Privacy Policy
Last updated: July 1, 2026
DATAGRIS CYBERSECURITY ("DATAGRIS," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
1. Information We Collect
Account Information: When you register, we collect your name, email address, company name, and password (stored as a salted hash).
Usage Data: We collect scan targets, results, reports, SOC logs, and configuration changes you make on the platform. This data is necessary to provide the service.
Technical Data: IP address, browser type, device information, and page interaction events are collected for security auditing and platform improvement.
Payment Data: Payment processing is handled by our PCI-compliant processor (Stripe). We do not store full credit card numbers on our servers.
2. How We Use Your Information
- To operate, maintain, and improve the DATAGRIS platform
- To generate scan reports and security assessments you request
- To send service-related communications (billing, security alerts, product updates)
- To detect, investigate, and prevent fraudulent or unauthorized activity
- To comply with legal obligations
3. Data Sharing
We do not sell your personal information. We may share data with:
- Service Providers: Third-party vendors who help us operate the platform (cloud hosting via AWS, payment processing via Stripe, email delivery via SendGrid). These providers are contractually bound to protect your data.
- Legal Compliance: When required by law, court order, or valid government request.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred with notice to you.
4. Data Retention
We retain your data for the duration of your account plus:
- Free Plans: 90 days after deletion
- Pro Plans: 365 days after deletion
- Enterprise: Per your Data Processing Agreement
You may request earlier deletion by contacting [email protected].
5. Security
We implement industry-standard security measures:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Regular security audits and penetration testing
- Access controls and multi-factor authentication for administrative access
- Strict data isolation between customer environments
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Request correction or deletion of your data
- Restrict or object to processing
- Data portability
- Withdraw consent at any time
To exercise these rights, contact [email protected].
7. Cookies
We use essential cookies for authentication and session management. We do not use tracking cookies or third-party analytics cookies without your explicit consent. You can control cookie preferences through your browser settings.
8. International Transfers
Your data is stored on AWS servers in the United States. If you are located outside the US, we ensure appropriate safeguards (Standard Contractual Clauses) are in place for data transfers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or platform notification. Your continued use after the effective date constitutes acceptance of the updated policy.
10. Contact
For privacy-related inquiries:
Email: [email protected]
Data Protection Officer: [email protected]
Address: DATAGRIS CYBERSECURITY, 251 Little Falls Drive, Wilmington, DE 19808, United States