Privacy Policy
1. Data Controller Identification
This Privacy Policy outlines how personal and technical data is processed on CRAscoping.com (the "Service", "Platform", or "Site").
The Data Controller responsible for processing operations under Regulation (EU) 2016/679 (General Data Protection Regulation - "GDPR") is cetome, a company registered in France under SIRET 84983610100014 (hereinafter referred to as "cetome", "we", "us", or "our").
For any privacy inquiries, data subject right requests, or technical compliance queries, you may contact us via our official contact form.
2. Categories of Data Collected & Purposes of Processing
We collect and process data across four main operational areas:
A. Technical Input Data & Product Specifications
- Data Collected: Product names, technical descriptions, architectural details, connectivity specifications, hardware components, microprocessors, intended operational context, and uploaded datasheets or files submitted via the web scoper interface or API endpoints (
/api/). - Purpose & Legal Basis: Processed strictly to translate, analyze, and compute regulatory classification reports under Regulation (EU) 2024/2847 (EU Cyber Resilience Act). Legal basis: Performance of a contract (Art. 6(1)(b) GDPR).
- Volatile Execution: Technical input payloads are processed in volatile execution memory for the transient duration required to deliver the output report. Input data is never utilised to automatically train, retrain, fine-tune, or adjust weights of any artificial intelligence models.
B. Account & Billing Data
- Data Collected: Corporate email address, contact name, billing address, tax identifier (e.g., European VIES VAT number), and subscription records. Payment card details are collected directly by our PCI-DSS certified payment processor, Stripe; cetome does not store raw credit card numbers.
- Purpose & Legal Basis: Account management, provisioning access keys, generating tax-compliant invoices, and executing subscription billing. Legal basis: Contract performance (Art. 6(1)(b) GDPR) and legal obligations regarding accounting and VAT directives (Art. 6(1)(c) GDPR).
C. API Telemetry & Security Logs
- Data Collected: Authenticated user identifier, API Key identifier, request timestamps, incoming IP address, user-agent string, endpoint payload dimensions, and HTTP response codes.
- Purpose & Legal Basis: Used to enforce rate limits, prevent credential sharing, detect malicious request patterns, guarantee platform stability, and ensure system defense. Legal basis: Legitimate interest in securing digital infrastructure (Art. 6(1)(f) GDPR).
D. First-Party Web Analytics (Matomo)
- Data Collected: Anonymized IP addresses, page views, referral URLs, outbound link clicks, browser type, screen resolution, and visit duration.
- Purpose & Legal Basis: Operated via our self-hosted analytics infrastructure (
stats.cetome.com) using Matomo Analytics (Site ID:3) to evaluate site usage, performance, and visitor navigation without transmitting data to third-party advertising networks. Legal basis: Legitimate interest in optimizing web interface utility (Art. 6(1)(f) GDPR).
3. Analytics and Tracking (Matomo Disclosure)
We utilize an isolated instance of Matomo Analytics hosted directly on our European infrastructure (stats.cetome.com).
Unlike conventional third-party analytics platforms, our Matomo installation processes data locally under our direct control. Collected telemetry is used exclusively for site optimization and aggregated traffic analysis. We do not correlate Matomo tracking records with API credentials, billing data, or submitted product specification files.
4. Security Infrastructure and Safeguards
We implement administrative, organizational, and physical security measures designed to protect your data against unauthorized access, loss, or alteration:
- Encryption in Transit: All web traffic, user sessions, and API communications are secured using mandatory Transport Layer Security (TLS/HTTPS) protocols.
- Cryptographic API Authentication: API access relies on unique cryptographic API key identifiers transmitted via secure request headers (
X-API-Key). - Infrastructure Isolation: Production services, processing workloads, and analytics platforms are hosted within secure, European-based cloud data centers operating under strict physical and logical access controls.
- Payment Compliance: All credit card transactions are handled via Stripe’s PCI-DSS Level 1 certified payment infrastructure.
5. Third-Party Service Providers (Data Processors)
To operate the Service, we share necessary data with trusted third-party service providers acting as Data Processors bound by data processing agreements:
- Stripe, Inc.: Payment processing, customer invoicing, and tax calculation.
- European Hosting & Cloud Infrastructure Providers: Transient execution servers, secure data storage, and network transport infrastructure located within the EU.
We do not sell, rent, or monetize personal data or submitted product descriptions under any circumstances.
6. Data Retention Policies
- Technical Specification Submissions: Processed in volatile memory for execution and discarded immediately after returning the classification report.
- Account & Billing Data: Retained for the duration of the active subscription plus mandatory statutory retention periods under French commercial law (up to 10 years for accounting records).
- Security Logs: Retained for a rolling window of up to 90 days for infrastructure protection and audit defense before being purged.
- Matomo Analytics Data: Retained in aggregated, anonymized formats for historical metric tracking.
7. Your Data Protection Rights under GDPR
Under the General Data Protection Regulation, individuals in the European Union hold specific rights regarding their personal data:
- Right of Access: Request confirmation and copies of personal data held about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where continuous processing is no longer required by law.
- Right to Restrict or Object: Object to or restrict processing activities based on legitimate interests.
- Right to Data Portability: Request export of account data in a structured, machine-readable format.
To exercise any of these rights, submit a request through our contact form. If you consider that our processing violates GDPR provisions, you retain the right to lodge a complaint with the French data protection authority, the CNIL (Commission Nationale de l'Informatique et des Libertés - cnil.fr).
8. Amendments to This Policy
cetome reserves the right to update or modify this Privacy Policy to reflect technical adjustments, regulatory updates, or operational changes. Material changes will be noted by updating the "Last updated" timestamp at the top of this document. Continued use of the Service following revisions constitutes acceptance of the updated practices.