Privacy Policy

Last updated: July 2026

This Privacy Policy explains how Vulnotes SASU("we", "us", "our"), a French société par actions simplifiée unipersonnelle, collects, uses, stores, and protects your personal data when you use our website at https://vulnotes.com and the Vulnotes service (together, the "Service").

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable French data protection laws.


1. Data Controller

The data controller responsible for processing your personal data is:

Vulnotes SASU

A French société par actions simplifiée unipersonnellewith a share capital of 1,000 €, represented by its Président, Hippolyte QUERE

5, Allée de la Grande Treille, Bureau 3

35200 Rennes

France

SIREN: 106 253 842

RCS: Rennes

Intra-community VAT number: FR41 106 253 842

Email: contact@vulnotes.com


2. Personal Data We Collect

We collect different types of personal data depending on how you interact with the Service:

2.1 Account and Registration Data

  • Email address
  • Name (if provided)
  • Password (stored hashed, never in plain text)
  • Organization name and role (if applicable)

2.2 Newsletter Data

  • Email address submitted via the newsletter subscription form

2.3 Usage and Technical Data

Server access logs (security and abuse prevention):

  • IP address (retained briefly — see Section 6)
  • User-agent string, request path, response status, timestamp

Product analytics— we use PostHog (EU-hosted) on the marketing website, the Manager portal and the SaaS edition of the app to understand how our products are used. Self-hosted deployments of the Vulnotes app do not load the analytics SDK.

  • Pageviews and a small set of product events (clicks on key buttons, onboarding steps, report exports).
  • IP address and approximate location are discarded before storage.
  • Once you log in to the Manager portal or the SaaS app, events are linked to your account (email, internal user ID, team / company name). Visitors to the marketing site stay anonymous.
  • Session replay is off by default and only enabled during the Manager onboarding flow, after you accept analytics cookies.

Marketing automation tracking (Brevo): on the marketing website only, and only after you accept analytics cookies, we load the Brevo web tracker to support our email marketing automations.

  • Pages you visit on the marketing site, and (once you identify yourself, for example by subscribing or contacting us) an association between your email address and that browsing activity.
  • This lets us send relevant, consent-based marketing emails and measure their effectiveness.
  • It is never loaded on self-hosted deployments, and never before you accept analytics cookies.

Authentication security data:

  • A cryptographic device fingerprint computed at sign-in and bound to your refresh token, used solely to detect and prevent token theft. It is not used for cross-site tracking, advertising, or any analytics purpose
  • Two-factor authentication (2FA) data: TOTP secret (encrypted), recovery codes (hashed), method preference

2.4 User Content

Reports, findings, notes, screenshots, and other content you create or upload within the Service. You retain ownership of your User Content as described in our Terms of Use.

2.5 Payment Data

Payment information (credit card details, billing address) is processed directly by Stripe and is never stored on our servers. We only receive confirmation of payment status, subscription details, and a truncated card identifier for display purposes.


3. Purposes and Legal Bases for Processing

We process your personal data for the following purposes under the indicated legal bases (Article 6 GDPR):

PurposeLegal Basis
Providing and operating the ServicePerformance of contract (Art. 6(1)(b))
Account creation and authenticationPerformance of contract (Art. 6(1)(b))
Processing payments and billingPerformance of contract (Art. 6(1)(b))
Newsletter communicationsConsent (Art. 6(1)(a))
Anonymous, aggregate audience measurementLegitimate interest (Art. 6(1)(f)) — CNIL audience-measurement exemption (no consent required)
Identified, cross-domain product analyticsConsent (Art. 6(1)(a)) via cookie banner
Email marketing automation and visitor identification (Brevo)Consent (Art. 6(1)(a)) via cookie banner
AI-powered features (content generation)Consent / Performance of contract (Art. 6(1)(a)/(b))
Security monitoring and fraud preventionLegitimate interest (Art. 6(1)(f))
Legal compliance and dispute resolutionLegal obligation (Art. 6(1)(c))

4. Third-Party Processors (Sub-processors)

We share personal data with the following third-party service providers, who process data on our behalf:

ProviderPurposeLocation
Contabo GmbHInfrastructure hostingGermany (EU)
Stripe, Inc.Payment processingUSA (EU SCCs)
Mistral AIAI features (Vulnotes AI)France (EU)
PostHog Inc.Product analytics (EU Cloud)Frankfurt, Germany (EU)
Brevo (Sendinblue SAS)Email marketing, automations, and consent-based website visitor trackingFrance (EU)
Discord, Inc.In-app live-chat support: messages you send via the support widget are bridged to our internal Discord workspace where our team respondsUSA (EU SCCs)
OpenAI / Anthropic / OtherOptional AI providers (user-configured)Varies

For transfers outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate safeguards under Chapter V of the GDPR.


5. Cookies and Tracking Technologies

5.1 Types of Cookies and Storage

We use the following categories of cookies and local storage:

  • Strictly necessary storage: essential for the website to function (authentication, session management, consent preference storage). These do not require consent.
  • Anonymous aggregate analytics (no consent required): by default PostHog runs in cookieless, in-memory mode to count pageviews. No cookie is set, no cross-session tracking takes place, and your IP address is discarded. This is exempt from prior consent under CNIL guidance on audience measurement.
  • Analytics cookies (consent required): if you accept on the cookie banner, PostHog sets a first-party cookie so we can link pageviews into sessions and measure conversion across our websites. Data is hosted in the EU (Frankfurt).
  • Marketing automation cookies (consent required): if you accept on the cookie banner, we load the Brevo web tracker, which sets first-party cookies to recognize your browser across visits and (once known) link it to your email address for our email marketing automations. It is not loaded if you decline. Brevo is operated by Sendinblue SAS (France, EU).

