1. INTRODUCTION
AIOpenSec Labs Limited ("AIOpenSec," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit https://aiopensec.com (the "Website") or use our self-service cybersecurity platform at https://platform.aiopensec.com (the "Platform").
Our services are not intended for users under 16. If you are under 16, please do not provide any personal data.
By accessing or using the Website or Platform, you agree to this Privacy Policy. If you do not agree, please do not use our services.
2. INFORMATION WE COLLECT
2.1 Information You Provide
We collect personal data you provide when using our Website or Platform, such as:
- Account Information: Name, email address, company name, and billing details during sign-up.
- Payment Information: Processed securely via third-party providers; we do not store credit card details.
- Support Requests: Details you share when contacting us for assistance.
2.2 Information Collected Automatically
- Website Visitors: We collect limited usage data on https://aiopensec.com, including IP address, device type, browser type, and interaction data for marketing analytics.
- Platform Users: We do not use tracking, cookies, or analytics on https://platform.aiopensec.com to ensure your privacy.
2.3 Cookies and Tracking Technologies
- Essential Cookies: Used only for login authentication on the Platform.
- Marketing Cookies: Used on the Website (https://aiopensec.com) with your consent via a cookie banner.
- No Tracking on Platform: No cookies, tracking, or third-party analytics are used on the Platform.
3. HOW WE USE YOUR INFORMATION
We process personal data only as necessary to:
- Deliver and operate the Platform securely.
- Process payments and issue invoices.
- Communicate service updates or respond to support requests.
- Improve the Website (via marketing analytics).
- Comply with legal and regulatory obligations.
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. LEGAL BASIS FOR PROCESSING
We process your data based on:
- Contract: To provide the Platform and fulfill our Terms of Service (e.g., account and payment data).
- Legitimate Interests: To enhance security, prevent fraud, and improve our services (e.g., Website analytics).
- Legal Obligation: To meet financial, tax, or regulatory requirements (e.g., billing records).
- Consent: For marketing cookies and optional communications (e.g., newsletters), which you can withdraw anytime.
5. DATA SHARING AND DISCLOSURE
We share data only in these cases:
- Payment Processors: Secure third-party providers such as trusted providers like Stripe to handle transactions.
- Legal Compliance: If required by law, court order, or government request.
- Business Transfers: In the event of a merger or acquisition, with privacy safeguards in place.
6. DATA SECURITY
We use robust measures to protect your data:
- Encrypted storage and secure transmission.
- Strict access controls for all customer data.
- No personal data in logs or reports.
No system is fully secure, so we recommend enabling two-factor authentication (2FA) and following best security practices.
7. DATA RETENTION
- Account Data: Kept as long as you use the Platform.
- Deletion: We delete your personal data within 30 days of your request, unless required by law (e.g., billing records kept for 6 years under UK tax law).
- Anonymized Data: Aggregated, non-identifiable insights may be retained for analytics.
8. YOUR RIGHTS
Depending on your location, you may have rights under applicable laws, including:
- Access: Request a copy of your data.
- Correction: Update inaccurate details.
- Deletion: Request removal of your data (subject to legal exceptions).
- Restriction: Limit how we process your data.
- Portability: Receive your data in a structured format.
- Objection: Oppose processing based on legitimate interests.
- Withdraw Consent: Opt out of marketing or cookies anytime.
To exercise these rights, email [email protected].
9. INTERNATIONAL DATA TRANSFERS
- Storage: Data is primarily stored in the United Kingdom.
- Transfers: If transferred outside the UK or EEA (e.g., to payment processors in the US), we use Standard Contractual Clauses (SCCs) and industry-standard safeguards to ensure compliance with applicable privacy laws.
10. THIRD-PARTY LINKS
Our Website may link to external sites. We’re not responsible for their privacy practices—review their policies before use.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically. Significant changes will be notified 30 days in advance where possible. We’ll notify you via email or a Website notice.
Last updated: March 18, 2025
12. CONTACT US
For privacy questions or to reach our Data Protection Officer:
AIOpenSec Labs Limited 38-44 St Ann's House, 2nd Floor St. Anns Rd, London, United Kingdom, HA1 1LA 📩 [email protected]