Terms & Services
The GCU below do not take precedence over the French GCU available on the French version of the website. Please consider reading them first.
1. Company Identification
The company Bastion Technologies (the "Company" or "Bastion Technologies") is a simplified joint-stock company registered with the RCS of Nanterre under number 921 179 925, with its headquarters located at 65 rue de la Croix, Nanterre, 92000.
Bastion Technologies can be contacted at the following details:
- Email address: contact@bastion.tech
2. Services Offered
Bastion Technologies provides a solution (the "Platform") designed for its business clients (the "Clients") to protect against cybersecurity risks (the "Services").
3. Contractual Document
The contractual relationship between the Client and Bastion Technologies is governed, in descending hierarchical order, by the following documents:
- The Quote (the "Quote"):
- It is prepared based on the Client's needs.
- The Client must accept it in writing (including by email) within 30 days from its issuance. Such acceptance implies acceptance of the General Conditions in effect at the date of the Quote.
- In case of any contradictions, the Quote takes precedence over the General Conditions.
- If there are conflicting Quotes, the most recent Quote takes precedence over the older one(s).
- The General Terms and Conditions (the "General Terms and Conditions"):
- They define:
- The terms of use of the Services,
- The respective obligations of the parties.
- They are accessible via a direct link at the bottom of the Platform’s page.
- They define:
4. Conditions for Accessing the Services
(i) The Client must be a legal entity represented by a physical person who has the authority or authorization required to enter into agreements on behalf of and for the Client.
(ii) The Client qualifies as a professional, defined as any physical or legal person acting for purposes within the scope of their commercial, industrial, craft, liberal, or agricultural activity, including when acting on behalf of or for another professional.
5. Access and Subscription Procedures for the Services
To subscribe to the Services, the Client must complete the designated form on the Platform. The Client must provide the Company with all mandatory information.
Registration automatically results in the creation of an account in the Client's name (the "Account"), which allows access to the Services using a login ID and password.
Once the Client's Account is created, they can freely create access for users ("Users") within the limits specified in the subscribed Services.
The Client is solely responsible for creating access for Users and their personal use of the Platform.
6. Description of the Services
6.1. The Services
The Client acknowledges that implementing the Services requires an internet connection and that the quality of the Services depends on this connection, which is not the responsibility of Bastion Technologies.
The Services subscribed to by the Client are described in the Quote. Bastion Technologies offers the following services:
- Assistance with certifications such as SOC2, ISO, GDPR, etc. (the "Certification Audit");
- An external surface audit for identifying vulnerabilities and configuration issues, leading to an actionable remediation plan;
- Immediate detection of data leaks and monitoring of the dark web;
- Cybersecurity training for the Client’s employees (interactive chatbot, cyber maturity tests, automated reports, phishing scenario implementation, etc.);
- Real-time email protection using artificial intelligence technology;
- Web navigation security (proactive threat prevention, continuous monitoring of risky websites, etc.);
- Cloud application protection, including continuous attack detection and instant remediation.
The Company reserves the right to offer additional Services.
Any request to modify subscribed Services will require a supplementary Quote.
6.2. Additional Services
6.2.1 Maintenance
The Client benefits from maintenance services throughout the duration of the Services, including corrective and evolutionary maintenance. In this context, access to the Platform may be limited or suspended.
Bastion Technologies makes every effort to provide corrective maintenance to resolve any malfunctions or bugs identified on the Platform.
The Client also benefits from evolutionary maintenance during the duration of the Services, which Bastion Technologies may carry out automatically and without prior notice. This includes improvements to the Platform’s features, the addition of new functionalities, and/or technical upgrades used as part of the Platform (including the introduction of minor or major extensions).
Updates are carried out throughout the duration of this agreement.
The Client must agree to install necessary updates to ensure that the Services remain compliant, meaning that the Services can continue to be used as agreed upon between the parties and as expected by the Client upon subscription.
Access to the Platform may also be limited or suspended for planned maintenance, which may include the aforementioned corrective and evolutionary maintenance operations.
6.2.2 Hosting
Bastion Technologies ensures, under a best-effort obligation, the hosting of the Platform as well as the data produced and/or entered on/by the Platform, through a professional hosting provider, on servers located within the territory of the European Union.
