Privacy Policy
Last updated: 2026-05-09 · Status: PLACEHOLDER — review with counsel before relying on it.
TODO: This is placeholder boilerplate. Replace with a policy reviewed by qualified privacy counsel before launch.
1. Who we are
secaudit (“we”, “us”) operates https://secaudit.xyz and the client portal at https://app.secaudit.xyz. Contact: [email protected].
2. What we collect
- Account data (name, email, organization, hashed password) when you register.
- Engagement data you submit through the portal.
- Usage and device telemetry necessary to operate the platform securely.
- Email correspondence and contact-form submissions.
3. Why we process it
To deliver contracted security testing services, communicate with you, prevent abuse, and meet legal obligations.
4. How long we keep it
Account data: while your account is active. Engagement artifacts: per the retention period in your SoW (default 12 months). Aggregated, anonymised telemetry: indefinitely.
5. Your rights
Subject to applicable law (including GDPR/UK GDPR), you may request access, correction, deletion, restriction, or portability of your data. Email us to exercise any of these rights.
6. Subprocessors
A current list is available on request as part of our DPA pack.
7. Changes
We will post material changes here and, where required, notify you by email.