Privacy policy — ReguNest
Version 1.2 · updated on 13/09/2026
This policy explains how ReguNest processes personal data under the GDPR, account security, and that the app was designed with AI tools (notice + liability limits).
1. Controller
ReguNest is operated by the platform publisher (N1 account). For privacy requests: contact email to be set by the publisher.
2. Legal framework
Processing complies with Regulation (EU) 2016/679 (GDPR) and applicable national law.
The official GDPR text is available on EUR-Lex (link at the bottom). Supervisory authority guidance (e.g. CNIL) complements this framework.
3. Data we process
Depending on your role, ReguNest may process: - account data (email, name, role, language, login logs); - entity / license data; - product and regulatory dossier data (fields, uploaded files); - sales data (volumes, forecasts, notes); - data-assistant conversations (when available); - evidence of acceptance of this policy (date and version); - security event logs (admin password resets, support impersonation).
4. Purposes
- provide and secure the SaaS service; - enable collaboration between clients and suppliers; - manage access and licenses; - restore account access if a user forgets credentials or becomes unreachable (controlled password reset); - provide technical/operational support when necessary; - send transactional notifications; - maintain service reliability (technical and security logs).
Main legal bases: performance of a contract / pre-contractual steps, and consent where required (including initial acceptance to access the service).
5. Recipients
- authorized users in your entity (according to rights); - technical processors needed for EU hosting, transactional email, backups; - the platform publisher only for support and service continuity, in a limited and logged manner.
No sale of personal data.
6. Transfers outside the EU
Hosting target is the European Union. Any later transfer outside the EU will be documented here with appropriate safeguards.
7. Retention
- account: for the contractual relationship, then deletion or anonymization within a reasonable period; - business documents/data: as needed for the client and legal obligations; - technical and security logs: limited to security, diagnostics and accountability needs.
8. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, objection, portability, and the right to lodge a complaint with a supervisory authority.
To exercise rights: contact your entity admin and/or the ReguNest publisher.
9. Account security and passwords
Reasonable measures include: - passwords stored only as hashes (never displayed or recoverable in clear text); - secure sessions, entity isolation, controlled file access; - self-service reset via email link (“forgot password”) when you can access your mailbox.
### 9.1 Administrator password reset
If you lose access to your account or mailbox, an authorized administrator may set a **new temporary password**: - your **entity Administrator** for accounts in **their** entity only; - the **platform publisher** (Owner / General Manager and other expressly authorized roles) according to internal rights.
The temporary password must be shared with you through an appropriate channel (not permanently stored in clear text in the app). The previous password stops working immediately. These operations are **logged** (who, when, which account).
### 9.2 Support login (“log in as”)
For support or service continuity, certain authorized platform roles may open a session on an account **without knowing the password**, with a banner to return to the original account. This feature: - is **restricted** to authorized roles (including Owner, General Manager, and Sales Manager for client accounts); - is **not** granted to the **Developer** profile on client accounts; - is **logged**.
It does not reveal the password. It is used only for assistance and continuity, under data minimization.
10. AI-assisted design — notice and acceptance
The user **acknowledges that they have been informed** that:
- the ReguNest application was **designed and developed with the assistance of artificial-intelligence tools** (help with code, documentation and configuration); - those tools do not replace a security audit, penetration test or certification.
**By clicking “I accept”, the user confirms** they have read this notice and accept it in order to use the service.
### 10.1 Limitation of liability (AI)
To the **extent permitted by applicable law**, neither the platform publisher / creator nor **ReguNest** shall be liable for a malfunction, error, outage or incident (including a data leak or loss) **that would result from the use of those AI tools during design**.
This clause **does not waive** the controller’s **statutory GDPR duties** (appropriate security, information, notification of authorities / data subjects when required by law, and data-subject rights). It limits **contractual** liability related to AI-assisted design and does not override mandatory law.
11. Updates
This policy is versioned. Material changes create a new version shown automatically on this page and require renewed consent when the accepted version is no longer the active one.
Official references
The ReguNest policy above is stored dynamically: when a new version is published in the database, this page and the consent prompt show the updated text automatically. EUR-Lex / CNIL links point to official EU sources (legal framework); they do not replace ReguNest’s own policy.