1. INTRODUCTION AND SCOPE
- 1.1 SecureHive Inc. ("we," "us," or "our") is committed to protecting your privacy and personal information in accordance with applicable data protection laws, including GDPR, CCPA, PIPEDA, and emerging 2025-2026 privacy regulations.
- 1.2 This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our security and compliance management platform.
- 1.3 This policy applies to all users of our services, including website visitors, customers, and authorized users of our platform.
2. INFORMATION WE COLLECT
- 2.1 Personal Information: We collect personal information you provide directly, including name, email address, company information, billing details, and contact information.
- 2.2 Usage Information: We collect information about how you use our platform, including log data, device information, IP addresses, and interaction patterns.
- 2.3 Business Data: We process business data you upload to our platform, including security frameworks, compliance documents, and audit materials.
- 2.4 Technical Information: We collect technical information, including browser type, operating system, and performance metrics, to improve our services.
3. HOW WE USE YOUR INFORMATION
- 3.1 Service Provision: We use your information to provide, maintain, and improve our security and compliance management services.
- 3.2 Communication: We use your contact information to send service-related communications, updates, and support messages.
- 3.3 Security and Compliance: We use your information to ensure platform security, prevent fraud, and maintain compliance with applicable laws.
- 3.4 Analytics and Improvement: We use aggregated and anonymized data to analyze usage patterns and improve our services.
4. ARTIFICIAL INTELLIGENCE AND AUTOMATION
- 4.1 AI Processing: We may use artificial intelligence and machine learning technologies to enhance our services, subject to your explicit consent where required by applicable law.
- 4.2 Algorithmic Transparency: We maintain transparency about our AI systems and provide information about automated decision-making processes.
- 4.3 Data Minimization: AI processing activities are conducted using only the minimum data necessary for the intended purpose.
- 4.4 Human Oversight: All AI systems include human oversight and review mechanisms to ensure accuracy and fairness.
5. INFORMATION SHARING AND DISCLOSURE
- 5.1 Service Providers: We may share your information with trusted third-party service providers who assist us in delivering our services.
- 5.2 Legal Requirements: We may disclose your information when required by law, legal process, or to protect our rights and interests.
- 5.3 Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.
- 5.4 Consent: We may share your information with your explicit consent for specific purposes.
6. DATA SECURITY AND PROTECTION
- 6.1 Encryption: We implement industry-standard encryption (AES-256 at rest, TLS 1.3 in transit) to protect your data.
- 6.2 Access Controls: We maintain strict access controls and authentication mechanisms to prevent unauthorized access.
- 6.3 Security Monitoring: We continuously monitor our systems for security threats and implement appropriate safeguards.
- 6.4 Incident Response: We maintain comprehensive incident response procedures and will notify you of any security incidents affecting your data.
7. DATA RETENTION AND DELETION
- 7.1 Retention Periods: We retain your personal information only as long as necessary to fulfill the purposes outlined in this policy.
- 7.2 Business Data: Business data is retained according to your subscription terms and applicable legal requirements.
- 7.3 Deletion Rights: You have the right to request deletion of your personal information, subject to legal and contractual obligations.
- 7.4 Secure Deletion: When data is deleted, we ensure it is securely removed from all systems and backups.
8. YOUR RIGHTS AND CHOICES
- 8.1 Access Rights: You have the right to access and obtain copies of your personal information.
- 8.2 Correction Rights: You have the right to correct inaccurate or incomplete personal information.
- 8.3 Portability Rights: You have the right to receive your data in a structured, machine-readable format.
- 8.4 Opt-Out Rights: You have the right to opt-out of certain data processing activities, including marketing communications.
9. INTERNATIONAL DATA TRANSFERS
- 9.1 Cross-Border Transfers: We may transfer your information internationally in accordance with applicable data protection laws.
- 9.2 Adequacy Decisions: We rely on adequacy decisions, standard contractual clauses, and other appropriate safeguards for international transfers.
- 9.3 Data Localization: We respect data localization requirements and may store data in specific jurisdictions when required.
10. CHILDREN'S PRIVACY
- 10.1 Age Restrictions: Our services are not intended for children under 16 years of age, and we do not knowingly collect personal information from children.
- 10.2 Parental Rights: If we become aware that we have collected personal information from a child, we will take steps to delete such information.
11. CHANGES TO THIS PRIVACY POLICY
- 11.1 Updates: We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws.
- 11.2 Notification: We will notify you of material changes through email or platform notifications.
- 11.3 Continued Use: Your continued use of our services after changes become effective constitutes acceptance of the updated policy.
12. CONTACT INFORMATION
- 12.1 Data Protection Officer: For privacy-related inquiries, contact our Data Protection Officer at privacy@securehive.ai.
- 12.2 General Inquiries: For general privacy questions, contact us at support@securehive.ai.
- 12.3 Regulatory Complaints: You have the right to lodge complaints with your local data protection authority.