Privacy policy
Last updated: September 13, 2026
This English version is provided for convenience. In case of discrepancy, the French version prevails.
How Mindstack, the publisher of FirmVox, processes personal data, pursuant to Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act.
1. Data controller
MINDSTACK (SAS), 59 rue de Ponthieu, bureau 326, 75008 Paris, France. Contact: contact@firmvox.io.
No data protection officer has been appointed. Data-protection matters are handled by Anthony L'Hostis, who can be reached at contact@firmvox.io.
2. The free diagnostic collects nothing
The diagnostic questionnaire and the resulting report are computed entirely in the browser. Until the user saves the report to an account, no answer is transmitted to our servers. Answers are kept in the browser's local storage so the questionnaire can be resumed; they are erased with the “start over” button or from the browser settings.
3. Data processed with an account
An account is required to save a diagnostic, unlock a report, activate monitoring or use the assistant. The following data is then processed:
- Identity and account: e-mail address, name, organisation and role within it, collected at sign-up through our authentication provider.
- Diagnostics: product name and profile (category, connectivity, sector, declared characteristics), economic role, questionnaire answers and computed results.
- Monitoring: submitted software bills of materials (components and versions), identified vulnerabilities, generated alerts and notification drafts.
- Billing: customer identifier with our payment provider, subscription and payment status. Card data never passes through our servers.
- Assistant: questions asked are sent to the language-model provider to produce the answer; we do not retain them.
- Audit log: timestamps of significant actions (diagnostic creation, bill-of-materials upload, payment, notification generation), kept as evidence of the vulnerability-handling process.
4. Purposes and legal bases
- Providing the subscribed service and managing the account — performance of the contract.
- Invoicing and keeping accounting records — legal obligation.
- Sending vulnerability alerts to the users concerned — performance of the contract.
- Ensuring the security of the service and the traceability of actions — legitimate interest of the publisher and its customers.
- Informing customers of service changes that directly concern them — legitimate interest; you may object at any time at contact@firmvox.io, with no effect on security alerts, which arise from the contract.
5. Recipients and processors
Data is processed by the following providers on behalf of Mindstack:
- Fly.io, Inc. (United States) — application hosting, on machines located in the Paris region; participant in the EU-U.S. Data Privacy Framework.
- Supabase Pte. Ltd. (Singapore) — database hosting, in a data centre located in Frankfurt, Germany (eu-central-1 region); European Commission standard contractual clauses.
- Clerk, Inc. (United States) — account creation and authentication; data hosted in the United States, participant in the EU-U.S. Data Privacy Framework, EU representative: VeraSafe Ireland Ltd. (Cork, Ireland).
- Stripe Payments Europe, Ltd. (Ireland) — payment and invoicing.
- Mistral AI (France) — generation of the assistant's answers.
- Cal.com, Inc. — scheduling for the guided diagnostic; data entered when booking is subject to its own privacy policy.
- Plus Five Five, Inc. (Resend, United States) — delivery of monitoring alert e-mails; e-mails and their metadata are processed in the United States; standard contractual clauses and the EU-U.S. Data Privacy Framework.
No data is sold or passed on to third parties for commercial purposes.
6. Transfers outside the European Union
Application hosting (Paris) and the database (Frankfurt) are located in the European Union. Four providers are established outside the Union: Fly.io, Inc., Clerk, Inc. and Plus Five Five, Inc. (Resend), in the United States, participants in the EU-U.S. Data Privacy Framework — Clerk additionally having an EU representative under Article 27 GDPR, and Resend also committing to standard contractual clauses —, and Supabase Pte. Ltd. (Singapore), which commits to the European Commission's standard contractual clauses in its data processing agreement. Account data (identity, e-mail address, organisation) is therefore processed in the United States by Clerk, and alert recipients' e-mail addresses by Resend.
7. Retention periods
- Account and diagnostic data: for the duration of the contractual relationship, then three years after account closure.
- Billing data: ten years, under accounting obligations.
- Audit log: retained for five years from the record date, including after account closure. This log evidences the vulnerability-handling process that Regulation (EU) 2024/2847 requires to be documented; its retention falls under the exception to the right to erasure provided for in Article 17(3) GDPR.
- Free diagnostic answers: in the user's browser only, until the user erases them.
8. Cookies
The site uses no audience-measurement tool and no advertising tracker. The only cookies set are strictly necessary: authentication session cookies and language preference. They do not require consent.
9. Security
Data is encrypted in transit and at rest. Access to an organisation's data is restricted to its members. The audit log is designed to be tamper-proof: it can be neither modified nor deleted, including by the application itself.
10. Your rights
You have the right to access, rectify, erase, restrict, object to and port your data, as well as the right to set directives on its fate after your death. To exercise them: contact@firmvox.io. You may lodge a complaint with the CNIL, the French supervisory authority.
We respond within thirty days. Requests must be sent from the e-mail address associated with the account; otherwise, proof of identity may be requested to prevent fraudulent disclosure or deletion.
11. Changes
This policy may be updated. The date of the last change appears at the top of the page.