Skip to main content
own2pwn

Privacy Policy

Last updated:

1. Introduction

own2pwn (hereinafter "own2pwn", "we", "our") places the utmost importance on protecting your personal data and respecting your privacy.

This Policy informs you how we collect, use, share and protect your personal data when you use the website own2pwn.fr and our Services (EASM, AI-Native AppSec, pentest engagements, technical scope of the NIS2 audit).

This policy complies with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the amended French Data Protection Act of 6 January 1978.

2. Data controller

  • Trade name: own2pwn
  • Company: THE HIVE (SASU (French single-shareholder simplified joint-stock company))
  • SIREN: 937 694 875, RCS Nice
  • Email: contact@own2pwn.fr

GDPR contact:

THE HIVE has not appointed a Data Protection Officer: its activity meets none of the conditions for mandatory appointment under article 37 of the GDPR (public body, systematic large-scale monitoring, large-scale processing of sensitive data). The address above is the dedicated point of contact for questions and requests relating to personal data.

3. Data collected

3.1 Account data

When creating an account on our SaaS platforms:

  • First name, last name
  • Professional email address
  • Password (stored encrypted via Argon2)
  • Organisation / employer
  • Professional role (optional)

3.2 Data submitted to the Services

When using our products:

  • EASM: root domains to monitor, IP scopes, scan configurations
  • AI-Native AppSec: source code, binaries, configurations, scan results, application scopes
  • Pentest engagements: context information provided by the Client (architecture, test accounts, documentation)

This data may incidentally contain personal data (emails, usernames, identifiers) present in the assets analysed.

3.3 Payment data

Payments are processed by Stripe. We do not retain your full card details, only:

  • The last 4 digits of your card
  • Card type
  • Expiry date
  • Transaction history

3.4 Technical data

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited and time spent
  • Cookies (see dedicated section and our cookie policy)

4. Purposes of processing

4.1 Provision of the Services

  • Creating and managing accounts
  • Performing the scans, analyses and engagements ordered
  • Generating and delivering reports
  • Security notifications and alerts

Legal basis: Performance of the contract (accepted Terms of Use / Terms of Sale).

4.2 Billing and payment

  • Processing payments and subscriptions
  • Issuing invoices
  • Fraud prevention

Legal basis: Performance of the contract, legal obligations (accounting).

4.3 Improving the Services

  • Anonymised usage analysis
  • Bug detection and correction
  • Aggregated usage statistics

Legal basis: Legitimate interest.

Important: we never use the content you submit to the Services (source code, scans, reports) to train our AI models, except with your explicit and formalised written consent.

4.4 Communication

  • Transactional emails (registration, password reset, scan notifications)
  • Important notices (Terms of Use updates, security incidents)
  • Technical newsletter (with explicit consent, unsubscribe possible at any time)

Legal basis: Performance of the contract (transactional), consent (newsletter).

4.5 Security and compliance

  • Audit logs for the security of our infrastructure
  • Detection of suspicious activity (abuse, compromise)
  • Compliance with legal and regulatory obligations

Legal basis: Legal obligations, legitimate interest (security).

5. Data sharing

Your data is never sold to third parties. It may only be shared in the following cases:

5.1 Service providers

We work with trusted providers, all bound by confidentiality obligations:

  • Contabo GmbH: server hosting (VPS, Germany, EU)
  • OVH: domain name (DNS) management (France)
  • Stripe: payment processing
  • Resend and Migadu: email delivery and hosting
  • Google Cloud (Vertex AI): inference of Anthropic's Claude models for certain contextual analyses (SecAI)
  • Cloudflare, Inc.: Turnstile anti-bot service on the contact and booking forms (processing of IP address and technical browser signals)

All these providers are GDPR-compliant and located in the EU or have appropriate safeguards in place (European Commission standard contractual clauses).

Audience measurement: our Plausible Analytics instance is self-hosted on our own servers (analytics.own2pwn.fr, Germany). It is therefore not a processing arrangement with a third party: no traffic data is transmitted to Plausible Insights OÜ or to any other third party.

5.2 Legal obligations

We may disclose data where required by law (judicial requisition, injunction from a competent authority).

5.3 Shared workspaces

If you use the organisation features (multi-user workspaces), members of your organisation may access the reports and scans shared within it.

6. Data retention

  • Account data: for the entire duration of the subscription + 3 years after closure (accounting and tax obligations)
  • Reports and scans: until manual deletion or account closure
  • Billing data: 10 years (legal obligation)
  • Technical logs: 12 months maximum
  • Trackers and local storage: 13 months maximum for interface preferences, 6 months for remembering your consent choice (see the cookie policy)

7. Data security

We implement technical and organisational measures to protect your data:

  • Encryption in transit: HTTPS / TLS 1.2+ on all communications
  • Encryption at rest: AES-256-GCM for sensitive data (reports, client secrets)
  • Secure authentication: passwords encrypted with Argon2, optional 2FA (TOTP)
  • Multi-tenant isolation: strict partitioning of client data
  • Secure servers: hosted in the EU (Germany), firewall, DDoS protection
  • Restricted access: principle of least privilege, access logs, periodic review
  • Backups: daily encrypted, restorable backups
  • Security audits: regular internal and external pentests, regular updates

In the event of a data breach, we will notify you in accordance with the GDPR within 72 hours.

8. Your rights

In accordance with the GDPR, you have the following rights:

  • Right of access: obtain a copy of the data we hold about you
  • Right of rectification: correct your inaccurate or incomplete data
  • Right to erasure: request deletion of your data, except where legally required to retain it
  • Right to restriction: request the temporary freezing of processing
  • Right to portability: retrieve your data in a structured format (JSON, CSV)
  • Right to object: object to certain processing based on our legitimate interest
  • Right to withdraw consent: at any time, where processing is based on consent
  • Post-mortem directives: define what happens to your data after your death

8.1 How to exercise your rights

Write to our GDPR contact:

  • Email: dpo@own2pwn.fr
  • Please specify your first name, last name, account email and the right you wish to exercise

We respond to your request within one month at most.

8.2 Complaint to the CNIL

If you believe your rights are not being respected, you may lodge a complaint with the CNIL (the French data protection authority):

  • Website: www.cnil.fr
  • Address: 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, France
  • Phone: +33 1 53 73 22 22

9. Cookies and trackers

The Site uses trackers strictly necessary for its operation — cookies, but also a write to the browser's local storage to remember your consent choice — and, with your agreement, cookie-free audience measurement. We do not use advertising cookies or third-party tracking.

For more details, see our cookie policy.

10. Transfers outside the EU

Your data is hosted within the European Union (Germany). Some providers are established outside the EU: Google Cloud (AI model inference), Resend (email) and Cloudflare (Turnstile anti-bot service on the forms) in the United States, and Migadu in Switzerland. They have appropriate safeguards in place in accordance with the GDPR (European Commission standard contractual clauses, or an adequacy decision for Switzerland).

11. Processing on behalf of a client (art. 28 GDPR)

Where own2pwn processes personal data on behalf of a Client (for example personal data present in an AppSec scan or a pentest deliverable), own2pwn acts as a processor within the meaning of article 28 of the GDPR. A Data Processing Agreement (DPA) is entered into between the parties on request.

12. Minors

The Services are intended for professionals. We do not knowingly collect data from persons under 16 years of age.

13. Changes to this policy

We may amend this Policy. Any substantial change will be notified to you by email or via the Services. The date of the last update is shown at the top of this page.

14. Contact