Skip to main content

Security & Compliance

Netinary guarantees regulatory compliance (GDPR, LCEN, PCI/DSS) and maximum security for your data, with sovereign France/EU hosting.

100% GDPR Compliant
France/EU Hosting
PCI/DSS Certified

GDPR

EU compliant

LCEN

French law

PCI/DSS

Secure payments

Sovereignty

Data in France/EU

GDPR Compliance

Netinary is 100% compliant with the General Data Protection Regulation (GDPR) in force since May 2018.

Consent & Transparency

  • Explicit consent - User consent collected for each processing of personal data
  • Clear information - Transparent display of how collected data is used
  • Granularity - Separate consent for each purpose (marketing, analytics, etc.)
  • Easy withdrawal - Option to withdraw consent at any time

User Rights

  • Right of access - Review of all collected data
  • Right to rectification - Correction of inaccurate information
  • Right to erasure ("right to be forgotten") - Deletion of data on request
  • Right to portability - Export of data in a usable format
  • Right to object - Refusal of processing for certain purposes

Data Minimisation

  • Strictly necessary collection - Only essential data is collected
  • Limited retention period - Automatic deletion after expiry
  • Anonymisation - Statistical data anonymised after the legal retention period
  • Pseudonymisation - Separation of identity and browsing data

Documentation & Accountability

  • Record of processing activities - Complete documentation of all processing operations
  • Impact assessment (DPIA) - Risk assessments available for audits
  • Privacy policy - Complete legal documentation
  • DPO available - Data Protection Officer contactable

MultiBox GDPR Features

Cookie Management

CNIL-compliant consent banner, granular cookie management, consent traceability

Data Export

Automatic export of user data (CSV, JSON, PDF) to handle portability requests

Automatic Deletion

Automatic purge of expired data according to your retention policies (30 days, 1 year, etc.)

Logging

Access logs, consent traceability, change history for CNIL audits

Encryption

Data at rest encrypted (AES-256), SSL/TLS communications, password hashing (bcrypt)

Access Control

Role management (RBAC), restricted data access, strong authentication (2FA available)

LCEN Compliance (French Law)

Netinary complies with the French Digital Economy Trust Act (LCEN) and its obligations to retain connection logs.

Log Retention (1 year)

In accordance with Article 6 of the LCEN and Decree No. 2021-1362, Netinary retains for 1 year the connection data needed to identify any user who has contributed to creating content:

  • Connection identifier (login, email, phone number)
  • Source IP address of the connection
  • Session start and end date and time
  • WiFi access point (AP MAC address)
  • Device MAC address (if collected)

Judicial Requisitions

Netinary facilitates judicial requisitions that comply with French law:

  • Export interface - Rapid extraction of logs for the competent authorities
  • Standard formats - CSV, PDF, syslog for analysis by investigators
  • Traceability - Secure timestamping (NTP), chain of trust
  • Legal assistance - Support to understand and respond to requisitions

Important: Only French judicial authorities may request access to connection logs as part of a lawful investigation.

Protection Against Abuse

Log retention also helps protect your network against abuse and breaches:

Intrusion detection - Behavioural analysis of connections
Abuse prevention - Identification of malicious users
Incident reports - Documentation for disputes or complaints

PCI/DSS Certification (Payments)

For paid WiFi solutions, Netinary complies with the PCI/DSS standard (Payment Card Industry Data Security Standard).

Payment Security

  • No payment card storage - Netinary never stores full card numbers
  • Tokenisation - Only secure tokens are retained
  • SSL/TLS encryption - All transactions are encrypted
  • 3D Secure - Support for strong customer authentication (SCA - Strong Customer Authentication)

Certified Payment Partners

Netinary integrates with payment providers certified PCI/DSS Level 1:

  • Stripe - Global leader in online payments
  • PayPal - Universal payment solution
  • French acquiring banks - Virtual payment terminal integration
  • Other PSPs - Open API to connect your own provider

Reducing Your PCI/DSS Burden

By using Netinary with a certified PSP, you significantly reduce your PCI/DSS compliance burden. As the MultiBox never directly processes payment card data, your infrastructure falls outside the PCI scope.

Network & Technical Security

Netinary integrates multiple layers of security to protect your network and your users.

Strong Authentication

  • RADIUS 802.1X (EAP-PEAP, EAP-TLS)
  • Multi-factor authentication (2FA/MFA)
  • X.509 digital certificates
  • Secure hashing (bcrypt, SHA-256)

Network Isolation

  • Dynamic VLANs per user profile
  • Client isolation (no inter-client communication)
  • Network segmentation (guest, staff, IoT)
  • Automatic quarantine of suspicious devices

Detection & Prevention

  • Intrusion detection (IDS)
  • DDoS protection and rate limiting
  • Automatic blacklisting (IP, MAC)
  • Real-time alerts (email, SMS, SNMP)

Encryption

  • SSL/TLS 1.2+ (HTTPS captive portals)
  • WPA2/WPA3 Enterprise (802.1X)
  • Data at rest (AES-256)
  • VPN/IPsec for remote administration

Access Control

  • RBAC (Role-Based Access Control)
  • Granular permission management
  • Logging of all admin access
  • Restricted IP access (whitelisting)

Backups & Recovery

  • Automatic daily backups
  • Encrypted backups (local + cloud)
  • Disaster recovery plan (DRP)
  • One-click restore (rollback)

Data Sovereignty & Hosting

Your data stays in France and Europe, under European jurisdiction.

France/EU Hosting

Netinary guarantees that all your personal data is hosted exclusively in France or the European Union.

  • French data centres - Paris, Lyon, Marseille (Tier III/IV)
  • Geographic redundancy - Multi-site replication across France
  • EU jurisdiction - European law applicable (GDPR, CJEU)
  • No transfer outside the EU - No US cloud (AWS US, Google US, etc.)

Digital Sovereignty

Netinary is a French company, a sovereign software publisher and hosting provider.

  • Made in France - 100% French development, support and hosting
  • Independence - No reliance on the Big Tech giants
  • Compliance with French law - Subject only to French and European laws
  • Protection against the Cloud Act - No possible access by US authorities

Your Data, Your Control

With Netinary, you keep full control of your data. It stays in France/EU, under your jurisdiction, protected by European law and beyond the reach of extraterritorial legislation.

France/EU Hosting
GDPR Jurisdiction
Guaranteed Sovereignty

Audits & Certifications

Netinary has been audited and validated by many demanding clients (banks, hospitals, public administrations).

Security Audits

Netinary has successfully passed numerous security audits conducted by our clients:

  • Banks - SWIFT and PCI/DSS security audits for the financial sector
  • Hospitals - CISO validation for sensitive health data
  • Public administrations - RGS compliance (French General Security Framework)
  • Large groups - Penetration tests, code audits, architecture reviews

Penetration Testing

Netinary regularly undergoes penetration testing (pentests) by specialist firms:

  • Annual pentest - External offensive security audit
  • Vulnerability scanning - Regular automated tests (Nessus, OpenVAS)
  • Bug bounty - Responsible vulnerability disclosure programme
  • Rapid fixes - Critical security patches applied in < 48h

Security Monitoring & Updates

Continuous Monitoring

Monitoring of CVEs, CERT-FR and ANSSI to anticipate threats

Regular Patches

Security updates applied quickly and tested

Transparency

Detailed release notes, public security changelog

Questions About Our Security or Compliance?

Our technical team is on hand to answer all your security questions and provide the documentation you need (DPIA, record of processing activities, audit reports).