1. Data controller
The data controller for personal data collected in connection with the site https://securantis.com, of the customer area, orders, licenses, downloads, security services and interactions with support is:
| Responsible party | AMPLIFEO SARL |
|---|---|
| Service | Securantis |
| Registered office | 32 allée de la Robertsau, 67000 Strasbourg, France |
| Personal data contact | support@securantis.com |
| Registration | RCS Strasbourg - SIRET 92150177100031 |
AMPLIFEO SARL undertakes to process personal data in compliance with applicable regulations, notably the General Data Protection Regulation and the French Data Protection Act (Informatique et Libertés).
2. Applied principles
AMPLIFEO SARL applies the following principles: data minimization, specified purposes, transparency, security, confidentiality, limited retention periods, restricted access to data and consideration of the rights of the data subjects.
Data is collected only when necessary for the provision of Securantis, to account management, billing, support, security, legal compliance or service improvement.
3. Categories of collected data
Depending on the use of the site and services, AMPLIFEO SARL may process the following categories of data:
| Identification data | Last name, first name, email, encrypted password, account ID, role, account creation date, login history. |
|---|---|
| Billing data | Company name, address, country, phone, VAT number, order information, number of licenses, invoices, payment status. |
| Payment data | Payment provider customer ID, payment status, partially masked payment method, transaction history. Full card details are processed by the payment provider. |
| License data | License keys, status, associated CMS, number of sites, domain, URL, activation date, plugin or module version, activation history. |
| Technical security data | IP address, user-agent, login logs, security events, alerts, scans, file paths, fingerprints, CMS versions, extensions, modules, themes, scan dates and technical results. |
| Support data | Messages, attachments, support requests, information voluntarily provided by the customer, exchange history. |
| Browsing data | Visited pages, timestamps, cookie preferences, audience data, visit source, technical information necessary for site security. |
4. Purposes and legal bases
The processing is carried out for the following purposes:
| Account creation and management | Allow access to the customer area, manage authentication, licenses, settings and account security. Legal basis: performance of the contract or pre-contractual measures. |
|---|---|
| Orders & billing | Process orders, payments, invoices, taxes, renewals and accounting obligations. Legal basis: performance of the contract and legal obligation. |
| Supply of Securantis | Activate licenses, provide downloads, private updates, alerts, reports, scans, dashboards and security features. Legal basis: performance of the contract. |
| Security and abuse prevention | Detect fraudulent use, secure access, prevent attacks, analyze incidents, control licenses and protect the infrastructure. Legal basis: legitimate interest and security obligation. |
| Customer support | Respond to requests, diagnose issues, track exchanges, provide technical support. Legal basis: performance of the contract or legitimate interest. |
| Operational communication | Send emails related to the account, security, payment, updates, incidents, support or essential information. Legal basis: performance of the contract or legitimate interest. |
| Service improvement | Understand usage, fix errors, improve features, measure performance and quality. Legal basis: legitimate interest or consent when required. |
| Cookies and analytics | Measure traffic, improve the site, remember certain preferences or ensure security. Legal basis: consent or legitimate interest depending on the nature of the tracker. |
5. Technical data from protected sites
Due to the nature of Securantis, some technical data may come from sites protected by the customer. They are used to enable security features, including scans, alerts, reports, logs, version control, private updates and anomaly detection.
The client remains responsible for their own site, their users and the information they decide to connect or transmit to Securantis. The customer must ensure they have the necessary rights to connect the site and transmit the required technical data.
AMPLIFEO SARL does not ask the client to voluntarily provide unnecessary sensitive data. The client should avoid sending plain-text passwords, secret keys, bank details, health data, highly sensitive data or information unrelated to the request to support.
6. Retention periods
Data is retained for periods proportionate to the purposes pursued. Indicative retention periods:
- account data: for the duration of the account, then limited archiving if necessary;
- contractual and billing data: duration necessary for accounting, tax and evidential obligations;
- payment data: according to the retention periods of the payment provider and applicable obligations;
- license and activation data: for the duration of the subscription, then archived for evidential purposes;
- security logs: duration necessary for security, diagnostics, fraud prevention and evidentiary purposes;
- support requests: duration necessary for processing, for the client history and for evidential purposes;
- cookies: duration varies depending on their purpose, nature and the choices expressed by the user.
Some data may be retained for longer if required by law, in the event of a dispute, an audit, fraud, non‑payment, an investigation, legal proceedings, or to defend the rights of AMPLIFEO SARL.
7. Recipients and subcontractors
Data may be communicated, to the extent necessary, to the following categories of recipients:
- authorized personnel of AMPLIFEO SARL ;
- hosting and infrastructure providers;
- payment providers, notably Stripe;
- transactional email, support, security, backup, analytics and maintenance providers;
- experts, advisors, insurers, lawyers, authorities or courts when necessary;
- providers acting on behalf of the client when the client authorizes them.
AMPLIFEO SARL ensures that its subcontractors provide appropriate guarantees of confidentiality, security and compliance.
8. Transfers outside the European Union
Some technical providers may process data outside the European Union. When this happens, AMPLIFEO SARL ensures that appropriate safeguards are put in place when required by regulation, such as adequacy decisions, standard contractual clauses, supplementary measures or appropriate contractual commitments.
The customer acknowledges that certain third‑party services, including payment, email, support or infrastructure providers, may involve international processing according to their own terms and hosting locations.
9. Data subject rights
Under the conditions provided by law, you may exercise the following rights:
- right to access your data;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to object;
- right to data portability;
- right to withdraw your consent where processing is based on consent;
- right to set directives regarding the handling of your data after your death;
- right to lodge a complaint with the CNIL.
To exercise your rights, you may write to support@securantis.com. Proof of identity may be requested when necessary to prevent any unauthorized communication.
11. Security and confidentiality
AMPLIFEO SARL implements technical and organizational measures aimed at protecting data against unauthorized access, loss, alteration, disclosure or destruction. These measures may include access control, encryption where relevant, logging, backups, isolation, access restrictions, monitoring and internal procedures.
Because no security measure is absolute, the customer must also protect their account, use strong passwords, avoid sharing access, keep their sites up to date, perform backups and report any suspicious incident promptly.
12. Minors
Securantis is intended for professional clients, site administrators, shop owners or persons with the capacity to contract. Minors must not use the service without valid authorization from their legal representative.
13. Policy modification
AMPLIFEO SARL may amend this privacy policy to account for legal, technical, functional or organizational developments. The applicable version is the one published on the site at the time of consultation, unless specific information is provided to the client.
14. Contact
For any question regarding personal data, cookies or the exercise of your rights, you can contact AMPLIFEO SARL at the following address: support@securantis.com.