Security Policy
Security Vulnerability Reporting
revzper SAS takes the security of the Euphile platform seriously. If you discover a security vulnerability, please report it responsibly by emailing contact@revzper.com. We will acknowledge receipt within 48 hours and aim to provide an initial assessment within 5 business days. We do not pursue legal action against researchers who follow responsible disclosure practices.
Compliance with Data Protection Regulations
revzper SAS, as the data controller for the Euphile platform, is committed to full compliance with the General Data Protection Regulation (GDPR) and other applicable EU data protection laws. This policy outlines our adherence to the following principles:
1. GDPR Principles
All data processing activities are conducted with a clear legal basis, including consent, contract performance, or legitimate interest, as specified in our Data Processing Records.
Ref: GDPR
2. Data Subject Rights
As a data subject, you have the following rights regarding your personal data processed on the Euphile platform:
Ref: GDPR
- Request confirmation of whether your data is being processed and access to that data.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of your personal data under specific conditions.
- Request limitation of processing in certain circumstances.
- Receive your personal data in a structured, commonly used, and machine-readable format.
- Object to processing based on legitimate interests or direct marketing.
- Withdraw consent for processing where it was the legal basis.
3. Legal Basis for Processing
The legal basis for processing personal data on the Euphile platform varies by product and service. For detailed information, refer to the Data Processing Records for each product (Solon, Vauban, Nassau, Leonardo, Atlas, Plutus, Tzu, Richelieu).
Ref: GDPR
4. Data Protection Officer (DPO)
revzper SAS has appointed a Data Protection Officer to oversee data protection practices. The DPO can be contacted at privacy@revzper.com.
Ref: GDPR
Security Measures
Our platform employs the following security measures to protect personal data:
1. Encryption
1. In Transit
All data transmitted between users and our platform is encrypted using industry-standard protocols to ensure secure communication channels.
2. At Rest
Sensitive data is encrypted using strong encryption standards, with encryption keys managed in accordance with best practices.
2. Access Controls
1. Role-Based Access Control
Role-based access control is implemented to ensure that users have access only to the data and functions necessary for their roles.
2. Multi-Factor Authentication
Multi-factor authentication is required for all administrative access to the platform.
3. Security Assessments
1. Vulnerability Scans and Penetration Tests
Regular vulnerability scans and penetration tests are conducted to identify and address security weaknesses.
2. Internal Security Assessments
Internal security assessments are performed to review access logs, system configurations, and compliance with security policies.
4. Automated Monitoring
1. Continuous Monitoring
Continuous monitoring of system logs, network traffic, and user activity to detect and respond to suspicious behavior in real-time.
2. Automated Alerts
Automated alerts are generated for potential security incidents, enabling rapid response.
5. Compliance Certifications
Our infrastructure and processes are designed to meet recognized security standards. Certifications are verified regularly and made available upon request. All data is processed within the European Union on infrastructure that meets industry security standards.
Incident Response and Breach Notification
revzper SAS has established a robust incident response procedure to address security incidents, data breaches, or unauthorized access to personal data. Our goal is to detect, contain, and mitigate incidents promptly while ensuring compliance with legal obligations.
1. Incident Response Procedure
Ref: GDPR
1. Detection and Reporting
Security incidents are detected through automated monitoring tools and manual reporting. Employees and contractors are trained to report suspected incidents immediately to the privacy@revzper.com or via the incident response hotline at contact@revzper.com.
Ref: GDPR
2. Assessment and Containment
The incident response team, led by the DPO, assesses the scope and impact of the incident. Immediate containment measures are implemented to prevent further unauthorized access or data loss.
Ref: GDPR
3. Notification to Supervisory Authorities
In the event of a personal data breach, revzper SAS will notify the competent supervisory authority within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to the rights and freedoms of data subjects. The notification will include: A description of the nature of the breach. The categories and approximate number of data subjects and records affected. The likely consequences of the breach. Measures taken or proposed to address the breach.