6.2.3 Technical Support
In case of any difficulties encountered while using the Services, the Client can contact Bastion Technologies via chat on the Platform or at the following address: support@bastion.tech.
The technical support service is available from Monday to Friday, excluding public holidays, from 9:00 AM to 6:00 PM. Depending on the identified need, Bastion Technologies will estimate the response time and keep the Client informed.
7. Subscription Duration for the Services
At the end of this trial, or if the Client does not wish to use the trial, or in the case of the Certification Audit, the Client subscribes to the Services in the form of an annual or monthly subscription based on the selected feature package (the "Subscription").
The Subscription begins on the date it is subscribed for an initial period specified in the Quote.
The Subscription is automatically renewed for successive periods of the same duration as the initial period (together with the initial period, the "Periods"), from date to date, unless the Subscription is terminated under the conditions set out in the article "End of Services."
8. Financial Terms of Bastion Technologies
8.1. Services Prices
The prices of the Services subscribed to by the Client are indicated in the Quote.Any Period that has commenced is due in full.Bastion Technologies' prices may be revised at any time under the conditions outlined in the article "Modification of the General Terms and Conditions."
8.2. Billing and Payment Methods of Bastion Technologies
Bastion Technologies sends an invoice to the Client for each Period using any useful means.Payment is made by automatic debit upon subscription to the Subscription and then at each renewal for annual subscriptions or monthly starting from the subscription date for monthly subscriptions.Other billing and payment methods may be specified in the Quote.The Client guarantees Bastion Technologies that they have the necessary authorizations to use this payment method.
8.3. Consequences of Late or Non-Payment
In the event of late or non-payment, Bastion Technologies reserves the right, starting the day after the due date indicated on the invoice, to:
- Immediately suspend the ongoing Services until full payment of all amounts due;
- Charge interest on overdue payments at a rate equal to three times the legal interest rate, calculated on the amount of unpaid sums at the due date, along with a fixed compensation of €40 for recovery costs, without prejudice to additional compensation if the actual recovery costs exceed this amount;
- If applicable, declare the acceleration of all amounts owed by the Client, making them immediately payable.
9. Intellectual Property Rights
9.1. Intellectual Property Rights on the Platform
The Platform is the property of Bastion Technologies, including the software, infrastructure, databases, and all types of content (texts, images, visuals, music, logos, trademarks, etc.) it uses. These are protected by all applicable intellectual property rights or database producer rights. The license granted by Bastion Technologies to the Client does not entail any transfer of ownership.
The Client and Users are granted a non-exclusive, non-transferable SaaS license to use the Platform for the duration specified in the article "Subscription Duration for the Services."
9.2. Intellectual Property Rights on the Deliverables
By this agreement, Bastion Technologies transfers to the Client the economic copyright it may hold on any deliverables provided as part of the Services, including files, reports, and other documents related to the Certification Audit (the "Deliverables").
However, this transfer does not include the tools and methods it has developed and uses, or more broadly any element that enabled the completion of the Services, as well as logos and trademarks affixed to the Deliverables.
This transfer will be carried out automatically as the Deliverables are delivered. The transfer is granted to the Client without restriction or reservation, in full ownership, exclusively and definitively. Bastion Technologies thereby prohibits itself from exploiting the Deliverables itself or granting any rights to them to a third party. The transfer is granted for the entire legal duration of copyright protection, worldwide, and for all forms of exploitation known or unknown to date, whether foreseeable or unforeseeable.
The transferred rights include:
a) The right to reproduce and fix the Deliverables, in whole or in part, in any format, on any medium, including paper or digital, and by any material or immaterial process, whether these media or processes currently exist or are yet to come, foreseeable or unforeseeable;
b) The right to produce, use, or publish the Deliverables, in whole or in part;
c) The right to adapt, translate, modify, arrange, transform, and correct the Deliverables, including, but not limited to, retouching, changing the format or colors of the Deliverables, subject to the moral rights of the author, if applicable.
It is noted that this agreement does not impose any obligation on the Client to exploit the Deliverables. The Client remains entirely free to use them or not.
