Privacy Policy
At Zyre, the confidentiality and security of your data are our absolute priority. This policy describes how we collect, use and protect your personal information, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
1. Who is the controller?
Zyre acts in two distinct capacities:
- Controller for the data of its own customers and users (account, billing, support). This is the subject of this policy.
- Processor for the technical data of visitors to the websites protected by our customers (IP addresses, user-agents analyzed by our web application firewall). For this processing, our customer remains the controller and the relationship is governed by our Data Processing Agreement (DPA).
2. Data collected
- Identification data: last name, first name, email address, phone (optional), organization name, avatar.
- Google login data (if you use "Continue with Google"): Google ID, email, name, profile picture.
- Billing data: payment history, subscribed plan. Banking data is collected and processed exclusively by Stripe, and we never have access to it.
- Technical data: connection and action logs (audit log), IP address, user-agent, for security and traceability purposes.
- Configuration data: the domains you add to the platform and their technical metadata (detected technology, SSL certificates, uptime).
- Preferences: language, theme, notification preferences, marketing consent.
3. Purposes and legal bases
- Provision of the Service (account, threat detection, reports): performance of the contract (ToS).
- Billing and accounting: performance of the contract and legal obligation. This includes transactional emails relating to the lifecycle of your subscription (renewal, failed payment, notice before suspension of protection, reinstatement). Being necessary to perform the contract, they are not subject to marketing consent and cannot be unsubscribed from for as long as an account exists.
- Platform security (audit log, rate limiting, blocking malicious IPs): legitimate interest (recital 49 of the GDPR).
- Newsletter and marketing communications: your consent, withdrawable at any time from your profile or the unsubscribe link in each email.
- Customer support: performance of the contract.
Each consent (acceptance of the terms, marketing choice) is timestamped and kept as proof, including after account deletion in pseudonymized form (cryptographic hash of the email).
4. Recipients and processors
Your data is accessible only to authorized internal Zyre teams. We never sell your personal data. We use the following processors:
- Host (see legal notice): hosting of the application and database (Switzerland).
- IPinfo — no data is sent to them. Their IP-to-country database is downloaded and queried locally on our servers, so visitor IP addresses never leave our infrastructure. Data licensed under CC BY-SA 4.0: IP geolocation by IPinfo.
- Stripe (United States): payment processing. Transfer governed by the EU-US Data Privacy Framework and standard contractual clauses.
- Brevo (France): sending of transactional emails and the newsletter. Data hosted in the EU.
- Google (United States): only if you choose Google login (OAuth). Transfer governed by the Data Privacy Framework.
- OpenAI (United States): two distinct purposes.
- Vulnerability intelligence — only public cybersecurity news headlines and the names of your sites' technologies are sent. No personal data.
- Conversational support assistant — the content of the messages you write in the chat is transmitted to OpenAI in order to generate the reply. If you enter personal data there (name, email address, domain name), it is transmitted. We attach no account identifier, and Zyre does not retain these conversations. The assistant is offered from your dashboard.
5. Transfers outside the European Union
The application and its database are hosted in Switzerland. Switzerland is a third country covered by an adequacy decision of the European Commission, reviewed and confirmed on 15 January 2024: personal data may be transferred there from the European Union without any additional safeguard being required.
Transfers to Stripe, Google and OpenAI (United States) are governed by the EU-US Data Privacy Framework and/or the European Commission's standard contractual clauses. You can obtain a copy of these safeguards by writing to dpo@zyre.fr.
6. Retention periods
- Account data: as long as the account is active. Accounts inactive for 12 months are deleted automatically (a warning email is sent in the 11th month).
- Threat logs (including the IPs of visitors to protected sites): 7 to 365 days depending on the subscribed plan (Starter: 7 days, Pro: 30 days, Agency: 90 days, Enterprise: 365 days).
- Audit log and security events: 12 months.
- Automatically blocked IPs: 6 months by default, duration configurable by the customer (from 7 days to 1 year). Blocking rules created manually by the customer are kept as long as they maintain them.
- Billing data: 10 years (accounting obligation under French Commercial Code L123-22), in anonymized form after account deletion.
- Proofs of consent: kept in pseudonymized form after account deletion, for defense purposes in case of dispute.
7. Your rights
In accordance with the GDPR, you have a right of access, rectification, erasure, restriction, portability and objection concerning your personal data. You can exercise most of these rights directly and immediately from your account:
- Access and portability: "Export my data" button in your profile (full JSON export).
- Rectification: editing your information from your profile.
- Erasure: "Delete my account" button in your profile. Deletion is immediate and permanent, including at our emailing processors. If a subscription is active, its prior cancellation is required: deletion is then possible from the end of the billing period already paid for.
- Withdrawal of marketing consent: checkbox to uncheck in your profile, or unsubscribe link in each email.
For any other request, contact us at: dpo@zyre.fr. We respond within a maximum of one month. You also have the right to lodge a complaint with the CNIL (www.cnil.fr).
In accordance with article 85 of the French Data Protection Act, you can set directives regarding the fate of your data after your death, by writing to us at the same address.
8. Cookies and local storage
Zyre uses no advertising, analytics or tracking cookies, and no third-party trackers. Only elements strictly necessary for the operation of the Service are used, exempt from consent in accordance with the CNIL guidelines:
- auth_token (cookie): maintaining your authenticated session.
- zyre_csrf (cookie): protection against CSRF attacks.
- Browser local storage: chosen theme (light/dark) and language.
9. Security
We implement appropriate technical and organizational measures: TLS encryption of all communications, password hashing (bcrypt), MFA secret encryption, two-factor authentication, strict data partitioning between organizations, access logging and rate limiting. In the event of a data breach likely to create a risk to your rights, we will notify the CNIL within 72 hours and inform you without undue delay.
For any legal enquiry, please contact legal@zyre.fr