Privacy policy
Publisher: Alessio Scatamacchia, operating ASCA
Website: asca-security.com
Contact: contact@asca-security.com
1. Introduction and scope
This Privacy Policy explains how ASCA collects, uses, shares and protects personal data when you visit asca-security.com, create an account or use the ASCA platform to test mobile applications (the "Service").
It applies to visitors of the website, registered users and members invited to a workspace. It is written to comply with the EU General Data Protection Regulation (GDPR) and the French Data Protection Act.
2. Who we are and how to contact us
The data controller for the website and for your account is Alessio Scatamacchia, operating ASCA.
For any question about this policy or to exercise your rights, write to contact@asca-security.com. This address is also our point of contact for all data protection matters.
3. Our two roles: controller and processor
ASCA acts as a data controller for the data needed to run your account, the website and our communications with you.
ASCA acts as a data processor, on your behalf, for the content you submit to the Service: the applications you upload or import, the test credentials you provide and any personal data these may contain. This processing is governed by our Data Processing Agreement.
4. What we process and why
• Account data
- Name, email address and password (stored only as a secure hash), or the identifier provided by Google or GitHub when you sign in with them.
- Purpose: creating and securing your account and giving you access to the Service. Legal basis: performance of the contract.
• Workspace data
- Workspace names, members, roles and invitations, including the email addresses of the people you invite.
- Purpose: letting you collaborate with your team. Legal basis: performance of the contract.
• Applications and scan data
- The application files you upload or import from Google Play, their metadata, the decompiled code produced during analysis, findings, reports and logs.
- Test credentials and instructions you choose to provide for a scan. They are used only during that scan and are not stored after it.
- Purpose: running the security assessment you request and delivering its results. Legal basis: performance of the contract.
• Communications
- Messages you send us and transactional emails we send you (account verification, password reset, workspace invitations).
- Purpose: answering you and operating your account. Legal basis: performance of the contract and our legitimate interest in responding to requests.
• Technical data
- IP address, browser information and server logs needed to keep the Service secure and available.
- Purpose: security, fraud prevention and troubleshooting. Legal basis: our legitimate interest.
5. How our AI agents use your applications
ASCA analyses applications with AI agents. During a scan, excerpts of the decompiled code of the application are sent to the large language model provider selected for that scan, which returns its analysis to ASCA.
The default model is provided by DeepSeek, whose servers are located in the People's Republic of China. Your account data is never sent to model providers, only the code and context needed for the analysis.
We do not use your applications, code or results to train AI models. The findings produced by the agents are suggestions that you should review before acting on them.
6. Sharing and sub-processors
We never sell your personal data. We share it only with the service providers that help us run ASCA:
- OVH SAS (France): hosting of the website, the platform, the databases and the stored files, in data centres located in the European Union.
- DeepSeek (People's Republic of China): large language model used to analyse application code during scans.
- Brevo (France): sending of transactional emails.
- Google and GitHub (United States): optional sign-in, only if you choose to use them.
- Google Play: retrieval of public application packages when you import an app from the store.
7. International transfers
Your account data is stored in the European Union. Some processing involves transfers outside the European Economic Area, in particular to the People's Republic of China when application code is analysed by the default model, and to the United States when you sign in with Google or GitHub.
These countries may not offer a level of data protection equivalent to the one in the European Union. We limit what is transferred to what the analysis strictly requires. If you do not want your applications analysed outside the European Union, contact us before launching a scan.
8. How long we keep your data
- Account and workspace data: for as long as your account is active, then deleted within 30 days of the account being closed.
- Applications, decompiled code, findings and reports: until you delete the scan or your account, then deleted within 30 days.
- Test credentials: only for the duration of the scan, never stored afterwards.
- Technical logs: up to 12 months.
- Emails exchanged with us: up to 3 years after our last exchange.
9. Security
Each scan runs in an isolated environment. Data is transmitted over encrypted connections, passwords are stored only as hashes, and access to stored files is restricted to the services that need it. Despite these measures, no system is completely secure, and we will notify you without undue delay if a breach affects your data.
10. Your rights
You have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to receive it in a portable format. You can also give instructions about what happens to your data after your death.
To exercise these rights, write to contact@asca-security.com. We answer within one month. If you believe your rights are not respected, you can lodge a complaint with the CNIL (cnil.fr).
11. Cookies
We only use cookies that are strictly necessary for the Service, such as the session cookie that keeps you signed in. We do not use advertising or audience measurement cookies.
12. Changes to this policy
We may update this policy as the Service evolves. If a change significantly affects how your data is processed, we will inform you by email or in the Service.