10. Commercial References
The parties may use each other's names, trademarks, and logos and refer to their respective platforms for commercial references during the term of their contractual relationship and for three years afterward.
11. Obligations and Responsibility of the Client
11.1. Regarding the Provision of Information
The Client agrees to provide Bastion Technologies with all necessary information for the subscription and use of the Services.
The Client acknowledges the importance of adhering to the deadlines communicated by Bastion Technologies as part of the Services, particularly in the case of the Certification Audit, which requires compliance with a specific schedule. The Client therefore agrees to respect any deadlines imposed by the Provider.
Any delay attributable to the Client in providing this information may:
- Delay the agreed schedule for the Services between the Parties;
- Make it impossible for the Provider to complete the Certification Audit, in which case the Client remains liable for the amounts specified in the Quote and cannot claim reimbursement of any deposit or amounts already paid for the Certification Audit.
Finally, the Client acknowledges that Bastion Technologies performs the Services based on the information provided on the Platform. Consequently, Bastion Technologies shall not be held liable, particularly in cases where the Client provides falsified or incorrect information or documents.
More generally, the Client acknowledges that the Certification Audit does not guarantee the issuance of the related certification, as this largely depends on the Client and the measures implemented by the Client in connection with the certification. Bastion Technologies cannot be held responsible for any failure of the Certification Audit, as it does not guarantee the successful completion of the certification process.
11.2. Regarding the Client’s Account
The Client:
- Guarantees that the information provided in the form is accurate and agrees to update it as needed.
- Acknowledges that this information serves as proof of their identity and binds them upon validation.
- Is responsible for maintaining the confidentiality and security of their login ID and password, with any access to the Platform using these credentials being deemed as carried out by the Client.
The Client must immediately contact Bastion Technologies using the details provided in the "Company Identification" section if they become aware that their Account has been used without authorization. The Client acknowledges that Bastion Technologies has the right to take appropriate measures in such cases.
The Client is solely responsible for creating access for Users.
11.3. Regarding the Use of Services
The Client is responsible for their use of the Services and any information they share within this context. They are also responsible for the use of the Services and any information shared by the Users. The Client agrees that the Services will be used exclusively by themselves and/or the Users, who are subject to the same obligations as the Client when using the Services.
The Client is prohibited from misusing the Services for purposes other than those for which they were designed, specifically:
- Engaging in illegal or fraudulent activities;
- Violating public order and moral standards;
- Harming third parties or their rights in any way;
- Violating any contractual, legislative, or regulatory provisions;
- Interfering with third-party computer systems, particularly to compromise their integrity or security;
- Engaging in actions aimed at promoting their services and/or websites or those of a third party;
- Assisting or encouraging a third party to commit any of the acts or activities listed above.
The Client is also prohibited from:
- Copying, modifying, or misappropriating any element belonging to Bastion Technologies or any concept it operates within the framework of the Services;
- Adopting any behavior likely to interfere with or misappropriate Bastion Technologies' computer systems or compromise its security measures;
- Harming the financial, commercial, or moral rights and interests of Bastion Technologies;
- Selling, transferring, or providing access to the Services, the information hosted on the Platform, or any elements belonging to Bastion Technologies in any way.
The Client is responsible for all content ("Content") of any kind that they distribute as part of the Services.
The Client acknowledges that Content distributed through the Solution may be visible to other Users of the Services.
The Client is prohibited from distributing any Content (this list is not exhaustive):
- That violates public order and moral standards (pornographic, obscene, indecent, shocking, or inappropriate for a family audience, defamatory, offensive, violent, racist, xenophobic, or revisionist);
- That infringes on the rights of third parties (counterfeit content, violations of personal rights, etc.) or more generally violates any contractual, legislative, or regulatory provision;
- That is harmful to third parties in any way;
- That is false, misleading, or promotes or proposes illegal, fraudulent, or deceptive activities;
- That is harmful to third-party computer systems.
The Client indemnifies Bastion Technologies against any claims and/or legal actions that may be brought against it as a result of the Client's violation of their obligations. The Client will compensate Bastion Technologies for any damages suffered and reimburse any expenses incurred as a result.
