CountAct

Privacy Policy for CountAct Applications

Updated on June 30, 2026

CountAct Applications Privacy Policy

Version 2.1 – June 2026

1. Preamble and Scope

This privacy policy (hereinafter the "Policy") describes how CountAct collects, uses and protects the personal data of users of the applications it publishes and which are accessible from its unified login page.

It applies to all applications published by CountAct, whether property security applications, personal security applications, or any other digital application published by CountAct, in their web and mobile versions.

This Policy does not cover the countact.fr showcase website, which has its own privacy policy accessible from its legal notice.

The General Terms of Use of CountAct Applications supplement this Policy by defining the contractual framework for use.

For the purposes of this Policy, the following terms have the meaning given to them by Article 4 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter "GDPR"), in particular: "personal data", "processing", "data controller", "data processor" and "data subject".

2. Data Controller

The controller of personal data collected in connection with CountAct applications is:

CountAct, a simplified joint-stock company (société par actions simplifiée), registered with the Trade and Companies Register under SIREN number 911 314 144, with its registered office at 24 rue Raspail, 38000 Grenoble, France, represented by its acting legal representative.

Any request relating to this Policy may be sent to dpo@countact.fr or by post to the registered office.

3. Data Protection Officer

CountAct has appointed a Data Protection Officer (DPO) reporting to Senior Management, in accordance with the functional independence requirements set out in Article 38.3 of the GDPR.

The appointment of the DPO has been officially declared to the French Data Protection Authority (Commission Nationale de l'Informatique et des Libertés, "CNIL").

The Data Protection Officer can be contacted at dpo@countact.fr or by post at the registered office address.

4. Data Collected and Purposes of Processing

The data collected varies depending on the CountAct application used. The following subsections describe the categories of data processed and the purposes pursued for each type of user.

4.1 Users of property security applications

In connection with property security applications (in particular regulatory compliance, risk analysis and document management), CountAct collects the following categories of data:

  • Professional identification data: last name, first name, professional e-mail address, job title and client organization
  • Technical account data: unique user identifier, connection logs, IP address
  • Business data entered by the user in the application: business objects (sites, branches, buildings and equivalent entities), compliance documents and their associated attributes
  • Documents uploaded by the user in the application: files in PDF and PNG format

This data is processed for the following purposes:

  • Enabling use of the application in accordance with its intended features
  • User account management (creation, authentication, modification, deletion)
  • Traceability of actions carried out in the application for compliance purposes
  • Production of aggregated and anonymized usage statistics
4.2 Users of personal security applications

In connection with personal security applications (in particular reporting, alert communication and coordination in risk situations), CountAct collects the following categories of data:

  • User identification data: last name, first name, e-mail address, unique user identifier
  • Data entered by the user in the application: manually entered emergency contacts, notes and reports
  • Device permissions: access to the microphone and to photos, requested when the application is first launched, allowing users to attach voice recordings or photos to their reports and alerts
  • Technical data of the device used: device identifier, operating system version, application version

This data is processed for the following purposes:

  • Enabling use of the application in accordance with its intended features
  • User account management
  • Sending security notifications
  • Internal security-related communication within the client organization
4.3 Mobile applications and cross-cutting note

Regardless of the functional scope they provide access to (property security applications or personal security applications), the mobile applications published by CountAct do not carry out any collection of geolocation data, nor any capture of Bluetooth signals, Wi-Fi, beacons or telecommunication antenna identifiers.

5. Legal Bases for Processing

In accordance with Article 6 of the GDPR, the processing carried out by CountAct is based on the following legal bases, depending on the purpose pursued:

  • Performance of the contract entered into with the client (Article 6.1.b of the GDPR): for user account management, the provision of the applications and associated support
  • Compliance with a legal obligation (Article 6.1.c of the GDPR): for security logging and archiving required by applicable legal and regulatory obligations
  • CountAct's legitimate interest (Article 6.1.f of the GDPR): for information system security, fraud prevention and improvement of the applications
  • The data subject's consent (Article 6.1.a of the GDPR): for optional informational communications

6. Retention Periods

CountAct retains personal data for a period strictly necessary for the purposes for which it is processed, in accordance with the following table:

  • User account data: 3 years from the last login
  • Connection and security audit logs: 1 year
  • Technical backups: 30 days
  • Business data entered in the application: duration of the client contract, plus the applicable legal archiving period
  • Customer support tickets and correspondence: duration of the client contract, plus 5 years for contractual limitation purposes

At the end of the periods indicated, the data is irreversibly deleted or anonymized.

