Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Vulnotes SASU("we", "us", "our"), a French société par actions simplifiée unipersonnelle, collects, uses, stores, and protects your personal data when you use our website at https://vulnotes.com and the Vulnotes service (together, the "Service").

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable French data protection laws.


1. Data Controller

The data controller responsible for processing your personal data is:

Vulnotes SASU

A French société par actions simplifiée unipersonnellewith a share capital of 1,000 €, represented by its Président, Hippolyte QUERE

5, Allée de la Grande Treille, Bureau 3

35000 Rennes

France

SIREN: 106 253 842

RCS: Rennes

Intra-community VAT number: FR41 106 253 842

Email: contact@vulnotes.com


2. Personal Data We Collect

We collect different types of personal data depending on how you interact with the Service:

2.1 Account and Registration Data

  • Email address
  • Name (if provided)
  • Password (stored hashed, never in plain text)
  • Organization name and role (if applicable)

2.2 Newsletter Data

  • Email address submitted via the newsletter subscription form

2.3 Usage and Technical Data

Server access logs (security and abuse prevention):

  • IP address (retained briefly — see Section 6)
  • User-agent string, request path, response status, timestamp

Product analytics— we use PostHog (EU-hosted) on the marketing website, the Manager portal and the SaaS edition of the app to understand how our products are used. Self-hosted deployments of the Vulnotes app do not load the analytics SDK.

  • Pageviews and a small set of product events (clicks on key buttons, onboarding steps, report exports).
  • IP address and approximate location are discarded before storage.
  • Once you log in to the Manager portal or the SaaS app, events are linked to your account (email, internal user ID, team / company name). Visitors to the marketing site stay anonymous.
  • Session replay is off by default and only enabled during the Manager onboarding flow, after you accept analytics cookies.

Marketing automation tracking (Brevo): on the marketing website only, and only after you accept analytics cookies, we load the Brevo web tracker to support our email marketing automations.

  • Pages you visit on the marketing site, and (once you identify yourself, for example by subscribing or contacting us) an association between your email address and that browsing activity.
  • This lets us send relevant, consent-based marketing emails and measure their effectiveness.
  • It is never loaded on self-hosted deployments, and never before you accept analytics cookies.

Authentication security data:

  • A cryptographic device fingerprint computed at sign-in and bound to your refresh token, used solely to detect and prevent token theft. It is not used for cross-site tracking, advertising, or any analytics purpose
  • Two-factor authentication (2FA) data: TOTP secret (encrypted), recovery codes (hashed), method preference

2.4 User Content

Reports, findings, notes, screenshots, and other content you create or upload within the Service. You retain ownership of your User Content as described in our Terms of Use.

2.5 Payment Data

Payment information (credit card details, billing address) is processed directly by Stripe and is never stored on our servers. We only receive confirmation of payment status, subscription details, and a truncated card identifier for display purposes.


3. Purposes and Legal Bases for Processing

We process your personal data for the following purposes under the indicated legal bases (Article 6 GDPR):

PurposeLegal Basis
Providing and operating the ServicePerformance of contract (Art. 6(1)(b))
Account creation and authenticationPerformance of contract (Art. 6(1)(b))
Processing payments and billingPerformance of contract (Art. 6(1)(b))
Newsletter communicationsConsent (Art. 6(1)(a))
Anonymous, aggregate audience measurementLegitimate interest (Art. 6(1)(f)) — CNIL audience-measurement exemption (no consent required)
Identified, cross-domain product analyticsConsent (Art. 6(1)(a)) via cookie banner
Email marketing automation and visitor identification (Brevo)Consent (Art. 6(1)(a)) via cookie banner
AI-powered features (content generation)Consent / Performance of contract (Art. 6(1)(a)/(b))
Security monitoring and fraud preventionLegitimate interest (Art. 6(1)(f))
Legal compliance and dispute resolutionLegal obligation (Art. 6(1)(c))

4. Third-Party Processors (Sub-processors)

We share personal data with the following third-party service providers, who process data on our behalf:

ProviderPurposeLocation
Contabo GmbHInfrastructure hostingGermany (EU)
Backblaze, Inc.Encrypted off-site disaster-recovery backupsEU Central region, Amsterdam, Netherlands (US provider; SCCs / EU-US DPF)
Stripe, Inc.Payment processingUSA (EU SCCs)
Mistral AIAI features (Vulnotes AI)France (EU)
PostHog Inc.Product analytics (EU Cloud)Frankfurt, Germany (EU)
Brevo (Sendinblue SAS)Email marketing, automations, and consent-based website visitor trackingFrance (EU)
Discord, Inc.In-app live-chat support: messages you send via the support widget are bridged to our internal Discord workspace where our team respondsUSA (EU SCCs)
OpenAI / Anthropic / OtherOptional AI providers (user-configured)Varies

For transfers outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate safeguards under Chapter V of the GDPR.

