Privacy policy / Data protection
Cridenty Platform
Current version: V1
English translation provided for convenience. In case of discrepancy, the French version shall prevail.
1. Introduction
This privacy policy informs professional users of the Cridenty platform about how data is processed when using the service, in accordance with Regulation (EU) 2016/679 (GDPR) and applicable French law.
Cridenty is designed according to data minimization principles, privacy by design, and evidence without interception.
2. Data controller and processing on behalf of customers
For processing activities determined by Cridenty itself, the data controller is:
96t (Cridenty) – SASU
SIRET: 898 234 463 00013
Address: 231 rue Saint-Honoré, 75001 Paris – France
Contact email: contact@cridenty.com
No formal Data Protection Officer (DPO) is appointed. For any data-related questions, please use the contact email above.
When Cridenty processes data on behalf of a professional customer, including within a customer tenant or evidence workflows configured by that customer, the customer is the controller and Cridenty acts as a processor within the meaning of Article 28 GDPR.
For Cridenty Guard / Agent Guard signals collected in a customer environment, the default logic is the same: the customer determines the purposes, scopes, policies, legal basis and retention periods; Cridenty processes the signals on its behalf, according to its instructions and the selected configuration.
In these cases, roles, instructions, security measures and processing commitments are governed by the customer contract and, where applicable, by a Data Processing Agreement (DPA).
3. Nature of the service and GDPR scope
Cridenty is a cryptographic evidence platform and critical operations security service intended exclusively for B2B use.
Cridenty:
- does not provide messaging services,
- does not transport communications,
- does not participate in message delivery.
Content submitted to the platform is processed strictly for technical and transient purposes, exclusively to generate a cryptographic proof, without storing the message in clear text.
4. Processed data
4.1 Collected data
Cridenty processes only the data strictly necessary to operate the service, including:
- technical identifiers for customers (tenants),
- agent identifiers,
- campaign identifiers or reference identifiers,
- technical metadata linked to proofs (timestamp, short identifier, signature, minimized technical identifiers).
Cridenty does not seek to collect or store when it is not necessary for the service:
- messages in clear text,
- semantic content,
- directly identifying data (first name, last name, phone number, address, etc.).
For certain action-control flows (for example Proof of Action), the platform may handle technical target identifiers required to execute a secured operation. Such identifiers are not intended to appear in exportable evidence in clear form: exportable proofs use a minimized and verifiable representation (for example an HMAC-based identifier), while internal audit and notification views use a readable but reduced representation limited to what is strictly necessary.
Some security features, including Cridenty Guard / Agent Guard, may nevertheless process technical data that could be indirectly linked to a natural person, for example a pseudonymized actor identifier, a machine identifier, a timestamp, a technical action, a normalized path or a target fingerprint.
This data is treated as potential personal data whenever an indirect link to a person is reasonably possible.
A dedicated notice describes the processing of Cridenty Guard technical security signals.
4.2 Excluded data
Cridenty:
- does not perform profiling for commercial, advertising or HR purposes,
- does not analyze content,
- does not sell or share data for commercial purposes.
Scores, correlations and classifications produced by Cridenty Guard are technical security signals intended to assess whether an action complies with a policy, not to assess a person’s performance, behavior or productivity.
5. Purposes of processing
Data is processed exclusively for the following purposes:
- generation of cryptographic proofs,
- integrity and timestamp verification,
- authentication and securing operations,
- audit and traceability of critical actions,
- technical operations and platform security,
- control of the authorized action scope for AI tools, software agents and development environments,
- construction, testing and improvement of security policies,
- detection of out-of-scope actions, abnormal extractions or unauthorized executions,
- production of technical signals required to validate or block sensitive actions.
6. Legal basis
Processing carried out by Cridenty is based on:
- performance of the contract between Cridenty and its professional customers,
- Cridenty’s legitimate interest in ensuring security, reliability and traceability of its service.
Where legitimate interest is relied upon, Cridenty takes into account the B2B nature of the service, data minimization, pseudonymization measures and the reasonable expectations of data subjects. For Guard deployments in a customer environment, the customer remains responsible for the legal basis applicable to its own context.
7. Retention period
Cryptographic proofs are retained for: 120 months (10 years).
This retention period is justified by:
- evidence needs,
- audit requirements,
- customers’ contractual and regulatory obligations.
Other technical data, including Cridenty Guard / Agent Guard signals, is retained according to its category, sensitivity, customer configuration and the duration necessary for its purpose.
8. Data location
Production data is hosted within the European Union, unless a specific contractual agreement is made with the customer.
When the customer requires enhanced localization, France-based hosting or a dedicated instance may be contractually agreed.
In case of data transfers outside the European Economic Area, Cridenty implements the appropriate safeguards required by Articles 44 to 49 GDPR, including Standard Contractual Clauses where applicable.
9. Data security
Cridenty implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- strong authentication (FIDO/WebAuthn),
- protection of secrets and keys,
- logging of critical events,
- access control and multi-tenant segregation.
Cridenty is bound by an obligation of means regarding security.
In case of a personal data breach, Cridenty applies an analysis, remediation and notification process aligned with Articles 33 and 34 GDPR, depending on its role in the relevant processing activity and the applicable contractual obligations.
10. Subprocessors
Cridenty may use technical subprocessors strictly necessary for hosting and operating the service.
Any use of a technical subprocessor is subject to appropriate contractual, security and confidentiality measures.
Such subprocessors:
- act on Cridenty’s instructions,
- are bound by contractual confidentiality and security obligations,
- are selected according to the requirements applicable to the service and the customer’s contractual commitments.
When Cridenty acts as a processor for a customer, information conditions relating to subprocessors and any changes to them are specified in the applicable customer contract or DPA.
11. Rights of data subjects
As Cridenty does not process direct personal data in clear form within its exportable proofs, the exercise of GDPR rights is limited by the nature of the service and by the retention of technical elements necessary for security, audit and evidentiary value.
However, where applicable, data subjects may exercise:
- right of access,
- right to rectification,
- right to erasure,
- right to restriction of processing,
- right to object, within legal limits,
- right to data portability where applicable,
- right not to be subject to a solely automated decision producing legal effects or significantly affecting the person, under the conditions of Article 22 GDPR.
Requests may be sent to: contact@cridenty.com
Data subjects also have the right to lodge a complaint with the CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr) or, for UK data subjects, with the ICO (ico.org.uk).
12. Cookies
Cridenty uses only technical cookies strictly necessary for the operation and security of the service. No advertising or audience-measurement cookies are used.
13. Policy changes
This privacy policy may be amended at any time to reflect changes in the service or regulatory requirements. The applicable version is the one published on the Cridenty website.
14. Governing law
This policy is governed by French law.