Data protection
Privacy policy
Last updated: July 2026
This page describes what data is processed when you visit this website or use the FirstSI platform, why it is processed, how long it is kept and how to exercise your rights.
Who is the data controller?
The data controller is the website publisher, identified in the legal notice. For any question: contact@firstsi.com.
Data processed on this website
- No tracking cookies — this website uses no advertising cookies, no third-party analytics trackers, and loads no resources from third-party servers.
- Display preference — if you use the light/dark theme toggle, your choice is stored only in your browser (local storage, key
fsi-theme), with no identifier and no transmission to the server. This storage is strictly necessary for the feature you requested; you can clear it at any time by deleting the site data in your browser. - Technical logs — like any web server, the hosting provider records connection logs (IP address, pages visited, timestamps) for security purposes, kept for a maximum of 12 months.
- Contact requests — if you write to us, your email address and the content of your message are used solely to reply to you, then deleted no later than 3 years after the last exchange.
These operations are based on the publisher's legitimate interest (ensuring the security and proper operation of the website) and, for contact requests, on steps taken at your request with a view to a possible contract. No data is ever used for advertising purposes.
Data processed by the FirstSI platform
FirstSI is an infrastructure monitoring tool. In that context, the client organization is the data controller and FirstSI acts as the technical means. Depending on the active modules, the platform processes:
- User accounts — name, email address, role, sign-in log.
- File events — file paths, Windows accounts that accessed the files, timestamps.
- Network flows and DNS queries — internal IP addresses, volumes, queried domains.
- Inventory — installed software and versions on monitored hosts.
This data is collected exclusively for the security and monitoring of the information system, on the basis of the client organization's legitimate interest. It is never resold and never used for any other purpose.
Retention periods
- Operational data — 90 days in direct access, then archived.
- Archives — retention configurable by the client organization according to its internal policy.
- Audit trail — kept for the duration of the contract to meet accountability obligations.
- Accounts — deleted when the account is closed or the contract ends.
Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict and port your personal data. The platform includes export and purge tools that allow your organization to answer these requests.
- If you are a FirstSI client — write to contact@firstsi.com.
- If you are an employee of an organization using FirstSI — contact your employer first, as the data controller.
You may also lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr).
Security
The technical and organizational measures protecting this data — per-client isolation, encryption, strong authentication, audit trail — are detailed on the Security & GDPR page.