12. Obligations and Responsibility of Bastion Technologies
Bastion Technologies commits to providing the Services diligently, noting that it is bound by a best-effort obligation.
In this regard, Bastion Technologies guarantees that it holds all intellectual property rights to the Platform and the Services.Any delay attributable to the Client will correspondingly extend the agreed delivery timelines.
12.1. Regarding the Quality of Services
Bastion Technologies makes every effort to provide the Client with quality Services.
To this end, it regularly conducts checks to verify the operation and accessibility of its Services and may carry out maintenance under the conditions specified in the "Maintenance" article.
However, Bastion Technologies is not responsible for temporary difficulties or impossibilities in accessing its Services that arise due to:
- Circumstances external to its network (including partial or total failure of the Client's servers);
- Malfunctions of equipment, cabling, services, or networks not included in its Services or not under its responsibility;
- Interruptions in Services caused by telecommunications operators or internet service providers;
- Actions by the Client, particularly through incorrect configurations applied to the Services;
- Force majeure.
Bastion Technologies is responsible for the operation of its servers, with external limits defined by connection points.
Moreover, it does not guarantee that the Services:
- Which are subject to constant research for improvement, particularly in performance and progress, will be entirely free of errors, defects, or flaws;
- Which are standard and not tailored to the Client's specific constraints, will meet the Client’s precise needs and expectations.
12.2. Regarding the Platform's Service Level Guarantee
Bastion Technologies does not offer a specific service level guarantee for the Platform.
However, Bastion Technologies makes every effort to maintain Platform access 24/7, except in cases of planned maintenance as defined in the "Maintenance" article or force majeure.
12.3. Regarding Data Backup on the Platform
Bastion Technologies makes its best efforts to back up all data produced and/or entered on/by the Platform.However, except in cases of proven faults by Bastion Technologies, it is not responsible for any loss of data during maintenance operations.
12.4. Regarding Data Storage and Security
Bastion Technologies provides sufficient storage capacity for the operation of the Services.Bastion Technologies makes its best efforts to ensure data security by implementing measures to protect infrastructure and the Platform, detect and prevent malicious activities, and recover data.
12.5. Regarding Subcontracting and Assignment
Bastion Technologies may use subcontractors for the execution of the Services. These subcontractors are subject to the same obligations as Bastion Technologies within the scope of their work. Nonetheless, Bastion Technologies remains solely responsible for the proper execution of the Services concerning the Client.
Bastion Technologies may substitute any person who will be subrogated to all its rights and obligations under its contractual relationship with the Client. If this occurs, Bastion Technologies will inform the Client of such substitution by any written means.
13. Limitation of Liability of Bastion Technologies
The liability of Bastion Technologies is limited to proven direct damages suffered by the Client due to the use of the Services.
Except for bodily injury, death, or gross negligence, and provided that a claim has been made by registered letter with acknowledgment of receipt within one month of the damage occurring, Bastion Technologies’ liability cannot exceed the amounts it has received in connection with the provision of its Services.
Bastion Technologies is bound only by a best-effort obligation in the execution of the Services, excluding any obligation of result. In the context of the Certification Audit, the Client acknowledges and accepts that the Services constitute assistance in their certification requests and that using the Services does not guarantee obtaining these certifications.
The Client acknowledges and accepts that Bastion Technologies cannot be held liable for:
(i) Decisions made by certification bodies; and
(ii) Any damages resulting from decisions made by the Client based on the recommendations and advice provided by Bastion Technologies as part of the Services.
In general, Bastion Technologies does not guarantee that the Services or the Deliverables resulting from them will meet the Client’s expectations.
14. Accepted Means of Evidence
Proof can be established by any means.The Client is informed that messages exchanged through the Platform, as well as data collected on the Platform and Bastion Technologies' IT equipment, constitute one of the accepted means of evidence, particularly to demonstrate the execution of the Services and the calculation of their cost.
15. Personal Data Processing Methods
15.1. General Provisions
Each party commits to complying with all applicable legal and regulatory obligations regarding personal data protection, including Law 78-17 of January 6, 1978, as amended, known as the "Data Protection and Freedoms Law," and Regulation EU 2016/679 of the European Parliament and Council of April 27, 2016 (collectively, the "Applicable Regulations").
