×

This Security & Compliance page explains the general approach Rahat.fr takes to information security, data protection, service reliability, third-party risk, artificial intelligence governance and compliance when providing websites, software, SaaS solutions, AI integrations, automation services and other digital services.


Security is a shared responsibility between Rahat.fr, its customers, users, technology providers and other parties involved in delivering or using digital services.


The measures described on this page may vary depending on the nature, architecture, sensitivity and contractual requirements of a particular service.


Unless expressly stated otherwise, references to security standards or recognized frameworks describe practices or principles that Rahat.fr may consider and do not constitute a claim of certification, accreditation or formal compliance with a particular certification scheme.


1. Service Provider:


The services covered by this page are provided by:


Rahat.fr

Legal form: Entrepreneur individuel (EI)

PDG: Rahat Ahmed


SIREN: 990 334 369

SIRET (Head Office): 990 334 369 00024

VAT Number: FR13990334369


Registered Address:

3 Impasse Pascal

14000 Caen

France


Website: www.rahat.fr

Email: info@rahat.fr


2. Security Commitment:


Rahat.fr seeks to protect its systems, services and information against risks including:


• Unauthorized access.

• Accidental or unlawful disclosure.

• Data loss.

• Unauthorized modification.

• Destruction.

• Misuse.

• Fraud.

• Malware.

• Credential compromise.

• Service disruption.

• Other reasonably foreseeable security threats.


We seek to apply security measures proportionate to the nature of the service, information being processed, available technology and identified risks.


3. Security by Design:


Where appropriate, security considerations may be incorporated into the design, development, implementation and maintenance of Rahat.fr services.


This may include consideration of:


• Authentication.

• Authorization.

• Access control.

• Data minimization.

• Encryption.

• Secure configuration.

• Logging.

• Backup.

• Error handling.

• API security.

• Input validation.

• Dependency security.

• Privacy requirements.

• Third-party integrations.

• Incident-response requirements.


Security measures may differ according to the technical architecture and contractual scope of a service.


4. Data Protection and GDPR:


Where Rahat.fr processes personal data, we seek to comply with applicable data-protection requirements, including the General Data Protection Regulation (GDPR/RGPD) and applicable French data-protection law.


Depending on the processing activity, Rahat.fr may act as:


• Data controller.

• Data processor.

• Joint controller where legally applicable.


Further information about personal-data processing is provided in our Privacy Policy.


Where Rahat.fr processes personal data on behalf of a professional customer as a processor, a Data Processing Agreement (DPA) may apply.


5. Data Minimization:


Rahat.fr seeks to limit the collection and processing of personal data to information that is relevant and reasonably necessary for the intended purpose.


Customers should also avoid providing unnecessary personal, confidential or sensitive information when it is not required for the relevant service.


Where AI or automation services are used, users should carefully consider whether personal or confidential information is necessary before submitting it.


6. Access Control:


Access to systems, administrative interfaces and information may be limited according to operational requirements.


Depending on the system concerned, measures may include:


• Role-based access.

• Individual user accounts.

• Authentication requirements.

• Administrative access restrictions.

• Permission management.

• Principle of least privilege.

• Periodic access review where appropriate.

• Removal or modification of access when no longer required.


The exact access-control mechanisms depend on the service and technology used.


7. Authentication and Account Security:


Rahat.fr may use authentication controls appropriate to particular systems.


Depending on the service, these may include:


• Password authentication.

• Strong password requirements.

• Multi-factor authentication where available or appropriate.

• Session management.

• Login monitoring.

• Access restrictions.

• Identity verification.

• OAuth or third-party authentication.


Customers and users are responsible for protecting their own passwords, credentials, API keys and authentication devices.


Credentials should not be shared with unauthorized persons.


8. Password Security:


Where passwords are managed directly by systems controlled by Rahat.fr, appropriate password-protection mechanisms should be used according to the technology concerned.


Users are encouraged to:


• Use strong and unique passwords.

• Avoid reusing passwords across unrelated services.

• Keep passwords confidential.

• Use multi-factor authentication where available.

• Immediately change credentials suspected of being compromised.

• Notify Rahat.fr of suspected unauthorized account access.


Rahat.fr will never ask users to send their full password by email.


9. Encryption:


Depending on the system, service and technical environment, Rahat.fr may use encryption or secure communication protocols to protect information.


Measures may include:


• HTTPS/TLS for web communications.

• Encryption provided by hosting or cloud platforms.

• Secure transmission of credentials.

• Encryption of selected stored data where appropriate.

• Encrypted backup or storage mechanisms where available and appropriate.


The availability and implementation of encryption may vary according to the technology and third-party infrastructure involved.


10. Network and Infrastructure Security:


Rahat.fr may rely on hosting, cloud, server and infrastructure providers for the operation of its digital services.


