Privacy Policy
Your privacy is our priority. Last updated: December 2024
Zero-Knowledge Commitment
1. Information We Collect
Account Information:
- Email address and name for account creation
- Company information for enterprise accounts
- Billing information for paid services
- Authentication credentials (encrypted)
Usage Data:
- Login times and frequency
- Feature usage patterns (anonymized)
- Performance and error logs
- Device and browser information
Your Content:
Important: All your data is encrypted with your own keys before it reaches our servers. We cannot decrypt or access your content.
2. How We Use Your Information
- Service Delivery: To provide, maintain, and improve our security services
- Account Management: To manage your account, process payments, and provide customer support
- Security: To detect and prevent unauthorized access, fraud, and security threats
- Communication: To send important service updates, security alerts, and support responses
- Compliance: To meet legal and regulatory requirements
- Analytics: To understand usage patterns and improve our services (using anonymized data only)
3. Data Protection Measures
Encryption:
- AES-256 encryption at rest
- TLS 1.3 for data in transit
- End-to-end encryption for all content
- Zero-knowledge architecture
Access Controls:
- Multi-factor authentication
- Role-based access control
- Regular access reviews
- Principle of least privilege
4. Data Sharing and Disclosure
We do not sell your personal information. We may share information only in these limited circumstances:
- Service Providers: Trusted partners who help us operate our services (under strict confidentiality agreements)
- Legal Requirements: When required by law, court order, or to protect our rights and safety
- Business Transfer: In the event of a merger, acquisition, or sale of assets (with advance notice)
- Emergency: To prevent imminent harm to persons or property
5. Your Privacy Rights
Under GDPR, CCPA, and other privacy laws, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data
- Export your data
- Restrict data processing
- Object to data processing
- Data portability
- Lodge complaints with authorities
6. Cookies and Tracking
We use minimal cookies and tracking:
- Essential Cookies: Required for authentication and security
- Functional Cookies: To remember your preferences and settings
- Analytics: Anonymized usage statistics to improve our service
- No Third-Party Tracking: We do not allow external tracking on our platform
7. Data Retention
- Active Accounts: Data retained as long as your account is active
- Deleted Accounts: Data permanently deleted within 30 days
- Backup Systems: Encrypted backups deleted within 90 days
- Legal Holds: Some data may be retained longer if required by law
8. International Data Transfers
SecuredALL operates globally. When we transfer data internationally, we ensure adequate protection through Standard Contractual Clauses, adequacy decisions, or other approved mechanisms under applicable data protection laws.
9. Policy Updates
We may update this privacy policy from time to time. Material changes will be communicated via email or service notification at least 30 days before taking effect. The "Last Updated" date at the top indicates when changes were made.
Privacy Questions or Concerns?
Our Data Protection Officer is available to help with any privacy-related questions or to exercise your rights.