Legal
Privacy Policy - CentralCSP
Last updated: July 9, 2026
1. Introduction and Scope
This Privacy Policy explains how CentralCSP ("CentralCSP", "we", "us", "our") collects, uses, and protects personal data. CentralCSP provides web security and compliance services centred on client-side monitoring: we collect and analyse the reports that browsers send through the Reporting API, maintain an inventory of the scripts running on our Clients' pages, generate event-based alerts, produce PCI DSS evidence, scan and evaluate website security configurations, and help our Clients build and optimise Content Security Policies (CSP) to defend against threats such as cross-site scripting (XSS) and data injection.
This policy applies to all personal data we process as a Data Controller. This includes data from visitors to our website (centralcsp.com), individuals who use our free tools (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool), registered users of our free trial and paid services, and individuals who contact us. It also explains our separate role as a Data Processor when we handle data on behalf of our Clients.
In line with data protection best practice, including the guidance of the French Data Protection Authority (CNIL) and the European Data Protection Board (EDPB), this policy is layered: summary tables and clear headings let you find what is relevant to you quickly, and each summary is followed by a fuller explanation. Our aim is to be concise, transparent, intelligible, and easily accessible, in keeping with the General Data Protection Regulation (GDPR).
2. Who We Are and How to Contact Us
2.1. Identity of the data controller
For the purposes of the GDPR and other applicable data protection laws, the Data Controller responsible for the processing described in this policy is:
- Company: CentralSaaS (operating the CentralCSP service)
- Address: 1 Allée des Frênes, 38240 Meylan, France
- SIRET: 927 890 756 00012
- VAT: FR36927890756
- Country: France
- Contact: contact@centralcsp.com
- Hosting provider: OVHcloud, 2 rue Kellermann, 59100 Roubaix, France
2.2. Contact for privacy matters
For any question, concern, or request relating to your personal data or to the exercise of your rights, contact us at contact@centralcsp.com. You can also reach our data protection contact directly at theotime.quere@centralcsp.com.
2.3. Data protection contact
The GDPR requires a formal Data Protection Officer (DPO) where an organisation's core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data.
We have assessed our activities against the criteria in Article 37 of the GDPR. Our services are designed to process technical security telemetry rather than personal data: the personal data contained in browser reports and scan data is limited and largely incidental, and we do not profile end-users. On that basis we have determined that the appointment of a formal DPO is not mandatory for us at this time.
We nonetheless take accountability seriously and have designated an internal data protection contact, reachable at contact@centralcsp.com or theotime.quere@centralcsp.com, to oversee our data protection practices and handle related requests. We keep this determination under review as our services evolve.
3. Key Definitions
- Personal Data: any information relating to an identified or identifiable natural person ("Data Subject"), including direct identifiers such as a name or email address, and indirect identifiers such as an IP address, an online identifier, or a URL where it can be linked back to an individual.
- Processing: any operation performed on Personal Data, whether automated or not, including collection, recording, storage, analysis, use, disclosure, and erasure.
- Data Subject: the individual to whom the Personal Data relates, whether a Client or an End-User.
- Client: the individual or entity that registers for and uses CentralCSP's services, including free trials and paid subscriptions. Our contractual relationship is with the Client.
- End-User: an individual who visits or interacts with a website or application operated by one of our Clients. We have no direct relationship with End-Users.
- Data Controller: the party that determines the purposes and means of the processing of Personal Data.
- Data Processor: the party that processes Personal Data on behalf of the Controller.
- Browser Report: a report generated by a web browser through the Reporting API and sent to a designated endpoint. This includes Content Security Policy (CSP), Network Error Logging (NEL), deprecation, intervention, crash, Cross-Origin-Opener-Policy / Cross-Origin-Embedder-Policy (COOP/COEP), Document-Policy, Certificate Transparency, and integrity reports. Such reports typically describe a technical event (for example a blocked resource and the page where it occurred) and may incidentally contain personal data such as an IP address, or identifiers embedded in a URL or query string.
The distinction between "Client" and "End-User" is fundamental to this policy: it lets us explain clearly our different roles and responsibilities for each group's data.
4. Our Two Roles: Controller and Processor
CentralCSP acts in two distinct capacities under the GDPR. Understanding this dual role explains which parts of this policy apply to you.
4.1. CentralCSP as a Data Controller
We are the Controller when we determine the "why" and "how" of processing for our own business purposes. This applies to:
- Client account information: name, work email, company, and a hashed password, collected when a Client registers, so we can create and manage the account, authenticate the Client, and provide the service.