Depending on the service architecture, security controls may include:


• Firewalls.

• Network access controls.

• Web application protection.

• Server hardening.

• Secure configuration.

• Monitoring.

• Rate limiting.

• DDoS protection provided by infrastructure providers.

• Restricted administrative access.

• Updates and patching.


Some infrastructure security controls may be operated directly by third-party hosting or cloud providers.


11. Secure Software Development:


For software and web-development projects, Rahat.fr seeks to consider secure development practices where appropriate.


These may include:


• Input validation.

• Output encoding.

• Authentication controls.

• Authorization checks.

• Protection against common web vulnerabilities.

• Secure session handling.

• Dependency review.

• Configuration management.

• Error handling.

• Appropriate API access controls.

• Avoidance of hard-coded secrets where reasonably possible.

• Testing before deployment.


The level of testing and security review may depend on the project scope and contractual requirements.


12. Vulnerability Management:


Rahat.fr may periodically review relevant systems, applications, dependencies and configurations for known or reasonably identifiable vulnerabilities.


Where appropriate, actions may include:


• Applying security updates.

• Updating dependencies.

• Replacing unsupported components.

• Correcting identified vulnerabilities.

• Reviewing configuration.

• Restricting vulnerable functionality.

• Monitoring relevant security advisories.


The timing of remediation may depend on severity, technical complexity, service availability and vendor dependencies.


13. Updates and Patch Management:


Security and maintenance updates may be applied to Rahat.fr-controlled systems when reasonably necessary.


Some applications, plugins, operating systems, hosting services, APIs and other components are maintained by third-party providers.


Rahat.fr cannot independently control the timing or availability of every third-party update.


Customers operating software or infrastructure under their own control remain responsible for maintaining those systems unless maintenance is expressly included in a Rahat.fr service agreement.


14. Logging and Monitoring:


Depending on the service, Rahat.fr or its technology providers may maintain technical logs for purposes including:


• Security.

• Authentication.

• Error diagnosis.

• Performance monitoring.

• Fraud prevention.

• Troubleshooting.

• Incident investigation.

• Service reliability.


Logs may include technical information such as timestamps, IP addresses, device information, account identifiers and system events where relevant and lawful.


Logging practices and retention periods vary according to the service and applicable requirements.


15. Backups and Recovery:


Where appropriate, Rahat.fr may use backup mechanisms intended to reduce the risk of permanent data loss.


Backup arrangements may vary according to:


• Service type.

• Hosting provider.

• Subscription plan.

• Contractual scope.

• Infrastructure architecture.

• Data sensitivity.


Backups are not a guarantee that all data can always be recovered.


Unless backup management is expressly included in the contracted service, customers should maintain appropriate independent backups of important data under their control.


16. Business Continuity and Service Resilience:


Rahat.fr seeks to take reasonable measures to support service continuity and recovery following technical incidents.


Depending on the service, this may include:


• Backups.

• Redundant infrastructure provided by third parties.

• Recovery procedures.

• Monitoring.

• Alternative service methods.

• Technical support.

• Restoration procedures.


No internet-based service can guarantee uninterrupted availability.


17. Security Incident Management:


If Rahat.fr becomes aware of a security incident affecting systems or information under its responsibility, we may take appropriate measures including:


• Investigating the incident.

• Containing the affected system.

• Restricting compromised access.

• Changing credentials.

• Correcting vulnerabilities.

• Restoring services.

• Reviewing logs.

• Assessing affected information.

• Documenting relevant findings.

• Implementing corrective measures.


Actions taken will depend on the nature and severity of the incident.


18. Personal Data Breaches:


Where a security incident constitutes a personal-data breach, Rahat.fr will assess the incident according to applicable data-protection requirements.


Where legally required, the relevant supervisory authority and/or affected individuals will be notified in accordance with applicable legal requirements and timeframes.


The competent data-protection supervisory authority in France is the Commission Nationale de l'Informatique et des Libertés (CNIL).


19. Security Notifications:


Customers who reasonably suspect:


• Unauthorized account access.

• Credential compromise.

• Data exposure.

• Suspicious activity.

• Security vulnerabilities.

• Fraudulent use of a Rahat.fr service.


should contact Rahat.fr as soon as reasonably possible at:


Email: info@rahat.fr


Please include sufficient information to help identify and assess the issue, but do not send passwords, complete payment-card details or unnecessary sensitive data.


20. Responsible Security Reporting:


Rahat.fr welcomes good-faith reports of potential security vulnerabilities affecting its services.


A vulnerability report should, where possible, include:


• The affected service or URL.

• A description of the issue.

• Steps reasonably necessary to reproduce the issue.

• The potential impact.

• Relevant technical evidence.


Submitting a vulnerability report does not authorize:


• Access to another person's account.

