Privacy Policy
Last updated: July 2026
1. Introduction & Data Controller
This Privacy Policy describes how Cryptaguard BV (hereinafter “the Company,” “we,” “our”) collects, uses, stores, and protects your personal data in connection with the use of the ResiPlan platform (hereinafter “the Service”).
In accordance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679) and applicable national laws, we are committed to protecting your privacy and personal data.
Two distinct roles: the Company is a controller for account, billing and website data (described in this policy), and a processor for the business data that each customer organization enters into the Service (BIA, plans, incidents, contacts, AI conversations): that data is processed on the organization's behalf, under our Data Processing Agreement (DPA) available at /legal/dpa. Data subject requests concerning such business data are forwarded to the relevant organization, which alone is entitled to respond.
Data Controller:
- Company: Cryptaguard BV
- Email: privacy@resiplan.eu
- Website: https://www.resiplan.eu
2. Data We Collect
We collect different categories of data in connection with providing the Service:
2.1 Account Data
- First name, last name, professional email address.
- Organization name and role within it.
- Login credentials (encrypted password).
- Language and notification preferences.
2.2 Usage Data
- IP address, browser type, operating system.
- Pages visited, features used, login times.
- Performance metrics and error logs (stored internally in Convex, EU region).
- Web Vitals indicators (browser performance).
2.3 Business Continuity Data
- Business Impact Analyses (BIA), continuity plans (BCP, DRP, IRP, ERP), risk assessments.
- IT asset information (CMDB): applications, servers, contracts.
- Organizational charts, business processes, critical dependencies.
- Incident and crisis management data.
- AI assistant conversations and generated recommendations.
3. How We Use Your Data
We use your data for the following purposes:
3.1 Service Delivery
- Creating and managing your user account.
- Hosting and processing your business continuity data.
- Real-time data synchronization between users within your organization.
- Generating reports and dashboards.
3.2 AI Features
- Transmitting contextual data to our AI providers (Anthropic or OpenAI by default; Mistral AI, hosted in the European Union, as a per-organization option) to generate continuity plans, risk analyses, and recommendations.
- No customer data is used to train AI models: this prohibition is imposed contractually on our AI providers in their capacity as sub-processors (see our DPA, Section 5.4.3).
- AI assistant conversations are stored in your data space for future reference.
3.3 Improvement & Analytics
- Analyzing aggregated usage metrics to improve the Service.
- Monitoring errors and technical performance (internal Convex logs, EU region, and Web Vitals).
- Audience measurement (Plausible): aggregated, cookieless traffic statistics. No personal data is collected; no consent required.
- Campaign attribution (first-party audience measurement): when you arrive via a campaign link (UTM parameters), and subject to your consent, we measure the browsing journey (pages visited, time spent) using an anonymous session identifier stored in your browser (sessionStorage). This data is hosted by us (Convex, no third party) and contains no directly identifying information.
- Heatmaps and session replay (Microsoft Clarity): subject to your consent, we use Microsoft Clarity to anonymously visualize interactions (clicks, scrolling) and improve usability. Clarity sets cookies and loads only after you accept the consent banner.
- Analytics data is anonymized; it does not allow individual user identification.
3.4 Communications
- Sending transactional emails (registration confirmation, password reset, invitations).
- Notifications regarding account security and Service updates.
- Alerts and reports configured by the user.
4. Legal Basis for Processing (GDPR Article 6)
We process your personal data on the following legal bases:
- Performance of a contract (Art. 6.1.b): processing is necessary for the performance of the subscription agreement to which you are a party (account creation, Service delivery, billing management).
- Legitimate interest (Art. 6.1.f): Service improvement, fraud prevention, system security, aggregated usage analysis.
- Consent (Art. 6.1.a): for marketing communications (if applicable) and non-essential cookies.
- Legal obligation (Art. 6.1.c): retention of billing data in compliance with accounting and tax obligations.
5. Data Sharing & Third Parties
We never sell your personal data. We share your data only with the following sub-processors, necessary for providing the Service:
| Sub-processor | Purpose | Data Processed | Location | Transfer safeguards |
|---|---|---|---|---|
| Convex | Database, serverless functions, real-time sync and file storage | All business and account data of the Service | European Union — AWS eu-west-1 (Ireland), dedicated EU deployment | Data hosted in the EU; US support access covered by SCCs (2021/914) |
| OVHcloud | Application hosting (web server of the Service) | Data in transit and technical server logs | European Union — France | No transfer outside the EU |
| Resend | Transactional email delivery (invitations, notifications, alerts) | Email addresses, content of outgoing emails | United States | SCCs (2021/914) |
| Stripe | Subscription payments and billing | Billing identity and contact details; card data is collected directly by Stripe and never passes through the Service | European Union, with intra-group transfers to Stripe, Inc. (United States) | SCCs (2021/914) and, where applicable, an active DPF certification |
| Anthropic | Default AI provider (assistant, plan generation, analyses) — no training on customer data | Contextual content of AI requests (excerpts of organization data needed for the request) | United States | SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available |
| OpenAI | Selected AI features and optional cloud transcription of crisis sessions (local alternative available) | Contextual content of AI requests; audio recordings of crisis sessions only when cloud transcription is enabled | United States | SCCs (2021/914) and, where applicable, an active DPF certification; per-organization "EU-only AI" option available |
| Mistral AI | "EU-only AI" option: substitute AI provider configurable per organization | Contextual content of AI requests when the organization opts in | European Union — France | No transfer outside the EU |
| Plausible Analytics | Aggregate, cookieless audience measurement (website and application) | Aggregate traffic statistics (page views, referrer); IP address processed in transit for counting, not stored | European Union | No transfer outside the EU |
| Microsoft Clarity | Heatmaps and anonymized session replay on the marketing site — consent-gated | Anonymized browsing interactions (clicks, scrolling) — never in-app data | European Union, with possible intra-group transfers to Microsoft Corporation (United States) | SCCs (2021/914) and, where applicable, an active DPF certification |
Note: error monitoring and performance tracking are performed in-house (logs stored in Convex, EU region) — no third-party provider such as Sentry is used for this purpose.
