1. Controller
CYBER CLUSTER LLC, 1209 MOUNTAIN ROAD PL NE STE R Albuquerque, NM 87110, is the controller for the processing described in this policy. A Privacy request may be submitted through the contact form.
2. Scope
This policy covers public-site visitors, account users, subscription customers, business contacts, support contacts and personal data that may appear in customer prospect records or service logs.
3. Data we process
| Category | Examples |
|---|---|
| Account and workspace data | Business email, verification state, workspace ID, plan, settings and authentication metadata. |
| Customer intelligence | Domains submitted or scanned by a customer, scan results, raw DNS evidence, notes, statuses, selected columns and exports. |
| Technical and security data | Request IDs, session identifiers, timestamps, errors, rate-limit events, logs and performance metadata. |
| Product analytics | Allowlisted product events such as page category, acquisition-channel category, CTA placement, selected plan or cadence, scan/export actions and aggregate counts. Public events are not assigned a SecuTest analytics identifier. Authenticated application events may be associated with a one-way hashed workspace reference. SecuTest does not store email addresses, prospect domains, IP addresses, query strings, browser user-agent strings or form contents in the product analytics store. |
| Billing data | Stripe customer and subscription references, amount, currency, status, business identity, billing address and tax data where supplied. |
| Contact data | Name, business email, company, topic and message. |
4. Customer Intelligence boundary
Customer-submitted domains, uploaded prospect files and customer scan history are processed for that customer's workspace. They are not injected into SecuTest Global Intelligence, the proprietary global dataset or SecuTest's proprietary global historical collection.
SecuTest's proprietary global intelligence, when collected, is sourced by SecuTest's own collection infrastructure rather than by reusing customer prospect lists.
5. Purposes and legal bases
We process data to provide accounts, scans, prospect intelligence, exports, subscriptions and support; prevent abuse and fraud; maintain security and reliability; measure high-level product and funnel performance; meet accounting and legal obligations; and improve detector and product quality using data we are permitted to use for that purpose.
6. Sources
We receive data from users, Stripe, Formspree, Inc., our hosting and security infrastructure, and publicly accessible internet services queried during authorized product operations or proprietary collection.
7. Providers
| Provider | Purpose |
|---|---|
| Stripe, Inc. and affiliates | Subscription checkout, payments, fraud prevention and invoicing. |
| Formspree, Inc. | Contact-form delivery and spam prevention. |
| OVH SAS | Website, API and infrastructure hosting in France. |
| OVHcloud | Backups, storage and related infrastructure services. |
| Bunny Fonts (BunnyWay d.o.o.) | Public-site web-font delivery. The authenticated application does not depend on this external font service. |
8. Retention
Retention depends on the data type, active product behavior, security needs and legal obligations.
| Legacy free scan reports | Up to 30 days. |
|---|---|
| Legacy paid scan reports and generated files | Up to 365 days. |
| Anti-abuse event data | Up to 48 hours under the current production policy. |
| Application and security logs | Up to 90 days unless needed for an incident or claim. |
| Product analytics events | Up to 90 days. The analytics store is first-party and uses no dedicated analytics cookie, local-storage identifier or session-storage identifier. |
| Contact-form submissions | Up to 24 months after the last relevant interaction. |
| Billing, invoice, tax and legal-acceptance records | Up to 10 years or the applicable statutory period. |
| Backups | Rolling copies for up to 14 days. |
Customer prospect and scan data may be retained while the workspace is active and according to product retention controls. Deletion requests are subject to security, billing and mandatory legal-retention constraints.
9. Rights
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability or objection. Individuals in France may lodge a complaint with the CNIL.
10. Automated infrastructure inference
SecuTest can automatically classify technical signals and generate confidence or commercial context. These outputs concern business infrastructure and are not intended to make decisions producing legal or similarly significant effects about natural persons.
11. Security
We use access controls, least privilege, transport encryption, signed payment webhooks, rate limiting, logging and backups. Security vulnerabilities affecting SecuTest may be reported under the security policy.
13. Changes and contact
We may update this policy prospectively. Privacy questions may be submitted through the contact form.