• Destruction or modification of data.

• Extraction of personal data.

• Service disruption.

• Denial-of-service testing.

• Social engineering.

• Installation of malware.

• Unauthorized penetration testing.

• Any activity prohibited by applicable law.


Researchers should minimize access to data and stop testing if personal, confidential or sensitive information is encountered.


21. Third-Party Security:


Rahat.fr may use third-party providers for services including:


• Hosting.

• Cloud infrastructure.

• Domain management.

• Payment processing.

• Email delivery.

• Analytics.

• Artificial intelligence.

• Communication.

• Authentication.

• Customer support.

• Storage.

• APIs.

• Cybersecurity tools.


Third-party providers are responsible for the security of systems under their own control.


Where appropriate, Rahat.fr seeks to consider factors such as security, privacy, contractual protections and reliability when selecting or configuring important providers.


22. Subprocessors:


Where Rahat.fr acts as a data processor and uses other providers to process personal data on behalf of a customer, those providers may act as subprocessors.


Where required, subprocessor arrangements may be governed by:


• Data Processing Agreements.

• Contractual confidentiality obligations.

• Data-protection requirements.

• International data-transfer safeguards.

• Other contractual controls.


Additional information may be provided in the applicable DPA or service documentation.


23. International Data Transfers:


Some technology providers used by Rahat.fr may process or store information outside France or the European Economic Area (EEA).


Where personal data is transferred internationally, Rahat.fr seeks to rely on legally recognized transfer mechanisms where required, which may include:


• Adequacy decisions.

• Standard Contractual Clauses (SCCs).

• Other legally recognized transfer safeguards.


Further information is provided in our Privacy Policy and, where applicable, Data Processing Agreement.


24. Artificial Intelligence Security:


Rahat.fr may provide or integrate AI-powered services.


Security considerations related to AI may include:


• Access control.

• Data minimization.

• API-key protection.

• Prompt and input handling.

• Provider selection.

• Output review.

• Logging where appropriate.

• Prevention of unauthorized system access.

• Protection of confidential information.

• Human oversight where appropriate.


Customers should avoid submitting unnecessary confidential, sensitive or regulated information to AI services unless the relevant service has been specifically designed and approved for that type of processing.


25. AI Governance and Responsible Use:


Rahat.fr seeks to use and provide artificial intelligence responsibly and in accordance with applicable legal requirements.


Depending on the service, considerations may include:


• Transparency.

• Human oversight.

• Data protection.

• Security.

• Accuracy limitations.

• User instructions.

• Risk assessment.

• Appropriate use restrictions.

• Third-party AI-provider requirements.


Where applicable, Rahat.fr may adapt relevant AI practices as European and French regulatory requirements evolve.


No statement on this page should be interpreted as a claim that every Rahat.fr AI service has obtained a particular external certification unless expressly stated.


26. Automated Outputs:


AI-generated or automated outputs may contain inaccuracies, omissions or unexpected results.


Customers and users are responsible for determining whether outputs are suitable for their intended purpose.


Appropriate human review should be applied where outputs may affect important legal, financial, employment, healthcare, regulatory, safety-related or other significant decisions.


Additional AI-related conditions may apply to individual services.


27. Payment Security:


Where Rahat.fr accepts electronic payments, payment processing may be performed through independent payment-service providers.


Payment providers may implement their own security measures and compliance obligations.


Where payment-card information is entered directly into an independent payment provider's interface, Rahat.fr may not receive or store complete payment-card details.


Customers should review the applicable payment provider's terms and privacy information.


28. Privacy and Confidentiality:


Rahat.fr seeks to protect personal and confidential information according to applicable contractual, legal and technical requirements.


Where appropriate, confidentiality controls may include:


• Restricted access.

• Contractual confidentiality clauses.

• Secure transmission.

• Confidentiality agreements.

• Data minimization.

• Controlled sharing.

• Appropriate deletion or retention procedures.


Customers remain responsible for ensuring that information they provide to Rahat.fr may lawfully be shared and processed.


29. Data Retention and Deletion:


Information is retained according to factors such as:


• Processing purpose.

• Contractual requirements.

• Account status.

• Security needs.

• Legal obligations.

• Tax and accounting requirements.

• Dispute or claim requirements.


Where retention is no longer necessary and no legal or contractual reason requires continued storage, information may be deleted, anonymized or otherwise handled according to the applicable system and policy.


Further information is available in our Privacy Policy.


30. Physical Security:


Where physical systems, workstations or devices are used to access Rahat.fr services or information, reasonable safeguards may be applied depending on the environment.


Physical security for servers and infrastructure hosted by external providers is generally managed by the relevant hosting, cloud or data-center provider.


31. Employee, Contractor and Authorized-Person Access:


Where personnel, contractors or other authorized persons require access to information or systems, access should be limited to legitimate operational requirements.


