Cridenty
FR / EN

Privacy policy / Data protection

Cridenty Platform

Current version: V1

English translation provided for convenience. In case of discrepancy, the French version shall prevail.

1. Introduction

This privacy policy informs professional users of the Cridenty platform about how data is processed when using the service, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable French law.

Cridenty is designed according to data minimization principles, privacy by design, and evidence without interception.

2. Data controller and processing on behalf of customers

For processing activities determined by Cridenty itself, the data controller is:

96t (Cridenty) – SASU

SIRET: 898 234 463 00013

Address: 231 rue Saint-Honoré, 75001 Paris – France

Contact email: contact@cridenty.com

No formal Data Protection Officer (DPO) is appointed. For any data-related questions, please use the contact email above.

When Cridenty processes data on behalf of a professional customer, including within a customer tenant or evidence workflows configured by that customer, the customer is the controller and Cridenty acts as a processor within the meaning of Article 28 GDPR.

For Cridenty Guard / Agent Guard signals collected in a customer environment, the default logic is the same: the customer determines the purposes, scopes, policies, legal basis and retention periods; Cridenty processes the signals on its behalf, according to its instructions and the selected configuration.

In these cases, roles, instructions, security measures and processing commitments are governed by the customer contract and, where applicable, by a Data Processing Agreement (DPA).

3. Nature of the service and GDPR scope

Cridenty is a cryptographic evidence platform and critical operations security service intended exclusively for B2B use.

Cridenty:

Content submitted to the platform is processed strictly for technical and transient purposes, exclusively to generate a cryptographic proof, without storing the message in clear text.

4. Processed data

4.1 Collected data

Cridenty processes only the data strictly necessary to operate the service, including:

Cridenty does not seek to collect or store when it is not necessary for the service:

For certain action-control flows (for example Proof of Action), the platform may handle technical target identifiers required to execute a secured operation. Such identifiers are not intended to appear in exportable evidence in clear form: exportable proofs use a minimized and verifiable representation (for example an HMAC-based identifier), while internal audit and notification views use a readable but reduced representation limited to what is strictly necessary.

Some security features, including Cridenty Guard / Agent Guard, may nevertheless process technical data that could be indirectly linked to a natural person, for example a pseudonymized actor identifier, a machine identifier, a timestamp, a technical action, a normalized path or a target fingerprint.

This data is treated as potential personal data whenever an indirect link to a person is reasonably possible.

A dedicated notice describes the processing of Cridenty Guard technical security signals.

4.2 Excluded data

Cridenty:

Scores, correlations and classifications produced by Cridenty Guard are technical security signals intended to assess whether an action complies with a policy, not to assess a person’s performance, behavior or productivity.

5. Purposes of processing

Data is processed exclusively for the following purposes:

6. Legal basis

Processing carried out by Cridenty is based on:

Where legitimate interest is relied upon, Cridenty takes into account the B2B nature of the service, data minimization, pseudonymization measures and the reasonable expectations of data subjects. For Guard deployments in a customer environment, the customer remains responsible for the legal basis applicable to its own context.

7. Retention period

Cryptographic proofs are retained for: 120 months (10 years).

This retention period is justified by:

Other technical data, including Cridenty Guard / Agent Guard signals, is retained according to its category, sensitivity, customer configuration and the duration necessary for its purpose.

8. Data location

Production data is hosted within the European Union, unless a specific contractual agreement is made with the customer.

When the customer requires enhanced localization, France-based hosting or a dedicated instance may be contractually agreed.

In case of data transfers outside the European Economic Area, Cridenty implements the appropriate safeguards required by Articles 44 to 49 GDPR, including Standard Contractual Clauses where applicable.

9. Data security

Cridenty implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Cridenty is bound by an obligation of means regarding security.

In case of a personal data breach, Cridenty applies an analysis, remediation and notification process aligned with Articles 33 and 34 GDPR, depending on its role in the relevant processing activity and the applicable contractual obligations.

10. Subprocessors

Cridenty may use technical subprocessors strictly necessary for hosting and operating the service.

Any use of a technical subprocessor is subject to appropriate contractual, security and confidentiality measures.

Such subprocessors:

When Cridenty acts as a processor for a customer, information conditions relating to subprocessors and any changes to them are specified in the applicable customer contract or DPA.

11. Rights of data subjects

As Cridenty does not process direct personal data in clear form within its exportable proofs, the exercise of GDPR rights is limited by the nature of the service and by the retention of technical elements necessary for security, audit and evidentiary value.

However, where applicable, data subjects may exercise:

Requests may be sent to: contact@cridenty.com

Data subjects also have the right to lodge a complaint with the CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr) or, for UK data subjects, with the ICO (ico.org.uk).

12. Cookies

Cridenty uses only technical cookies strictly necessary for the operation and security of the service. No advertising or audience-measurement cookies are used.

13. Policy changes

This privacy policy may be amended at any time to reflect changes in the service or regulatory requirements. The applicable version is the one published on the Cridenty website.

14. Governing law

This policy is governed by French law.