AI-powered access security monitoring
This Privacy Policy describes how Le Bouzin ("we", "our", or "us") collects, uses, stores, and protects information when you use the Le Bouzin mobile application (the "App"). The App is an enterprise-grade, AI-powered security monitoring platform designed to help organizations detect and analyze suspicious access patterns across their business software.
Please read this policy carefully. By using the App, you confirm that you have been informed of these practices by your organization (the data controller). If you have questions, refer to the Contact section below.
Le Bouzin is published by [Company legal name — to be completed], a company registered in France.
For questions about this policy, contact us at the address listed in the Contact section.
Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies, your organization (the enterprise that deployed this App) is the data controller and we act as a data processor on its behalf, under a Data Processing Agreement (DPA) signed between Le Bouzin and your organization.
We collect only the data that is strictly necessary for the App to function and for your organization to fulfill its security monitoring objectives.
| Data point | Purpose | Stored |
|---|---|---|
| Email address | Account identification and login | Server (your org's infrastructure) |
| Password (hashed) | Credential-based authentication | Server — never in plaintext |
| Session token | Maintaining authenticated sessions securely | Device (Shared Preferences, encrypted) |
| Assigned role | Determining access level (User / Admin / Super Admin) | Server |
The core purpose of Le Bouzin is to analyze connection events. The following data points are processed per login event recorded in your organization's software:
| Data point | Purpose |
|---|---|
| User identifier (internal ID) | Linking connection events to accounts |
| Timestamp of connection | Detecting out-of-hours access |
| IP address | Detecting unexpected geographic or network changes |
| Connected software name | Scoping the analysis to the relevant application |
| AI-computed severity level (Alert / Warning / Info) | Risk classification output |
| Suspicion indicators (hours, IP change, behavior) | Granular risk explanation per event |
| Data point | Purpose | Stored |
|---|---|---|
| Firebase Cloud Messaging (FCM) token | Sending push notifications to the correct device | Server + Firebase |
| Device type (iOS / Android) | Platform-specific notification formatting | Server |
| Notification permission status | Respecting user preferences | Device only |
Administrators may input the following data through the App as part of their organization's security configuration:
We use collected data exclusively for the following purposes:
We do not use your data for advertising, profiling for commercial purposes, or sale to third parties.
For users located in the European Economic Area (EEA), processing is based on the following legal grounds under Article 6 GDPR:
| Processing activity | Legal basis |
|---|---|
| Authentication and session management | Performance of a contract (Art. 6(1)(b)) |
| Connection log analysis and risk scoring | Legitimate interests of the organization — workplace security (Art. 6(1)(f)) |
| Push notifications | Legitimate interests — security alerts / consent where required (Art. 6(1)(a) or (f)) |
| Admin configuration data | Performance of a contract (Art. 6(1)(b)) |
| Biometric authentication | Explicit consent, processed locally on device (Art. 9(2)(a)) — see Section 8 |
As Le Bouzin processes data on behalf of your organization, the organization is responsible for establishing and documenting the appropriate legal basis for monitoring employee connections.
We do not sell your personal data. We share data only in the following limited circumstances:
All data processed by the App is made available to your organization's administrators and authorized personnel, as the App is deployed at your organization's request and for its security purposes.
We use Firebase Cloud Messaging (FCM), a service provided by Google LLC, to deliver push notifications. FCM processes your device's FCM token for this purpose. Google LLC acts as a sub-processor. Firebase data may be processed in the United States; appropriate safeguards (Standard Contractual Clauses) are in place.
Firebase Privacy Policy: firebase.google.com/support/privacy
The App communicates with servers operated by or on behalf of your organization. The infrastructure provider and its location are determined by your organization.
We may disclose data if required by law, regulation, legal process, or enforceable governmental request, to the extent permitted by applicable law.
As a data processor, we retain data for as long as your organization instructs us to, or as required by the service agreement between Le Bouzin and your organization.
When your organization terminates its contract with Le Bouzin, data is deleted or returned within the timeframe agreed in the Data Processing Agreement.
We implement appropriate technical and organizational measures to protect your data, including:
No method of transmission over the internet or method of electronic storage is 100% secure. We strive to use commercially acceptable means to protect your data, but cannot guarantee absolute security.
The App offers optional biometric authentication (fingerprint or face recognition) as a convenient and secure alternative to entering your password each time.
The App uses Firebase Cloud Messaging (FCM) to send you real-time security alerts and notifications related to your organization's monitored events.
Depending on your location and applicable law (including GDPR for EEA residents), you may have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your data where no legitimate ground exists for retention.
Request that processing be restricted in certain circumstances.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests.
EEA residents also have the right to lodge a complaint with their national data protection supervisory authority. In France, this is the CNIL (www.cnil.fr).
Le Bouzin is an enterprise application intended exclusively for use by adults in a professional context. We do not knowingly collect personal data from anyone under the age of 16. If you believe a minor has provided data through the App, please contact us immediately and we will take steps to delete such data.
We may update this Privacy Policy from time to time to reflect changes in the App, legal requirements, or our data practices. When we do, we will:
We encourage you to review this policy periodically. Continued use of the App after changes constitutes acceptance of the revised policy.
For any questions, requests, or concerns about this Privacy Policy or how your data is handled, please contact us:
Email: contact@arociel.fr