7. Recipients and Data Processors

The personal data collected is intended for:

  • CountAct personnel authorized to access it strictly within the scope of their duties, on a need-to-know basis
  • Data processors within the meaning of Article 28 of the GDPR, acting on behalf of CountAct under contractually defined conditions

The main data processors involved in processing the data handled by CountAct applications are as follows:

  • Amazon Web Services (AWS): hosting of the web and mobile applications, OCR services (Amazon Textract) and artificial intelligence inference (Amazon Bedrock) — France (Paris)
  • OVH: domain name system (DNS) management — France
  • HubSpot: ticketing tool for customer support — Germany (EU)

A detailed description of the data processing arrangements and a Data Processing Agreement can be provided to clients upon contractual request.

In accordance with Article 28.4 of the GDPR, in the event of the addition of a new data processor or the replacement of an existing data processor likely to process the client's data, the client will be informed in advance and will have a right to object.

8. Hosting and Transfers Outside the European Union

Personal data processed by CountAct applications is hosted exclusively within the European Union: in France for the main hosting (AWS) and domain name management (OVH) services, and in Germany for the customer support ticketing tool (HubSpot).

9. Security Measures

CountAct implements appropriate technical and organizational measures to ensure a level of security adapted to the risks, in accordance with Article 32 of the GDPR. These measures include in particular the encryption of data at rest and in transit, access control, multi-factor authentication, traceability of actions, regular backups, vulnerability monitoring, automatic anti-malware scanning of files uploaded by users, and strict separation of environments.

Details of the security measures implemented may be provided to clients as part of supplier security questionnaires, upon request.

10. Use of Artificial Intelligence

Some CountAct applications include a data-entry assistance module based on a language model hosted on CountAct's cloud infrastructure in the European region, without any data being sent to a third-party provider.

This module is intended to facilitate the completion of fields when reviewing documents uploaded to the application. Each suggestion made by the module is subject to manual validation by the user before being taken into account. No suggestion is applied automatically.

Each decision suggested by the module is logged for traceability and auditability purposes, in accordance with the requirements of Regulation (EU) 2024/1689 (the "AI Act"). This log includes in particular the identifier of the model used, the associated confidence indicator and the user's validation status.

No decision producing legal effects or significantly affecting the user is made in a fully automated manner within the meaning of Article 22 of the GDPR. No profiling is carried out.

This processing complies with the principles of Regulation (EU) 2024/1689 (the "AI Act") and falls within the category of limited-risk artificial intelligence systems.

11. Rights of Data Subjects

In accordance with the GDPR and French Act No. 78-17 of 6 January 1978, as amended, any person concerned by processing carried out by CountAct has the following rights:

  • Right of access to their data (Article 15 of the GDPR)
  • Right to rectification of inaccurate or incomplete data (Article 16 of the GDPR)
  • Right to erasure of data under the conditions set out in the GDPR (Article 17 of the GDPR)
  • Right to restriction of processing (Article 18 of the GDPR)
  • Right to data portability (Article 20 of the GDPR)
  • Right to object to processing (Article 21 of the GDPR)
  • Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before its withdrawal
  • Right to set directives regarding the fate of their data after death (Article 85 of the French Data Protection Act)

12. Exercising Rights and Lodging a Complaint with the CNIL

The rights mentioned in section 11 may be exercised by sending a request to dpo@countact.fr or by post to the registered office address. Proof of identity may be requested in the event of reasonable doubt as to the identity of the requester, in accordance with Article 12.6 of the GDPR.

CountAct undertakes to respond within one month of receiving the request. This period may be extended by a further two months in the event of a complex request or a high number of requests, in accordance with Article 12.3 of the GDPR. In such cases, the data subject is informed of this extension and the reasons for it.

In accordance with Article 77 of the GDPR, any data subject has the right to lodge a complaint with a supervisory authority, in particular the French Data Protection Authority (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, or online via the form available at www.cnil.fr.

13. Changes to this Policy

CountAct may amend this Policy to adapt it to legislative, regulatory, case-law, technical or organizational developments.

The date of the last update appears on the first page of this Policy. In the event of a substantial change, application users are informed by e-mail and by a message displayed at their next login.

The history of previous versions of this Policy may be provided upon request sent to dpo@countact.fr.

14. Cookies

The web versions of CountAct applications use only cookies that are strictly necessary to keep the login session active between visits. No audience-measurement, tracking or advertising cookies are used.

In accordance with Article 82 of the French Data Protection Act, these cookies, being strictly necessary to provide the service requested by the user, do not require prior consent.

15. Contact

For any question relating to this Policy or the exercise of data subjects' rights:

  • Data Protection Officer: dpo@countact.fr
  • Postal address: CountAct, 24 rue Raspail, 38000 Grenoble, France