- Billing and subscription information: the information needed to process payments and manage subscriptions, handled by our third-party payment processor.
- Website visitor data: technical data such as browser and device information processed when you visit centralcsp.com. Our marketing website is cookieless and our analytics do not identify you (see Section 7).
- Free tool usage data: the website URL, CSP policy, or HTTP headers you submit to a free tool (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, or Compare tool), processed to return the requested analysis.
- Communication data: your name, contact details, and message content when you contact us through our contact form or by email.
4.2. CentralCSP as a Data Processor
We are a Processor when we process personal data on behalf of, and under the instructions of, our Clients. In that scenario the Client is the Controller. This applies primarily to the Browser Reports and related security telemetry ingested through our monitoring service.
- How it works: our service provides Clients with a reporting endpoint. The Client configures their website to send Browser Reports to this endpoint, and we collect and analyse the resulting telemetry, maintain a script inventory, detect known vulnerabilities (CVEs), raise alerts, generate PCI DSS evidence, and help build CSP policies.
- Data processed: the data within these reports (which may include an End-User's IP address, the page visited, and the blocked or referenced resource) is Personal Data of the End-User. We process it solely to provide our services to the Client.
- The Client's responsibility: as the Controller for their End-Users' data, the Client is responsible for having a lawful basis (for example legitimate interest) to collect this data and to instruct us to process it, and for informing their End-Users in their own privacy notice.
- Data Processing Agreement (DPA): our processing on the Client's behalf is governed by our Data Processing Agreement, which sets out our obligations as a Processor, including processing only on the Client's instructions, applying appropriate security measures, and assisting the Client with its own GDPR obligations.
5. What We Process, Why, and On What Lawful Basis
Every processing activity must rest on a lawful basis under Article 6 of the GDPR. As a Controller, we rely principally on:
- Performance of a contract (Art. 6(1)(b)): where processing is necessary to provide a service you have requested or to take pre-contract steps.
- Legitimate interests (Art. 6(1)(f)): where we have a legitimate business interest that is not overridden by your rights.
- Consent (Art. 6(1)(a)): where you have given clear, affirmative agreement for a specific purpose.
5.1. Summary of our processing (as a Data Controller)
| When you... | Categories of personal data | Purpose | Lawful basis |
|---|---|---|---|
| Browse centralcsp.com | Browser/device information, approximate location, pages viewed (cookieless, non-identifying analytics). | To operate, secure, and measure the performance of our website. | Legitimate interest. |
| Use any free tool (CSP Scanner, CSP Evaluator, CSP/SRI hash calculators, Security Headers Scanner, Reporting-API Checker, Compare) | Submitted website URL, CSP policy or HTTP headers, IP address. | To return the requested security analysis, and to maintain and improve our tools. | Legitimate interest. |
| Register for a free trial or paid account | Name, work email, company, password (hashed). | To create and manage your account, authenticate you, and provide the service. | Performance of a contract. |
| Use our paid services (monitoring, alerting, CSP Builder, PCI DSS, script inventory) | Account and usage data, configuration, generated policies and reports, billing information. | To deliver, maintain, support, and bill for the services you have subscribed to. | Performance of a contract. |
| Contact us | Name, email, company (optional), the content of your message. | To respond to your enquiry and manage our relationship with you, and to protect the form from abuse. | Legitimate interest. |
5.2. Free tools
Our free tools (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool) provide an immediate analysis of a site's security posture. When you submit a URL, policy, or set of headers, we process it, together with your IP address for security and abuse prevention, on the basis of our legitimate interest: first to provide the analysis you have requested, and second to maintain and improve our tools. The website URL, CSP policy, and headers you submit describe a website's configuration, not a person, and do not contain personal data; we retain them as described in Section 11. The processing is initiated by you and limited to the data you submit. Our browser extension runs entirely in your browser and sends us no data.
5.3. Registering for and using our services
When you sign up for a free trial or a paid account you enter into a service agreement with us. Processing your account data (name, email, hashed password) and usage data is necessary for the performance of that contract: to create and authenticate your account, provide the service, manage your subscription, process payments, and send you essential service notices (for example security alerts or billing information).
5.4. Contacting us
When you contact our support or sales teams we process the information you provide on the basis of our legitimate interest in responding to enquiries and managing our relationships.
5.5. Service communications
We do not send marketing or promotional communications, and we do not use your data to build a marketing profile. We only send communications that are necessary to provide the service, such as security alerts, billing notices, and important changes to our terms or this policy (transactional messages on the basis of performance of a contract).
