S SecuTest
Guides Pricing For Partners About
Log In

Data protection

Privacy Policy

How SecuTest collects, uses, retains, protects and shares personal data in its B2B service.

Effective: August 7, 2026Version: 2026-08-07-v2B2B only

1. Controller

CYBER CLUSTER LLC, 1209 MOUNTAIN ROAD PL NE STE R Albuquerque, NM 87110, is the controller for the processing described in this policy.

Privacy requests may be submitted through the contact form by selecting “Privacy request”.

2. Scope and business users

This policy covers visitors, professional users, purchasers, contacts and individuals whose business contact details are included in support or billing records. SecuTest is not directed to children or consumers.

3. Data we process

CategoryExamples
Technical request dataSubmitted domain or URL, scan identifier, timestamps, status, public findings and errors.
Security and anti-abuse dataIP-derived pseudonymous client key, rate-limit events, domain, decisions, logs and security events.
Purchase dataStripe session and payment references, amount, currency, status, purchaser email, company name, billing address and tax identifier where supplied.
Contact dataName, business email, company, topic, message, submitted target and Formspree metadata.
Usage dataServer logs, user agent, referrer, request path, response status and performance data where logged.

Do not submit credentials, private keys, special-category data or unnecessary personal information.

4. Purposes and legal bases

PurposeLegal basis
Provide scans, reports, checkout, invoicing and supportContract and steps requested before contract.
Prevent abuse, fraud and service disruptionLegitimate interests in service and network security.
Maintain logs, diagnose failures and improve reliabilityLegitimate interests in operating a secure and effective service.
Accounting, tax, disputes and legal complianceLegal obligations and legitimate interests in establishing or defending claims.
Respond to privacy, legal, security and abuse requestsLegal obligations and legitimate interests.

5. Sources

We receive data directly from users and purchasers, from Stripe and Formspree, from our hosting and security infrastructure, and from publicly accessible internet services queried during an assessment.

6. Recipients, subprocessors and providers

Access is limited to authorised personnel and providers that need data to operate the service.

ProviderPurposeData categoriesPrimary location
Stripe, Inc. and affiliatesCheckout, payment processing, fraud prevention and invoices.Purchaser identity, company, billing, tax and transaction data.United States and provider locations.
Formspree, Inc.Contact-form delivery and spam prevention.Contact identity, company, email, topic, target and message.United States and provider locations.
OVH SASWebsite, API, storage and infrastructure hosting.Technical request data, scans, reports, logs and purchase references.France, European Union
OVHcloudEncrypted or access-controlled backups.Backup copies of application data.European Union
OVHcloudAuthoritative DNS and related security infrastructure.DNS request metadata and service logs as applicable.Global Anycast network operated by OVHcloud; OVH SAS is established in France

We select providers based on operational need, security, reliability and contractual protections. Where a provider acts as a processor, we seek terms addressing confidentiality, security, incident notification, deletion and lawful international transfers. We may update this provider list as infrastructure changes; material changes are reflected by updating the effective date or version.

7. International transfers

CYBER CLUSTER LLC is established in the United States. Data may be processed in the United States and other countries where providers operate. Where required, transfers are governed by an adequacy decision, approved contractual safeguards, another lawful transfer mechanism or a permitted derogation.

8. Retention

DataStandard period
Free scan reportsUp to 30 days.
Paid scan reports and generated filesUp to 365 days; download access is contractually guaranteed for at least 30 days.
Anti-abuse event data and pseudonymous client keysUp to 48 hours under the current production policy.
Application and security logsUp to 90 days unless needed for an incident or claim.
Contact-form submissionsUp to 24 months after the last relevant interaction.
Purchase, invoice, tax and legal-acceptance recordsUp to 10 years or the applicable statutory period.
BackupsRolling copies for up to 14 days.

Data may be retained longer where reasonably necessary for security incidents, disputes, fraud prevention, legal holds or mandatory law. The internal retention tool enforces operational deletion schedules for scan and cache data.

9. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. We may need to verify identity and authority. Some records must be retained for legal, security or contractual reasons.

Individuals in France may lodge a complaint with the CNIL; individuals elsewhere may contact their competent supervisory authority.

10. Automated assessment

SecuTest automatically scores technical signals, but does not make decisions that produce legal or similarly significant effects about natural persons. Customers must perform human review before acting on a report.

11. Security

We use access controls, least privilege, bounded execution, transport encryption, signed payment webhooks, tokenised report access, rate limiting, backups and logging. No system is completely secure, and users must protect report links and downloaded files.

Security vulnerabilities affecting SecuTest may be reported under the vulnerability disclosure policy.

12. Cookies and local storage

See the Cookie Policy. SecuTest does not currently deploy advertising or behavioural-tracking cookies on its public pages.

13. Changes and contact

We may update this policy prospectively. The effective date and version identify the current policy. Submit privacy, provider or data-transfer questions through the contact form.

ContentsControllerDataPurposesProvidersTransfersRetentionRightsSecurity
Privacy PolicyTerms & ConditionsCookie Policy