Where Vulnotes acts as a processor for a customer, we will give that customer prior notice of any intended addition or replacement of a sub-processor that may process the customer's personal data. The customer may object on reasonable data-protection grounds within the period specified in the applicable Data Processing Agreement. We will work in good faith to address the objection, including by proposing a commercially reasonable alternative where one is available.


5. Cookies and Tracking Technologies

5.1 Types of Cookies and Storage

We use the following categories of cookies and local storage:

  • Strictly necessary storage: essential for the website to function (authentication, session management, consent preference storage). These do not require consent.
  • Anonymous aggregate analytics (no consent required): by default PostHog runs in cookieless, in-memory mode to count pageviews. No cookie is set, no cross-session tracking takes place, and your IP address is discarded. This is exempt from prior consent under CNIL guidance on audience measurement.
  • Analytics cookies (consent required): if you accept on the cookie banner, PostHog sets a first-party cookie so we can link pageviews into sessions and measure conversion across our websites. Data is hosted in the EU (Frankfurt).
  • Marketing automation cookies (consent required): if you accept on the cookie banner, we load the Brevo web tracker, which sets first-party cookies to recognize your browser across visits and (once known) link it to your email address for our email marketing automations. It is not loaded if you decline. Brevo is operated by Sendinblue SAS (France, EU).

5.2 Managing Cookies

When you first visit our website, a cookie banner allows you to accept or decline analytics cookies. You can change your preference at any time by clicking to reopen the cookie banner.

You can also configure your browser to block or delete cookies. Note that blocking strictly necessary cookies may affect the functionality of the Service.


6. Data Retention

We retain your personal data only as long as necessary:

Data TypeRetention Period
Account dataDuration of the active account; removed from active systems within 30 days after deletion, subject to the backup cycle described below
User Content (reports, findings)Duration of the active account; removed from active systems within 30 days after deletion, subject to the backup cycle described below
Newsletter emailsUntil unsubscribe request or 3 years of inactivity
Payment and billing records10 years (French tax obligations)
Analytics data (PostHog)12 months
Marketing automation data (Brevo)Until unsubscribe or objection, or 3 years of inactivity
Cookie-banner consent decision12 months (then re-asked)
Server access logs (IP, user-agent)30 days, then deleted or aggregated
Security and audit logs12 months

After the applicable retention period, data is permanently deleted or anonymized so that it can no longer identify you.

Disaster-recovery backups are kept separately from active systems in two layers: Contabo Auto Backup, normally on a rolling 10-day cycle, and daily off-site backups sent to Backblaze B2's EU Central region in Amsterdam, the Netherlands. Backblaze backups are encrypted by Vulnotes with restic before transfer and normally retain seven daily, four weekly and six monthly recovery points. Data deleted from active systems may therefore remain in the last monthly backup containing it for up to approximately six months. Backup copies are not used for ordinary business purposes. If a backup is restored following an incident, deletion requests and expired retention periods are reapplied to the restored data.


7. Your Rights Under GDPR

Under the GDPR and applicable French law, you have the following rights regarding your personal data:

  • Right of access (Art. 15): obtain confirmation of whether we process your data and request a copy of it.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17):request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction (Art. 18): request that we limit the processing of your data in certain circumstances.
  • Right to data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling.
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

How to Exercise Your Rights

To exercise any of these rights, contact us at contact@vulnotes.com. We will respond within 30 days of receiving your request. We may ask you to verify your identity before processing.

If you believe that we have not adequately addressed your request, you have the right to lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr


8. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS)
  • Encrypted exports (AES-256) for secure report delivery
  • Hashed passwords using industry-standard algorithms
  • Role-based access control and granular permissions
  • Two-factor authentication (2FA) support
  • Regular security updates and vulnerability monitoring

Despite these measures, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it through our responsible disclosure policy.


