Privacy and Data Protection Policy

Privacy and Data Protection Policy

Last updated: 14/02/2026

 

Introduction

MR SURICATE places particular importance on the protection of personal data and the respect for the privacy of individuals concerned.

In the course of its activities, Mr Suricate collects and processes personal data, particularly concerning:

  • its professional prospects and clients
  • the users of its SaaS platform
  • its suppliers and partners
  • job applicants
  • visitors to its websites

Mr Suricate ensures that the collection and processing of this data comply with Regulation (EU) 2016/679 of April 27, 2016 (GDPR) and the amended French Data Protection Act (Loi Informatique et Libertés).

Committed to building lasting relationships based on trust and transparency, Mr Suricate implements appropriate technical and organizational measures to ensure an adequate level of protection for the personal data it processes.

The purpose of this policy is to consolidate into a single document clear, precise, and accessible information regarding the processing operations carried out by Mr Suricate.

MR SURICATE
7 rue Mathurin Brissonneau
44100 Nantes – France

 

Mr Suricate's Role in Data Processing

Depending on the situation, Mr Suricate may act as:

As Data Controller

Mr Suricate acts as Data Controller for data related to:

  • Sales management and B2B prospecting
  • Customer relationship management
  • Administrative support
  • Recruitment
  • Compliance with legal and regulatory obligations

In this capacity, Mr Suricate determines the purposes and means of the processing operations.

As Data Processor

Test scenarios generally utilize test data sets provided or validated by the client.

Depending on the configuration chosen by the client, certain processing operations may, however, involve personal data under the client's responsibility.

In this situation:

  • The Client acts as Data Controller
  • Mr Suricate acts as Data Processor

These processing operations are contractually governed by a specific Data Processing Agreement (DPA).

 

Categories of Data Processed

Depending on the circumstances, Mr Suricate may process, among others:

  • identification data (name, first name)
  • professional contact details (email, company)
  • connection data and technical logs
  • information related to platform usage
  • application data (CV, professional experience)

 

Principles Applicable to Processing Operations

Mr Suricate is committed to adhering to the fundamental principles of the GDPR.

Determined and Legitimate Purpose

Personal data is collected for specified, explicit, and legitimate purposes, including:

  • Provision and Operation of the SaaS Platform
  • User Account Management
  • Technical Support
  • Invoicing
  • System Security and Monitoring
  • B2B Commercial Communication
  • Application Management
  • Compliance with Legal Obligations

Data is not subsequently processed in a manner incompatible with these purposes.

Data Minimization

Mr Suricate ensures that only data strictly necessary for the intended purpose is collected.

The data collected is:

  • Relevant
  • Adequate
  • Limited to what is necessary

Accuracy and Updates

Mr Suricate implements reasonable measures to ensure data accuracy and, where necessary, keeps it updated.

Storage Limitation

Data is retained only for the period necessary to fulfill the processing purposes and in compliance with applicable legal obligations.

By way of indication:

  • Prospect data: 3 years after the last contact
  • Client data: duration of the contractual relationship
  • Technical logs: 12 months
  • Application data: maximum 2 years

 

Legal Bases for Processing

The processing operations implemented are based on one of the following legal grounds:

  • Performance of a contract or pre-contractual measures
  • The legitimate interest of Mr Suricate
  • The consent of the data subject when required
  • Compliance with a legal obligation

 

Hosting and Security

The Mr Suricate platform is hosted on Google Cloud Platform, europe-west1 region (Belgium), with multi-zone deployment.

Mr Suricate implements appropriate technical and organizational measures, including:

  • Encryption of data at rest (AES-256)
  • Encryption of data in transit (TLS)
  • Access management based on the principle of least privilege
  • Multi-factor authentication for privileged accounts
  • Logging of access and security events
  • Daily Backups
  • Indicative RPO (24h) and RTO (8 business hours) Objectives

These measures are integral to an Information Security Management System structured in accordance with ISO 27001 principles.

They fall under a reinforced obligation of means.

 

Subprocessors and Transfers

MR SURICATE use technical subcontractors (cloud hosting, communication services, DNS services, device farms, etc.). The list of subcontractors used by MR SURICATE available in the document titled “Subprocessors List.”

These subprocessors:

  • Are selected based on appropriate security guarantees
  • Are contractually bound
  • Are subject to regular evaluation

In the event of data transfers outside the European Union, Mr Suricate ensures that appropriate safeguards are implemented (standard contractual clauses or equivalent mechanisms).

 

Incident Management

Mr Suricate employs a formalized incident management procedure encompassing:

  • Detection
  • Qualification
  • Containment
  • Remediation
  • Notification without undue delay when necessary
  • Post-incident Analysis

In the event of a personal data breach, obligations stipulated by the GDPR and contractual commitments are adhered to.

 

Artificial Intelligence

Certain platform functionalities may incorporate AI-powered assistance mechanisms.

These mechanisms:

  • Are designed as technical assistance tools
  • Remain under human supervision
  • Do not make automated legal decisions
  • Are integrated into the ISMS risk analysis.

The governance of these mechanisms is described in a separate AI Governance Statement.

 

Data Subject Rights

In accordance with the GDPR, individuals possess the following rights:

  • Right of access
  • Right to Rectification
  • Right to Erasure
  • Right to Restriction of Processing
  • Right to Object
  • Right to Data Portability
  • Right to Withdraw Consent
  • Right to Lodge a Complaint with the CNIL

Requests may be submitted to: dpo@mrsuricate.com

A response will be provided within one month, except in cases of particular complexity.

 

Security and Shared Responsibility

The security of personal data is based on a shared responsibility model:

  • MR SURICATE ensures the security of its platform and infrastructure.
  • Clients and users are responsible for managing their own access and configuring their internal environments.

 

Data Protection Contact

For any questions regarding personal data protection or for exercising the rights stipulated by the GDPR: dpo@mrsuricate.com

 

Policy Update

This policy may be amended to reflect:

  • Regulatory developments
  • Technological advancements
  • Organizational changes

The update date is indicated in the header.

Image by François-Xavier Le Gal

François-Xavier Le Gal

François-Xavier Le Gal is Deputy CEO of Mr Suricate, a French provider of a no-code SaaS solution for automated testing and monitoring. He helps companies ensure the reliability of their digital experiences and manage software quality, including functional, non-regression, performance, accessibility, and compliance testing. On the Mr Suricate blog, he shares insights, methodologies, and real-world feedback on automated testing, QA, and digital performance.

Find him on LinkedIn