iDuerp logo
Gov Legal · Report Generation

iDuerp

iDuerp is a French mobile and web platform that helps employers build and maintain their DUERP, the workplace risk assessment document France requires from the first employee, with AI risk scoring, action plans, incident logging and PDF reporting.

Active GDPR compliant Free plan · Free trial Freemium API available Verified by Guidaio
Overview

What is iDuerp?

In France, every employer must produce a DUERPDocument Unique d'Évaluation des Risques Professionnels, the single occupational risk assessment document — from the moment they hire their first employee. The obligation dates from decree 2001-1016 of 5 November 2001 and was reinforced by the law of 2 August 2021, in force since 31 March 2022. iDuerp, published by the French company DUOPP (SAS) in Aix-en-Provence, is built entirely around that document and positions itself as the first mobile AI application dedicated to the DUERP.

The product has three parts: native iOS and Android apps, a web console for oversight, and an AI agent specialised in the DUERP. Opening an account starts with automatic company identification from the official INSEE SIRENE registry — SIREN, SIRET, NAF code and legal form are pulled in — after which a risk library is preloaded and tailored to the sector. Eight sector modules exist: bakery and pastry, construction, food service, healthcare, services, transport, retail and education.

Work then follows four stages inside the app — Preparation, Risk assessment, Actions, Documents — with a live completion indicator. Each risk is rated with sliders for severity, likelihood and the number of people exposed, plus exposure factors and contextual photographs (up to two of the hazardous situation and four of the preventive measures). The AI analyses a risk and proposes actions with a description and an estimated deadline; a human validates them, or writes the action manually. Three roles frame access: Admin, Pilote and Participant. A separate Incidents module feeds the accident register, triggers a corrective action and updates the assessment. Once completion is high enough, the DUERP report is generated automatically as a PDF.

The site argues its case in figures: a €4,000 fine per employee for a missing DUERP (€8,000 for a repeat offence), €7,500 for a missing PAPRIPACT — the associated prevention action plan — above 50 employees, and a real accident costing €15,000 to €24,000. The stated audience runs from sole traders and small businesses to multi-site groups, the latter served by an Enterprise offer with SSO, SCIM, a REST API, optional dedicated hosting and SecNumCloud on request. The App Store rating displayed on the site is 4.8.

What it does

  • Score every workplace risk on severity, likelihood and number of people exposed using guided sliders
  • Photograph a hazard from the shop floor and let the AI qualify it and suggest a corrective action
  • Generate the official DUERP report as a PDF from the Docs tab
  • Build and follow an action plan with an owner, a deadline, sub-tasks, photo evidence and recurrence
  • Report an incident in two minutes: title, casualties, severity, location, witnesses, first aid, photos
  • Run guided safety audits and safety briefings, and keep the accident register up to date
  • Steer several establishments from one central web console
Audience

When to use iDuerp / When not to

A quick filter to help you decide if iDuerp is the right fit.

When to use iDuerp

  • French employers of roughly 1 to 200 staff with no dedicated health and safety function, who have to produce their DUERP themselves
  • Owner-managers, craft businesses and small companies working in one of the eight preloaded sectors: bakery and pastry, construction, food service, healthcare, services, transport, retail and education
  • HR managers and field supervisors who need to score risks, assign corrective actions and log incidents from a phone rather than from a desk
  • Multi-site networks and groups that want a single web console with granular roles and site-by-site comparison
  • Accountants, employment lawyers and prevention consultants equipping a whole portfolio of client companies

When not to use iDuerp

  • Employers outside France: the entire reference framework is French labour law (DUERP, PAPRIPACT, Code du travail), and no equivalent regime is documented on this site
  • Consumers and private individuals, since the offer is strictly business-to-business
  • Anyone expecting an audit, an on-site inspection or legal, medical or regulatory advice, all three of which article 3 of the terms explicitly rules out
  • Directors hoping to shift liability: the publisher states the tool grants no delegation of authority and no exemption from criminal responsibility
  • Teams that need to record health data, biometrics, political opinions or criminal convictions, which customers contractually undertake never to enter
Get started

How to use iDuerp

A typical end-to-end flow, from setup to results.

