﻿---
title: "Privacy Policy - CentralCSP"
description: "How CentralCSP, the EU-hosted client-side security platform, collects, uses, and protects your personal data."
url: "https://centralcsp.com/en/legal/privacy/"
lang: "en"
---

Legal

# Privacy Policy - CentralCSP

Last updated: August 9, 2026  Effective: September 13, 2026

## 1\. Introduction and Scope

This Privacy Policy explains how CentralCSP ("CentralCSP", "we", "us", "our") collects, uses, and protects personal data. CentralCSP provides web security and compliance services centred on client-side monitoring: we collect and analyse the reports that browsers send through the Reporting API, maintain an inventory of the scripts running on our Clients' pages, generate event-based alerts, produce PCI DSS evidence, scan and evaluate website security configurations, and help our Clients build and optimise Content Security Policies (CSP) to defend against threats such as cross-site scripting (XSS) and data injection.

This policy applies to all personal data we process as a Data Controller. This includes data from visitors to our website (centralcsp.com), individuals who use our free tools (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool), registered users of our free trial and paid services, and individuals who contact us. It also explains our separate role as a Data Processor when we handle data on behalf of our Clients.

In line with data protection best practice, including the guidance of the French Data Protection Authority (CNIL) and the European Data Protection Board (EDPB), this policy is layered: summary tables and clear headings let you find what is relevant to you quickly, and each summary is followed by a fuller explanation. Our aim is to be concise, transparent, intelligible, and easily accessible, in keeping with the General Data Protection Regulation (GDPR).

## 2\. Who We Are and How to Contact Us

### 2.1. Identity of the data controller

For the purposes of the GDPR and other applicable data protection laws, the Data Controller responsible for the processing described in this policy is:

-   Company: CentralSaaS, _société par actions simplifiée_ (SAS), operating the CentralCSP service
-   Registered office: 1 Allée des Frênes, 38240 Meylan, France
-   RCS: Grenoble 927 890 756
-   Contact: [contact@centralcsp.com](mailto:contact@centralcsp.com)

Full statutory information (share capital, SIRET, VAT number, hosting) is available on our [Legal Notice](https://centralcsp.com/en/legal/mentions-legales/) page.

### 2.2. Contact for privacy matters

For any question, concern, or request relating to your personal data or to the exercise of your rights, contact us at [contact@centralcsp.com](mailto:contact@centralcsp.com), which reaches our data protection contact.

### 2.3. Data protection contact

The GDPR requires a formal Data Protection Officer (DPO) where an organisation's core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data.

We have assessed our activities against the criteria in Article 37 of the GDPR. Our services are designed to process technical security telemetry rather than personal data: the personal data contained in browser reports and scan data is limited and largely incidental, and we do not profile end-users. On that basis we have determined that the appointment of a formal DPO is not mandatory for us at this time.

We nonetheless take accountability seriously and have designated an internal data protection contact, reachable at [contact@centralcsp.com](mailto:contact@centralcsp.com), to oversee our data protection practices and handle related requests. We keep this determination under review as our services evolve.

## 3\. Key Definitions

-   **Personal Data**: any information relating to an identified or identifiable natural person ("Data Subject"), including direct identifiers such as a name or email address, and indirect identifiers such as an IP address, an online identifier, or a URL where it can be linked back to an individual.
-   **Processing**: any operation performed on Personal Data, whether automated or not, including collection, recording, storage, analysis, use, disclosure, and erasure.
-   **Data Subject**: the individual to whom the Personal Data relates, whether a Client or an End-User.
-   **Client**: the individual or entity that registers for and uses CentralCSP's services, including free trials and paid subscriptions. Our contractual relationship is with the Client.
-   **End-User**: an individual who visits or interacts with a website or application operated by one of our Clients. We have no direct relationship with End-Users.
-   **Data Controller**: the party that determines the purposes and means of the processing of Personal Data.
-   **Data Processor**: the party that processes Personal Data on behalf of the Controller.
-   **Browser Report**: a report generated by a web browser through the Reporting API and sent to a designated endpoint. This includes Content Security Policy (CSP), Network Error Logging (NEL), deprecation, intervention, crash, Cross-Origin-Opener-Policy / Cross-Origin-Embedder-Policy (COOP/COEP), Document-Policy, Certificate Transparency, and integrity reports. Such reports typically describe a technical event (for example a blocked resource and the page where it occurred) and may incidentally contain personal data such as an IP address, or identifiers embedded in a URL or query string.