All our sub-processors are bound by Data Processing Agreements (DPA) compliant with the GDPR. We may also disclose data in response to a valid legal request from a competent authority.
6. International Data Transfers
Some of our sub-processors are located outside the European Economic Area (EEA), particularly in the United States. For these transfers, we implement the following safeguards:
- Standard Contractual Clauses (SCCs): we use the SCCs approved by the European Commission (Implementing Decision 2021/914) with each sub-processor located outside the EEA.
- EU-US Data Privacy Framework (DPF): where applicable, our US sub-processors are certified under the Data Privacy Framework.
- Additional measures: data encryption in transit (TLS 1.3) and at rest, transfer impact assessment, and technical measures to prevent unauthorized access.
7. Data Retention
We retain your data according to the following periods:
- Account data: for the duration of your subscription, then 30 days after termination to allow data export.
- Business data: for the duration of your subscription, then deleted 30 days after termination.
- Billing data: 10 years in compliance with French accounting and tax obligations.
- Technical server access logs: 12 months.
- Application audit log (SHA-256 integrity chain): 7 years by default for regulatory traceability (BCMS/DORA), reducible upon the organization's request (minimum 1 year) — see the DPA.
- Backups: daily backups are retained for 30 days, then automatically deleted.
- Free trial data: 30 days after the trial period expires, unless a subscription is activated.
At the end of retention periods, data is securely deleted from our systems and backups.
8. Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Right of access (Art. 15): obtain confirmation that your data is being processed and receive a copy of it.
- Right to rectification (Art. 16): correct inaccurate or incomplete data concerning you.
- Right to erasure (Art. 17): request the deletion of your data under the conditions provided by law.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, and machine-readable format (JSON). The Service provides built-in export tools.
- Right to object (Art. 21): object to the processing of your data based on legitimate interest.
- Right to restriction of processing (Art. 18): request restriction of processing in certain cases.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
- Right to lodge a complaint: with the CNIL (Commission Nationale de l'Informatique et des Libertes) or any other competent supervisory authority.
To exercise your rights, contact us at privacy@resiplan.eu. We will respond to your request within 30 days.
9. Cookies & Tracking
The Service uses the following cookies and technologies:
Strictly Necessary Cookies
- Authentication session: manages your login session (secure, HttpOnly cookie).
- Language preferences: stores your language choice (fr/en).
- Theme preferences: stores your light/dark mode selection.
These cookies are necessary for the operation of the Service and do not require consent.
Performance Cookies
- Internal error logs (Convex): error collection and technical metadata to improve the quality of the Service. Stored in-house in Convex (EU region), without recourse to a third-party provider such as Sentry.
- Web Vitals: measurement of browser performance indicators.
Audience-measurement cookies (consent-based)
The following trackers are set only after you accept them via the consent banner, and can be declined at any time:
- Microsoft Clarity: session-replay and heatmap cookies used to anonymously analyze site usability (data in the EU, possible intra-group transfers to the United States covered by SCCs 2021/914).
- Campaign attribution (first-party): an anonymous session identifier (sessionStorage) measuring the journey of visitors arriving from our marketing campaigns.
Plausible audience measurement sets no cookies and collects no personal data; in line with CNIL guidance, it does not require consent.
The Service uses no advertising cookies and no third-party retargeting or advertising-tracking tool (no Google Analytics, no ad network).
10. Security Measures
We implement appropriate technical and organizational measures to protect your data:
- Encryption: all data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- Authentication: passwords are hashed with secure algorithms; two-factor authentication (2FA) is available.
- Data isolation: multi-tenant architecture with strict data isolation between organizations.
- Access control: two-level role system (platform and organization) with the principle of least privilege.
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Content-Security-Policy.
- API protection: rate limiting, input validation (Zod), webhook signature verification (HMAC SHA-256).
- Backups: automated daily backups with 30-day retention.
- Monitoring: continuous error and anomaly monitoring via internal logs (Convex, EU region).
11. Children's Privacy
The Service is intended for professional use and is not designed for individuals under 16 years of age. We do not knowingly collect personal data from minors. If we discover that a minor's data has been collected, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal developments. In case of substantial changes:
- We will notify you by email and in-app notification at least 30 days before the changes take effect.
- The “last updated” date at the top of this page will be changed accordingly.
- Your continued use of the Service after the effective date constitutes acceptance of the modified policy.
13. Contact & DPO Information
For any questions regarding this Privacy Policy or to exercise your rights, contact us:
- Data Protection Officer: Cryptaguard BV - DPO Service
- Email: privacy@resiplan.eu
- General email: contact@resiplan.eu
- Website: https://www.resiplan.eu
You may also file a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertes): www.cnil.fr