1. Data controller
ASN NET SASU, whose registered office is located at 54 ALLEE DARIUS MILHAUD, 26000 VALENCE, is the controller of the personal data collected on the asncloud.fr website and in the course of its services.
2. Data collected
- Via the contact form: name, email address, phone (optional), company (optional), subject of the request, free-text message.
- Server logs: IP address, date and time of access, user-agent, URL visited. Collected for security and access-statistics purposes.
- Customer data: contractual information required to deliver the services (company name, technical and billing contact, bank details where applicable). Detailed in the Terms and Conditions.
3. Purposes of processing
- Responding to information requests submitted via the contact form
- Managing the contractual relationship with our customers
- Handle billing and collection
- Ensure the security of the site and our services
- Comply with our legal obligations (accounting, taxation, archiving)
4. Legal basis
Depending on the case, processing relies on one of the following legal bases:
- Consent: contact form, eligibility request
- Performance of a contract: managing customer services
- Legal obligation: invoicing, accounting record retention
- Legitimate interest: site security, fraud prevention
5. Recipients
Your data is shared only with authorized staff of the ASN CLOUD team. No data is transferred, sold or rented to third parties for commercial purposes.
For strictly necessary technical purposes (for example the SMTP service that delivers emails from the contact form), subprocessors may be involved. They are then governed by GDPR-compliant data processing agreements (DPA - Data Processing Agreement) that impose on them the same obligations of confidentiality and security.
6. Transfers outside the European Union
No transfer outside the European Union. Your data is hosted exclusively in France, in our own datacenters in Lyon and Grenoble. The transit network is operated on our sovereign AS (AS204948). This is the central argument of ASN Cloud's regional sovereign positioning.
7. Retention period
- Prospect requests (contact form): 3 years after the last contact
- Customer data: contract term + statutory periods (10 years for accounting records)
- Server logs: 12 months maximum
- Technical cookies: see our cookie policy
8. Your GDPR rights
In accordance with the GDPR, you have the following rights over your personal data:
- Right of access: obtain a copy of the data concerning you
- Right to rectification: correcting inaccurate data
- Right to erasure (the "right to be forgotten"): have your data deleted
- Right to restriction of processing: temporarily suspend use
- Right to data portability: retrieve your data in a structured format
- Right to object: refuse processing based on legitimate interest
- Right to define post-mortem directives: the fate of your data after your death
- Right not to be subject to an automated decision without human intervention
9. How to exercise your rights
To exercise your rights, contact our Data Protection Officer (DPO) at dpo@asncloud.fr, enclosing a copy of your identity document for verification (the document will be kept only for the time strictly necessary for verification).
A response will be provided within a maximum of 1 month from receipt of your request, in accordance with article 12 of the GDPR.
10. Data Protection Officer (DPO)
ASN NET SASU has appointed an internal DPO: Anthony SIBIODON, reachable at dpo@asncloud.fr.
11. Complaint to the CNIL
If you believe that your rights are not being respected or that the processing of your data does not comply with the GDPR, you can lodge a complaint with the French Data Protection Authority (CNIL):
- Online: cnil.fr/fr/plaintes
- By post: CNIL - 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
- By phone: 01 53 73 22 22
12. Data security
We implement appropriate technical and organizational measures to protect your personal data against loss, alteration, disclosure or unauthorized access:
- Encryption of communications via TLS
- Strict access control to servers and databases
- Logging of access and sensitive operations
- Regular, redundant backups
- Security updates applied continuously
- Network segmentation and perimeter filtering
13. Changes to the policy
This policy may be amended at any time, in particular to reflect changes in legislation or in our services. The applicable version is the one in force at the time of your visit. Last updated: 01/04/2026.