The distinction between "Client" and "End-User" is fundamental to this policy: it lets us explain clearly our different roles and responsibilities for each group's data.

## 4\. Our Two Roles: Controller and Processor

CentralCSP acts in two distinct capacities under the GDPR. Understanding this dual role explains which parts of this policy apply to you.

### 4.1. CentralCSP as a Data Controller

We are the Controller when we determine the "why" and "how" of processing for our own business purposes. This applies to:

-   **Client account information**: name, work email, company, and a hashed password, collected when a Client registers, so we can create and manage the account, authenticate the Client, and provide the service.
-   **Billing and subscription information**: the information needed to process payments and manage subscriptions, handled by our third-party payment processor.
-   **Website visitor data**: technical data such as browser and device information processed when you visit centralcsp.com. Our marketing website is cookieless and our analytics do not identify you (see Section 7).
-   **Free tool usage data**: the website URL, CSP policy, or HTTP headers you submit to a free tool (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, or Compare tool), processed to return the requested analysis.
-   **Communication data**: your name, contact details, and message content when you contact us through our contact form or by email.

### 4.2. CentralCSP as a Data Processor

We are a Processor when we process personal data on behalf of, and under the instructions of, our Clients. In that scenario the Client is the Controller. This applies primarily to the Browser Reports and related security telemetry ingested through our monitoring service.

-   **How it works**: our service provides Clients with a reporting endpoint. The Client configures their website to send Browser Reports to this endpoint, and we collect and analyse the resulting telemetry, maintain a script inventory, detect known vulnerabilities (CVEs), raise alerts, generate PCI DSS evidence, and help build CSP policies.
-   **Data processed**: the data within these reports (which may include an End-User's IP address, the page visited, and the blocked or referenced resource) is Personal Data of the End-User. We process it solely to provide our services to the Client.
-   **The Client's responsibility**: as the Controller for their End-Users' data, the Client is responsible for having a lawful basis (for example legitimate interest) to collect this data and to instruct us to process it, and for informing their End-Users in their own privacy notice.
-   **Data Processing Agreement (DPA)**: our processing on the Client's behalf is governed by our [Data Processing Agreement](https://centralcsp.com/en/legal/dpa/), which sets out our obligations as a Processor, including processing only on the Client's instructions, applying appropriate security measures, and assisting the Client with its own GDPR obligations.

## 5\. What We Process, Why, and On What Lawful Basis

Every processing activity must rest on a lawful basis under Article 6 of the GDPR. As a Controller, we rely principally on:

-   **Performance of a contract (Art. 6(1)(b))**: where processing is necessary to provide a service you have requested or to take pre-contract steps.
-   **Legitimate interests (Art. 6(1)(f))**: where we have a legitimate business interest that is not overridden by your rights.
-   **Consent (Art. 6(1)(a))**: where you have given clear, affirmative agreement for a specific purpose.

