Last updated: August 24, 2026

Privacy Policy

This policy explains what personal data EtcSec collects, how we use it, how long we retain it, and which rights you can exercise when using our identity security platform.

Data Controller

ETCSEC, a French société par actions simplifiée à associé unique (SASU) with share capital of €100.00, registered with the Evry Trade and Companies Register (RCS) under number 108 548 074, is the data controller for personal data collected through etcsec.com and the related platform services.

For any privacy or data processing request, contact: privacy@etcsec.com

Data protection

For any question about the protection of your personal data, a dedicated point of contact can be reached at:

dpo@etcsec.com

Information We Collect

Account data

  • Email address and name provided during registration
  • Organization name and workspace details
  • Authentication credentials stored in hashed form

Audit data

Security audit results submitted through ETC Collector for Active Directory and Microsoft Entra ID environments.

Self-hosted collection model

ETC Collector runs on your infrastructure. In standalone mode, collected data stays local. In SaaS mode, processed findings are transmitted to EtcSec over encrypted TLS connections with scoped authentication tokens.

Usage data

  • Browser type, IP address, and visited pages
  • Product usage analytics used to improve reliability and usability

How We Use Your Information

  • Provide and maintain the identity security audit service (legal basis: performance of the contract)
  • Generate security findings, MITRE ATT&CK mappings, and remediation guidance (legal basis: performance of the contract)
  • Send service communications such as security alerts and important product notices (legal basis: performance of the contract)
  • Improve platform reliability, detection coverage, and customer support (legal basis: legitimate interest)
  • Comply with legal and regulatory obligations (legal basis: legal obligation)

Data Storage and Security

  • Data is hosted within the European Union
  • Encryption at rest and encryption in transit are enabled
  • Scoped authentication tokens are used instead of long-lived shared secrets
  • Access controls and audit logging protect administrative actions
  • Security monitoring and internal reviews are performed on the production environment

Data Sharing

We do not sell your data. We do not disclose personal data to third parties for advertising or unrelated marketing purposes.

  • Cloudflare, Inc. — CDN, anti-bot protection, and reverse proxy (Cloudflare Turnstile)
  • SendGrid (Twilio Inc.) — sends the service's transactional emails from [email protected]
  • Google LLC (Google Tag Manager) — audience measurement, loaded only if you consent to analytics cookies
  • Ahrefs Pte Ltd — third-party audience measurement, loaded only if you consent to analytics cookies
  • Umami — analytics self-hosted by EtcSec, cookie-free and never shared with a third party
  • Competent authorities when disclosure is required by law or legal process

The service's primary hosting is located within the European Union. Google and Ahrefs are US-based companies: a transfer outside the European Union only occurs if you consent to analytics cookies, under the safeguards required by applicable law.

Your Rights Under GDPR

If GDPR applies to your data, you can exercise the following rights:

Right of access

Request a copy of the personal data we hold about you.

Right to rectification

Ask us to correct inaccurate or incomplete personal data.

Right to erasure

Request deletion of your personal data when applicable.

Right to restrict processing

Ask us to limit how we use your data in specific cases.

Right to data portability

Receive your data in a portable format when applicable.

Right to object

Object to certain processing activities where the law allows it.

Right to lodge a complaint

Lodge a complaint with the CNIL (the French data protection authority, EtcSec's lead supervisory authority) or with your local supervisory authority, if you believe your rights are not being respected.

Right to withdraw consent

Withdraw your consent to analytics cookies at any time, as easily as it was given, via the "Manage cookies" button in the footer.

To exercise these rights, contact privacy@etcsec.com.

Cookies and local storage

We set a cookie that remembers your consent and your language, and local storage for your theme, your consent detail, your device identifier, your session state, and the dismissal of certain banners. Only if you accept, third-party analytics and marketing cookies (Google Tag Manager, Ahrefs) may also be set — Umami sets none.

IdentifierPurposeDuration
etcsec_cookie_consentCookie — Stores your cookie preferences (all / essential / custom)1 year
etcsec_localeCookie — Remembers your language preference1 year
NEXT_LOCALECookie — Next.js locale sync (httpOnly)1 year
GTM-PL5D5NV4Third-party cookie — Google Tag Manager container, audience and marketing measurement; set only if you accept, exact cookies defined by the tags configured in the containerVariable, depends on the tags
analytics.ahrefs.comThird-party cookie — Ahrefs Analytics, third-party audience measurement, set only if you acceptVariable (managed by Ahrefs)
etcsec_themeLocal storage — Interface theme preferencePersistent
etcsec_consentLocal storage — Detail of your consent choice (analytics / marketing)Persistent
etcsec_device_idLocal storage — Your device identifier, for the "trusted devices" featurePersistent
etcsec_session_metaLocal storage — Your session expiry (the authentication token itself is an httpOnly cookie set by the cloud platform)Until sign-out
trial_upsell_dismissed_*Local storage — Remembers you dismissed the upsell banner for a given auditPersistent
blog_cta_dismissed_*Local storage — Remembers you dismissed the call-to-action banner for a given articlePersistent

Data Retention

  • Account data: retained while your account is active and for a limited period after deletion when required for support, security, or legal reasons.
  • Audit data: retained according to your subscription plan and workspace configuration; after account termination, it is retained for 30 days and then permanently deleted.
  • Anonymous trial results: retained for 7 days and then automatically purged; you can keep them beyond that window by creating a free account during that period.
  • Usage logs: kept for a limited period necessary for security monitoring, troubleshooting, and abuse prevention.

Job applications and recruitment

When you apply for a role at EtcSec, we process the information you send us as part of your application.

  • Purpose: to process your application and communicate with you about it.
  • Legal basis: pre-contractual measures taken at your request.
  • Retention period: 2 years maximum after our last contact with you, if your application is not retained.
  • Recipient: EtcSec's founder, the sole recipient of applications at this stage.
  • Your rights: the same rights described above, exercised via the same point of contact.
  • Your resume: it's submitted through the application form, attached to the internal email we receive, and is not stored on any of our servers.

Policy Changes and Contact

We may update this privacy policy from time to time. When changes materially affect how we process personal data, we will update the date above and, when appropriate, notify customers through the platform or by email.

If you have any question about this privacy policy, contact privacy@etcsec.com or visit our contact page.