9. International Data Transfers

Our primary infrastructure is hosted in the European Union (Contabo, Germany), our encrypted off-site backups are stored in Backblaze B2's EU Central region in Amsterdam, the Netherlands, and our analytics data stays in the EU on PostHog Cloud EU (Frankfurt). Backblaze, Inc. and our payment processor Stripe, Inc. are US-based, and some optional AI providers you may configure (OpenAI, Anthropic, Google Gemini) operate outside the EU/EEA. Backblaze receives backups already encrypted by Vulnotes; its processing is also governed by its data processing agreement, including the EU Standard Contractual Clauses, and the EU-US Data Privacy Framework where applicable.

For transfers of personal data outside the EU/EEA, we ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs)
  • EU-US Data Privacy Framework, where applicable
  • Adequacy decisions by the European Commission, where available

10. AI Features and Data Processing

Vulnotes offers AI-powered features that may process portions of your User Content (e.g., findings, screenshots, report sections). When using AI features:

  • Vulnotes AI (powered by Mistral AI, France) is included by default. You can also configure third-party providers (OpenAI, Anthropic, Google Gemini, or any OpenAI API-compatible endpoint).
  • An automatic anonymization feature is available to strip sensitive data before it is sent to the AI provider.
  • AI features can be completely disabled from the administration panel.
  • Vulnotes does not train any models on your data.Whether third-party AI providers retain or train on inputs depends on their own terms of service — please refer to each provider's privacy policy. The default Vulnotes AI (powered by Mistral, France) is operated with training disabled and Zero Data Retention (ZDR) enabled. Its requests use stateless API endpoints covered by ZDR, so inputs and outputs are not retained beyond what is required to return the response.
  • If you configure a local model (any OpenAI-compatible endpoint pointing at your own infrastructure), no data leaves your network and no third-party AI provider is involved.

For details on how each AI provider handles data, please refer to their respective privacy policies.


11. Self-Hosted and Air-Gapped Deployments

If you use the Self-Hosted Version or an Air-Gapped Version of Vulnotes, you are the data controller for all personal data stored and processed within your own infrastructure. Vulnotes provides the software and does not act as a processor for report content, findings, evidence, attachments, notes, or other data stored solely within that deployment. Vulnotes acts as a separate controller for the limited account, contractual, billing, and licensing data that it processes for its own purposes.

Self-hosted and air-gapped deployments do not collect, transmit, or process any analytics, telemetry, or usage data. Our analytics SDK is only loaded into the user's browser when our backend confirms — via a public bootstrap endpoint and the active license type — that the deployment is the SaaS edition. On self-hosted instances the SDK is never downloaded and no analytics network traffic is generated.

Air-gapped deployments operate without any outbound connection to Vulnotes infrastructure: licensing and updates are handled through signed offline files, and Vulnotes cannot access data held inside the air-gapped environment.

For a standard, connected self-hosted deployment, the only network traffic to our infrastructure is:

  • License validation: the license key and a periodic heartbeat are sent to verify entitlement and seat counts. No report content, finding content, user emails, or other personal data is transmitted.
  • Update checks: the current version number is sent to determine whether a newer release is available. No user data is transmitted.
  • AI features (if enabled and configured to use cloud providers): requests are sent directly from your instance to the AI provider you selected (Mistral, OpenAI, Anthropic, etc.). They do not pass through Vulnotes' infrastructure.

If a customer voluntarily sends report content or other personal data to Vulnotes for a specific support, migration, or professional-services request, Vulnotes may act as a processor solely for that limited operation. Such access must be expressly requested or authorized by the customer and is governed by the applicable agreement and documented instructions.


12. Data Breach Notification

Our notification obligations depend on the role in which Vulnotes processes the affected personal data:

  • Where Vulnotes is the data controller: if required by Article 33 GDPR, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
  • Where Vulnotes is a processor for a customer:we will notify that customer without undue delay after becoming aware of a breach affecting personal data processed on the customer's behalf, and provide the information and reasonable assistance needed for the customer to meet its obligations. The customer, as data controller, is responsible for deciding whether to notify the supervisory authority or affected individuals, unless otherwise required by law or expressly agreed in documented instructions.
  • Where Vulnotes is the data controller, we will notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 GDPR.
  • We document personal data breaches, their effects, and the remedial actions taken.

13. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us so we can delete it promptly.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements.

  • Significant changes will be communicated via email or in-app notification.
  • The updated policy will be posted on this page with a revised "Last updated" date.

We encourage you to review this page periodically to stay informed about how we protect your data.


15. Contact

For any questions about this Privacy Policy, your personal data, or to exercise your rights, contact us:

Vulnotes / Hippolyte QUERE

Email: contact@vulnotes.com

You may also lodge a complaint with the CNIL(Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr