← Back ARES
ARES

Privacy Policy — ARES Attest

ARES SIGNUM  ·  ares-signum.eu  ·  Effective: 1 September 2026  ·  Last updated: 1 September 2026

1. Who We Are

ARES Attest is published by ARES SIGNUM SAS, a company incorporated under French law, with its registered office in Frouzins, France.

For any privacy-related inquiries, contact us at: contact@ares-signum.eu

2. What ARES Attest Does

ARES Attest is a device security compliance agent. It is deployed by organisations to continuously monitor the security configuration of mobile devices in their fleet and to produce audit-ready compliance evidence.

ARES Attest is not a Mobile Device Management (MDM) solution. It does not manage, control, lock, wipe, or restrict the device in any way. It reports what the device's security configuration is — nothing more.

3. What Data We Collect

ARES Attest collects device security configuration data only: anonymous, non-personal technical readings that describe the security posture of the device. These readings cover categories such as operating system version and patch status, device encryption state, screen lock configuration, network interface states, and other security-relevant system settings.

Each reading is a factual state observation (e.g., whether a security feature is enabled or disabled). No reading identifies a person, and no reading reveals the content of any user activity.

ARES Attest also collects its own application version for fleet management purposes.

Device identity is established through a hardware-attested cryptographic key generated on the device at enrolment. This key is bound to the device hardware and cannot be extracted, copied, or used to identify the device owner.

4. What We Do Not Collect

ARES Attest does not collect any personal data. Specifically, the application never accesses, reads, or transmits:

No GDPR Article 6 legal basis for processing personal data is required because no personal data is processed. No Data Protection Impact Assessment (DPIA) is required. No Data Processing Agreement (DPA) is required between the deploying organisation and ARES SIGNUM.

5. Legal Basis

The device security configuration data collected by ARES Attest is anonymous technical data that does not constitute personal data under the General Data Protection Regulation (GDPR). It cannot, alone or in combination with other data held by ARES SIGNUM, identify a natural person.

Where the deploying organisation considers the data to fall within the scope of GDPR due to its specific context of use, the applicable legal basis is the legitimate interest of the data controller (the deploying organisation) in maintaining the security of its device fleet, pursuant to GDPR Article 6(1)(f), or the performance of a contract between the organisation and the device user, pursuant to GDPR Article 6(1)(b).

6. How Data Is Used

The data collected by ARES Attest is used exclusively for:

Data is never used for advertising, profiling, behavioural analysis, or any purpose unrelated to device security compliance.

7. Data Storage and Security

All data is processed and stored on EU-sovereign infrastructure operated by OVH, a French company subject exclusively to European Union law. There is no US-origin hyperscaler dependency and no exposure to extraterritorial data-access legislation.

Data is encrypted in transit between the device and the backend. Device identity is hardware-attested and cryptographically bound to the device.

8. Third-Party Sharing

Device security configuration data is shared only with the administrators of the organisation that enrolled the device. It is not sold, rented, or disclosed to any third party for any purpose.

ARES SIGNUM does not use third-party analytics, advertising, or tracking services within the application.

9. Data Retention

Data is retained for the duration of the device's enrolment with the deploying organisation, in accordance with the contractual terms between ARES SIGNUM and the organisation. Upon unenrolment or contract termination, data is deleted in accordance with applicable retention schedules.

10. Your Rights

If you believe that any data processed by ARES Attest constitutes personal data in your specific context, you may exercise the following rights under GDPR:

To exercise any of these rights, contact your organisation's IT administrator or ARES SIGNUM directly at contact@ares-signum.eu.

You also have the right to lodge a complaint with the French data protection authority (CNIL) or with the supervisory authority of your EU member state of residence.

11. Children

ARES Attest is a business application intended for use by organisations. It is not directed at individuals under the age of 18.

12. Changes to This Policy

We may update this privacy policy to reflect changes in our practices or applicable law. The updated policy will be published at this URL with a revised effective date. We encourage you to review this page periodically.

13. Contact

ARES SIGNUM SAS
Frouzins, France
contact@ares-signum.eu