### 5.1. Summary of our processing (as a Data Controller)

| When you... | Categories of personal data | Purpose | Lawful basis |
| --- | --- | --- | --- |
| Browse centralcsp.com | Browser/device information, approximate location, pages viewed (cookieless, non-identifying analytics). | To operate, secure, and measure the performance of our website. | Legitimate interest. |
| Use any free tool (CSP Scanner, CSP Evaluator, CSP/SRI hash calculators, Security Headers Scanner, Reporting-API Checker, Compare) | Submitted website URL, CSP policy or HTTP headers. Your IP address is used to apply rate limits and appears in our server security logs, but is not stored with the submission. | To return the requested security analysis, and to maintain and improve our tools. | Legitimate interest. |
| Register for a free trial or paid account | Name, work email, company, password (hashed). | To create and manage your account, authenticate you, and provide the service. | Performance of a contract. |
| Use our paid services (monitoring, alerting, CSP Builder, PCI DSS, script inventory) | Account and usage data, configuration, generated policies and reports, billing information. | To deliver, maintain, support, and bill for the services you have subscribed to. | Performance of a contract. |
| Contact us | Name, email, company (optional), the content of your message. | To respond to your enquiry and manage our relationship with you, and to protect the form from abuse. | Legitimate interest. |

### 5.2. Free tools

Our free tools (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool) provide an immediate analysis of a site's security posture. When you submit a URL, policy, or set of headers, we process it on the basis of our legitimate interest: first to provide the analysis you have requested, and second to maintain and improve our tools. The processing is initiated by you and limited to the data you submit.

What you submit is intended to describe a website's configuration rather than a person, and in most cases it contains no personal data. It can nonetheless contain personal data where an identifier is embedded in a URL or query string you submit, for example a session token, a user ID, or an email address in a parameter. We treat any such identifier as personal data, and we ask that you avoid submitting URLs that contain one.

We do not keep your submission as an individual record. Submissions are aggregated into anonymous statistics, which contain no personal data and no IP address and which we keep indefinitely, as described in Section 11.

By submitting a URL to a tool that fetches or scans it, you confirm that you own the corresponding website or that you have authorisation from its owner to have it analysed. We apply rate limits to detect and prevent abuse. Your IP address appears in our server security logs, which we keep for twelve (12) months, but it is not stored with your submission.

Our browser extension runs entirely in your browser and sends us no data.

### 5.3. Registering for and using our services

When you sign up for a free trial or a paid account you enter into a service agreement with us. Processing your account data (name, email, hashed password) and usage data is necessary for the performance of that contract: to create and authenticate your account, provide the service, manage your subscription, process payments, and send you essential service notices (for example security alerts or billing information).

### 5.4. Contacting us

When you contact our support or sales teams we process the information you provide on the basis of our legitimate interest in responding to enquiries and managing our relationships.

### 5.5. Service communications

We do not send marketing or promotional communications, and we do not use your data to build a marketing profile. We only send communications that are necessary to provide the service, such as security alerts, billing notices, and important changes to our terms or this policy (transactional messages on the basis of performance of a contract).

## 6\. Automated Processing and the CSP Builder

Our services, and the CSP Builder in particular, use automation to simplify security for our Clients. This section explains how that works.

### 6.1. How the CSP Builder works

The CSP Builder generates an optimised Content Security Policy for a Client's website by analysing the Browser Reports the site sends to our reporting endpoint over a chosen period. From these reports it identifies the external domains and resources the site legitimately needs, combines that analysis with security best practice and compliance requirements, and recommends a new, more secure policy.

### 6.2. Automated decision-making under Article 22 GDPR

Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. The CSP Builder does not fall within Article 22 because:

-   **No legal or significant effect on individuals**: its output is a technical policy recommendation delivered to our Client (a developer or administrator), not to the End-User. The policy governs which resources a browser may load; it does not affect an End-User's legal status or deny them a service.
-   **Human intervention**: the process is not solely automated. An interactive review and approval workflow requires the Client to review, assess, and approve any recommended policy before it is deployed. The Client remains the decision-maker.

### 6.3. Safeguards

In line with guidance from authorities such as the CNIL, we apply safeguards to our automated processing:

-   **Purpose limitation**: report data is processed only to provide the service to the specific Client that is its source, namely generating and optimising CSP policies, delivering security insights, maintaining the script inventory, detecting vulnerabilities (CVEs), and raising alerts. It is not used to profile End-Users or for any unrelated purpose.
-   **Data minimisation and aggregation**: the system identifies patterns from aggregated data (for example "domain cdn.example.com was requested 10,000 times") rather than tracking any single End-User.
-   **A rule-based engine**: the CSP Builder is a rule-based analysis engine, not a generative large language model, and its recommendations are always subject to the Client's review before deployment.

