Cyber Dream
  • Home
  • About Us
  • + Our SaaS
    • Mlab.sh Threat Intelligence
    • Mlab IR Incident Response
    • Mlab TPRM for DORA
    • Mon Audit RGPD
    • FraudCodex
  • OSINT
  • Contact

Privacy Policy

  • HOME
  • LEGAL
  • PRIVACY POLICY

Last updated: September 13, 2026

1. Introduction

Cyber Dream SAS (SIREN 951 325 984, capital social 500 EUR, registered at 3 rue Jacques Daguerre, 44300 Nantes, France) is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, your rights under the GDPR, and how we ensure its protection.

This policy applies to cyberdream.io. The platforms we operate alongside it — mlab.sh (including ir.mlab.sh and tprm.mlab.sh), monauditrgpd.fr and fraudcodex.org — each publish their own privacy policy covering the data they process; where one exists, it governs that service.

2. Data We Collect

We may collect the following categories of personal data:

  • Identification data: name, email address, company name (via contact forms or account creation).
  • Technical data: IP address, browser type, operating system, pages visited, session duration, server logs.
  • Authentication data: timestamps, access logs, cookies, tokens, anonymous session identifiers.
  • Payment data: billing details and transaction records (processed exclusively via secure third-party providers; we do not store card numbers).
  • Communication data: messages sent via our contact form or email exchanges.

3. Purpose of Data Processing

Your data may be processed for the following purposes:

  • Providing, operating, and improving our services and platforms.
  • Managing user accounts, authentication, and security.
  • Responding to inquiries and providing support.
  • Processing orders, payments, and invoices.
  • Complying with legal and regulatory obligations.

4. Legal Basis for Processing

Depending on the context, data processing is based on:

  • Your consent (e.g., non-essential cookies, newsletter subscription).
  • Performance of a contract (e.g., delivering a service you purchased).
  • Legal obligation (e.g., tax and accounting requirements).
  • Legitimate interest (e.g., fraud prevention, service improvement), provided your fundamental rights are not overridden.

5. Cookies and Tracking Technologies

We use cookies and similar technologies to ensure proper website functionality, collect anonymous usage statistics, and manage consent preferences. For full details, see our Cookie Policy.

6. Data Recipients

Your data may be shared with:

  • Our hosting provider (Scaleway SAS, located in France/EU).
  • Cloudflare, Inc. (United States), which provides the CDN, TLS termination and DDoS protection in front of the site and therefore processes connection data including your IP address. Transfers are covered by Cloudflare's standard contractual clauses and its EU–US Data Privacy Framework certification.
  • Discord Netherlands B.V. / Discord, Inc. (United States), which receives contact form submissions: messages sent through the form are delivered to a private internal channel so our team is notified. Only the fields you fill in are transmitted (name, email, optional company, message). Transfers rely on standard contractual clauses.
  • Payment processors for transaction handling.
  • Public authorities or courts when legally required.

We do not sell your personal data to third parties. We do not use third-party advertising trackers.

7. Data Transfers Outside the EU

Our infrastructure is hosted within the European Union (Scaleway, France). Two processors named in section 6 — Cloudflare and Discord — may process data outside the EU; in both cases the transfer relies on standard contractual clauses, supplemented for Cloudflare by its EU–US Data Privacy Framework certification. No other category of personal data leaves the European Union.

8. Data Retention

We retain personal data only for as long as necessary:

  • Server logs (including IP addresses): up to 12 months, for security and abuse prevention.
  • Contact form submissions: 12 months after the last interaction, after which the message is deleted from the internal channel it was delivered to.
  • Client and billing data: for the duration required by applicable tax and commercial law (up to 10 years for invoices).
  • Account data: until account deletion request.

9. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the right to:

  • Access your personal data and obtain a copy.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict processing in certain circumstances.
  • Data portability: receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time, without affecting the lawfulness of prior processing.
  • Lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertes, www.cnil.fr).

To exercise your rights, contact us at: [email protected]

10. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS) and at rest, access controls, regular security audits, and secure development practices.

11. Policy Updates

This Privacy Policy may be updated periodically. The most recent version will always be available at cyberdream.io/legal/privacy. Significant changes will be communicated via email or on-site notice.

12. Contact

For any questions regarding this Privacy Policy:

  • Cyber Dream SAS
  • 3 rue Jacques Daguerre, 44300 Nantes, France
  • Email: [email protected]

Cyber Dream helps you build, secure, and scale your digital infrastructure. Let’s talk about your next project.

Company

  • About Us
  • Contact Us

Legal

  • Mentions Legales
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

Solutions

  • Mlab.sh
  • Mlab IR
  • Mlab TPRM
  • Mon Audit RGPD
  • FraudCodex
  • OSINT Investigation
Cyber Dream

Copyright © CyberDream. All rights reserved.