  1. Download the iOS or Android app and create an account with an email address and a password
  2. Search for your company: INSEE SIRENE auto-completion fills in the official details, then confirm the summary sheet
  3. Choose a subscription and the sector modules that match your business
  4. Invite your team from Settings > Team (+): first name, last name, email, role, phone, first-aid training and gender
  5. Work through the four stages in order: Preparation, Risk assessment, Actions, Documents
  6. Rate each preloaded risk, or create a custom one from the Risks tab (+)
  7. Review the AI's suggested actions and their estimated deadlines, then validate them or write your own
  8. Generate the DUERP as a PDF from the Docs tab
  9. Switch to the web console at console.iduerp.com for centralised oversight, backed by an eleven-article getting-started path
  10. Book a Calendly slot if you need the Enterprise team, a data migration or an API integration
Quick read

Pros & Cons

Pros

  • Covers the whole French regulatory chain end to end: DUERP, then action plan, then PAPRIPACT, then safety registers
  • Sector-specific risk libraries load at account creation, so nobody starts from a blank page
  • Field capture on mobile, by photo and voice, instead of re-keying notes back at the office
  • The AI is optional: off by default, activated explicitly by the establishment owner, and switchable off again at any time
  • EU hosting on Google Cloud through Google Ireland, a detailed GDPR policy, an explicit commitment not to resell personal data and no advertising SDK
  • Permanent free plan, no credit card needed to start and no lock-in commitment
  • Low entry price for this market at €9.99 excluding VAT per month for up to five users, with three distinct roles and a multi-site console from the standard offer onwards

Cons

  • The reference framework is entirely French: outside the DUERP regime the tool loses most of its value (an OSHAid trademark is announced for the United States, but nothing about it is documented on this site)
  • The site contradicts itself on its own prices: the pricing page shows Gratuit, then €9.99 excluding VAT per month for 1 to 5 users, then €1.99 excluding VAT per additional user, while the support FAQ shows Essentiel at €149 per year, Équipe at €499 and Structure at €799
  • Sector modules are announced as included in every paid subscription on the pricing page, but billed €17.99 per year and restricted to annual billing in the FAQ
  • No data processing agreement is published or explicitly offered, even though the publisher declares itself an article 28 processor
  • No maintained sub-processor list: only OpenAI and Google Ireland are named, in prose, and the GDPR policy carries neither an effective date nor a version number, with retention expressed generically as the duration of the contract
  • Article 7 of the terms authorises the commercialisation of irreversibly anonymised aggregate data, with no dedicated objection mechanism
  • A very young publisher, with no Wayback Machine capture, no public API documentation despite a documented REST API being sold, and a blog whose articles are all listed as coming soon
Pricing

Pricing & Plans

A permanent free plan is available at €0 per month, with no credit card required. The lowest paid entry point advertised on the pricing page is €9.99 excluding VAT per month, and it is a flat fee covering the 1-to-5-user tier rather than a price per user; the same tier costs €89 excluding VAT per year, a stated 25% discount. Beyond five users, each additional user is billed €1.99 excluding VAT per month. Every amount shown on the site is quoted excluding VAT, in euros. Buyers should be aware that a second, incompatible price list is published on the same site: the support FAQ describes Essentiel at €149 per year, Équipe at €499 per year and Structure at €799 per year, with sector modules at €17.99 per year each and annual billing mandatory. This entry retains the figures from the dedicated pricing page; the discrepancy is not resolved anywhere by the publisher. Data migration, API integration and the Enterprise offer are all quoted on request, with no public amount.

Plan 1
  • Gratuit — €0 per month
  • to start the process and test the solution
Plan 3
  • Au-delà de 5 utilisateurs — €1.99 excluding VAT per user per month
Solutions Entreprise — price on request
  • multi-site
  • SSO
  • SCIM
  • API and optional dedicated hosting
Alternative list quoted in the support FAQ and inconsistent with the pricing page
  • Essentiel €149 per year
  • Équipe €499 per year
  • Structure €799 per year
  • plus modules at €17.99 per year
Special offers — Permanent free plan at €0 per month, with no credit card required · Annual billing at €89 excluding VAT per year instead of €9.99 excluding VAT per month, a stated 25% discount · Full free press access to the platform for journalists, with credentials issued within 24 hours · Free prescriber kit for accountants and lawyers: sales argument, template email and supporting materials
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how iDuerp handles your data.