### 6.4. No AI training on your data

We do not use your data, including account data, browser reports, scan results, and free-tool submissions, to train, fine-tune, or develop artificial intelligence or machine-learning models, and we do not ourselves disclose it to any third-party AI provider or service. Our tools rely on rule-based analysis engines rather than generative AI.

### 6.5. When you connect an AI assistant yourself

This commitment describes what we do with your data. It does not restrict what you choose to do with it.

Our platform offers an API and an MCP (Model Context Protocol) integration, which exist so you can connect your own tools, including an AI assistant or agent, to your CentralCSP workspace. If you enable one of these, the data you request flows from us to the destination you have chosen, on your instruction. That transmission is initiated and controlled by you, not by us. You are responsible for it, including for the terms on which the recipient handles the data, for whether it is used to train a model, and for any transfer outside the European Economic Area that results. The same applies to alerts you route to a channel such as Slack, Microsoft Teams, PagerDuty, an email address, or a webhook endpoint.

## 7\. Cookies and Analytics

Our marketing website centralcsp.com is designed to be cookieless. We do not use advertising or third-party tracking cookies on it, and we do not need a cookie consent banner for our analytics.

-   **Analytics**: we measure website performance with a privacy-focused, cookieless analytics tool that we self-host on our EU infrastructure. It does not use cookies, does not collect personal data for advertising, does not build cross-site profiles, and does not track you across websites. Aggregated, non-identifying metrics are processed on the basis of our legitimate interest, consistent with CNIL guidance on audience measurement.
-   **Authenticated services**: our sign-in service (auth.centralcsp.com) and dashboard (app.centralcsp.com) are separate from this marketing website and use only strictly necessary cookies (for example a session token to keep you signed in and a routing cookie). They are self-hosted on our EU infrastructure, are essential to provide the service you have requested, and are not used for tracking.

## 8\. Sharing, Service Providers and Sub-processors

We do not sell your personal data. We share it only with carefully selected third-party service providers who help us run our business, under binding data processing agreements that require them to uphold strict security and data protection standards. Our lawful basis for this sharing is the same as for the underlying processing (performance of a contract or legitimate interest).

| Recipient | Purpose | Types of data processed | Location |
| --- | --- | --- | --- |
| OVHcloud | Cloud hosting and infrastructure for all core platform services and data. | All Client and account data, service configuration, browser reports, scan results, backups. | France (EU) |
| Bunny.net | Content delivery network (CDN) and edge layer, including in front of the reporting endpoint, and delivery of static assets. | IP address, browser/device information, requested URLs, and browser reports in transit through the reporting endpoint edge. | European Union |
| Scaleway | Transactional and notification email delivery. | Name, email address, email content, engagement data. | France (EU) |
| Stripe | Payment processing for subscriptions and billing. | Name, email, payment method, billing address, transaction details. | Ireland (contracting entity); limited US transfers governed by DPF + SCC |

OVHcloud, Bunny.net and Scaleway are also Sub-processors of Client Data within the meaning of our [Data Processing Agreement](https://centralcsp.com/en/legal/dpa/), and are listed in its Annex 3. Stripe is not: we engage it for our own billing purposes as an independent controller, so it receives account and billing data but never Client Data, and it is deliberately absent from that Annex.

Stripe processes payments as our processor when facilitating transactions, and additionally acts as an independent data controller for certain purposes inherent to payment processing (such as fraud monitoring, compliance with anti-money-laundering law, and its relationships with banks and card networks), as described in its own privacy documentation.