5.2 Managing Cookies

When you first visit our website, a cookie banner allows you to accept or decline analytics cookies. You can change your preference at any time by clicking to reopen the cookie banner.

You can also configure your browser to block or delete cookies. Note that blocking strictly necessary cookies may affect the functionality of the Service.


6. Data Retention

We retain your personal data only as long as necessary:

Data TypeRetention Period
Account dataDuration of active account + 30 days after deletion
User Content (reports, findings)Duration of active account + 30 days after deletion
Newsletter emailsUntil unsubscribe request or 3 years of inactivity
Payment and billing records10 years (French tax obligations)
Analytics data (PostHog)12 months
Marketing automation data (Brevo)Until unsubscribe or objection, or 3 years of inactivity
Cookie-banner consent decision12 months (then re-asked)
Server access logs (IP, user-agent)30 days, then deleted or aggregated
Security and audit logs12 months

After the applicable retention period, data is permanently deleted or anonymized so that it can no longer identify you.


7. Your Rights Under GDPR

Under the GDPR and applicable French law, you have the following rights regarding your personal data:

  • Right of access (Art. 15): obtain confirmation of whether we process your data and request a copy of it.
  • Right to rectification (Art. 16): request correction of inaccurate or incomplete personal data.
  • Right to erasure (Art. 17):request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction (Art. 18): request that we limit the processing of your data in certain circumstances.
  • Right to data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to object (Art. 21): object to processing based on legitimate interests, including profiling.
  • Right to withdraw consent (Art. 7(3)): withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal.

How to Exercise Your Rights

To exercise any of these rights, contact us at contact@vulnotes.com. We will respond within 30 days of receiving your request. We may ask you to verify your identity before processing.

If you believe that we have not adequately addressed your request, you have the right to lodge a complaint with the French Data Protection Authority (CNIL): www.cnil.fr


8. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS)
  • Encrypted exports (AES-256) for secure report delivery
  • Hashed passwords using industry-standard algorithms
  • Role-based access control and granular permissions
  • Two-factor authentication (2FA) support
  • Regular security updates and vulnerability monitoring

Despite these measures, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it through our responsible disclosure policy.


9. International Data Transfers

Our primary infrastructure is hosted in the European Union (Contabo, Germany), and our analytics data stays in the EU on PostHog Cloud EU (Frankfurt). Our payment processor Stripe, Inc. is US-based, and some optional AI providers you may configure (OpenAI, Anthropic, Google Gemini) operate outside the EU/EEA.

For transfers of personal data outside the EU/EEA, we ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs)
  • EU-US Data Privacy Framework, where applicable
  • Adequacy decisions by the European Commission, where available

10. AI Features and Data Processing

Vulnotes offers AI-powered features that may process portions of your User Content (e.g., findings, screenshots, report sections). When using AI features:

  • Vulnotes AI (powered by Mistral AI, France) is included by default. You can also configure third-party providers (OpenAI, Anthropic, Google Gemini, or any OpenAI API-compatible endpoint).
  • An automatic anonymization feature is available to strip sensitive data before it is sent to the AI provider.
  • AI features can be completely disabled from the administration panel.
  • Vulnotes does not train any models on your data.Whether third-party AI providers retain or train on inputs depends on their own terms of service — please refer to each provider's privacy policy. The default Vulnotes AI (powered by Mistral, France) is operated under enterprise terms that prohibit training on customer inputs.
  • If you configure a local model (any OpenAI-compatible endpoint pointing at your own infrastructure), no data leaves your network and no third-party AI provider is involved.

For details on how each AI provider handles data, please refer to their respective privacy policies.


11. Self-Hosted Deployments

If you use the Self-Hosted Version of Vulnotes, you are the data controller for all personal data stored and processed within your own infrastructure. Vulnotes operates only the licensing service for your deployment.

Self-hosted deployments do not collect, transmit, or process any analytics, telemetry, or usage data. Our analytics SDK is only loaded into the user's browser when our backend confirms — via a public bootstrap endpoint and the active license type — that the deployment is the SaaS edition. On self-hosted instances the SDK is never downloaded and no analytics network traffic is generated.

The only network traffic from a self-hosted Vulnotes instance to our infrastructure is:

  • License validation: the license key and a periodic heartbeat are sent to verify entitlement and seat counts. No report content, finding content, user emails, or other personal data is transmitted.
  • Update checks: the current version number is sent to determine whether a newer release is available. No user data is transmitted.
  • AI features (if enabled and configured to use cloud providers): requests are sent directly from your instance to the AI provider you selected (Mistral, OpenAI, Anthropic, etc.). They do not pass through Vulnotes' infrastructure.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the CNIL within 72 hours of becoming aware of the breach (Art. 33 GDPR)
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR)
  • Document the breach, its effects, and remedial actions taken

13. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us so we can delete it promptly.


14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements.

  • Significant changes will be communicated via email or in-app notification.
  • The updated policy will be posted on this page with a revised "Last updated" date.

We encourage you to review this page periodically to stay informed about how we protect your data.


15. Contact

For any questions about this Privacy Policy, your personal data, or to exercise your rights, contact us:

Vulnotes / Hippolyte QUERE

Email: contact@vulnotes.com

You may also lodge a complaint with the CNIL(Commission Nationale de l'Informatique et des Libertés) at www.cnil.fr