DPO / Privacy

Pseudonymisation as a security measure : not a substitute for your governance.

Safe-Doc implements pseudonymisation under GDPR art. 4(5) and constitutes an appropriate technical measure under art. 32. It complements your compliance framework : it does not replace it.

Pseudonymisation : art. 4(5)

Identifying data is replaced with neutral tokens while keeping a mapping that allows re-identification under your control. The data remains personal data under GDPR; processing stays subject to your obligations.

Safe-Doc does not store this mapping centrally: in reversible mode, it is encrypted, TTL-controlled, and under your sole control.

Security measure : art. 32

Pseudonymisation is a security measure recognised under GDPR article 32. Safe-Doc deploys it at the moment risk materialises: before a sensitive document leaves for a third-party AI model.

This measure fits within a controlled framework: data choices, legal basis, AI vendor, final review : your controller responsibilities remain intact.

Audit logs

Every operation generates operation logs and an export report with residual risk indicators. Traceability is ensured without retaining document content in the database or application logs.

  • Entity types detected and replaced
  • Residual risk score
  • Timestamp and operation metadata (no content)

Subprocessors

Safe-Doc documents its subprocessors and their locations. Data processing: Hetzner (Germany). Transactional email: Scaleway (France).

[list to be published : names + regions]

Contractual framework: DPA available. Full list on the Security page.

Security documentation

Data lifecycle, encryption, hosting, compliance and certification roadmap: everything is documented on the dedicated page.

Full security page →