For more details on the data processing carried out by Bastion Technologies, the Client is invited to review Bastion Technologies' privacy policy available here: https://bastion.tech/fr/privacy-policy.
15.2. Methods of Processing Personal Data by Bastion Technologies as a Subcontractor
This clause defines the terms under which Bastion Technologies undertakes, on behalf of the Client, the processing of personal data described below.
Bastion Technologies and the Client mutually commit to complying with the applicable regulations on personal data, particularly the General Data Protection Regulation (GDPR, Regulation EU 2016/679 of April 27, 2016) and the amended Data Protection and Freedoms Law of January 6, 1978 (collectively referred to as the "Applicable Regulations").
Description of Subcontracted Processing
As part of the Services, Bastion Technologies processes personal data as a subcontractor on behalf of and for the Client, who acts as the data controller under the Applicable Regulations. The processing characteristics are described below:
- Purposes of Processing: Providing the Services in accordance with these General Terms and Conditions.
- Nature of Processing Operations: Any operations required to fulfill the aforementioned purposes, including collection, recording, organization, storage, consultation, use, communication by transmission, anonymization, deletion, or destruction.
- Types of Personal Data Processed:
- Identification data (name, first name, photograph)
- Contact details (email addresses, phone numbers)
- Professional data (company, role)
- Data related to training and awareness of cybersecurity risks (history of completed training, chatbot conversation history, responses to phishing campaigns [ignored email, opened email, reported email, compromised credentials, etc.], password strength, and cybersecurity awareness evaluation).
- Connection and browsing data (connection date and time, IP address, location, device, browser, operating system).
- Categories of Individuals Concerned: Clients, employees, and collaborators of the Client.
- Duration of Processing: The duration of the commercial relationship between Bastion Technologies and the Client.
Obligations of Bastion Technologies Toward the Client
- Data Processing: Bastion Technologies agrees to process personal data solely for the purposes listed above and in accordance with the documented instructions of the Client, including regarding transfers of data outside the European Union. Bastion Technologies will notify the Client if any instruction constitutes a violation of the Applicable Regulations. Furthermore, if Bastion Technologies is required to transfer data to a third country or an international organization under applicable law, it will inform the Client of this obligation unless prohibited for significant public interest reasons.
- Data Security and Confidentiality: Bastion Technologies commits to implementing appropriate technical and organizational measures to ensure the security and integrity of personal data, their backup, and the restoration of their availability in case of physical or technical incidents. Bastion Technologies also ensures that individuals authorized to process personal data are bound by confidentiality obligations.
- Other Subcontractors: Bastion Technologies is authorized to engage subcontractors (hereafter referred to as "Subsequent Subcontractors") listed in the General Terms and Conditions for specific processing activities. If there is a change in the list of authorized Subsequent Subcontractors, Bastion Technologies will notify the Client in writing. The Client will have 15 days from receipt of the notification to object based on legitimate reasons. In the absence of objections, the Client will be deemed to have accepted the use of the Subsequent Subcontractor.
- Bastion Technologies ensures that any Subsequent Subcontractor complies with the obligations set forth in the General Terms and Conditions. If a Subsequent Subcontractor fails to meet its data protection obligations, Bastion Technologies remains liable to the Client for ensuring these obligations are fulfilled.
Authorized Subsequent Subcontractors:
Personal Data Transfers Outside the European Union
Bastion Technologies is authorized to transfer personal data processed under the General Terms and Conditions to countries outside the European Union, provided that appropriate safeguards, as defined in Chapter V of the GDPR, are implemented.
Assistance and Information Provision: Bastion Technologies will assist the Client and respond promptly to requests for information, whether they concern exercising individuals’ rights, conducting impact assessments, or responding to inquiries from data protection authorities or the Client’s Data Protection Officer.
Data Breach Notification: Bastion Technologies commits to notifying the Client of any personal data breaches related to the contracted processing and providing all relevant information to allow the Client to notify the competent authority, if necessary, promptly.
Data Disposal: Upon completion of the Services, Bastion Technologies will delete or return the personal data to the Client and will not retain any copies unless required by Applicable Regulations.
