Privacy notice.
How SecurityVault Systems Private Limited collects, uses, and protects information. We try to write this plainly. The legal text below is the operative version; everything we do is grounded in it.
01 · Scope
This notice applies to SecurityVault Systems Private Limited (“SecurityVault,” “we,” “us”) and the websites, products, and services we operate. It does not apply to data your organization processes inside its own SecurityVault tenant — your organization is the controller for that data and its own privacy notice governs.
If you are a visitor to our marketing site or a contact at a company that uses (or evaluates) our platform, this notice describes how we handle your personal data.
02 · What we collect
Information you give us
- Contact data. Name, work email, employer, role — when you book a demo, sign up, or contact support.
- Account data. Authentication identifiers, role assignments, organization metadata.
- Billing data. Billing contact and invoicing details. We invoice directly and do not store payment card numbers.
Information we collect automatically
- Product telemetry. Feature usage, performance metrics, error reports — scrubbed of customer content.
- Edge request logs. Standard web-server and CDN logs (IP address, user agent, requested page), retained briefly for security and capacity planning. This site runs no analytics scripts, sets no cookies, and uses no cross-site advertising trackers — see the cookie policy.
- Security signals. Authentication events, suspicious activity, source IP. Used for product security only.
Information we do not collect
- We do not buy personal data from data brokers.
- We do not send customer content to third-party AI providers — AI features run on models hosted inside our own infrastructure.
- We do not train models on customer data.
03 · How we use it
Purposes and legal bases (UK/EU GDPR terminology in parentheses):
- Deliver the service — to provide, secure, and operate SecurityVault (contract).
- Communicate — to respond to inquiries, notify about changes, and provide support (contract, legitimate interest).
- Improve the product — aggregated telemetry to identify defects and prioritize work (legitimate interest).
- Comply with law — retain records and respond to lawful requests (legal obligation).
- Marketing — limited to non-personalized communications with opt-out in every message (consent / legitimate interest).
04 · Sharing & subprocessors
We share personal data only with subprocessors operating under written DPAs equivalent to our customer DPA. The current list is published at securityvault.io/subprocessors and updated with 30 days’ advance notice for material changes.
We do not sell personal data. We do not share personal data for cross-context behavioral advertising.
We may disclose information when required by valid legal process. We require valid process, scope-narrow our response, notify the affected party unless legally prohibited, and publish a transparency report annually.
05 · Retention
- Account data is retained for the life of your account plus 90 days, then deleted from production systems.
- Billing records are retained for seven years for tax and accounting compliance.
- Marketing contacts are retained until you unsubscribe or for two years of inactivity, whichever is first.
- Security logs are retained for one year; signed evidence may be retained per customer DPA configuration.
06 · Your rights
Depending on jurisdiction, you may have the right to access, correct, delete, or port your personal data; to object to or restrict processing; and to withdraw consent. To exercise these rights, contact us using the address below; we will respond within 30 days (or sooner where law requires).
California residents have additional rights under the CCPA/CPRA, including the right to know, delete, correct, and limit. We do not sell personal information or share it for cross-context behavioral advertising, and we honor Global Privacy Control signals. A jurisdiction-by-jurisdiction guide, including the notice at collection, is at Your privacy choices. Cookie and browser-storage practices are documented in the cookie policy.
07 · International transfers
SecurityVault operates infrastructure in multiple regions; tenant data location is customer-elected. Cross-border transfers of personal data outside the EEA, UK, or Switzerland rely on Standard Contractual Clauses and supplementary measures (technical, organizational, contractual) as required by the Schrems II framework.
08 · Security
We follow industry-standard practices, including encryption in transit (TLS 1.3) and at rest (AES-256-GCM), HSM-backed key management, mTLS between services, FIDO2 hardware-key MFA for all staff, and zero standing production access. Our security posture is documented in detail on the Security page and the trust center.
09 · Children
SecurityVault is a B2B platform. We do not knowingly collect personal data from anyone under 16, or under 18 where you are in India. If you believe we have, contact us and we will delete it.
10 · India — DPDP Act
For Data Principals in India, SecurityVault Systems Private Limited is the Data Fiduciary for personal data collected through this website and a Data Processor for customer tenant data under the Digital Personal Data Protection Act, 2023. You have the rights to access, correction, erasure, grievance redressal, and nomination, and you may withdraw consent as easily as it was given. Our Grievance Officer can be reached at grievance@securityvault.io; grievances are acknowledged within 72 hours and resolved within 30 days, and you may escalate to the Data Protection Board of India. Full details, including how to exercise each right: Your privacy choices.
11 · Contact
Data Protection Officer
SecurityVault Systems Private Limited
India
privacy@securityvault.io
EU / UK representatives: none appointed yet. Until a representative is named here, EU and UK data subjects should write to privacy@securityvault.io and may lodge a complaint with their national supervisory authority.
If you believe we have not addressed a concern adequately, you have the right to lodge a complaint with your local data protection authority.