1. Legal notice

Last updated: 5 September 2026

1.1 Website publisher

The website available at ident1ty.com is published by:

IDENT1TY France Société par actions simplifiée with a share capital of EUR 50,000 Registered office: Campus Cyber, Tour Eria, 5-7 rue Bellini, 92800 Puteaux (La Défense), France Registered with the Nanterre Trade and Companies Register under number 981 864 846 SIRET: 981 864 846 00010 Intra-Community VAT number: FR12 981 864 846 Business code (APE): 6201Z, computer programming Telephone: +33 7 55 50 66 70 Email: hello@ident1ty.com

Publication director: Audrey ACHER, President.

1.2 Hosting

The website is hosted by:

OVH SAS 2 rue Kellermann, 59100 Roubaix, France Société par actions simplifiée with a share capital of EUR 50,000,000 Lille Métropole Trade and Companies Register 424 761 419 Telephone: +33 (0)9 72 10 10 07

Data is hosted on infrastructure located within the European Union.

1.3 Group entities

IDENT1TY operates through several separate legal entities:

  1. IDENT1TY France, a French company, publisher of this website.
  2. IDENT1TY Inc, a United States company, 111B S Governors Ave, STE 28217, Dover, Delaware, United States.
  3. ARK Consulting FZCO, a United Arab Emirates company, 01 IFZA Building A2, Dubai Silicon Oasis, IFZA, United Arab Emirates.

Each entity contracts in its own name. Information published on this website creates no joint liability between these entities.

1.4 Intellectual property

All elements making up this website, including its structure, texts, visuals, videos, diagrams, logos and graphic identity, are the exclusive property of IDENT1TY France or are used under licence. They are protected under the French Intellectual Property Code.

Any reproduction, representation, adaptation or exploitation, in whole or in part, by any means and on any medium whatsoever, without the prior written consent of IDENT1TY France, is prohibited and constitutes an infringement under articles L.335-2 et seq. of the French Intellectual Property Code.

1.5 Third-party trademarks

The trademarks, names and logos of the vendors referenced on this website, including BeyondTrust, CyberArk, Delinea, Devolutions, Okta, Saviynt, Secomea, Sphere, Silverfort, Zilla, cidaas and Omada, remain the exclusive property of their respective owners. Their presence reflects a partnership or certification relationship and constitutes neither a transfer of rights nor an endorsement of the content published by IDENT1TY France.

1.6 Credits

Website design, development and search optimisation: Blue Star, digital agency, Blue Star FZ-LLC, United Arab Emirates.

Visuals: IDENT1TY France, image production and processing carried out with Magnific.

1.7 Reporting content

In accordance with article 6 of French law no. 2004-575 of 21 June 2004 on confidence in the digital economy, any user may report content they consider unlawful to hello@ident1ty.com. The report must specify the exact address of the page concerned and the grounds relied upon.

1.8 Governing law

This legal notice is governed by French law. In the event of a dispute, and failing an amicable settlement, jurisdiction is granted to the courts within the jurisdiction of the Versailles Court of Appeal, subject to any mandatory legal provisions.

1.9 Language

This document is a translation provided for information purposes. In the event of any discrepancy, the French version prevails.


2. Privacy policy

Last updated: 5 September 2026

IDENT1TY works on digital identity security. Protecting the data you entrust to us is held to the same standard we apply to our clients’ environments. This policy sets out what we collect, why, for how long, and with whom that data is shared.

2.1 Data controller

The data controller is IDENT1TY France, a société par actions simplifiée registered with the Nanterre Trade and Companies Register under number 981 864 846, whose registered office is at Campus Cyber, Tour Eria, 5-7 rue Bellini, 92800 Puteaux, France.

Any request relating to your personal data may be sent to hello@ident1ty.com.

2.2 Data collected

We collect only the data required for the purposes described below. No special category data within the meaning of article 9 GDPR is collected through this website.

Contact form and meeting requests Last name, first name, business email address, telephone number, company, job title, message content.

Applications Last name, first name, contact details, curriculum vitae, cover letter, professional background and certifications, together with any information provided spontaneously by the candidate, whether the application is submitted through a form or by email.

Browsing IP address, browser type and version, operating system, pages viewed, date and time of access, referral source. This data is processed as described in our cookie policy.

No newsletter subscription is offered on the website at this time.