Documentation: Bastion Technologies provides the Client, upon request, with all necessary information and documents to demonstrate compliance with its obligations and to facilitate audits. The Client may conduct audits once per year at their own expense, with a minimum two-week notice. Audits must not disrupt Bastion Technologies’ operations or compromise the security and confidentiality of other clients’ data. Audit reports are considered confidential information.
Obligations of the Client Toward Bastion Technologies
The Client agrees to:a) Provide Bastion Technologies only with relevant, proportional, and necessary personal data, excluding any "special" data as defined by the Applicable Regulations unless justified by the processing.b) Collect data lawfully, transparently, and fairly, ensuring the legal basis for the collection and informing individuals concerned.c) Maintain a processing register and comply with the principles of the Applicable Regulations.d) Ensure compliance with Applicable Regulations before and during processing.
16. Force majeure
Bastion Technologies cannot be held responsible for failures or delays in fulfilling its contractual obligations due to a force majeure event occurring during its relationship with the Client, as defined in Article 1218 of the French Civil Code.
If Bastion Technologies is prevented from performing its obligations due to a force majeure event, it must inform the Client by registered letter with acknowledgment of receipt. Obligations are suspended upon receipt of the letter and must be resumed within a reasonable timeframe after the cessation of the force majeure event.
However, Bastion Technologies remains responsible for fulfilling obligations that are not affected by the force majeure event.
17. Termination of Services
The Subscription must be canceled at least 30 days before the end of the current Period for annual Subscriptions and 14 days before the end of the current Period for monthly Subscriptions by:
- The Client, by sending a request to Bastion Technologies at the following email address: support@bastion.tech;
- Bastion Technologies, by sending an email to the Client.
Any Period that has begun is due in full.
In the case of unused credits purchased in advance, the surplus will be refunded via bank transfer within 30 days.
It is the Client's responsibility to download all documents accessible on the Platform before the end date of the Services. Bastion Technologies cannot be held responsible for the deletion of these documents after this date.
The Client will no longer have access to their Account from the end date of the Services.
18. Sanctions in Case of Breach
The following are considered essential obligations for the Client ("Essential Obligations"):
- Payment of the price;
- Providing the necessary information for the Certification Audit in compliance with the schedule set by Bastion Technologies;
- Not providing erroneous or incomplete information to Bastion Technologies;
- Adhering to usual rules of politeness and courtesy in exchanges with Bastion Technologies;
- Not using the Services for a third party;
- Not engaging in illegal, fraudulent activities, or activities that infringe on the rights or safety of third parties, disturb public order, or violate applicable laws and regulations.
In the event of a breach of any of these Essential Obligations, Bastion Technologies may:
- Suspend or revoke the Client's access to the Services;
- Publish any informational message on the Platform that Bastion Technologies deems appropriate;
- Notify any competent authority, cooperate with them, and provide any necessary information to investigate and suppress illegal or unlawful activities;
- Initiate legal action.
These sanctions are without prejudice to any damages that Bastion Technologies may claim from the Client.
For breaches of any obligation other than an Essential Obligation, Bastion Technologies will request the Client to address the breach within a maximum of 15 calendar days via any appropriate written means. If the breach is not rectified within this timeframe, the Services will be terminated.
The termination of Services results in the deletion of the Client's Account.
19. Modification of the General Terms and Conditions
Bastion Technologies may modify its General Terms and Conditions at any time and will inform the Client by any written means (including email) at least 30 calendar days before they take effect.
The modified General Terms and Conditions apply upon the renewal of the Client's Subscription.
If the Client does not accept these changes, they must terminate their Subscription as outlined in the article "End of Services."
If the Client uses the Services after the modifiedGeneral Terms and Conditions come into effect, Bastion Technologies will consider the Client to have accepted them.
20. Language
The French language prevails in case of contradiction or dispute regarding the meaning of a term or provision.
21. Governing Law and Jurisdiction
The General Terms and Conditions are governed by French law.
In the event of a dispute between the Client and Bastion Technologies, and failing an amicable agreement within two months of the first notification, the dispute will fall under the exclusive jurisdiction of the courts of Paris (France), except for mandatory contrary provisions.