Privacy Policy
This Privacy Policy explains what personal data Sintropyc collects as a controller, why we collect it, how we use and share it, how long we keep it, and the choices and rights you have. Customer data we process on your behalf is governed by our Data Processing Addendum.
01 Who we are
Sintropyc ("Sintropyc", "we", "us", "our") provides an AI-driven security-testing service. The Sintropyc legal entity named in the applicable Order Form, invoice, or enterprise agreement is the contracting party. For account, website, sales, support, and billing data described in this Policy, Sintropyc acts as data controller. For personal data contained in a Customer's authorised Targets, Content, Findings, or Reports, Customer is the controller and Sintropyc acts only as its processor under our Data Processing Addendum. Contact details are in Section 14.
02 Information we collect
We collect only what we need to provide the Service, take payment, and communicate with you.
- Information you provide. When you request a scan or contact us, you may give us your first and last name, your role or position, your email address, the website or system URL you want tested, and any details you include in a message.
- Scan-scope information. The targets you designate, the authorization you confirm, and any configuration you supply so that we can run the scan correctly and safely.
- Payment information. When you buy a scan or subscribe to a plan, payment is handled by our third-party payment provider (see Section 5). We receive confirmation of the transaction and limited billing details (such as name, country, and the last digits or brand of the card); we do not receive or store full card numbers.
- Technical and usage data. Like most websites, our site and infrastructure automatically record limited technical data such as IP address, browser and device type, pages viewed, referring page, and timestamps, primarily to keep the site secure and working.
- Communications. Records of correspondence with you (for example email or support messages) and the scan reports and findings we deliver to you.
03 How we use information
We use personal data to:
- provide, schedule, and deliver the Service, including confirming scope and sending you your scan report;
- process payments, issue receipts, and handle refunds and billing enquiries;
- communicate with you about your request, your account, and the results of a scan;
- operate, secure, and maintain our website and the Service, and measure reliability using de-identified operational metrics;
- comply with legal obligations, enforce our Terms, and protect our rights and the safety of others.
We do not sell personal data. We do not use Customer Content, Target identifiers, Findings, or Reports for shared-model training, product improvement for other customers, marketing, case studies, investor materials, or demonstrations unless Customer gives separate, specific, prior written consent. Consent for those optional uses is never required to receive the Service and may be withdrawn prospectively.
04 Legal bases
Where the GDPR or a similar law applies and we act as controller, we rely on: performance of a contract (to deliver a requested Service and take payment); legitimate interests (to secure and operate the Service and communicate with business users), balanced against your rights; consent (where we ask for it), which you may withdraw at any time; and legal obligation (for example tax and accounting records). Where we act as processor, we process Customer Personal Data only on Customer's documented instructions under the DPA; Customer determines the applicable legal basis.
05 Payments & billing
Payments are processed by our third-party payment provider, Paddle, which acts as merchant of record for purchases made through our site. When you check out, the information you enter to pay is collected and processed by Paddle under its own privacy policy and terms. Paddle shares with us the information we need to fulfil and account for your order, such as your name, billing country, order details, and payment status. We recommend you review Paddle's privacy notice at paddle.com/legal/privacy.
06 Cookies & analytics
Our website uses a minimal set of cookies and similar technologies that are necessary for the site and the checkout to function and to keep them secure. Our payment provider may also set cookies as part of the checkout.
We keep a first-party visit log for traffic analytics and to protect the site from automated abuse. For each visit it records the date and time, the page and referrer, your IP address, the approximate location (country, region, city) and network provider derived from that IP address, your browser user-agent, and an automated bot-or-human signal. To count unique visitors we store a random identifier in your browser's local storage — a first-party value, not a cross-site tracking cookie, which you can clear at any time. We do not use third-party advertising or cross-site tracking. This log is stored in our hosting provider's key-value store (Vercel) and is limited to the most recent visits (up to 10,000) for traffic analysis. You can control or delete cookies and local storage through your browser settings; disabling necessary cookies may affect how the site works.
07 How we share information
We share personal data only as needed to run the Service and only with parties bound to protect it:
- Service providers that help us operate — limited to the providers and purposes disclosed on our Subprocessor List where they process Customer Personal Data on our behalf;
- Legal and safety recipients, where disclosure is required by law, regulation, or legal process, or to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of Sintropyc, our users, or the public;
- Business transfers, if Sintropyc is involved in a merger, acquisition, or sale of assets, in which case we will continue to protect your data and notify you where required.
We do not disclose Customer Content, Target identifiers, Findings, or Reports to investors, prospective customers, advisors, or commercial partners to demonstrate our capabilities. We do not sell personal data or share it for cross-context behavioural advertising.
08 Data from your scan targets
A scan may cause our agent to encounter data inside the systems you designate. We handle it with care:
- Where the Service runs within your infrastructure, your source code and data remain in your environment and are not exfiltrated by us.
- Any secrets or credentials encountered during testing are handled cautiously: raw secret values are redacted from reports and logs, and validation of a secret is limited to a single benign, read-only check.
- Scan reports and findings are Customer-owned Confidential Information. We process them only to provide and secure the Service, follow Customer's documented instructions, and meet legal obligations. No marketing, demonstration, investor, case-study, shared-model training, or cross-customer product-improvement use is permitted without a separate written opt-in.
You are responsible for having the authority to permit testing of a target and for any personal data that resides within it. You must not designate a system that holds other people's personal data unless you are lawfully entitled to have it tested.
09 Data retention
We keep personal data only for as long as necessary for the purposes described in this Policy. Unless an Order Form sets a shorter period, Findings and Reports are retained for up to 12 months. After a verified deletion request or termination, Customer Personal Data is deleted from active systems within 30 days and from backups within 90 days. Billing and tax records are kept for the period required by law. Narrowly scoped security, abuse-prevention, and legal-defence records may be retained only while necessary, isolated from ordinary use, and deleted when that need ends. More detail is in Section 6.3 of the Terms and Section 10 of the DPA.
10 Security
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including access controls, encryption in transit, redaction of secrets from reports and logs, and least-privilege operational practices. No method of transmission or storage is perfectly secure; while we work hard to protect your data, we cannot guarantee absolute security.
11 International transfers
We and our service providers may process personal data in countries other than your own. Where personal data is transferred across borders, we take steps to ensure it remains protected in line with applicable law, including using recognised safeguards such as standard contractual clauses where required.
12 Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten"), subject to legal exceptions;
- restrict or object to certain processing, including processing based on legitimate interests;
- portability — receive your data in a portable format;
- withdraw consent at any time where processing is based on consent;
- complain to your local data-protection authority.
To exercise any of these rights, email us at [email protected]. We will respond within the time required by applicable law and may need to verify your identity first.
13 Children
The Service is intended for businesses and professional users and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14 Changes & contact
We may update this Policy from time to time; the "last updated" date above reflects the current version, and material changes will be indicated on this page. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
Questions, requests, or privacy concerns? Email us at [email protected]. For business processing, also see our Data Processing Addendum and Subprocessor List.