### 8.1. Destinations you choose

The providers above are ones we engage to run our platform. They are distinct from the destinations you configure yourself: an alert channel (Slack, Microsoft Teams, PagerDuty, an email address, a webhook endpoint) or an AI assistant connected through our API or MCP integration. Those are not our sub-processors: you engage them directly, and data reaches them because you instructed us to send it. We do not control what they do with it. Section 6.5 explains this in more detail.

## 9\. International Data Transfers

Our aim is to keep your data within the European Economic Area (EEA) wherever possible.

### 9.1. Primary storage

All Client data and End-User data processed for our core services (including Browser Reports and all scan results from the Scanner, Evaluator, and CSP Builder) is stored and processed on OVHcloud servers within the European Union. Website scans that a Client requests are performed from within the European Union. This significantly reduces the complexity and risk of international transfers for our core service.

### 9.2. Safeguards for other transfers

Some ancillary sub-processors (for example our payment processor) may transfer limited data outside the EEA, in particular to the United States. Where we or a sub-processor transfers personal data to a country without an adequacy decision, the transfer is protected by a recognised GDPR mechanism, namely the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework.

### 9.3. Transfers you initiate

Our EU-residency commitment covers the data we hold on our own infrastructure and that of our sub-processors. It does not cover destinations you choose. If you route alerts to a channel hosted outside the EEA, or connect an AI assistant through our API or MCP integration, that transfer is made on your instruction and under your control. Where you act as a Controller, you are responsible for identifying the appropriate transfer mechanism for it.

## 10\. Data Security

Securing the data we process is central to our mission. We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in line with the GDPR. These include:

-   **Encryption**: data is encrypted in transit using industry-standard TLS (1.2 or higher), and all data we store, including backups and generated policies, is encrypted at rest using AES-256.
-   **Access control**: access to personal data is restricted to authorised personnel on a need-to-know basis under the principle of least privilege, with multi-factor authentication for production systems.
-   **Pseudonymisation**: passwords are stored using irreversible hashing.
-   **Resilience and redundancy**: our infrastructure is designed for high availability, with regular backups to enable restoration after an incident.
-   **Testing and auditing**: we run regular vulnerability scans and security assessments.
-   **Abuse prevention**: automated measures protect our website, forms, and tools against bots and automated abuse. They run on our own EU infrastructure and share no data with any third party.
-   **Breach response**: we identify and investigate personal data breaches. Where a breach affects data we process for a Client, we notify the Client (the Controller) without undue delay so it can meet its own notification obligations.

## 11\. Data Retention

In line with the GDPR's storage-limitation principle, we keep personal data in an identifiable form no longer than necessary for the purposes for which it was collected. Retention depends on the type of data and any legal obligations, and we review our schedule periodically.

| Type of data | Retention period | Justification |
| --- | --- | --- |
| Client account data (name, email, company) | Kept until you delete your account; deleted thereafter, subject to legal retention obligations. | Performance of contract; legitimate interest (business records); legal obligations (for example tax and accounting rules require keeping certain records after account deletion). |
| Browser Reports (processed for Clients) | Rolling 90 days maximum (or sooner if you delete the corresponding website or workspace in the dashboard), then deleted or irreversibly aggregated. | Necessary for monitoring, alerting, the CSP Builder, and statistics, which rely on recent historical data. Deleted automatically on a rolling basis. |
| Scan results (on-demand website scans, processed for Clients) | No expiry. Kept indefinitely or aggregated into statistics. | Performance of contract and legitimate interest: so you can track a site's security posture over time and so we can produce security statistics. Scan results are designed to describe a website's publicly accessible configuration; where one incidentally contains personal data (for example an identifier embedded in a submitted URL), we delete or redact it on request. |
| Free tool submissions (CSP Scanner, CSP Evaluator, hash and header tools, etc.) | Not kept as an individual record. Submissions are aggregated into anonymous statistics, which contain no personal data and no submitter IP address, and which are kept indefinitely. | Legitimate interest: to maintain and improve our tools and to produce security statistics. Free-tool users have no account, so we aggregate rather than keep individual submissions we could not later link to a deletion request. |
| Website visitor and analytics data (centralcsp.com) | Aggregated, non-identifying metrics retained for 24 months. No individual visitor record is kept. | Legitimate interest: measuring and improving the performance of our website. Our analytics are cookieless and do not identify you. |
| Security, access, and audit logs | 12 months, then deleted. Logs relating to an active security investigation are kept until it closes. | Legitimate interest: detecting, investigating, and responding to security incidents and abuse; and demonstrating accountability. |
| Anonymised / aggregated statistics | Indefinitely. | Used for service improvement, security research, and our periodic 'State of the Web' report. This data is no longer personal data. |
| Contact and support enquiries | 36 months from the last contact, then deleted. | Legitimate interest: context for future communications and quality control. |
| Billing and accounting records | 10 years from the end of the financial year. | Legal obligation: Article L.123-22 of the French Code de commerce. |

