Security & Compliance
Netinary guarantees regulatory compliance (GDPR, LCEN, PCI/DSS) and maximum security for your data, with sovereign France/EU hosting.
GDPR
EU compliant
LCEN
French law
PCI/DSS
Secure payments
Sovereignty
Data in France/EU
GDPR Compliance
Netinary is 100% compliant with the General Data Protection Regulation (GDPR) in force since May 2018.
Consent & Transparency
- Explicit consent - User consent collected for each processing of personal data
- Clear information - Transparent display of how collected data is used
- Granularity - Separate consent for each purpose (marketing, analytics, etc.)
- Easy withdrawal - Option to withdraw consent at any time
User Rights
- Right of access - Review of all collected data
- Right to rectification - Correction of inaccurate information
- Right to erasure ("right to be forgotten") - Deletion of data on request
- Right to portability - Export of data in a usable format
- Right to object - Refusal of processing for certain purposes
Data Minimisation
- Strictly necessary collection - Only essential data is collected
- Limited retention period - Automatic deletion after expiry
- Anonymisation - Statistical data anonymised after the legal retention period
- Pseudonymisation - Separation of identity and browsing data
Documentation & Accountability
- Record of processing activities - Complete documentation of all processing operations
- Impact assessment (DPIA) - Risk assessments available for audits
- Privacy policy - Complete legal documentation
- DPO available - Data Protection Officer contactable
MultiBox GDPR Features
Cookie Management
CNIL-compliant consent banner, granular cookie management, consent traceability
Data Export
Automatic export of user data (CSV, JSON, PDF) to handle portability requests
Automatic Deletion
Automatic purge of expired data according to your retention policies (30 days, 1 year, etc.)
Logging
Access logs, consent traceability, change history for CNIL audits
Encryption
Data at rest encrypted (AES-256), SSL/TLS communications, password hashing (bcrypt)
Access Control
Role management (RBAC), restricted data access, strong authentication (2FA available)
LCEN Compliance (French Law)
Netinary complies with the French Digital Economy Trust Act (LCEN) and its obligations to retain connection logs.
Log Retention (1 year)
In accordance with Article 6 of the LCEN and Decree No. 2021-1362, Netinary retains for 1 year the connection data needed to identify any user who has contributed to creating content:
- Connection identifier (login, email, phone number)
- Source IP address of the connection
- Session start and end date and time
- WiFi access point (AP MAC address)
- Device MAC address (if collected)
Judicial Requisitions
Netinary facilitates judicial requisitions that comply with French law:
- Export interface - Rapid extraction of logs for the competent authorities
- Standard formats - CSV, PDF, syslog for analysis by investigators
- Traceability - Secure timestamping (NTP), chain of trust
- Legal assistance - Support to understand and respond to requisitions
Important: Only French judicial authorities may request access to connection logs as part of a lawful investigation.
Protection Against Abuse
Log retention also helps protect your network against abuse and breaches:
PCI/DSS Certification (Payments)
For paid WiFi solutions, Netinary complies with the PCI/DSS standard (Payment Card Industry Data Security Standard).
Payment Security
- No payment card storage - Netinary never stores full card numbers
- Tokenisation - Only secure tokens are retained
- SSL/TLS encryption - All transactions are encrypted
- 3D Secure - Support for strong customer authentication (SCA - Strong Customer Authentication)
Certified Payment Partners
Netinary integrates with payment providers certified PCI/DSS Level 1:
- Stripe - Global leader in online payments
- PayPal - Universal payment solution
- French acquiring banks - Virtual payment terminal integration
- Other PSPs - Open API to connect your own provider
Reducing Your PCI/DSS Burden
By using Netinary with a certified PSP, you significantly reduce your PCI/DSS compliance burden. As the MultiBox never directly processes payment card data, your infrastructure falls outside the PCI scope.
Network & Technical Security
Netinary integrates multiple layers of security to protect your network and your users.
Strong Authentication
- RADIUS 802.1X (EAP-PEAP, EAP-TLS)
- Multi-factor authentication (2FA/MFA)
- X.509 digital certificates
- Secure hashing (bcrypt, SHA-256)
Network Isolation
- Dynamic VLANs per user profile
- Client isolation (no inter-client communication)
- Network segmentation (guest, staff, IoT)
- Automatic quarantine of suspicious devices
Detection & Prevention
- Intrusion detection (IDS)
- DDoS protection and rate limiting
- Automatic blacklisting (IP, MAC)
- Real-time alerts (email, SMS, SNMP)
Encryption
- SSL/TLS 1.2+ (HTTPS captive portals)
- WPA2/WPA3 Enterprise (802.1X)
- Data at rest (AES-256)
- VPN/IPsec for remote administration
Access Control
- RBAC (Role-Based Access Control)
- Granular permission management
- Logging of all admin access
- Restricted IP access (whitelisting)
Backups & Recovery
- Automatic daily backups
- Encrypted backups (local + cloud)
- Disaster recovery plan (DRP)
- One-click restore (rollback)
Data Sovereignty & Hosting
Your data stays in France and Europe, under European jurisdiction.
France/EU Hosting
Netinary guarantees that all your personal data is hosted exclusively in France or the European Union.
- French data centres - Paris, Lyon, Marseille (Tier III/IV)
- Geographic redundancy - Multi-site replication across France
- EU jurisdiction - European law applicable (GDPR, CJEU)
- No transfer outside the EU - No US cloud (AWS US, Google US, etc.)
Digital Sovereignty
Netinary is a French company, a sovereign software publisher and hosting provider.
- Made in France - 100% French development, support and hosting
- Independence - No reliance on the Big Tech giants
- Compliance with French law - Subject only to French and European laws
- Protection against the Cloud Act - No possible access by US authorities
Your Data, Your Control
With Netinary, you keep full control of your data. It stays in France/EU, under your jurisdiction, protected by European law and beyond the reach of extraterritorial legislation.
Audits & Certifications
Netinary has been audited and validated by many demanding clients (banks, hospitals, public administrations).
Security Audits
Netinary has successfully passed numerous security audits conducted by our clients:
- Banks - SWIFT and PCI/DSS security audits for the financial sector
- Hospitals - CISO validation for sensitive health data
- Public administrations - RGS compliance (French General Security Framework)
- Large groups - Penetration tests, code audits, architecture reviews
Penetration Testing
Netinary regularly undergoes penetration testing (pentests) by specialist firms:
- Annual pentest - External offensive security audit
- Vulnerability scanning - Regular automated tests (Nessus, OpenVAS)
- Bug bounty - Responsible vulnerability disclosure programme
- Rapid fixes - Critical security patches applied in < 48h
Security Monitoring & Updates
Continuous Monitoring
Monitoring of CVEs, CERT-FR and ANSSI to anticipate threats
Regular Patches
Security updates applied quickly and tested
Transparency
Detailed release notes, public security changelog
Questions About Our Security or Compliance?
Our technical team is on hand to answer all your security questions and provide the documentation you need (DPIA, record of processing activities, audit reports).