2.3 Purposes and legal bases

PurposeLegal basisDetails
Responding to a contact requestPre-contractual steps taken at the request of the individual (art. 6.1.b)The request cannot be handled without this data
Business-to-business prospectingLegitimate interest (art. 6.1.f)You may object at any time
Managing applicationsPre-contractual steps (art. 6.1.b)Retention beyond the recruitment process requires consent
Audience measurement and website improvementConsent (art. 6.1.a)See our cookie policy
Website security and loggingLegitimate interest (art. 6.1.f)Prevention of unauthorised access and abuse
Compliance with legal and accounting obligationsLegal obligation (art. 6.1.c)Statutory retention periods

2.4 Recipients

Data is accessible only to IDENT1TY staff whose duties require it, on a least-privilege basis.

The following providers are also recipients, acting as processors within the meaning of article 28 GDPR:

  1. OVH SAS (France), for hosting the website, its databases and the associated mail service.
  2. Google Ireland Limited, for audience measurement, only after your consent has been obtained.

Personal data is never sold, rented or transferred to third parties for commercial purposes.

2.5 Transfers outside the European Union

Where a request falls within the geographical scope of another group entity, the related data may be transmitted to IDENT1TY Inc (United States) or ARK Consulting FZCO (United Arab Emirates).

As at the date of this policy, neither country benefits from a general European Commission adequacy decision applicable to these transfers. They are therefore governed by the standard contractual clauses adopted by the European Commission on 4 June 2021, supplemented by appropriate technical and organisational measures.

A copy of these safeguards is available on request at hello@ident1ty.com.

2.6 Retention periods

  1. Contact request with no commercial follow-up: 3 years from the last contact initiated by the individual.
  2. Client relationship: for the duration of the contract, then 5 years under the commercial limitation period, and 10 years for accounting records.
  3. Unsuccessful application: 2 years from the last contact, in line with CNIL guidance, unless earlier deletion is requested.
  4. Connection logs: 12 months.
  5. Cookies and trackers: 13 months maximum, with consent stored for 6 months.

2.7 Your rights

Under Regulation (EU) 2016/679 and French law no. 78-17 of 6 January 1978 as amended, you have the following rights: access, rectification, erasure, restriction of processing, objection, portability, withdrawal of consent at any time, and the right to issue directives regarding the fate of your data after your death.

These rights may be exercised at hello@ident1ty.com or by post to IDENT1TY France, Tour Eria, 5-7 rue Bellini, 92800 Puteaux, France. We will respond within one month, extendable by two months for complex requests. Proof of identity may be requested where there is reasonable doubt as to the identity of the requester.

You also have the right to lodge a complaint with the French data protection authority: Commission nationale de l’informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, or at cnil.fr.

2.8 Security

Data is hosted within the European Union. Exchanges with the website are encrypted using TLS. Access to internal systems relies on multi-factor authentication and least-privilege entitlement management. Privileged access is subject to dedicated monitoring.

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, you will be informed in accordance with article 34 GDPR.

2.9 Automated decision-making

The website does not carry out any automated individual decision-making or profiling producing legal effects concerning you.

2.10 Minors

The website is intended for a professional audience. No data is knowingly collected from persons under the age of 15.

2.11 Changes

This policy may be amended to reflect legal, technical or organisational developments. The date of the latest update appears at the top of this page. Any material change will be announced on the website.

2.12 Language

This document is a translation provided for information purposes. In the event of any discrepancy, the French version prevails.


3. Cookie policy

Last updated: 5 September 2026

3.1 Definition

A cookie is a file placed on your device when you visit a website. It allows your browser to be recognised, certain information to be stored, and website traffic to be analysed.

3.2 Applicable principle

In accordance with article 82 of the French Data Protection Act and CNIL guidance, only cookies strictly necessary for the operation of the website are placed without your agreement. Any other tracker, including non-exempt audience measurement, is placed only after your explicit consent has been obtained.

Refusing is as straightforward as accepting. Where no choice is made, this counts as a refusal.

3.3 Trackers used

TrackerIssuerPurposeConsentDuration
Session and security cookiesident1ty.comWebsite operation, form protectionNot requiredSession to 12 months
Language preferenceident1ty.comDisplaying the site in English or FrenchNot required12 months
Consent choice storageident1ty.comStoring your decision on trackersNot required6 months
_ga, _ga_*Google Analytics 4Audience measurement, traffic statisticsRequired13 months

No advertising tracker, social media pixel or session recording tool is placed on this website.

