Le Bouzin

AI-powered access security monitoring

Privacy Policy
Effective date: June 10, 2026 | Last updated: June 10, 2026 | Version: 1.0 | Applies to: iOS & Android mobile applications

This Privacy Policy describes how Le Bouzin ("we", "our", or "us") collects, uses, stores, and protects information when you use the Le Bouzin mobile application (the "App"). The App is an enterprise-grade, AI-powered security monitoring platform designed to help organizations detect and analyze suspicious access patterns across their business software.

Please read this policy carefully. By using the App, you confirm that you have been informed of these practices by your organization (the data controller). If you have questions, refer to the Contact section below.

B2B context Le Bouzin is deployed by organizations for their employees and IT teams. Your organization acts as the data controller and Le Bouzin acts as the data processor. Your organization's own data-protection policies also apply to your use of this App.

Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Bases (GDPR)
  5. Data Sharing & Third Parties
  6. Data Retention
  7. Security
  8. Biometric Authentication
  9. Push Notifications
  10. Your Rights
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact

01 Who We Are

Le Bouzin is published by [Company legal name — to be completed], a company registered in France.

For questions about this policy, contact us at the address listed in the Contact section.

Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies, your organization (the enterprise that deployed this App) is the data controller and we act as a data processor on its behalf, under a Data Processing Agreement (DPA) signed between Le Bouzin and your organization.

02 Data We Collect

We collect only the data that is strictly necessary for the App to function and for your organization to fulfill its security monitoring objectives.

2.1 Account & Authentication Data

Data point Purpose Stored
Email address Account identification and login Server (your org's infrastructure)
Password (hashed) Credential-based authentication Server — never in plaintext
Session token Maintaining authenticated sessions securely Device (Shared Preferences, encrypted)
Assigned role Determining access level (User / Admin / Super Admin) Server

2.2 Connection & Access Log Data

The core purpose of Le Bouzin is to analyze connection events. The following data points are processed per login event recorded in your organization's software:

Data point Purpose
User identifier (internal ID) Linking connection events to accounts
Timestamp of connection Detecting out-of-hours access
IP address Detecting unexpected geographic or network changes
Connected software name Scoping the analysis to the relevant application
AI-computed severity level (Alert / Warning / Info) Risk classification output
Suspicion indicators (hours, IP change, behavior) Granular risk explanation per event
No content of communications is processed Le Bouzin analyzes connection metadata only. We do not access, read, or process any messages, files, or content exchanged within your organization's software.

2.3 Device & Notification Data

Data point Purpose Stored
Firebase Cloud Messaging (FCM) token Sending push notifications to the correct device Server + Firebase
Device type (iOS / Android) Platform-specific notification formatting Server
Notification permission status Respecting user preferences Device only

2.4 Configuration Data (Admins only)

Administrators may input the following data through the App as part of their organization's security configuration:

2.5 Data We Do NOT Collect

03 How We Use Your Data

We use collected data exclusively for the following purposes:

We do not use your data for advertising, profiling for commercial purposes, or sale to third parties.

04 Legal Bases for Processing (GDPR)

For users located in the European Economic Area (EEA), processing is based on the following legal grounds under Article 6 GDPR:

Processing activity Legal basis
Authentication and session management Performance of a contract (Art. 6(1)(b))
Connection log analysis and risk scoring Legitimate interests of the organization — workplace security (Art. 6(1)(f))
Push notifications Legitimate interests — security alerts / consent where required (Art. 6(1)(a) or (f))
Admin configuration data Performance of a contract (Art. 6(1)(b))
Biometric authentication Explicit consent, processed locally on device (Art. 9(2)(a)) — see Section 8

As Le Bouzin processes data on behalf of your organization, the organization is responsible for establishing and documenting the appropriate legal basis for monitoring employee connections.

05 Data Sharing & Third Parties

We do not sell your personal data. We share data only in the following limited circumstances:

5.1 Your Organization

All data processed by the App is made available to your organization's administrators and authorized personnel, as the App is deployed at your organization's request and for its security purposes.

5.2 Firebase (Google LLC)

We use Firebase Cloud Messaging (FCM), a service provided by Google LLC, to deliver push notifications. FCM processes your device's FCM token for this purpose. Google LLC acts as a sub-processor. Firebase data may be processed in the United States; appropriate safeguards (Standard Contractual Clauses) are in place.

Firebase Privacy Policy: firebase.google.com/support/privacy

5.3 Hosting & Infrastructure

The App communicates with servers operated by or on behalf of your organization. The infrastructure provider and its location are determined by your organization.

5.4 Legal Obligations

We may disclose data if required by law, regulation, legal process, or enforceable governmental request, to the extent permitted by applicable law.

06 Data Retention

As a data processor, we retain data for as long as your organization instructs us to, or as required by the service agreement between Le Bouzin and your organization.

When your organization terminates its contract with Le Bouzin, data is deleted or returned within the timeframe agreed in the Data Processing Agreement.

07 Security

We implement appropriate technical and organizational measures to protect your data, including:

No method of transmission over the internet or method of electronic storage is 100% secure. We strive to use commercially acceptable means to protect your data, but cannot guarantee absolute security.

Report a vulnerability If you discover a security issue in the App, please contact us responsibly at the address in the Contact section before any public disclosure.

08 Biometric Authentication

The App offers optional biometric authentication (fingerprint or face recognition) as a convenient and secure alternative to entering your password each time.

Your biometric data never leaves your device Biometric verification is performed entirely by your device's operating system (Face ID / Touch ID on iOS; Biometric API on Android). Le Bouzin does not have access to, store, transmit, or process any biometric template or raw biometric data. Only a cryptographic confirmation ("authentication succeeded / failed") is returned to the App.

09 Push Notifications

The App uses Firebase Cloud Messaging (FCM) to send you real-time security alerts and notifications related to your organization's monitored events.

10 Your Rights

Depending on your location and applicable law (including GDPR for EEA residents), you may have the following rights regarding your personal data:

👁️

Right of Access

Request a copy of the personal data we hold about you.

✏️

Right to Rectification

Request correction of inaccurate or incomplete data.

🗑️

Right to Erasure

Request deletion of your data where no legitimate ground exists for retention.

⏸️

Right to Restriction

Request that processing be restricted in certain circumstances.

📦

Right to Portability

Receive your data in a structured, machine-readable format.

🚫

Right to Object

Object to processing based on legitimate interests.

How to exercise your rights Because your organization is the data controller, most data-subject requests should be directed to your organization's DPO or HR/IT department. You may also contact us directly at the address below; we will coordinate with your organization as required.

EEA residents also have the right to lodge a complaint with their national data protection supervisory authority. In France, this is the CNIL (www.cnil.fr).

11 Children's Privacy

Le Bouzin is an enterprise application intended exclusively for use by adults in a professional context. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided data through the App, please contact us immediately and we will take steps to delete such data.

12 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the App, legal requirements, or our data practices. When we do, we will:

We encourage you to review this policy periodically. Continued use of the App after changes constitutes acceptance of the revised policy.

13 Contact

For any questions, requests, or concerns about this Privacy Policy or how your data is handled, please contact us:

Le Bouzin — Data Protection Contact

Email: contact@arociel.fr