Legal information
How Kalisecu collects, uses and protects your personal data. Compliant with the General Data Protection Regulation (EU 2016/679) and the French Data Protection Act.
The controller of personal data is:
No personal data is collected when simply visiting the site. No third-party tracking, audience-measurement or advertising cookies are stored.
Purposes: execution of the subscribed service (audit, monitoring, report), invoicing, contractual communication, support, service improvement.
Legal bases: performance of the contract (art. 6.1.b GDPR) for data necessary for the service; legal obligation (art. 6.1.c) for invoicing and accounting retention; legitimate interest (art. 6.1.f) for platform security and fraud prevention.
While performing the service, Kalisecu produces and stores technical data about the Client's site (observed configuration, detected vulnerabilities, recommendations, screenshots). This data is strictly confidential and accessible only to the Kalisecu team and the holding Client.
All operational data (reports, dashboard, service database) is hosted in mainland France, with no transit through servers outside the EU.
All sub-processors have signed a data-processing agreement (DPA) compliant with articles 28 and 32 GDPR. No data transfer occurs to jurisdictions without an adequacy decision from the European Commission.
Personal and technical data is protected by the following measures:
In accordance with articles 15 to 22 of the GDPR, you have the following rights over your personal data:
To exercise a right, write to hello@kalisecu.com. We respond within one month maximum.
You also have the right to lodge a complaint with the French data protection authority (CNIL, 3 place de Fontenoy, 75007 Paris).
This policy may be updated to reflect a legal or organisational change. The date of last update is shown below. Clients are notified by email of any substantial change.
Last updated: 4 May 2026 · Lire en français