Legal
Privacy Policy
Last updated: 21 July 2026
This policy explains what personal data KIROSEC ("we", "us") processes when you use the KIROSEC website, account console, and desktop application, and the rights you have over it.
Offline by design
The KIROSEC desktop analyzer processes the logs and cases you import entirely on your own device. That log data — and the findings derived from it — is never transmitted to us unless you explicitly enable an optional sync feature. If you never sign in, the app collects no personal data about you at all.
Data we process
- Account: your organization name, email address, and a hashed (never plaintext) password. Analyst invitations you send include the invitee's email.
- Billing: plan and subscription status. Card payments are handled by our payment processor (PayMongo) — we do not receive or store your card details.
- Support: the subject and content of any support ticket or contact-form message you send us.
- Security & server logs: when you use the console, our servers temporarily log your IP address, user agent, and request timestamps, and we record authentication events (sign-in, password reset, invitation acceptance) with an IP address and timestamp. This is used to keep accounts secure, prevent abuse, and debug problems.
- Analytics (optional, consent-only): if you accept analytics, we record coarse, cookieless usage — page path, referring site, and a small/medium/large screen bucket — using our own first-party endpoint. No third-party trackers are used, and your IP address is not stored for analytics. Nothing is collected until you opt in, and you can withdraw consent at any time.
Legal bases (GDPR Article 6)
- Contract: creating and running your account and subscription.
- Legitimate interests: keeping the service and accounts secure, preventing abuse, and debugging — balanced against your rights.
- Consent: optional analytics. You may withdraw it at any time without affecting the service.
Retention
Account data is kept for the life of your account and deleted when you delete it. Security and server logs are retained only as long as needed for security and debugging (typically a short period). Consented analytics events are stored in aggregate and are not tied to a persistent identifier.
Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or a portable copy of your personal data; object to or restrict certain processing; and withdraw consent. You can delete your account (and its data) yourself from Plan & Billing, or contact us to exercise any right. You also have the right to complain to your local data protection authority.
Sub-processors & transfers
We share personal data only with providers that help us run the service — our payment processor (PayMongo), our transactional email provider, and our hosting/infrastructure provider — under appropriate safeguards, and only as needed. We do not sell personal data.
Contact
Questions or requests: support@kirosec.com. See also our Cookie Policy.