Ref: GDPR
4. Communication to Affected Data Subjects
If the breach is likely to result in a high risk to the rights and freedoms of data subjects, revzper SAS will communicate the breach to affected individuals without undue delay. The communication will include: A clear description of the breach. The measures taken to address the breach. Recommendations for data subjects to protect their rights.
Ref: GDPR
5. Documentation and Review
All incidents are documented, including the root cause, response actions, and lessons learned. The incident response procedure is reviewed and updated regularly to incorporate improvements.
Ref: GDPR
2. Escalation Path
Minor Incidents: Handled by the internal security team with oversight from the DPO. Major Incidents: Escalated to senior management and the board of directors, with mandatory notification to the supervisory authority.
Ref: GDPR
3. Contact for Incidents
For questions or to report an incident, contact the DPO at privacy@revzper.com.
Ref: GDPR
Third-Party Risk Management
revzper SAS recognizes that third-party vendors, sub-processors, and service providers may process personal data on behalf of our platform. We are committed to ensuring that all third parties adhere to the same high standards of data protection and security as revzper SAS.
1. Sub-Processors and Service Providers
The following third parties are engaged by revzper SAS to provide services that involve the processing of personal data. Each sub-processor is selected based on rigorous due diligence and contractual safeguards:
Ref: GDPR
- Service: Cloud hosting
Sub-processor: Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, France
Data location: France (Paris region), European Union
Compliance certifications: ISO/IEC 27001:2022; HDS (health data hosting)
Data processing agreement: Scaleway Data Processing Agreement, https://www.scaleway.com/en/contracts/
- Service: Payment processing
Sub-processor: Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands
Data location: European Union (Netherlands)
Compliance certifications: PCI DSS Level 1 service provider; payment institution authorised by De Nederlandsche Bank
Data processing agreement: Mollie processes payment data as an independent controller under its User Agreement and Privacy Statement, https://www.mollie.com/legal/privacy
2. Due Diligence and Selection
All potential sub-processors are evaluated based on their security practices, compliance certifications, and data protection commitments. Data Processing Agreements are established with all sub-processors, outlining their obligations regarding data protection, security, and breach notification. revzper SAS regularly reviews the performance and compliance of sub-processors to ensure continued adherence to applicable regulations.
Ref: GDPR
3. Incident Response and Breach Notification
Sub-processors are required to notify revzper SAS immediately of any suspected or actual data breaches. revzper SAS will assess the impact of the breach and take appropriate action, including notifying the competent supervisory authority and affected data subjects, as required by applicable regulations.
Ref: GDPR
4. Contact for Third-Party Risk Management
For questions about our third-party risk management practices, contact the DPO at privacy@revzper.com.
Ref: GDPR
Employee Security Training and Awareness
revzper SAS is committed to fostering a culture of security awareness among all employees and contractors. Regular training and education are essential to maintaining the security of our platform and protecting personal data.
1. Training Program
1. Scope
All employees and contractors with access to revzper SAS systems or data are required to complete security training.
2. Topics Covered
Awareness of common security threats (e.g., phishing, social engineering). Secure authentication practices. Access control and least privilege principles. Incident reporting procedures. Data protection principles and regulatory compliance. Secure development practices (for technical staff). Physical security and workplace safety.
3. Training Frequency
New Hires: Mandatory security training within the first 30 days of employment. Annual Refresher: All employees and contractors must complete an annual security training update. Ad-Hoc Training: Additional training is provided for new systems, policies, or emerging threats.
4. Documentation
Training attendance and completion are documented and stored securely. Employees are required to acknowledge their understanding of the training materials.
2. Awareness Campaigns
Phishing Simulations: Regular phishing simulations are conducted to assess employee awareness and reinforce training. Security Newsletters: Periodic newsletters are distributed to share updates on security threats, best practices, and policy changes. Incident Reviews: Post-incident reviews are conducted to analyze lessons learned and improve security practices.
3. Compliance and Enforcement
Non-compliance with security training requirements may result in disciplinary action, up to and including termination. revzper SAS reserves the right to audit training completion and compliance with security policies.
4. Contact for Training Inquiries
For questions about our security training program, contact the DPO at privacy@revzper.com.