Legal

Privacy Policy

This Privacy Policy explains what personal data Sintropyc collects as a controller, why we collect it, how we use and share it, how long we keep it, and the choices and rights you have. Customer data we process on your behalf is governed by our Data Processing Addendum.

Last updated: 9 August 2026  ·  Effective immediately

Contents
  1. Who we are
  2. Information we collect
  3. How we use information
  4. Legal bases
  5. Payments & billing
  6. Cookies & analytics
  7. How we share information
  8. Data from your scan targets
  9. Data retention
  10. Security
  11. International transfers
  12. Your rights
  13. Children
  14. Changes & contact

01 Who we are

Sintropyc ("Sintropyc", "we", "us", "our") provides an AI-driven security-testing service. The Sintropyc legal entity named in the applicable Order Form, invoice, or enterprise agreement is the contracting party. For account, website, sales, support, and billing data described in this Policy, Sintropyc acts as data controller. For personal data contained in a Customer's authorised Targets, Content, Findings, or Reports, Customer is the controller and Sintropyc acts only as its processor under our Data Processing Addendum. Contact details are in Section 14.

02 Information we collect

We collect only what we need to provide the Service, take payment, and communicate with you.

03 How we use information

We use personal data to:

We do not sell personal data. We do not use Customer Content, Target identifiers, Findings, or Reports for shared-model training, product improvement for other customers, marketing, case studies, investor materials, or demonstrations unless Customer gives separate, specific, prior written consent. Consent for those optional uses is never required to receive the Service and may be withdrawn prospectively.

05 Payments & billing

Payments are processed by our third-party payment provider, Paddle, which acts as merchant of record for purchases made through our site. When you check out, the information you enter to pay is collected and processed by Paddle under its own privacy policy and terms. Paddle shares with us the information we need to fulfil and account for your order, such as your name, billing country, order details, and payment status. We recommend you review Paddle's privacy notice at paddle.com/legal/privacy.

06 Cookies & analytics

Our website uses a minimal set of cookies and similar technologies that are necessary for the site and the checkout to function and to keep them secure. Our payment provider may also set cookies as part of the checkout.

We keep a first-party visit log for traffic analytics and to protect the site from automated abuse. For each visit it records the date and time, the page and referrer, your IP address, the approximate location (country, region, city) and network provider derived from that IP address, your browser user-agent, and an automated bot-or-human signal. To count unique visitors we store a random identifier in your browser's local storage — a first-party value, not a cross-site tracking cookie, which you can clear at any time. We do not use third-party advertising or cross-site tracking. This log is stored in our hosting provider's key-value store (Vercel) and is limited to the most recent visits (up to 10,000) for traffic analysis. You can control or delete cookies and local storage through your browser settings; disabling necessary cookies may affect how the site works.

07 How we share information

We share personal data only as needed to run the Service and only with parties bound to protect it:

We do not disclose Customer Content, Target identifiers, Findings, or Reports to investors, prospective customers, advisors, or commercial partners to demonstrate our capabilities. We do not sell personal data or share it for cross-context behavioural advertising.

08 Data from your scan targets

A scan may cause our agent to encounter data inside the systems you designate. We handle it with care:

Your responsibility

You are responsible for having the authority to permit testing of a target and for any personal data that resides within it. You must not designate a system that holds other people's personal data unless you are lawfully entitled to have it tested.

09 Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy. Unless an Order Form sets a shorter period, Findings and Reports are retained for up to 12 months. After a verified deletion request or termination, Customer Personal Data is deleted from active systems within 30 days and from backups within 90 days. Billing and tax records are kept for the period required by law. Narrowly scoped security, abuse-prevention, and legal-defence records may be retained only while necessary, isolated from ordinary use, and deleted when that need ends. More detail is in Section 6.3 of the Terms and Section 10 of the DPA.

10 Security

We apply technical and organisational measures appropriate to the sensitivity of the data we handle, including access controls, encryption in transit, redaction of secrets from reports and logs, and least-privilege operational practices. No method of transmission or storage is perfectly secure; while we work hard to protect your data, we cannot guarantee absolute security.

11 International transfers

We and our service providers may process personal data in countries other than your own. Where personal data is transferred across borders, we take steps to ensure it remains protected in line with applicable law, including using recognised safeguards such as standard contractual clauses where required.

12 Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, email us at [email protected]. We will respond within the time required by applicable law and may need to verify your identity first.

13 Children

The Service is intended for businesses and professional users and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

14 Changes & contact

We may update this Policy from time to time; the "last updated" date above reflects the current version, and material changes will be indicated on this page. Your continued use of the Service after an update constitutes acceptance of the revised Policy.

Questions, requests, or privacy concerns? Email us at [email protected]. For business processing, also see our Data Processing Addendum and Subprocessor List.

← Back to Sintropyc