GDPR overview

GDPR is addressed in detail, although not on a dedicated page: the privacy policy sits as a fifteen-section block inside the single legal page, alongside the legal notice and the terms of sale. iDuerp declares itself a processor under article 28 for customer data and a controller for accounts, billing, support, security and legal compliance; the legal bases cited are contract performance, legal obligation and legitimate interest. Access, rectification, erasure, restriction, objection and portability are all guaranteed, exercised through the customer company with contractual assistance from iDuerp. Transfers outside the EU for the AI services are covered by standard contractual clauses plus additional technical measures, and article 22 is addressed: no automated decision producing legal or significant effects. Cookies are limited to strictly necessary ones plus anonymised audience measurement under consent. The GDPR contact is contact@duopp.fr. No effective date and no version number are displayed.

Who owns the data?

The terms are explicit: data entered in the application remains the property of the Client. For that business data iDuerp acts as a processor under article 28 of the GDPR, while the customer company remains the controller for its own employees' records. For its own purposes — accounts and access, billing, support, security, logging, fraud prevention and legal compliance — iDuerp is itself a controller. Article 7 of the terms goes one step further: once data has been irreversibly anonymised, iDuerp may exploit and commercialise it, and the Client expressly waives any claim, ownership right, right of oversight or right to remuneration over that aggregated material.

Reuse rights

Because the data stays the Client's property, the customer can consult, export and reuse its own risk assessments, action plans and generated documents freely, with no permission to request from the publisher. On its own side iDuerp restricts processing to structuring, managing and tracking the DUERP, documenting risks, keeping an audit trail of actions, support, maintenance and service security. There is no monetisation of identifiable personal data: no sale, no rental, no advertising sharing, no commercial profiling, no third-party advertising SDK and no marketing behavioural tracking. When the AI features are switched on, only risk descriptions, technical assessments, photos of work situations and the metadata strictly required are transmitted; names, emails, identifiers, passwords, financial data, tokens, files from the Documents module, device identifiers and IP addresses never are. Irreversibly anonymised data, by contrast, may be reused by the publisher for statistics, algorithm and AI model improvement, research and development, sector benchmarks and the sale of non-identifiable aggregate datasets.

Data retention & training

Retention summary
Retention is described only in general terms. Section 10 of the GDPR policy states that data is kept for the duration of the contract, then deleted or returned according to the customer's instructions, unless a legal obligation requires otherwise, and that technical backups may persist temporarily. No figure is given anywhere: no retention period in months or years, no purge deadline after termination, and no effective date or version number on the policy itself to date the commitment. Separately, irreversibly anonymised records are explicitly reused for statistics, algorithm improvement and sector benchmarks, with no stated end point. Elsewhere the site mentions the French regulatory context that a DUERP history must be kept for forty years, but it does not say that iDuerp itself stores data for that long.
Trains on customer data
Configurable
Training opt-out available
Yes
GDPR contact

Hosting summary

User data is hosted in the European Union on Google Cloud Platform, under Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. That Dublin address is the hosting provider's, not the publisher's: iDuerp is published by DUOPP (SAS), a French company. The legal notice states that iDuerp user data is hosted in the European Union in accordance with the GDPR, and the press kit describes a Google Cloud Suite setup with data encrypted, backed up and continuously synchronised. Transfers outside the EU remain possible for the AI services; the publisher says they are framed by standard contractual clauses together with additional technical measures. Enterprise customers can request dedicated hosting, and SecNumCloud is offered on demand. No data centre region is named more precisely than Ireland, and no hosting contract or certification document is published.

Hosting countries
🇮🇪 Ireland
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting iDuerp.

  • Two incompatible price lists are live on the site at the same time, the pricing page against the support FAQ: get the real price confirmed in writing before you subscribe
  • Sector modules are described as included on the pricing page but as €17.99 per year and annual-billing-only in the FAQ; check which version your contract applies
  • Every amount displayed excludes VAT, so French VAT has to be added before you compare budgets
  • Automation complacency is the real human risk here: the AI proposes actions and deadlines and it is tempting to validate them wholesale, yet a rubber-stamped risk assessment is still legally yours. Note too that the AI is off by default, so without an explicit activation none of the analysis features run
  • Data ownership: article 7 of the terms authorises the publisher to exploit and commercialise irreversibly anonymised aggregate data, with no dedicated way to object, and contractual liability is capped at the subscription fees of the last twelve months
  • No data processing agreement is published even though the publisher acts as an article 28 processor: ask for one before entering anything tied to your employees
  • The tool exempts a director from no criminal or administrative liability whatsoever, and it is neither an audit nor legal advice. Note also that the legal notice gives Aix-en-Provence as the registered office while the French national register records 6 rue Jeanne Jugan, 50400 Granville
Setup

