Privacy Policy

Last Updated Dec. 2025

Purpose of this policy

This privacy policy explains how Metroscope processes personal data in the context of the use of its public website and the use of its SaaS application by its clients. It is intended to provide clear and transparent information in accordance with the General Data Protection Regulation.

Data processing related to the website

Metroscope processes personal data collected through its website as data controller.

Personal data are processed in order to manage contact requests, respond to inquiries, organise exchanges with interested parties, ensure the proper functioning and security of the website, and analyse its usage in order to improve its content and performance.

The personal data processed in this context are limited to professional identification and contact data provided via website forms, as well as technical and usage data generated when the website is accessed.

These processing activities are based on Metroscope’s legitimate interest in operating and improving its website, and on consent where required by law, in particular for the use of cookies and similar technologies.

Metroscope uses Google Analytics 4 to measure website audience and analyse usage. This tool may collect information such as pages visited and country derived from IP address. Where required, analytics are activated only after consent has been obtained through the cookie management mechanism. Google are located outside the European Union. In such case, data transfers are governed by appropriate safeguards in accordance with applicable data protection rules, including the EU–US Data Privacy Framework and equivalent contractual mechanisms.

Personal data collected via the website are retained for a limited period, consistent with the purpose of the processing and Metroscope’s internal data retention rules.

Data processing related to the SaaS product

When the SaaS application is used by Metroscope’s clients, Metroscope acts as a data processor on behalf of those clients, who remain the data controllers.

In this context, personal data are processed solely for the purpose of providing access to the application and managing client user accounts, on the basis of the performance of the contract concluded with the client.

Only very limited personal data are processed within the application. These data are restricted to professional identification data necessary for account management, such as name and professional email address. The application is not intended to process personal data beyond what is required for these purposes.

Personal data are processed solely on documented instructions from the client and in accordance with the applicable contractual framework, including the data processing agreement where applicable.

Security of personal data

Metroscope implements appropriate technical and organisational measures to ensure the security and confidentiality of personal data, taking into account the nature of the data and the risks associated with the processing. These measures include access controls, traceability mechanisms, and staff awareness actions.

Data subject rights

In accordance with the General Data Protection Regulation, individuals have rights in relation to their personal data, including rights of access, rectification, erasure, restriction of processing, objection and data portability.

For personal data processed in the context of the SaaS application, requests should primarily be addressed to the relevant client acting as data controller.

Contact

For any questions relating to this privacy policy or the processing of personal data, you may contact:

Metroscope

63 Boulevard Haussmann

75008 Paris – France

dpo@metroscope.tech