Privacy Policy
This Privacy Policy explains what personal data Sintropyc collects, why we collect it, how we use and share it, how long we keep it, and the choices and rights you have. It applies to this website and to the security-testing service we provide (the "Service").
01 Who we are
Sintropyc ("Sintropyc", "we", "us", "our") provides an AI-driven security-testing service. For personal data described in this Policy, Sintropyc acts as the data controller. If you have any question about this Policy or about how your data is handled, contact us using the details in Section 14.
02 Information we collect
We collect only what we need to provide the Service, take payment, and communicate with you.
- Information you provide. When you request a scan or contact us, you may give us your first and last name, your role or position, your email address, the website or system URL you want tested, and any details you include in a message.
- Scan-scope information. The targets you designate, the authorization you confirm, and any configuration you supply so that we can run the scan correctly and safely.
- Payment information. When you buy a scan or subscribe to a plan, payment is handled by our third-party payment provider (see Section 5). We receive confirmation of the transaction and limited billing details (such as name, country, and the last digits or brand of the card); we do not receive or store full card numbers.
- Technical and usage data. Like most websites, our site and infrastructure automatically record limited technical data such as IP address, browser and device type, pages viewed, referring page, and timestamps, primarily to keep the site secure and working.
- Communications. Records of correspondence with you (for example email or support messages) and the scan reports and findings we deliver to you.
03 How we use information
We use personal data to:
- provide, schedule, and deliver the Service, including confirming scope and sending you your scan report;
- process payments, issue receipts, and handle refunds and billing enquiries;
- communicate with you about your request, your account, and the results of a scan;
- operate, secure, maintain, and improve our website and the Service;
- comply with legal obligations, enforce our Terms, and protect our rights and the safety of others.
We do not sell your personal data. We may use your scan results — including what the agent found in your systems — to operate, analyse, and improve the Service and our products, and to demonstrate our capabilities (including to investors, advisors, and partners), as described in Section 6.7 of our Terms of Service. Wherever practicable we do so in a de-identified or aggregated form, and raw secrets and credentials always stay redacted.
04 Legal bases
Where the GDPR or a similar law applies, we rely on the following legal bases: performance of a contract (to deliver a scan you requested and to take payment); legitimate interests (to secure and improve the Service and to communicate with you), balanced against your rights; consent (where we ask for it, for example certain non-essential cookies), which you may withdraw at any time; and legal obligation (for example tax and accounting records).
05 Payments & billing
Payments are processed by our third-party payment provider, Paddle, which acts as merchant of record for purchases made through our site. When you check out, the information you enter to pay is collected and processed by Paddle under its own privacy policy and terms. Paddle shares with us the information we need to fulfil and account for your order, such as your name, billing country, order details, and payment status. We recommend you review Paddle's privacy notice at paddle.com/legal/privacy.
06 Cookies & analytics
Our website uses a minimal set of cookies and similar technologies that are necessary for the site and the checkout to function and to keep them secure. Our payment provider may also set cookies as part of the checkout. If we add optional analytics in the future, we will do so in a way that respects your choices and update this Policy. You can control or delete cookies through your browser settings; disabling necessary cookies may affect how the site works.
07 How we share information
We share personal data only as needed to run the Service and only with parties bound to protect it:
- Service providers that help us operate — for example our payment provider (Paddle), website hosting and content delivery, and email — acting on our instructions;
- Legal and safety recipients, where disclosure is required by law, regulation, or legal process, or to establish, exercise, or defend legal claims, or to protect the rights, property, or safety of Sintropyc, our users, or the public;
- Investors, advisors & partners, to whom we may present examples of what the Service found in order to demonstrate our capabilities, wherever practicable in a de-identified or aggregated form and always with raw secrets redacted (see Section 6.7 of the Terms);
- Business transfers, if Sintropyc is involved in a merger, acquisition, or sale of assets, in which case we will continue to protect your data and notify you where required.
We do not sell your personal data and we do not share it for cross-context behavioural advertising.
08 Data from your scan targets
A scan may cause our agent to encounter data inside the systems you designate. We handle it with care:
- Where the Service runs within your infrastructure, your source code and data remain in your environment and are not exfiltrated by us.
- Any secrets or credentials encountered during testing are handled cautiously: raw secret values are redacted from reports and logs, and validation of a secret is limited to a single benign, read-only check.
- Scan reports and findings are treated as confidential; we may use and present them to improve and demonstrate the Service — including to investors, advisors, and partners — as described in Section 6.7 of our Terms of Service, wherever practicable in de-identified form and always with raw secrets redacted.
You are responsible for having the authority to permit testing of a target and for any personal data that resides within it. You must not designate a system that holds other people's personal data unless you are lawfully entitled to have it tested.
09 Data retention
We keep personal data only for as long as necessary for the purposes described in this Policy. Scan requests, reports, and related correspondence are retained for the period needed to deliver and support the Service and to handle any follow-up; billing and tax records are kept for the period required by law. When data is no longer needed, we delete or anonymise it. You may ask us to delete your data sooner, subject to the exceptions in Section 12.
10 Security
We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including access controls, encryption in transit, redaction of secrets from reports and logs, and least-privilege operational practices. No method of transmission or storage is perfectly secure; while we work hard to protect your data, we cannot guarantee absolute security.
11 International transfers
We and our service providers may process personal data in countries other than your own. Where personal data is transferred across borders, we take steps to ensure it remains protected in line with applicable law, including using recognised safeguards such as standard contractual clauses where required.
12 Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten"), subject to legal exceptions;
- restrict or object to certain processing, including processing based on legitimate interests;
- portability — receive your data in a portable format;
- withdraw consent at any time where processing is based on consent;
- complain to your local data-protection authority.
To exercise any of these rights, email us at support@sintropyc.com. We will respond within the time required by applicable law and may need to verify your identity first.
13 Children
The Service is intended for businesses and professional users and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
14 Changes & contact
We may update this Policy from time to time; the "last updated" date above reflects the current version, and material changes will be indicated on this page. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
Questions, requests, or privacy concerns? Email us at support@sintropyc.com and we will get back to you.