Privacy Notice
We take data privacy seriously. This notice explains what we collect, why, and your rights under GDPR and CCPA/CPRA.
1. Who We Are
SecuryxAI (“SecuryxAI”, “we”, “our”, “us”) is a governance, risk, and compliance (GRC) software platform. We act as the data controller for personal data collected through our website and platform, and as a data processor for compliance data that our customers store on their behalf within SecuryxAI.
Contact: privacy@securyxai.com
2. Data We Collect
2.1 Account & Identity Data
- Full name and work email address
- Hashed password (bcrypt, never stored in plaintext)
- Job title and organisation name
- Profile preferences (timezone, notification settings)
2.2 Usage & Technical Data
- IP address and approximate geolocation
- Browser type, version, and operating system
- Pages visited, features used, and session duration
- Error logs and performance metrics
- Authentication event timestamps
2.3 Compliance Content (Processor Role)
When you use SecuryxAI to manage controls, evidence, policies, and questionnaires, the data you upload or generate is your organisation’s data. We process it on your behalf under our Data Processing Addendum. This data may include employee names, vendor information, and audit findings depending on your use case.
2.4 Payment Data
Billing information is processed by our payment provider. We do not store full card numbers. We retain billing records (amount, date, invoice reference) for legal and tax compliance purposes.
3. How We Use Your Data
- Service delivery: Creating and managing your account, authenticating you, and operating the platform features you use.
- Security: Detecting and preventing fraud, abuse, and unauthorised access. Rate-limiting login attempts. Maintaining audit logs.
- Communication: Sending transactional emails (account confirmation, password reset, security alerts). We do not send marketing emails without your explicit consent.
- Product improvement: Analysing aggregated, anonymised usage patterns to improve platform features. We do not profile individual users for this purpose.
- Legal compliance: Retaining records as required by applicable law, responding to lawful requests from public authorities.
4. Legal Basis for Processing (GDPR)
If you are located in the EU/EEA or UK, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)): Processing necessary to provide the SecuryxAI service you have contracted for — account management, authentication, and platform operation.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, platform analytics, and service improvement. We balance our interests against your rights.
- Legal obligation (Art. 6(1)(c)): Retaining financial records, responding to lawful authority requests.
- Consent (Art. 6(1)(a)): Optional analytics and marketing communications, where you have opted in. You may withdraw consent at any time.
5. Data Sharing & Disclosure
We do not sell your personal data. We share data only with:
- Infrastructure subprocessors: Vercel (hosting), Supabase (database), Resend (email). See our Subprocessors list.
- AI processing: When you use AI-powered features, relevant content may be processed by OpenAI. See our Subprocessors list for details.
- Legal authorities: When required by law, court order, or to protect the rights and safety of SecuryxAI and others.
- Business transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred. We will notify you beforehand.
6. International Data Transfers
SecuryxAI is hosted in the United States. If you are located in the EU/EEA, UK, or other regions with data transfer restrictions, your data is transferred to the US under appropriate safeguards, including Standard Contractual Clauses (SCCs) as adopted by the European Commission.
Our subprocessors maintain their own transfer mechanisms. Supabase and Vercel participate in the EU-US Data Privacy Framework. Details are available in each subprocessor’s privacy documentation.
7. Data Retention
- Active account data: Retained for the duration of your account plus 30 days after deletion request.
- Audit logs: Retained for 12 months from creation, then anonymised.
- Financial records: Retained for 7 years to comply with tax and accounting requirements.
- Compliance content (processor): Deleted within 30 days of account termination unless a longer period is required by law or specified in your contract.
- Backup copies: May persist for up to 90 days in encrypted backups before permanent deletion.
8. Your Rights
Under GDPR (EU/EEA/UK Residents)
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): Request deletion of your data where no legitimate basis exists for continued processing.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to restriction: Restrict processing in certain circumstances.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: At any time, where processing is based on consent.
- Right to lodge a complaint: With your local supervisory authority (e.g. ICO in the UK, CNIL in France).
Under CCPA/CPRA (California Residents)
- Right to know: What personal information we collect, use, disclose, and sell.
- Right to delete: Request deletion of personal information we have collected.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt-out of sale/sharing: We do not sell or share personal information for cross-context behavioural advertising.
- Right to limit use of sensitive personal information: We do not use sensitive personal information beyond what is necessary to provide the service.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact privacy@securyxai.com. We will respond within 30 days (GDPR) or 45 days (CCPA) of a verifiable request.
9. Security
We implement technical and organisational security measures appropriate to the risk, including TLS encryption in transit, bcrypt password hashing, JWT-based session management, rate limiting on authentication endpoints, role-based access control, and an immutable audit log. See our Security Overview for full details.
10. Children’s Privacy
SecuryxAI is a business-to-business platform and is not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data to us, contact us at privacy@securyxai.com.
11. Changes to This Notice
We may update this Privacy Notice from time to time. Material changes will be communicated via email to account holders at least 14 days before taking effect. Continued use of SecuryxAI after the effective date constitutes acceptance of the updated notice.
12. Contact Us
For privacy enquiries, data subject rights requests, or questions about this notice:
- Email: privacy@securyxai.com
- General contact: securyxai.com/contact