PRIVACY
Information on the processing of personal data under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). Here you will find what data we collect, why, how long we keep it and how to exercise your rights.
Last updated: 4 August 2026 · Version 1.0
Enya Security — sole trader under French law
Controller: Marina Bruno
SIRET: 993 348 382 00017
NACE/APE code: 6201Z
Email: marinabruno@enyasecurity.com
Enya Security has not appointed a DPO: the conditions set out in Article 37 of the GDPR are not met. For any question relating to personal data, you can write directly to the controller at the address shown alongside.
This policy covers the enyasecurity.com website and the contacts arising from it. Enya Security is established in France: the GDPR and French Act no. 78-17 (Informatique et Libertés) apply.
Data you provide
Data collected automatically
We do not collect special categories of data (Article 9 GDPR) and we ask you not to enter any in the contact form. If you need to send us sensitive information as part of an audit, this is done through a dedicated channel set out in the contract.
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry and identifying together the most suitable service | Pre-contractual steps taken at your request — Art. 6(1)(b) GDPR |
| Preparing a quote, entering into and performing the contract | Performance of a contract — Art. 6(1)(b) GDPR |
| Issuing and keeping invoices and accounting records | Legal obligation to which the controller is subject — Art. 6(1)(c) GDPR |
| Keeping the website secure and operational (technical logs, abuse protection) | Legitimate interest in protecting the site and preventing abuse — Art. 6(1)(f) GDPR |
| Measuring website audience in aggregate form | Consent, withdrawable at any time — Art. 6(1)(a) GDPR |
| Establishing or defending legal claims, in the event of a dispute | Legitimate interest — Art. 6(1)(f) GDPR |
We do not use your data for automated marketing or profiling. No automated decision-making within the meaning of Article 22 of the GDPR takes place.
Providing your data is optional, but name, email and message are needed for us to reply: without them we are unable to follow up on your enquiry.
Your data is never sold, rented or traded to third parties for commercial purposes. It is processed by Marina Bruno, the only person in the organisation with access to it.
To run the website and the mailbox we rely on a number of technical providers, acting as processors under Article 28 of the GDPR, on the basis of contracts binding them to our instructions:
| Provider | Role | Location / transfers |
|---|---|---|
| Formspree, Inc. | Delivery of messages sent through the contact form | United States — European Commission standard contractual clauses |
| GitHub, Inc. | Website hosting (GitHub Pages) | United States — standard contractual clauses |
| Cloudflare, Inc. | Content delivery and protection against attacks | United States — standard contractual clauses |
| Google Ireland Ltd. | Audience measurement (Google Analytics), only with your consent | Ireland, with possible transfers to Google LLC (United States) |
| OVH SAS | Business email hosting | France — no transfer outside the European Union |
Transfers outside the European Union. Some of these providers are based in the United States. Transfers rely on the standard contractual clauses adopted by the European Commission (Art. 46 GDPR) and, where applicable, on the providers' certification under the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023). You may ask us for a copy of the safeguards applied.
Data may also be shared with our accountant and, on a reasoned request, with the competent authorities where the law requires it.
| Category | Retention period |
|---|---|
| Enquiries not followed by an engagement | 24 months from the last contact, then deleted |
| Client data (contracts, engagement correspondence) | Duration of the relationship, then archived until the applicable limitation period expires |
| Invoices and accounting records | 10 years (French accounting obligation, Art. L123-22 of the Commercial Code) |
| Technical data collected during an audit engagement | Deleted within 30 days of report delivery, with a certificate of deletion |
| Website and security logs | Up to 12 months |
| Audience measurement data | 2 months (event and user data, Google Analytics configuration) |
| Proof of cookie consent | 12 months |
At the end of these periods, data is securely deleted or irreversibly anonymised.
Security is our profession and we apply to ourselves the measures we recommend to clients, in line with Article 32 of the GDPR:
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform you directly where the risk is high (Articles 33 and 34 GDPR).
Under Articles 15 to 22 of the GDPR you have the right to:
To exercise these rights, write to marinabruno@enyasecurity.com. We reply within one month of receiving the request. We may ask for an element confirming your identity where there is reasonable doubt about who is making the request.
Complaints. If you believe the processing of your data does not comply with the regulation, you may lodge a complaint with the French supervisory authority, competent because Enya Security is established in France (CNIL), or with the supervisory authority of the country where you habitually reside.
When we carry out an audit, the data we access belongs to the client, who remains the controller: in that context Enya Security acts as a processor, on the basis of a dedicated agreement (DPA) and rules of engagement signed before any work begins.
Our services are non-intrusive, declarative and diagnostic in nature: we carry out no penetration testing and no active exploitation of vulnerabilities. Technical data collected is deleted within 30 days of report delivery and the client receives a certificate of deletion.
No non-essential cookie is placed before you give your consent. The banner is managed by Tarteaucitron and you can change your choices at any time.
| Cookie | Purpose | Lifetime | Consent |
|---|---|---|---|
| tarteaucitron | Stores your cookie preferences | 12 months | Exempt (essential cookie) |
| _ga | Distinguishes website visitors (Google Analytics 4) | 12 months | Required |
| _ga_BB0S06Q6LJ | Persists the measurement session state (Google Analytics 4) | 12 months | Required |
Manage your cookie preferences — you can accept or refuse, either as a whole or tool by tool, and change your mind whenever you like. Refusing does not restrict access to any of the website's content.
You can also configure your browser to block cookies. Some statistical functions will then be unavailable, but the website will continue to work normally.
Minors. This website is aimed at professionals and organisations. It is not intended for minors and we do not knowingly collect data from people under 16. If you believe this has happened, write to us and we will delete the data.
External links. This website may link to third-party sites. Enya Security does not control those sites and is not responsible for their personal data practices.
Changes. This policy may be updated to reflect changes in our services or in the applicable regulation. The version in force is always the one published on this page, with the last update date shown at the top. Where changes are substantial, we will inform the people concerned whenever we hold their contact details.