3.4 Managing your choice

Your consent is collected through the banner displayed on your first visit. You may change your choice at any time using the “Manage cookies” link in the footer.

Consent is stored for 6 months. After that period, you will be asked again.

You may also configure your browser to refuse or delete cookies. Doing so may degrade certain website features. The steps vary by browser and are described in its online help.

3.5 Data retention

Data collected through trackers is retained for a maximum of 13 months. The resulting aggregated statistics may be retained for 25 months.

3.6 Contact

Any question relating to trackers may be sent to hello@ident1ty.com.

3.7 Language

This document is a translation provided for information purposes. In the event of any discrepancy, the French version prevails.


4. Terms of use

Last updated: 5 September 2026

4.1 Purpose

These terms set out the conditions of access to and use of the ident1ty.com website. Browsing the website constitutes unreserved acceptance of these terms.

4.2 Access to the website

The website is freely accessible to any user with an internet connection. Connection and equipment costs remain the user’s responsibility.

IDENT1TY France reserves the right to suspend access to the website, without notice and without compensation, in particular for maintenance, update or security reasons.

4.3 Nature of the content

Content published on this website is provided for information purposes. It constitutes neither an audit, nor tailored advice, nor a binding recommendation on information systems security. Browsing the website gives rise to no firm commercial offer.

Any engagement is governed by a separate contract between IDENT1TY France and its client, which alone is binding.

4.4 Intellectual property

Article 1.4 of the legal notice applies in full to these terms.

4.5 Prohibited conduct

Any conduct liable to compromise the integrity, availability or confidentiality of the website and its underlying systems is prohibited, including:

  1. Any attempt to gain unauthorised access to any part of the website or to the servers hosting it.
  2. Any penetration test, vulnerability scan or injection carried out without prior written authorisation.
  3. Any large-scale automated extraction of content, including scraping or mirroring.
  4. Any action intended to overload the infrastructure or degrade its operation.

Such conduct may engage the liability of its author under articles 323-1 et seq. of the French Criminal Code.

Security researchers wishing to report a vulnerability are invited to refer to our vulnerability disclosure policy.

4.6 Hyperlinks

The website may link to resources published by third parties, including our technology partners. IDENT1TY France exercises no control over that content and accepts no liability in respect of it.

Linking to the website is permitted provided the link does not harm the image of IDENT1TY and does not imply a partnership that does not exist.

4.7 Liability

IDENT1TY France takes the greatest care over the accuracy of the information published, without being able to guarantee that it is exhaustive or permanently up to date. It cannot be held liable for any indirect damage arising from use of the website, nor for any temporary unavailability, nor for any malfunction of the user’s device or network.

4.8 Personal data

The processing of personal data is described in our privacy policy, which forms an integral part of these terms.

4.9 Changes to these terms

IDENT1TY France may amend these terms at any time. The applicable version is the one online on the day of consultation.

4.10 Governing law

These terms are governed by French law. Any dispute falls within the jurisdiction of the courts within the jurisdiction of the Versailles Court of Appeal, subject to any mandatory provisions.

4.11 Language

This document is a translation provided for information purposes. In the event of any discrepancy, the French version prevails.


5. Vulnerability disclosure policy

Last updated: 5 September 2026

5.1 Commitment

IDENT1TY welcomes reports of vulnerabilities affecting its internet-facing assets. No legal action will be taken against a researcher acting in good faith and in compliance with the rules below.

5.2 Scope

The ident1ty.com domain and its subdomains are in scope. Services operated by our technology partners and our clients’ environments are out of scope.

5.3 Rules of engagement

  1. Do not access, modify or exfiltrate data that does not belong to you.
  2. Do not degrade service availability, which excludes any denial of service attack.
  3. Do not use social engineering against our staff.
  4. Allow us a reasonable remediation period before any publication.

5.4 Reporting

Reports should be sent to hello@ident1ty.com, including a description of the vulnerability, reproduction steps and the estimated impact. An acknowledgement is sent within 5 business days.

5.5 Legal framework

In accordance with article L.2321-4 of the French Defence Code, IDENT1TY may pass information relating to a vulnerability to ANSSI, the French national cybersecurity agency, which preserves the confidentiality of the reporter’s identity.

5.6 Language

This document is a translation provided for information purposes. In the event of any discrepancy, the French version prevails.

FrançaisEnglish