GDPR

Privacy Policy

Processing of personal data at DarkMoon, in accordance with the GDPR: purposes, legal bases, retention periods, recipients, cookies, transfers and your rights.

Document being finalized, subject to legal review.

The French version is the legally binding version.

This policy describes the way in which ASC processes personal data, pursuant to Regulation (EU) 2016/679 (GDPR) and to French Act No. 78-17 of 6 January 1978 as amended. It distinguishes the processing for which the Publisher is the controller from that for which it acts as a processor on behalf of its clients.

Article 1 — Controller and contact

The controller is ASC, 4 rue de Dunkerque, Appt 9, 31200 Toulouse, France. For any question or to exercise your rights: contact@asc-it.fr. The need to appoint a data protection officer (DPO) within the meaning of Article 37 of the GDPR is the subject of a documented analysis in view of the processing of security data; failing an appointment, a data-protection referent is named.

Article 2 — Allocation of roles

The Publisher is the controller for: the management of accounts and authentication, the commercial relationship and billing, support, the security of its platforms, and prospecting.

The Publisher is a processor for the test and vulnerability data processed on behalf of a client (Pentest on Demand service and associated engagements): the client determines the scope and the purpose and remains the controller. The Data Processing Agreement governs this processing.

Self-hosted Community edition: the Publisher processes no user data; it provides a tool. The user is solely responsible for the processing carried out with the software. No telemetry is collected by this edition.

Self-hosted Pro editions: as the test data remains with the client, the Publisher has no access to it.

Article 3 — Processing, purposes, legal bases, retention periods and mandatory nature

The processing operations carried out by the Publisher as controller are as follows:

  • Account management and authentication (email, role, connection logs) — Purpose: provide access to the areas. Legal basis: performance of the contract (Art. 6.1.b). Retention: for the life of the account, then 5 years for the data strictly necessary to prove the contract.
  • One-time passcode (OTP) — Purpose: authenticate a connection. Legal basis: performance of the contract (Art. 6.1.b). Retention: deleted on use or on expiry (a few minutes).
  • Security logs and connection IP addresses — Purpose: security, prevention of fraud and abuse. Legal basis: legitimate interest (Art. 6.1.f; recital 49). Retention: 6 months, extendable to 1 year if the risk justifies it.
  • Billing and accounting (identity, company, SIREN/VAT, contact details, payment references) — Purpose: invoice, keep the accounts. Legal basis: legal obligation (Art. 6.1.c). Retention: 10 years (Art. L. 123-22 of the French Commercial Code).
  • Commercial relationship and support — Purpose: manage the relationship. Legal basis: performance of the contract (Art. 6.1.b). Retention: for the life of the relationship + 5 years.
  • Prospecting to a named business email address — Purpose: promote the services. Legal basis: legitimate interest (Art. 6.1.f) + Art. L. 34-5 of the French Post and Electronic Communications Code (opt-out). Retention: 3 years from the last contact.
  • Prospecting to a natural person (personal email address) and newsletter — Purpose: inform interested persons. Legal basis: consent (Art. 6.1.a). Retention: until consent is withdrawn.
  • Pentest order (company identity, contacts, electronic signature, IP, user agent) — Purpose: contractualise and prove the authorisation. Legal basis: performance of the contract (Art. 6.1.b) and evidentiary legitimate interest. Retention: the duration of the engagement + statutory evidentiary periods.
  • Test and vulnerability data (processing) — Purpose: perform the audit on the client's behalf. Legal basis: determined by the client acting as controller. Retention: the engagement + 60 days in the active database, then deletion or return.
  • Portal database back-ups — Purpose: continuity and security. Legal basis: legitimate interest (Art. 6.1.f). Retention: 30 days by rotation (IONOS, OVH, GitHub artefacts).

Mandatory nature of the provision: providing the email address and the identity and billing data is necessary for the conclusion and performance of the contract; failing this, the order cannot be processed. Non-essential prospecting data is optional. The Publisher draws up and keeps up to date the records provided for in Articles 30.1 and 30.2 of the GDPR as well as the legitimate-interest balancing analyses.

Article 4 — Recipients and sub-processors

The data is accessible to the Publisher's authorised staff and to the following providers, acting on instructions:

  • IONOS — Hosting of the website, the portal and the database — Germany (EU) — Intra-EU.
  • OVH — Continuous integration and back-ups — France (EU) — Intra-EU.
  • GitHub (Microsoft) — Continuous integration and retention of back-up artefacts — United States — Standard contractual clauses and/or Data Privacy Framework.
  • Stripe — Payment and billing — EU / United States — Data Privacy Framework (certified entity) or standard contractual clauses; a copy is available on request.
  • Cryptolens — Licence management — European Union (Sweden, hosting location to be confirmed) — Intra-EU, or standard contractual clauses where applicable.
  • Infomaniak (kmeet) — Debrief video conference — Switzerland — Adequacy decision.
  • AI model providers (Anthropic, OpenAI, OpenRouter, Mistral, Groq) — Processing of the product's requests — EU or a third country, or local — See Article 6.