Setup & Integrations

Technical difficulty

Very low for the standard offer. There is nothing to install: native iOS and Android apps plus a web console. The publisher advertises account creation in two minutes and onboarding in under thirty; the company is identified automatically from INSEE SIRENE records, and a sector-specific risk library is preloaded as soon as the account exists. An eleven-article getting-started path is published on the site. Complexity appears only at the Enterprise end, with SAML/OIDC SSO, SCIM provisioning, the REST API and data migration, and the publisher handles those itself on a quote.

Deployment

Web appMobile appIOS appAndroid appAPI

Apps stores

Integrations

INSEE SIRENE OpenAI

Supported languages

FrenchEnglish
Company

Behind iDuerp

Company name
DUOPP
Founded
INFORMATION_NOT_FOUND
Country of origin
🇫🇷 France
Headquarters
Aix-en-Provence, France
US office
Los Angeles (CA), United States
UBO
Jean-Christophe Paturel
UBO country
🇫🇷 France
Domain registrar country
🇱🇹 Lithuania
Legal contact
Support contact

Social

Official links

Resources

All the official URLs gathered for verification and reference.

Compare

Alternatives

Tools that compete with or complement iDuerp.

O OiRA
FAQ

Frequently asked questions

Is the DUERP actually mandatory?
Yes. In France the Document Unique d'Évaluation des Risques Professionnels is required of every employer from the first employee onwards, under articles L4121-1 and R4121-1 of the Labour Code.
Is there a free plan?
Yes. The Gratuit plan is permanent, costs €0 per month and needs no credit card to get started.
What does the cheapest paid plan cost?
€9.99 excluding VAT per month for the 1-to-5-user tier, or €89 excluding VAT per year. Be aware that the support FAQ on the same site publishes a different list, starting at €149 per year.
Is there a mobile app?
Yes, native apps on the App Store and on Google Play, plus a web console for centralised oversight.
Are the AI features mandatory?
No. They are disabled by default, require an explicit activation by the establishment owner, and can be switched off again at any time.
Is my data used to train AI models?
Not for public models. Irreversibly anonymised data may however be used to improve iDuerp's own algorithms and AI models.
Where is the data hosted?
In the European Union, on Google Cloud Platform under Google Ireland Limited in Dublin.
What user roles are available?
Three: Admin for full management, Pilote to follow risks and actions, and Participant to consult and contribute.
Is there an API?
Yes, a REST API covering risks, actions, incidents, documents and establishments, alongside SAML/OIDC SSO, SCIM provisioning and webhooks. No public documentation is available online.
Can I migrate an existing DUERP?
Yes, through an on-demand service covering Excel, CSV, PDF files and exports from legacy software, quoted after a scoping call.
Conclusion

Should you pick iDuerp?

iDuerp is a narrow tool, deliberately so: it does one regulatory job — French DUERP compliance — from end to end. Its strengths follow from that focus. The regulatory chain is covered without gaps, from risk scoring through the action plan to the generated report and the safety registers. Field capture on a phone, with photos and voice notes, matches how small businesses actually work. The AI is genuinely optional, off until someone switches it on. Hosting sits in the European Union and the privacy policy is unusually detailed for a product of this size. The entry price is low: a permanent free plan, then €9.99 excluding VAT a month for up to five users.

The reservations are just as clear. DUOPP, the publisher, has no Wayback Machine history and very little public track record — normal for a young company, but worth knowing before signing. The site contradicts itself on price, with two incompatible lists live at once, and on whether sector modules are included or billed separately; neither discrepancy is resolved anywhere. No data processing agreement is published, although iDuerp declares itself an article 28 processor, and no maintained sub-processor list exists. Article 7 of the terms lets the publisher commercialise irreversibly anonymised aggregate data with no dedicated objection mechanism.

The practical verdict: for a French employer with one to a few hundred employees and no dedicated safety function, iDuerp is a reasonable and inexpensive way to produce a real DUERP and keep it alive. For a larger group, everything material — price, hosting, contract terms — should be settled in the quote rather than read off the site.