New: export PCI DSS v4 evidence from real browser traffic.

Legal

Privacy Policy - CentralCSP

Last updated: July 9, 2026

1. Introduction and Scope

This Privacy Policy explains how CentralCSP ("CentralCSP", "we", "us", "our") collects, uses, and protects personal data. CentralCSP provides web security and compliance services centred on client-side monitoring: we collect and analyse the reports that browsers send through the Reporting API, maintain an inventory of the scripts running on our Clients' pages, generate event-based alerts, produce PCI DSS evidence, scan and evaluate website security configurations, and help our Clients build and optimise Content Security Policies (CSP) to defend against threats such as cross-site scripting (XSS) and data injection.

This policy applies to all personal data we process as a Data Controller. This includes data from visitors to our website (centralcsp.com), individuals who use our free tools (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool), registered users of our free trial and paid services, and individuals who contact us. It also explains our separate role as a Data Processor when we handle data on behalf of our Clients.

In line with data protection best practice, including the guidance of the French Data Protection Authority (CNIL) and the European Data Protection Board (EDPB), this policy is layered: summary tables and clear headings let you find what is relevant to you quickly, and each summary is followed by a fuller explanation. Our aim is to be concise, transparent, intelligible, and easily accessible, in keeping with the General Data Protection Regulation (GDPR).

2. Who We Are and How to Contact Us

2.1. Identity of the data controller

For the purposes of the GDPR and other applicable data protection laws, the Data Controller responsible for the processing described in this policy is:

2.2. Contact for privacy matters

For any question, concern, or request relating to your personal data or to the exercise of your rights, contact us at contact@centralcsp.com. You can also reach our data protection contact directly at theotime.quere@centralcsp.com.

2.3. Data protection contact

The GDPR requires a formal Data Protection Officer (DPO) where an organisation's core activities consist of processing operations that require regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data.

We have assessed our activities against the criteria in Article 37 of the GDPR. Our services are designed to process technical security telemetry rather than personal data: the personal data contained in browser reports and scan data is limited and largely incidental, and we do not profile end-users. On that basis we have determined that the appointment of a formal DPO is not mandatory for us at this time.

We nonetheless take accountability seriously and have designated an internal data protection contact, reachable at contact@centralcsp.com or theotime.quere@centralcsp.com, to oversee our data protection practices and handle related requests. We keep this determination under review as our services evolve.

3. Key Definitions

The distinction between "Client" and "End-User" is fundamental to this policy: it lets us explain clearly our different roles and responsibilities for each group's data.

4. Our Two Roles: Controller and Processor

CentralCSP acts in two distinct capacities under the GDPR. Understanding this dual role explains which parts of this policy apply to you.

4.1. CentralCSP as a Data Controller

We are the Controller when we determine the "why" and "how" of processing for our own business purposes. This applies to:

4.2. CentralCSP as a Data Processor

We are a Processor when we process personal data on behalf of, and under the instructions of, our Clients. In that scenario the Client is the Controller. This applies primarily to the Browser Reports and related security telemetry ingested through our monitoring service.

5. What We Process, Why, and On What Lawful Basis

Every processing activity must rest on a lawful basis under Article 6 of the GDPR. As a Controller, we rely principally on:

5.1. Summary of our processing (as a Data Controller)

When you...Categories of personal dataPurposeLawful basis
Browse centralcsp.comBrowser/device information, approximate location, pages viewed (cookieless, non-identifying analytics).To operate, secure, and measure the performance of our website.Legitimate interest.
Use any free tool (CSP Scanner, CSP Evaluator, CSP/SRI hash calculators, Security Headers Scanner, Reporting-API Checker, Compare)Submitted website URL, CSP policy or HTTP headers, IP address.To return the requested security analysis, and to maintain and improve our tools.Legitimate interest.
Register for a free trial or paid accountName, work email, company, password (hashed).To create and manage your account, authenticate you, and provide the service.Performance of a contract.
Use our paid services (monitoring, alerting, CSP Builder, PCI DSS, script inventory)Account and usage data, configuration, generated policies and reports, billing information.To deliver, maintain, support, and bill for the services you have subscribed to.Performance of a contract.
Contact usName, email, company (optional), the content of your message.To respond to your enquiry and manage our relationship with you, and to protect the form from abuse.Legitimate interest.

5.2. Free tools

Our free tools (the CSP Scanner, CSP Evaluator, CSP Hash Calculator, SRI Hash Calculator, Security Headers Scanner, Reporting-API Checker, and Compare tool) provide an immediate analysis of a site's security posture. When you submit a URL, policy, or set of headers, we process it, together with your IP address for security and abuse prevention, on the basis of our legitimate interest: first to provide the analysis you have requested, and second to maintain and improve our tools. The website URL, CSP policy, and headers you submit describe a website's configuration, not a person, and do not contain personal data; we retain them as described in Section 11. The processing is initiated by you and limited to the data you submit. Our browser extension runs entirely in your browser and sends us no data.

5.3. Registering for and using our services

When you sign up for a free trial or a paid account you enter into a service agreement with us. Processing your account data (name, email, hashed password) and usage data is necessary for the performance of that contract: to create and authenticate your account, provide the service, manage your subscription, process payments, and send you essential service notices (for example security alerts or billing information).

5.4. Contacting us

When you contact our support or sales teams we process the information you provide on the basis of our legitimate interest in responding to enquiries and managing our relationships.

5.5. Service communications

We do not send marketing or promotional communications, and we do not use your data to build a marketing profile. We only send communications that are necessary to provide the service, such as security alerts, billing notices, and important changes to our terms or this policy (transactional messages on the basis of performance of a contract).

