PRIVACY POLICY
1. Scope & Categories of Data Collected
-
Account & Business Data: Contact details, corporate email, billing information, identity verification records, and transaction history.
-
Technical Assessment Data: IP addresses, domain names, target URLs, network configurations, system metadata, and scan logs submitted by the Customer for security testing.
-
AI & Chatbot Interactions: Prompts, configuration queries, remediation text, and conversation transcripts submitted through the customized AI advisory interfaces.
-
Automated Device Data: Browser types, access timestamps, log files, and analytical cookies necessary for service delivery and fraud prevention.
2. Legal Basis & Purpose of Processing
Data is collected and processed strictly to:
-
Execute security assessments, penetration tests, and vulnerability reports as contracted.
-
Operate, customize, and deliver responsive outputs via AI advisory chatbot interfaces.
-
Prevent trial abuse (such as unauthorized re-registrations under the Starter plan) and verify authorized use.
-
Process payments, issue invoices, and fulfill accounting or audit compliance obligations.
-
Protect against unauthorized system access and mitigate service abuse.
3. AI Processing & Model Training Safeguards
-
No Unauthorized Model Training: Customer-specific vulnerability reports, confidential system configurations, and proprietary source code submitted during assessments or chat sessions are not used to train publicly accessible AI models or shared across unaffiliated third-party organizations.
-
Advisory Interface Logs: Prompts entered into AI chatbots are processed solely to generate real-time technical guidance within the active contract term and are retained only for the duration necessary to provide the service.
-
Customer Responsibility for PII: Customer agrees not to transmit unmasked third-party personal data, payment card details, or protected consumer records through automated AI chat interfaces.
4. Data Sharing & Third-Party Processors
The Company does not sell, rent, or trade Customer personal data. Data is shared exclusively with:
-
Infrastructure & Compute Providers: Cloud hosting, database management, and API gateway partners operating under strict confidentiality and security commitments.
-
Payment Processors: Compliant third-party gateways processing subscription billing and transactions.
-
Legal & Regulatory Authorities: Disclosures required to comply with binding legal processes, court orders, or enforceable lawful government requests.
5. Cross-Border Data Transfers
-
Because services are provided globally, Customer data may be stored and processed on secure servers located outside Customer’s local jurisdiction.
-
The Company implements recognized international data transfer safeguards, standard contractual protections, and robust encryption protocols to ensure that transferred data receives a level of protection consistent with globally recognized privacy standards.
6. Data Security & Storage Controls
-
Technical Safeguards: Industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256), multi-factor authentication, network firewalls, and role-based access controls.
-
Vulnerability Findings: Detailed security reports and technical vulnerability findings are treated as highly confidential and restricted to authorized project personnel only.
7. Data Retention & Deletion
-
Audit & Scan Logs: Technical scan results and vulnerability assessment reports are retained for the duration of the active contract term plus a standard operational retention window (e.g., 12 to 24 months) for audit trail verification, after which they are permanently deleted or irreversibly anonymized.
-
Billing Records: Retained in accordance with mandatory statutory accounting obligations.
-
Account Deactivation: Upon formal contract termination, Customer may request the deletion of account records and raw assessment data, subject to legal and regulatory retention duties.
8. Confidentiality & Data Protection
Subject to applicable global privacy laws, authorized representatives of the Customer retain the right to:
-
Access and review the personal information held about them.
-
Request rectification of inaccurate account details.
-
Request the restriction or deletion of personal data where retention is no longer legally required.
-
Withdraw consent for optional marketing communications at any time.
9. Contact & Inquiries
-
For any questions regarding this Privacy Policy, data handling practices, or to exercise data rights, inquiries may be submitted via the designated contact channel at info@cyberez.net.
