Privacy policy

Your data.
Our framework.

Predictive CyberLab is a professional service published by OPEN C FUTURE. This page describes processing for the programme (film, Briefings, exam, certificate), the organisation workspace and payment.

Our commitments

No advertising tracking

The public site does not use analytics, advertising or social cookies. The signed-in workspace uses a session cookie strictly required for authentication. Interface language is a server preference, not a marketing tracker.

Minimisation

For the organisation: professional identity, company record, VAT number, licences and options. For staff: name, professional email, language, role and seniority. Predictive CyberLab does not store card data.

Delegated payment

Card payments are processed by Stripe (PCI DSS). Predictive CyberLab receives payment status, amount, currency and a transaction identifier — never the card number, expiry or CVC.

EU hosting

The application, databases and programme media are hosted in the European Union. Any non-EU processor is covered by standard contractual clauses.

Processing policy

1. Controller and processor

OPEN C FUTURE, SAS, 80 rue d’Assas, 75006 Paris, RCS Paris 953 641 628, is controller for the organisation account (creation, billing, support). For the staff and network-invitee file, the Client is controller; OPEN C FUTURE acts as processor.

2. Data processed

Account and organisation (legal name, country, NACE sector, intra-community VAT number, administrator). Licences, options and contract period. Learning progress (viewing, Briefings, exam, certificate and public verification token). Network invitations and partner codes (link between organisations, aggregates — not named employees to the network head). Billing data and payment status.

3. Purposes

To deliver the programme and admin workspace, issue the certificate, invoice and collect payment, honour a voucher or invitation, provide support, and meet legal duties (accounts, VAT).

4. Recipients

Stripe (card payments). An e-invoicing provider where applicable. Transactional email (invitations, sign-in, invoices). EU host. Optional AI models via enterprise APIs, with no training on Client content.

5. Retention

Account and invoices: statutory accounting periods. Progress and certificate: contract term, then proof of issue. Session: duration of the signed-in session. Card data does not pass through our application servers.

6. Transfers

Processing in the EU by default. Any processor outside the EU is covered by appropriate safeguards (European Commission standard clauses).

7. Your GDPR rights

Access, rectification, erasure, restriction, portability and objection. Staff should first contact their organisation. The organisation or its CISO may write to dpo@predictivecyberlab.com.

8. Security

TLS in transit, isolation by organisation, card payments at Stripe. The public certificate page shows certificate statements only, not the staff file.

Contact the DPO

For questions about this processing or to exercise a right.

Email the DPO