6. Automated Processing and the CSP Builder
Our services, and the CSP Builder in particular, use automation to simplify security for our Clients. This section explains how that works.
6.1. How the CSP Builder works
The CSP Builder generates an optimised Content Security Policy for a Client's website by analysing the Browser Reports the site sends to our reporting endpoint over a chosen period. From these reports it identifies the external domains and resources the site legitimately needs, combines that analysis with security best practice and compliance requirements, and recommends a new, more secure policy.
6.2. Automated decision-making under Article 22 GDPR
Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. The CSP Builder does not fall within Article 22 because:
- No legal or significant effect on individuals: its output is a technical policy recommendation delivered to our Client (a developer or administrator), not to the End-User. The policy governs which resources a browser may load; it does not affect an End-User's legal status or deny them a service.
- Human intervention: the process is not solely automated. An interactive review and approval workflow requires the Client to review, assess, and approve any recommended policy before it is deployed. The Client remains the decision-maker.
6.3. Safeguards
In line with guidance from authorities such as the CNIL, we apply safeguards to our automated processing:
- Purpose limitation: report data is processed only to provide the service to the specific Client that is its source, namely generating and optimising CSP policies, delivering security insights, maintaining the script inventory, detecting vulnerabilities (CVEs), and raising alerts. It is not used to profile End-Users or for any unrelated purpose.
- Data minimisation and aggregation: the system identifies patterns from aggregated data (for example "domain cdn.example.com was requested 10,000 times") rather than tracking any single End-User.
- A rule-based engine: the CSP Builder is a rule-based analysis engine, not a generative large language model, and its recommendations are always subject to the Client's review before deployment.
6.4. No AI training on your data
We do not use your data, including account data, browser reports, scan results, and free-tool submissions, to train, fine-tune, or develop artificial intelligence or machine-learning models, and we do not share it with any third-party AI service. Our tools rely on rule-based analysis engines rather than generative AI.
7. Cookies and Analytics
Our marketing website centralcsp.com is designed to be cookieless. We do not use advertising or third-party tracking cookies on it, and we do not need a cookie consent banner for our analytics.
- Analytics: we measure website performance with a privacy-focused, cookieless analytics tool (Plausible, self-hosted on our EU infrastructure). It does not use cookies, does not collect personal data for advertising, does not build cross-site profiles, and does not track you across websites. Aggregated, non-identifying metrics are processed on the basis of our legitimate interest, consistent with CNIL guidance on audience measurement.
- Authenticated services: our sign-in service (auth.centralcsp.com) and dashboard (app.centralcsp.com) are separate from this marketing website and use only strictly necessary cookies (for example a session token to keep you signed in and a routing cookie). They are self-hosted on our EU infrastructure, are essential to provide the service you have requested, and are not used for tracking.
8. Sharing and Sub-processors
We do not sell your personal data. We share it only with carefully selected third-party providers (sub-processors) who help us run our business, under binding data processing agreements that require them to uphold strict security and data protection standards. Our lawful basis for this sharing is the same as for the underlying processing (performance of a contract or legitimate interest).
| Sub-processor | Purpose | Types of data processed | Location |
|---|---|---|---|
| OVHcloud | Cloud hosting and infrastructure for all core platform services and data. | All Client and account data, service configuration, browser reports, scan results, backups. | France (EU) |
| Bunny.net | Content delivery network (CDN) for static assets and edge caching. | IP address, browser/device information, requested URLs. | European Union |
| Scaleway | Transactional and notification email delivery. | Name, email address, email content, engagement data. | France (EU) |
| Stripe | Payment processing for subscriptions and billing. | Name, email, payment method, billing address, transaction details. | Ireland (contracting entity); limited US transfers governed by DPF + SCC |
9. International Data Transfers
Our aim is to keep your data within the European Economic Area (EEA) wherever possible.
9.1. Primary storage
All Client data and End-User data processed for our core services (including Browser Reports and all scan results from the Scanner, Evaluator, and CSP Builder) is stored and processed on OVHcloud servers within the European Union. Website scans that a Client requests are performed from within the European Union. This significantly reduces the complexity and risk of international transfers for our core service.
9.2. Safeguards for other transfers
Some ancillary sub-processors (for example our payment processor) may transfer limited data outside the EEA, in particular to the United States. Where we or a sub-processor transfers personal data to a country without an adequacy decision, the transfer is protected by a recognised GDPR mechanism, namely the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework.
10. Data Security
Securing the data we process is central to our mission. We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in line with the GDPR. These include:
- Encryption: data is encrypted in transit using industry-standard TLS, and sensitive data (including backups and generated policies) is encrypted at rest.
