Draft. This policy has not been reviewed by a lawyer yet. Items in [brackets] must be completed before it is relied on.
Privacy Policy
Last updated: [date of publication]
This policy explains how [GebSecure legal entity name] ("GebSecure", "we") handles personal data when you visit gebsecure.com, create an account or use the GebSecure service. Questions: admin@gebsecure.com.
Who is responsible
For account, billing and website data, GebSecure is the controller. For the data your organization and its agents send through the service (requests, policies, audit records), your organization is the controller and GebSecure processes it on your behalf under your agreement with us.
What we collect
- Account data: name, email address, organization name, and the identity returned by Google or GitHub if you sign in with them.
- Security data: multi-factor authentication settings (secrets are stored encrypted), sign-in times and IP addresses, used to protect your account.
- Service data: the agent actions, policies, approvals and audit records your organization creates. Credentials you store are encrypted and never shown back to anyone.
- Billing data: plan and usage. Card details are handled by Stripe; we never see or store full card numbers.
- Communications: emails you send us.
This website itself sets no cookies and loads no third-party scripts or analytics. The console uses a strictly necessary session cookie to keep you signed in.
How we use it
- To provide, secure and support the service (performance of our contract with you).
- To bill you for paid plans (contract and legal obligations).
- To detect abuse and protect accounts (legitimate interests).
- To send service emails such as sign-in, approval and billing messages. We do not send marketing email without your consent.
We do not sell personal data, and we do not use your service data to train AI models.
Who we share it with
Only service providers that help us run GebSecure, under contracts that limit their use of the data:
- Amazon Web Services (hosting, encryption keys, email delivery), United States region by default;
- Stripe (payments);
- Google and GitHub, only if you choose to sign in with them.
We disclose data to authorities only when the law requires it.
Where it is stored
Data is stored in the data region chosen for your organization. Transfers outside your region use appropriate safeguards [such as the EU Standard Contractual Clauses].
How long we keep it
Audit records are kept for your plan's retention period (7 days on Free up to 7 years on Enterprise). Account data is kept while your account is active and deleted within [30] days after it is closed, except where we must keep records longer by law (for example invoices).
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, object to or restrict its use, and complain to your data-protection authority. Write to admin@gebsecure.com; we answer within 30 days. Members of an organization may be redirected to their organization's administrators for service data.
Security
Data is encrypted in transit and at rest, secrets use envelope encryption with cloud key management, organizations are isolated from each other in the database, and access is logged. See the security overview.
Children
GebSecure is a business service and is not directed at children under 16.
Changes
We will post changes on this page and, for material changes, notify account owners by email before they take effect.