Legal
Privacy Policy
Effective Date: March 30, 2026
This Privacy Policy describes how PRAGMABLE ("we", "us", "Provider") collects, uses, stores, and protects personal data in connection with the WHOCAN platform ("Service"). It applies to all users, visitors, and customers ("you", "Customer").
1. Data Controller
The data controller responsible for processing your personal data is:
PRAGMABLE SAS — Email: privacy@pragmable.com
2. Personal Data We Collect
2.1 Account Data
When you create an account or subscribe to the Service, we collect:
- Full name
- Professional email address
- Company name and role
- Billing information (processed by our payment provider or AWS Marketplace)
- Password (stored in hashed form only)
2.2 Usage Data
When you use the Service, we automatically collect:
- IP address and approximate geolocation
- Browser type, operating system, and device information
- Pages visited, features used, and actions taken within the Service
- Timestamps of access and session duration
- API call logs
2.3 Cloud Environment Metadata
When you connect a cloud environment to the Service, we process:
- IAM configurations, policies, roles, and permission structures
- Resource identifiers and metadata (e.g., ARN, resource tags)
- Security configuration data necessary for analysis
We do not access or store the contents of your cloud resources (e.g., S3 object contents, database records, application data).
2.4 Communications Data
When you contact us, we collect:
- Email correspondence
- Support ticket content
- Feedback and survey responses
3. Legal Basis for Processing
We process personal data under the following legal bases (GDPR Article 6):
- Providing the Service — Performance of a contract (Art. 6(1)(b))
- Account creation and management — Performance of a contract (Art. 6(1)(b))
- Billing and payment processing — Performance of a contract (Art. 6(1)(b))
- Security monitoring and fraud prevention — Legitimate interest (Art. 6(1)(f))
- Service improvement, error monitoring, and debugging — Legitimate interest (Art. 6(1)(f))
- Legal compliance — Legal obligation (Art. 6(1)(c))
- Marketing communications — Consent (Art. 6(1)(a)), only if opted in
4. How We Use Your Data
We use personal data to:
- Provide, operate, and maintain the Service
- Authenticate your identity and manage your account
- Process payments and manage subscriptions
- Generate security analysis Findings within your connected cloud environments
- Provide customer support
- Send transactional communications (account confirmations, security alerts, service updates)
- Monitor, debug, and improve the reliability of the Service
- Comply with legal obligations
- Send marketing communications (only with your explicit consent)
5. Data Sharing
5.1 We Do Not Sell Personal Data
PRAGMABLE does not sell, rent, or trade personal data to third parties.
5.2 Subprocessors
We share personal data with the following categories of subprocessors, strictly for the purposes of providing the Service:
- Cloud infrastructure providers (e.g., AWS) — hosting and data storage within the EU/EEA
- Payment processors (e.g., AWS Marketplace, Stripe) — billing and subscription management
- Email service providers — transactional and, where opted in, marketing communications
- Error monitoring and observability (e.g., Datadog) — application performance monitoring, error tracking, and debugging
- Customer support tools — support ticket management
A current list of subprocessors with their names, purposes, and locations is available upon request at privacy@pragmable.com or on the PRAGMABLE website.
5.3 Legal Disclosure
We may disclose personal data if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of PRAGMABLE, our customers, or others.
6. International Data Transfers
Customer data is hosted and stored within the European Union / European Economic Area (EU/EEA) by default.
We do not transfer personal data outside the EU/EEA unless:
- you have given prior written consent;
- an adequacy decision of the European Commission applies to the destination country; or
- appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by a Transfer Impact Assessment where required.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy:
- Account data — duration of the account + 12 months after deletion
- Usage and access logs — 12 months
- Cloud environment metadata — duration of the active connection to the Service
- Security analysis Findings — duration of the subscription + 30 days
- Billing records — 10 years (French legal requirement)
- Support correspondence — 24 months after resolution
- Marketing consent records — duration of consent + 3 years
Upon expiration of the retention period, data is securely deleted or anonymized.
Free Tier accounts: data may be deleted 15 days after account termination, as set forth in the Terms of Use.
8. Data Security
We implement appropriate technical and organizational measures to protect personal data, including:
- Encryption at rest and in transit (TLS 1.2+)
- Access controls based on the principle of least privilege
- Regular security assessments and vulnerability management
- Logging and monitoring of access to personal data
- Incident response procedures with 72-hour breach notification (GDPR Article 33)
9. Your Rights (GDPR Articles 15–22)
As a data subject under the GDPR, you have the following rights:
- Right of access (Art. 15) — obtain confirmation of whether your data is processed and request a copy
- Right to rectification (Art. 16) — correct inaccurate or incomplete personal data
- Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten")
- Right to restriction (Art. 18) — restrict processing in certain circumstances
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest, including profiling
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time for processing based on consent
- Right not to be subject to automated decision-making (Art. 22) — the Service does not make automated decisions with legal or similarly significant effects
To exercise any of these rights, contact us at privacy@pragmable.com. We will respond within thirty (30) days. We may request identification to verify your identity before processing your request.
If you believe your rights have been violated, you have the right to lodge a complaint with the French data protection authority: Commission Nationale de l'Informatique et des Libertés (CNIL) — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — www.cnil.fr
10. Cookies
The WHOCAN website and Service use only strictly necessary cookies. We do not use analytics, advertising, or third-party tracking cookies, and we do not build behavioural profiles of visitors.
- Strictly necessary cookies — required for the Service to function (for example, authentication and session management) and, on our website, for the security and anti-abuse of embedded forms. These are exempt from consent under the ePrivacy Directive and the GDPR.
Because we set no analytics or marketing cookies, no cookie-consent banner is required. You can still clear or block cookies through your browser settings, though disabling strictly necessary cookies may affect the functionality of the Service.
Any basic traffic statistics we review from our hosting provider's standard server access logs (for example, most-visited pages or referrers) rely only on server-side logs — they use no cookies and store nothing on your device, so they require no consent.
If we later introduce cookie-based or third-party analytics, we will update this policy and — where the law requires — request your consent (including a cookie banner, if applicable) before enabling it.
11. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
12. Customer-Managed Deployments
For Customer-Managed Deployments (where the Service is deployed in the Customer's own infrastructure), PRAGMABLE does not host, store, or process Customer data. The Customer acts as the sole data controller and processor for data within its own environment.
PRAGMABLE may still collect limited telemetry data (license validation, anonymized usage metrics, error reports) as described in Section 7 of the Terms of Use. This Privacy Policy applies to such telemetry data.
13. Data Processing Agreement (DPA)
For customers who require a formal Data Processing Agreement under GDPR Article 28, PRAGMABLE provides a DPA upon request. The DPA specifies:
- the subject matter and duration of processing
- the nature and purpose of processing
- the categories of personal data and data subjects
- the obligations and rights of the controller
- PRAGMABLE's obligations as a data processor
- subprocessor management and notification procedures
- data breach notification procedures
- audit rights
- data deletion and return upon termination
To request the DPA, contact privacy@pragmable.com.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a prominent notice within the Service at least thirty (30) days before the changes take effect.
Your continued use of the Service after the effective date of a revised Privacy Policy constitutes acceptance of the updated terms.
15. Contact
For any questions about this Privacy Policy or to exercise your data subject rights:
PRAGMABLE SAS — Email: privacy@pragmable.com