The choice of AI model provider is made by the user for the self-hosted editions; for the Pentest on Demand service, it is made by the Publisher on the client's documented instruction (Article 6). A technical infrastructure flow (downloading images from a registry such as Docker Hub, in the United States) may expose the IP address of the user who performs it; this flow is outside the Publisher's processing scope for the self-hosted editions. The list of sub-processors is kept up to date and communicated on request; any change is notified to the clients concerned, who may object to it under the conditions of the Data Processing Agreement.

Article 5 — Cookies and trackers

The website uses session cookies strictly necessary for authentication and operation, exempt from consent pursuant to Article 82 of the French Data Protection Act. No advertising tracker or non-exempt third-party audience-measurement tool is placed without your consent. Any embedded third-party content liable to place cookies (for example a video hosted by an external service) or to transmit your IP address to a third party (for example fonts or stylesheets loaded from an external content delivery network) is loaded only after your consent has been obtained, by means of a cookie-management banner allowing refusal as easily as acceptance; consent is sought again at most every six (6) months. A dedicated page details each tracker (name, purpose, duration, issuer).

Article 6 — Transfers outside the European Union and the role of the Privacy Gateway

Where the user, or the Publisher on the client's documented instruction, chooses to run DarkMoon with an AI model hosted outside the European Union, data may be transmitted to that provider. These transfers are framed by an adequacy decision (in particular the Data Privacy Framework where the provider is certified) or, failing this, by the standard contractual clauses of Implementing Decision (EU) 2021/914, supplemented by a transfer impact assessment and by supplementary measures.

The Privacy Gateway constitutes a minimisation and pseudonymisation measure within the meaning of Article 4(5) of the GDPR: before transmission to the model, the identified sensitive values are replaced by deterministic markers, the mapping table remaining in the user's environment. In its default configuration, it covers IP addresses, internal host names and email addresses. Extended coverage (domains, URLs, paths, identifiers) can be enabled; secret-type credentials are protected only when they are explicitly registered. Consequently: the use of a model hosted outside the European Union to process personal data is subject to the activation of the extended coverage, the Privacy Gateway constituting a sufficient supplementary measure only under this condition; the residual flows remain covered by the applicable transfer mechanism and documented in the impact assessment. The fully local mode (self-hosted AI model) entails no transfer of the test data to a model provider; technical infrastructure calls may remain (Article 4). This mode is recommended for the most sensitive data.

Article 7 — Security

The Publisher implements technical and organisational measures appropriate to the risk (Article 32 of the GDPR): systematic encryption of communications in transit; encryption at rest of the vulnerability deliverables (AES-256-GCM); for the portal database, access-control measures, with infrastructure-level encryption and encryption of the back-ups being rolled out; pseudonymisation via the Privacy Gateway; least privilege and compartmentalisation; logging; back-ups. The vulnerability data is subject to reinforced measures. The Publisher carries out a screening under Article 35 to determine whether a data protection impact assessment is required for its own processing. In the event of a data breach presenting a risk, the Publisher notifies the CNIL within 72 hours (Article 33) and, in the event of a high risk, informs the data subjects (Article 34); as a processor, it notifies the client acting as controller within the time limit set in the Data Processing Agreement.

Article 8 — Your rights

You have the rights of access, rectification, erasure, restriction, objection and portability, the right to withdraw your consent at any time, and the right to lay down directives on the fate of your data after your death. The right to object to prospecting is absolute. You exercise these rights at the address in Article 1; the Publisher responds within a period of one (1) month, extendable by two (2) months for complex requests, by means of a traceable erasure procedure covering the active database and the back-up reserve. Where your request concerns data processed on behalf of a client (test data), the Publisher directs you to that client, who is the controller, and assists it. You may lodge a complaint with the CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr).

Article 9 — Data not collected directly from you

Some data may be obtained indirectly: business contact details from public sources in the context of prospecting, or third-party data exposed during an audit and transmitted by our client. In accordance with Article 14 of the GDPR, we inform you, at the latest at the time of the first communication, of the origin of the data, of the categories concerned and of the purposes, and you may exercise all of your rights (Article 8).

Article 10 — Automated decision-making

DarkMoon takes no decision producing legal effects concerning you based solely on automated processing within the meaning of Article 22 of the GDPR. The results generated by the AI are decision-support aids intended to be reviewed by a professional.

Article 11 — Updates

This policy may be updated. The applicable version is the one published at the date of consultation. Version of 20 August 2026.