## 12\. Your Data Protection Rights

Under the GDPR you have a number of rights over your personal data. This section applies to data for which we are the Controller.

### 12.1. How to exercise your rights

Submit your request in writing to [contact@centralcsp.com](mailto:contact@centralcsp.com). We will respond without undue delay and within one month of receipt at the latest; this may be extended by two further months where necessary given the complexity or number of requests, in which case we will tell you within the first month. We do not charge a fee unless your request is manifestly unfounded or excessive.

### 12.2. Your rights

-   **To be informed**: to receive clear, transparent information about how we use your data (which is why we provide this policy).
-   **Of access**: to obtain a copy of your personal data and related information.
-   **To rectification**: to have inaccurate or incomplete data corrected.
-   **To erasure** ("right to be forgotten"): to have your data deleted where there is no overriding reason for us to keep it (this is not an absolute right).
-   **To restrict processing**: to have further use of your data suppressed in certain circumstances.
-   **To data portability**: to receive and reuse data you provided to us where processing is based on consent or contract and carried out by automated means.
-   **To object**: to object to processing based on our legitimate interests, and to object to direct marketing at any time.
-   **To withdraw consent**: where a processing operation is based on your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
-   **To set post-mortem directives**: under Article 85 of the French _Loi Informatique et Libertés_, to define directives on the retention, erasure, and communication of your personal data after your death, and to designate a person responsible for their execution. You may register or update such directives, or designate that person, by contacting us at the address above; absent directives, your heirs may exercise the rights provided by law.
-   **In relation to automated decision-making**: not to be subject to a decision based solely on automated processing with legal or similarly significant effects. As explained in Section 6, our services do not carry out such processing.

You also have the right to lodge a complaint with a supervisory authority, in France the CNIL ([www.cnil.fr](http://www.cnil.fr)).

### 12.3. An important note for End-Users

The rights above are exercised against the Data Controller.

-   If you are a **Client**, you can exercise your rights directly with us regarding your account and usage data.
-   If you are an **End-User** of one of our Clients' websites, the Controller for any data contained in a Browser Report is the owner of that website (our Client).

If your request concerns data collected while you visited a third-party website that uses our services, you must direct it to the owner of that website. As a Processor we are legally bound to act on our Client's instructions and will assist them in responding, in accordance with our DPA.

## 13\. Children's Privacy

Our services are intended for a professional audience and are not directed at individuals under 16. We do not knowingly collect personal data from children under 16. If we learn that we have inadvertently done so, we will delete it as soon as possible.

## 14\. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we do, we will update the "Last updated" date above. For material changes we will give notice at least thirty (30) days before the change takes effect, by email to Clients or by a prominent notice on our website.

This policy is a notice, not a contract. Changes to it do not modify the Terms of Service, which are amended only as set out in Section 11.7 of those Terms.

## 15\. Language

This policy is published in English and French. The English version is authoritative; if there is any discrepancy between the two, the English version prevails.

---

Available in: [en](https://centralcsp.com/en/legal/privacy/), [fr](https://centralcsp.com/fr/legal/privacy/)