6. Automated Processing and the CSP Builder

Our services, and the CSP Builder in particular, use automation to simplify security for our Clients. This section explains how that works.

6.1. How the CSP Builder works

The CSP Builder generates an optimised Content Security Policy for a Client's website by analysing the Browser Reports the site sends to our reporting endpoint over a chosen period. From these reports it identifies the external domains and resources the site legitimately needs, combines that analysis with security best practice and compliance requirements, and recommends a new, more secure policy.

6.2. Automated decision-making under Article 22 GDPR

Article 22 gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them. The CSP Builder does not fall within Article 22 because:

6.3. Safeguards

In line with guidance from authorities such as the CNIL, we apply safeguards to our automated processing:

6.4. No AI training on your data

We do not use your data, including account data, browser reports, scan results, and free-tool submissions, to train, fine-tune, or develop artificial intelligence or machine-learning models, and we do not share it with any third-party AI service. Our tools rely on rule-based analysis engines rather than generative AI.

7. Cookies and Analytics

Our marketing website centralcsp.com is designed to be cookieless. We do not use advertising or third-party tracking cookies on it, and we do not need a cookie consent banner for our analytics.

8. Sharing and Sub-processors

We do not sell your personal data. We share it only with carefully selected third-party providers (sub-processors) who help us run our business, under binding data processing agreements that require them to uphold strict security and data protection standards. Our lawful basis for this sharing is the same as for the underlying processing (performance of a contract or legitimate interest).

Sub-processorPurposeTypes of data processedLocation
OVHcloudCloud hosting and infrastructure for all core platform services and data.All Client and account data, service configuration, browser reports, scan results, backups.France (EU)
Bunny.netContent delivery network (CDN) for static assets and edge caching.IP address, browser/device information, requested URLs.European Union
ScalewayTransactional and notification email delivery.Name, email address, email content, engagement data.France (EU)
StripePayment processing for subscriptions and billing.Name, email, payment method, billing address, transaction details.Ireland (contracting entity); limited US transfers governed by DPF + SCC

9. International Data Transfers

Our aim is to keep your data within the European Economic Area (EEA) wherever possible.

9.1. Primary storage

All Client data and End-User data processed for our core services (including Browser Reports and all scan results from the Scanner, Evaluator, and CSP Builder) is stored and processed on OVHcloud servers within the European Union. Website scans that a Client requests are performed from within the European Union. This significantly reduces the complexity and risk of international transfers for our core service.

9.2. Safeguards for other transfers

Some ancillary sub-processors (for example our payment processor) may transfer limited data outside the EEA, in particular to the United States. Where we or a sub-processor transfers personal data to a country without an adequacy decision, the transfer is protected by a recognised GDPR mechanism, namely the European Commission's Standard Contractual Clauses and, where applicable, certification under the EU-US Data Privacy Framework.

10. Data Security

Securing the data we process is central to our mission. We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in line with the GDPR. These include:

11. Data Retention

In line with the GDPR's storage-limitation principle, we keep personal data in an identifiable form no longer than necessary for the purposes for which it was collected. Retention depends on the type of data and any legal obligations, and we review our schedule periodically.

Type of dataRetention periodJustification
Client account data (name, email, company)Kept until you delete your account; deleted thereafter, subject to legal retention obligations.Performance of contract; legitimate interest (business records); legal obligations (for example tax and accounting rules require keeping certain records after account deletion).
Browser Reports (processed for Clients)Rolling 90 days maximum (or sooner if you delete the corresponding website or workspace in the dashboard), then deleted or irreversibly aggregated.Necessary for monitoring, alerting, the CSP Builder, and statistics, which rely on recent historical data. Deleted automatically on a rolling basis.
Scan results (on-demand website scans, processed for Clients)No automatic expiry; kept until you delete the corresponding website or workspace in the dashboard.Performance of contract and legitimate interest: so you can track a site's security posture over time. Scan results describe a website's configuration.
Free tool submissions (CSP Scanner, CSP Evaluator, hash and header tools, etc.)Retained to operate and improve the tools.Legitimate interest: to let you review your results and to maintain and improve our tools. The website URL, CSP policy, and headers you submit describe a website's configuration.
Anonymised / aggregated statisticsIndefinitely.Used for service improvement, security research, and our periodic 'State of the Web' report.
Contact and support enquiriesFor as long as needed to handle the enquiry and for a reasonable period afterwards.Legitimate interest: context for future communications and quality control.

12. Your Data Protection Rights

Under the GDPR you have a number of rights over your personal data. This section applies to data for which we are the Controller.

12.1. How to exercise your rights

Submit your request in writing to contact@centralcsp.com. We will respond without undue delay and within one month of receipt at the latest; this may be extended by two further months where necessary given the complexity or number of requests, in which case we will tell you within the first month. We do not charge a fee unless your request is manifestly unfounded or excessive.

12.2. Your rights

You also have the right to lodge a complaint with a supervisory authority, in France the CNIL (www.cnil.fr).

12.3. An important note for End-Users

The rights above are exercised against the Data Controller.

If your request concerns data collected while you visited a third-party website that uses our services, you must direct it to the owner of that website. As a Processor we are legally bound to act on our Client's instructions and will assist them in responding, in accordance with our DPA.

13. Children's Privacy

Our services are intended for a professional audience and are not directed at individuals under 16. We do not knowingly collect personal data from children under 16. If we learn that we have inadvertently done so, we will delete it as soon as possible.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. When we do, we will update the "Last updated" date above. For material changes we will provide notice, for example by email to Clients or a prominent notice on our website before the change takes effect. We encourage you to review this policy periodically.

15. Language

This policy is published in English and French. The English version is authoritative; if there is any discrepancy between the two, the English version prevails.