Politique de Confidentialité · Privacy Policy

Privacy Policy

Last updated / Mise à jour : Mars / March 2026

1. Who We Are

Hexanion is a SASU registered in France. We operate the Signal platform — a cyber threat intelligence service that provides automated exposure profiling and threat monitoring for small and mid-sized businesses. "We", "us", and "our" refer to Hexanion.

For any data-related question or request, contact us at support@hexanion.fr.

2. What We Collect and Why

Account data

When you create an account we collect your name and email address. If you sign up via Google OAuth, we receive the name and email from your Google profile. This is required to identify you, send security alerts, and manage your subscription.

Domain and scan data

When you submit a domain for discovery or a full Signal scan, we store the domain name and results (subdomains, open ports, certificates, technology stack, etc.). This data is the core of the service and is associated with your account.

Technical data

We collect your IP address and standard HTTP headers when you access our service. This is used for security, abuse prevention, and session management.

Usage data

We may use privacy-first, cookieless analytics to understand aggregate traffic patterns. No personal identifiers are used in analytics.

3. Payment Data

We do not process or store any payment card information on our servers. All payments, billing, and invoicing are handled exclusively by our Merchant of Record, Lemon Squeezy (Lemon Squeezy LLC). When you subscribe to Signal, you interact directly with Lemon Squeezy's secure payment infrastructure. Lemon Squeezy is responsible for PCI-DSS compliance on all payment transactions. We only receive confirmation that a payment was successful and the subscription tier purchased.

4. Legal Basis (GDPR)

We process your data on the following legal bases:

  • Contract performance — account and scan data are necessary to deliver the service.
  • Legitimate interest — IP address and technical data for security and fraud prevention.
  • Consent — marketing communications, if any, require your explicit opt-in.

5. Data Retention

We retain your account data for as long as your account is active. When you delete your account, your personal data is deleted within 30 days. Anonymized, aggregated scan statistics may be retained indefinitely.

6. Data Sharing

We do not sell your personal data. We share data only with the following sub-processors:

  • Hetzner Online GmbH — infrastructure and hosting (EU).
  • Lemon Squeezy LLC — payment processing and subscription management.

7. Cookies

We only use strictly necessary cookies — specifically, a session cookie required to keep you logged in. We do not use advertising cookies, cross-site tracking cookies, or any cookies that require a consent banner under the ePrivacy Directive.

8. Your Rights

Under GDPR, you have the right to access, rectify, delete, or export your personal data at any time. Email us at support@hexanion.fr and we will respond within 30 days.

You also have the right to lodge a complaint with the French data protection authority, the CNIL (cnil.fr).

9. Changes to This Policy

If we make material changes, we will notify active users by email before the changes take effect. The "last updated" date at the top reflects the most recent revision.