Privacy Policy

Last updated: 2026-05-09 · Status: PLACEHOLDER — review with counsel before relying on it.

TODO: This is placeholder boilerplate. Replace with a policy reviewed by qualified privacy counsel before launch.

1. Who we are

secaudit (“we”, “us”) operates https://secaudit.xyz and the client portal at https://app.secaudit.xyz. Contact: [email protected].

2. What we collect

  • Account data (name, email, organization, hashed password) when you register.
  • Engagement data you submit through the portal.
  • Usage and device telemetry necessary to operate the platform securely.
  • Email correspondence and contact-form submissions.

3. Why we process it

To deliver contracted security testing services, communicate with you, prevent abuse, and meet legal obligations.

4. How long we keep it

Account data: while your account is active. Engagement artifacts: per the retention period in your SoW (default 12 months). Aggregated, anonymised telemetry: indefinitely.

5. Your rights

Subject to applicable law (including GDPR/UK GDPR), you may request access, correction, deletion, restriction, or portability of your data. Email us to exercise any of these rights.

6. Subprocessors

A current list is available on request as part of our DPA pack.

7. Changes

We will post material changes here and, where required, notify you by email.