top of page

PRIVACY POLICY

1. Scope & Categories of Data Collected

  • Account & Business Data: Contact details, corporate email, billing information, identity verification records, and transaction history.

  • Technical Assessment Data: IP addresses, domain names, target URLs, network configurations, system metadata, and scan logs submitted by the Customer for security testing.

  • AI & Chatbot Interactions: Prompts, configuration queries, remediation text, and conversation transcripts submitted through the customized AI advisory interfaces.

  • Automated Device Data: Browser types, access timestamps, log files, and analytical cookies necessary for service delivery and fraud prevention.

2. Legal Basis & Purpose of Processing

Data is collected and processed strictly to:

  • Execute security assessments, penetration tests, and vulnerability reports as contracted.

  • Operate, customize, and deliver responsive outputs via AI advisory chatbot interfaces.

  • Prevent trial abuse (such as unauthorized re-registrations under the Starter plan) and verify authorized use.

  • Process payments, issue invoices, and fulfill accounting or audit compliance obligations.

  • Protect against unauthorized system access and mitigate service abuse.

3. AI Processing & Model Training Safeguards

  • No Unauthorized Model Training: Customer-specific vulnerability reports, confidential system configurations, and proprietary source code submitted during assessments or chat sessions are not used to train publicly accessible AI models or shared across unaffiliated third-party organizations.

  • Advisory Interface Logs: Prompts entered into AI chatbots are processed solely to generate real-time technical guidance within the active contract term and are retained only for the duration necessary to provide the service.

  • Customer Responsibility for PII: Customer agrees not to transmit unmasked third-party personal data, payment card details, or protected consumer records through automated AI chat interfaces.

4. Data Sharing & Third-Party Processors

The Company does not sell, rent, or trade Customer personal data. Data is shared exclusively with:

  • Infrastructure & Compute Providers: Cloud hosting, database management, and API gateway partners operating under strict confidentiality and security commitments.

  • Payment Processors: Compliant third-party gateways processing subscription billing and transactions.

  • Legal & Regulatory Authorities: Disclosures required to comply with binding legal processes, court orders, or enforceable lawful government requests.

5. Cross-Border Data Transfers

  • Because services are provided globally, Customer data may be stored and processed on secure servers located outside Customer’s local jurisdiction.

  • The Company implements recognized international data transfer safeguards, standard contractual protections, and robust encryption protocols to ensure that transferred data receives a level of protection consistent with globally recognized privacy standards.

6. Data Security & Storage Controls

  • Technical Safeguards: Industry-standard encryption in transit (TLS 1.2+) and at rest (AES-256), multi-factor authentication, network firewalls, and role-based access controls.

  • Vulnerability Findings: Detailed security reports and technical vulnerability findings are treated as highly confidential and restricted to authorized project personnel only.

7. Data Retention & Deletion

  • Audit & Scan Logs: Technical scan results and vulnerability assessment reports are retained for the duration of the active contract term plus a standard operational retention window (e.g., 12 to 24 months) for audit trail verification, after which they are permanently deleted or irreversibly anonymized.

  • Billing Records: Retained in accordance with mandatory statutory accounting obligations.

  • Account Deactivation: Upon formal contract termination, Customer may request the deletion of account records and raw assessment data, subject to legal and regulatory retention duties.

8. Confidentiality & Data Protection

Subject to applicable global privacy laws, authorized representatives of the Customer retain the right to:

  • Access and review the personal information held about them.

  • Request rectification of inaccurate account details.

  • Request the restriction or deletion of personal data where retention is no longer legally required.

  • Withdraw consent for optional marketing communications at any time.

9. Contact & Inquiries

  • For any questions regarding this Privacy Policy, data handling practices, or to exercise data rights, inquiries may be submitted via the designated contact channel at info@cyberez.net.

bottom of page