Legal

Privacy Policy

This Privacy Policy explains what personal data Sintropyc collects, why we collect it, how we use and share it, how long we keep it, and the choices and rights you have. It applies to this website and to the security-testing service we provide (the "Service").

Last updated: 30 July 2026  ·  Effective immediately

Contents
  1. Who we are
  2. Information we collect
  3. How we use information
  4. Legal bases
  5. Payments & billing
  6. Cookies & analytics
  7. How we share information
  8. Data from your scan targets
  9. Data retention
  10. Security
  11. International transfers
  12. Your rights
  13. Children
  14. Changes & contact

01 Who we are

Sintropyc ("Sintropyc", "we", "us", "our") provides an AI-driven security-testing service. For personal data described in this Policy, Sintropyc acts as the data controller. If you have any question about this Policy or about how your data is handled, contact us using the details in Section 14.

02 Information we collect

We collect only what we need to provide the Service, take payment, and communicate with you.

03 How we use information

We use personal data to:

We do not sell your personal data. We may use your scan results — including what the agent found in your systems — to operate, analyse, and improve the Service and our products, and to demonstrate our capabilities (including to investors, advisors, and partners), as described in Section 6.7 of our Terms of Service. Wherever practicable we do so in a de-identified or aggregated form, and raw secrets and credentials always stay redacted.

05 Payments & billing

Payments are processed by our third-party payment provider, Paddle, which acts as merchant of record for purchases made through our site. When you check out, the information you enter to pay is collected and processed by Paddle under its own privacy policy and terms. Paddle shares with us the information we need to fulfil and account for your order, such as your name, billing country, order details, and payment status. We recommend you review Paddle's privacy notice at paddle.com/legal/privacy.

06 Cookies & analytics

Our website uses a minimal set of cookies and similar technologies that are necessary for the site and the checkout to function and to keep them secure. Our payment provider may also set cookies as part of the checkout. If we add optional analytics in the future, we will do so in a way that respects your choices and update this Policy. You can control or delete cookies through your browser settings; disabling necessary cookies may affect how the site works.

07 How we share information

We share personal data only as needed to run the Service and only with parties bound to protect it:

We do not sell your personal data and we do not share it for cross-context behavioural advertising.

08 Data from your scan targets

A scan may cause our agent to encounter data inside the systems you designate. We handle it with care:

Your responsibility

You are responsible for having the authority to permit testing of a target and for any personal data that resides within it. You must not designate a system that holds other people's personal data unless you are lawfully entitled to have it tested.

09 Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy. Scan requests, reports, and related correspondence are retained for the period needed to deliver and support the Service and to handle any follow-up; billing and tax records are kept for the period required by law. When data is no longer needed, we delete or anonymise it. You may ask us to delete your data sooner, subject to the exceptions in Section 12.

10 Security

We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including access controls, encryption in transit, redaction of secrets from reports and logs, and least-privilege operational practices. No method of transmission or storage is perfectly secure; while we work hard to protect your data, we cannot guarantee absolute security.

11 International transfers

We and our service providers may process personal data in countries other than your own. Where personal data is transferred across borders, we take steps to ensure it remains protected in line with applicable law, including using recognised safeguards such as standard contractual clauses where required.

12 Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, email us at support@sintropyc.com. We will respond within the time required by applicable law and may need to verify your identity first.

13 Children

The Service is intended for businesses and professional users and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

14 Changes & contact

We may update this Policy from time to time; the "last updated" date above reflects the current version, and material changes will be indicated on this page. Your continued use of the Service after an update constitutes acceptance of the revised Policy.

Questions, requests, or privacy concerns? Email us at support@sintropyc.com and we will get back to you.

← Back to Sintropyc