Your data.
Our framework.
Predictive CyberLab is a professional service published by OPEN C FUTURE. This page describes processing for the programme (film, Briefings, exam, certificate), the organisation workspace and payment.
Our commitments
No advertising tracking
The public site does not use analytics, advertising or social cookies. The signed-in workspace uses a session cookie strictly required for authentication. Interface language is a server preference, not a marketing tracker.
Minimisation
For the organisation: professional identity, company record, VAT number, licences and options. For staff: name, professional email, language, role and seniority. Predictive CyberLab does not store card data.
Delegated payment
Card payments are processed by Stripe (PCI DSS). Predictive CyberLab receives payment status, amount, currency and a transaction identifier — never the card number, expiry or CVC.
EU hosting
The application, databases and programme media are hosted in the European Union. Any non-EU processor is covered by standard contractual clauses.
Processing policy
1. Controller and processor
OPEN C FUTURE, SAS, 80 rue d’Assas, 75006 Paris, RCS Paris 953 641 628, is controller for the organisation account (creation, billing, support). For the staff and network-invitee file, the Client is controller; OPEN C FUTURE acts as processor.
2. Data processed
Account and organisation (legal name, country, NACE sector, intra-community VAT number, administrator). Licences, options and contract period. Learning progress (viewing, Briefings, exam, certificate and public verification token). Network invitations and partner codes (link between organisations, aggregates — not named employees to the network head). Billing data and payment status.
3. Purposes
To deliver the programme and admin workspace, issue the certificate, invoice and collect payment, honour a voucher or invitation, provide support, and meet legal duties (accounts, VAT).
4. Recipients
Stripe (card payments). An e-invoicing provider where applicable. Transactional email (invitations, sign-in, invoices). EU host. Optional AI models via enterprise APIs, with no training on Client content.
5. Retention
Account and invoices: statutory accounting periods. Progress and certificate: contract term, then proof of issue. Session: duration of the signed-in session. Card data does not pass through our application servers.
6. Transfers
Processing in the EU by default. Any processor outside the EU is covered by appropriate safeguards (European Commission standard clauses).
7. Your GDPR rights
Access, rectification, erasure, restriction, portability and objection. Staff should first contact their organisation. The organisation or its CISO may write to dpo@predictivecyberlab.com.
8. Security
TLS in transit, isolation by organisation, card payments at Stripe. The public certificate page shows certificate statements only, not the staff file.