Where appropriate, controls may include:


• Confidentiality obligations.

• Access restrictions.

• Individual accounts.

• Permission management.

• Security instructions.

• Removal of access when no longer required.


The exact controls may vary depending on the role and service concerned.


32. Customer Security Responsibilities:


Customers and users also play an important role in protecting services.


Customers should:


• Protect account credentials.

• Use strong passwords.

• Enable multi-factor authentication where available.

• Maintain secure devices.

• Keep customer-controlled software updated.

• Restrict access to authorized users.

• Protect API keys and access tokens.

• Maintain appropriate backups.

• Review account activity.

• Promptly report suspected incidents.

• Avoid transmitting unnecessary sensitive information.

• Follow relevant security instructions.


Rahat.fr is not responsible for security failures caused exclusively by systems, credentials or infrastructure controlled by the customer, subject to applicable mandatory law.


33. API and Integration Security:


Where Rahat.fr provides or configures APIs and integrations, security may depend on both Rahat.fr systems and external providers.


Customers should protect:


• API keys.

• Access tokens.

• Webhook secrets.

• Client secrets.

• Administrative credentials.


Such credentials should not be publicly published or embedded in insecure client-side environments unless specifically intended for public use.


Compromised credentials should be revoked or replaced promptly.


34. Email and Communication Security:


Email and electronic communications may be subject to phishing, impersonation and other fraud risks.


Customers should verify unusual payment requests, account changes or credential requests before acting on them.


Rahat.fr will not normally request passwords or complete payment-card details by ordinary email.


Suspicious communications claiming to represent Rahat.fr may be reported to:


info@rahat.fr


35. Compliance Approach:


Depending on the services provided and activities concerned, Rahat.fr seeks to take account of applicable requirements relating to:


• French law.

• European Union law.

• GDPR/RGPD.

• Privacy and electronic communications.

• Consumer protection.

• Digital services.

• Cybersecurity.

• Artificial intelligence.

• Intellectual property.

• Electronic commerce.

• Contractual obligations.

• Tax and invoicing requirements.

• Accessibility where applicable.


The precise legal requirements applicable to a particular service depend on the nature of the activity, customer, data and technology involved.


36. Security Standards and Certifications:


Rahat.fr may take guidance from recognized security principles, standards or industry practices where relevant.


However, unless explicitly stated and verifiable, Rahat.fr does not claim certification under frameworks such as:


• ISO/IEC 27001.

• SOC 2.

• PCI DSS.

• HDS.

• SecNumCloud.

• Other external certification schemes.


The use of third-party providers that hold particular certifications does not automatically mean that Rahat.fr itself holds the same certification.


37. Audits and Assessments:


Depending on business requirements, Rahat.fr may conduct or commission security, privacy or compliance assessments.


These may include:


• Internal reviews.

• Configuration reviews.

• Vulnerability assessments.

• Access reviews.

• Privacy reviews.

• Third-party assessments.

• Formal audits where appropriate.


The scope and frequency of such activities may depend on risk, contractual commitments and technical requirements.


38. No Absolute Security Guarantee:


No website, application, cloud service, network or internet-connected system can guarantee absolute security.


Although Rahat.fr seeks to apply reasonable safeguards, risks may remain due to factors such as:


• New vulnerabilities.

• Human error.

• Third-party failures.

• Cyberattacks.

• Credential compromise.

• Software defects.

• Infrastructure incidents.

• Events outside reasonable control.


Users should take appropriate precautions when using online services.


39. Compliance Documentation:


Depending on the service and relationship with the customer, relevant compliance documentation may include:


• Privacy Policy.

• Cookie Policy.

• Terms of Use.

• Terms of Sale.

• Refund & Cancellation Policy.

• Data Processing Agreement (DPA).

• Accessibility information.

• Specific service agreements.

• Confidentiality agreements.

• Security information.

• Other contractual documents.


These documents should be read together where applicable.


40. Updates to This Security & Compliance Page:


Rahat.fr may update this page to reflect changes in:


• Security practices.

• Services.

• Infrastructure.

• Technology.

• Third-party providers.

• Legal requirements.

• Regulatory requirements.

• Artificial intelligence practices.

• Risk-management measures.


The latest version will be published on the Rahat.fr website.


41. Contact:


For questions regarding security, privacy, compliance or a suspected security issue, contact:


Rahat.fr

Legal form: Entrepreneur individuel (EI)

PDG: Rahat Ahmed


SIREN: 990 334 369

SIRET (Head Office): 990 334 369 00024

VAT Number: FR13990334369


3 Impasse Pascal

14000 Caen

France


Email: info@rahat.fr

Website: www.rahat.fr


For security-related messages, please include “Security” in the email subject where possible.


Last updated: 9 August 2026