your identity before we answer.

You may also lodge a complaint with the competent supervisory authority. In France that is the Commission nationale de l'informatique et des libertés, the CNIL.

Automated decision-making

Our services use automated technologies, including security rules, correlation and functionality assisted by artificial intelligence, to identify vulnerabilities, security events, risks and recommended remediation.

Unless expressly stated otherwise for a particular service, Cybershen does not take decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them, within the meaning of article 22 of the GDPR.

Children

Cybershen provides professional cybersecurity services to organisations. The services are not directed to children, and we do not knowingly offer them to children or collect their personal data through the services.

2. Where Cybershen is the processor

When a client uses the services to monitor, assess, protect or manage its information systems, devices, users or cloud services, Cybershen may process personal data on that client's behalf. The client is then generally the controller and Cybershen the processor. What is processed depends on the services and the features the client enables.

What is processed

Depending on the services subscribed to and configured by the client, we may process information relating to employees, contractors, administrators, users, customers or other people whose accounts, devices or activity form part of the client's authorised security perimeter.

  • names and professional email addresses

  • usernames and account identifiers

  • IP addresses and network identifiers

  • device identifiers and characteristics

  • operating system and software information

  • device security configuration and posture

  • vulnerability and patch information

  • authentication and access events

  • security events, alerts and logs

  • network and connection metadata

  • domain, address or web-security information where web protection is enabled

  • Microsoft 365, Google Workspace or other supported cloud service configuration and security information

  • information about externally exposed assets, domains and services

  • governance, security assessment and remediation information

  • other technical security data submitted to or generated by the services

What it is used for

Depending on the features the client configures, processing may serve to assess cybersecurity posture, detect vulnerabilities and configuration weaknesses, monitor and protect endpoints and workstations, identify and reduce external attack surfaces, detect potentially malicious activity, secure web access and network connections, analyse the security configuration of supported cloud and collaboration platforms, generate alerts, reports, scores and remediation recommendations, support governance, compliance and evidence requirements, authenticate and authorise access to protected resources, support investigations and incident response, and provide and maintain the services.

Cybershen does not determine the client's own purposes. The client is responsible for configuring and using the services in compliance with applicable law.

Artificial intelligence and automated analysis

Some services use automated analysis or functionality assisted by artificial intelligence to correlate security information, identify risks, prioritise findings, generate recommendations or assist users.

Where personal data is processed through these functions while Cybershen acts as processor, that processing is carried out on the client's behalf and for the purpose of providing the service.

How long

Cybershen processes personal data on the client's behalf for the duration of the services, and afterwards only for the period needed to return, delete or secure the data under the applicable contract, the client's documented instructions and legal obligations. Specific technical logs or backups may be kept for limited additional periods where security, integrity, disaster recovery or compliance require it.

Our obligations as processor

  • process personal data only on the client's documented instructions, unless applicable law requires otherwise

  • ensure that authorised persons are bound by appropriate confidentiality obligations

  • implement appropriate technical and organisational security measures

  • assist the client, given the nature of the processing, in answering requests from data subjects where reasonably possible

  • assist the client with security, breach, impact assessment and regulatory consultation obligations

  • make available the information reasonably needed to demonstrate compliance

  • delete or return personal data at the end of the services, as the contract and the law require

Sub-processors

Cybershen may engage third-party providers to process personal data on a client's behalf where the services require it, including infrastructure, hosting and communications providers. We require them to give data-protection and security commitments appropriate to the processing and consistent with our own obligations.

Where the law or the contract requires it, we inform clients of additions or changes to relevant sub-processors and give an opportunity to object under the applicable agreement.

What the client is responsible for

  • having an appropriate legal basis for the processing carried out through the services

  • using and configuring the services in compliance with applicable law

  • giving the required privacy information to data subjects

  • obtaining any required consents

  • issuing lawful, documented instructions to Cybershen

  • answering data subject requests

  • deciding retention periods and security settings for its own processing

Requests from individuals

Where Cybershen acts as processor, requests should be addressed to the client, which is the controller. If we receive such a request directly, we forward it to the client where appropriate, or tell the individual to address the controller. We assist the client in answering, as the law and the agreement require.

Personal data breaches

If Cybershen becomes aware of a breach affecting personal data processed on a client's behalf, we notify the client without undue delay, as the law and our contractual commitments require, and provide the information reasonably available to us so the client can assess the incident and meet its own notification obligations. The client decides whether a supervisory authority or the individuals concerned must be notified, unless the law provides otherwise.

Records, documentation and audits

Cybershen keeps records of the categories of processing carried out on behalf of clients where article 30 of the GDPR or other applicable law requires it.

We make available the information reasonably needed to demonstrate compliance with our obligations as processor and support audits to the extent the law and the agreement require. Audit arrangements may be subject to reasonable conditions that protect the security, confidentiality, availability and integrity of our systems and those of other clients.

End of processing

When the services end, Cybershen deletes or returns the personal data processed on the client's behalf, as the agreement and the client's instructions provide, unless the law requires it to be kept. Where immediate deletion from backups or segregated systems is not reasonably possible, we continue to protect that data and prevent further processing except as needed for deletion, restoration, security or legal compliance.

3. Security

Cybershen applies technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

  • confidentiality obligations for employees and contractors

  • security and data-protection awareness and training

  • identity and access management

  • strong authentication

  • least privilege and role-based access

  • secure configuration of workstations and infrastructure

  • protection of data in transit and, where appropriate, at rest

  • logging and security monitoring

  • vulnerability management and security updates

  • backup and recovery

  • physical and environmental protection of the relevant infrastructure

  • security incident management

  • periodic review and improvement of controls

No system is perfect

No information system can be guaranteed completely secure. We therefore review and improve our controls regularly, according to the nature of the services, the risks and developments in cybersecurity practice. More detail may be set out in the applicable contract, the data processing agreement, our security documentation or the Trust Center.

4. Changes to this policy

We may change this policy to reflect changes in our services, our processing, the law or our practices. Where appropriate, material changes are announced on the website, in the services or through another suitable channel.

5. Contact

For any question about this policy, our processing of personal data or the exercise of your rights, write to the Data Protection Officer at [email protected].

Cybershen, 5 rue Robert Lavergne, 92600 Asnières-sur-Seine, France.

One score. One policy.
One trusted system.

Start with your Cyber Score. In two weeks you know where you stand and what to fix first.