- Access control: access to personal data is restricted to authorised personnel on a need-to-know basis under the principle of least privilege, with multi-factor authentication for production systems.
- Pseudonymisation: passwords are stored using irreversible hashing.
- Resilience and redundancy: our infrastructure is designed for high availability, with regular backups to enable restoration after an incident.
- Testing and auditing: we run regular vulnerability scans and security assessments.
- Abuse prevention: automated measures protect our website, forms, and tools against bots and automated abuse. They run on our own EU infrastructure and share no data with any third party.
- Breach response: we maintain a formal procedure to identify, investigate, and respond to personal data breaches. Where a breach affects data we process for a Client, we notify the Client (the Controller) without undue delay so it can meet its own notification obligations.
11. Data Retention
In line with the GDPR's storage-limitation principle, we keep personal data in an identifiable form no longer than necessary for the purposes for which it was collected. Retention depends on the type of data and any legal obligations, and we review our schedule periodically.
| Type of data | Retention period | Justification |
|---|---|---|
| Client account data (name, email, company) | Kept until you delete your account; deleted thereafter, subject to legal retention obligations. | Performance of contract; legitimate interest (business records); legal obligations (for example tax and accounting rules require keeping certain records after account deletion). |
| Browser Reports (processed for Clients) | Rolling 90 days maximum (or sooner if you delete the corresponding website or workspace in the dashboard), then deleted or irreversibly aggregated. | Necessary for monitoring, alerting, the CSP Builder, and statistics, which rely on recent historical data. Deleted automatically on a rolling basis. |
| Scan results (on-demand website scans, processed for Clients) | No automatic expiry; kept until you delete the corresponding website or workspace in the dashboard. | Performance of contract and legitimate interest: so you can track a site's security posture over time. Scan results describe a website's configuration. |
| Free tool submissions (CSP Scanner, CSP Evaluator, hash and header tools, etc.) | Retained to operate and improve the tools. | Legitimate interest: to let you review your results and to maintain and improve our tools. The website URL, CSP policy, and headers you submit describe a website's configuration. |
| Anonymised / aggregated statistics | Indefinitely. | Used for service improvement, security research, and our periodic 'State of the Web' report. |
| Contact and support enquiries | For as long as needed to handle the enquiry and for a reasonable period afterwards. | Legitimate interest: context for future communications and quality control. |
12. Your Data Protection Rights
Under the GDPR you have a number of rights over your personal data. This section applies to data for which we are the Controller.
12.1. How to exercise your rights
Submit your request in writing to contact@centralcsp.com. We will respond without undue delay and within one month of receipt at the latest; this may be extended by two further months where necessary given the complexity or number of requests, in which case we will tell you within the first month. We do not charge a fee unless your request is manifestly unfounded or excessive.
12.2. Your rights
- To be informed: to receive clear, transparent information about how we use your data (which is why we provide this policy).
- Of access: to obtain a copy of your personal data and related information.
- To rectification: to have inaccurate or incomplete data corrected.
- To erasure ("right to be forgotten"): to have your data deleted where there is no overriding reason for us to keep it (this is not an absolute right).
- To restrict processing: to have further use of your data suppressed in certain circumstances.
- To data portability: to receive and reuse data you provided to us where processing is based on consent or contract and carried out by automated means.
- To object: to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- In relation to automated decision-making: not to be subject to a decision based solely on automated processing with legal or similarly significant effects. As explained in Section 6, our services do not carry out such processing.
You also have the right to lodge a complaint with a supervisory authority, in France the CNIL (www.cnil.fr).
12.3. An important note for End-Users
The rights above are exercised against the Data Controller.
- If you are a Client, you can exercise your rights directly with us regarding your account and usage data.
- If you are an End-User of one of our Clients' websites, the Controller for any data contained in a Browser Report is the owner of that website (our Client).
If your request concerns data collected while you visited a third-party website that uses our services, you must direct it to the owner of that website. As a Processor we are legally bound to act on our Client's instructions and will assist them in responding, in accordance with our DPA.
13. Children's Privacy
Our services are intended for a professional audience and are not directed at individuals under 16. We do not knowingly collect personal data from children under 16. If we learn that we have inadvertently done so, we will delete it as soon as possible.
14. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we do, we will update the "Last updated" date above. For material changes we will provide notice, for example by email to Clients or a prominent notice on our website before the change takes effect. We encourage you to review this policy periodically.
15. Language
This policy is published in English and French. The English version is authoritative; if there is any discrepancy between the two, the English version prevails.