Privacy Policy
Retrievy — Unified Security Posture Management Platform
Effective Date: April 15, 2026 Last Updated: April 15, 2026 Version: 1.0
This Privacy Policy explains how Retrievy ("Company," "we," "us," or "our") collects, uses, stores, discloses, and protects information about you when you visit our websites (including retrievy.com and app.retrievy.com), use our services, or interact with us in any way (collectively, the "Service"). By accessing or using the Service, you agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.
This Privacy Policy is incorporated by reference into our Terms of Service. Capitalized terms not defined here have the meanings given to them in the Terms of Service.
Table of Contents
- Who We Are and How to Contact Us
- Scope of This Policy
- Information We Collect
- How We Collect Information
- How We Use Your Information
- Legal Bases for Processing (GDPR)
- Customer Data and Tenant Isolation
- Data Sharing and Disclosure
- Data Retention
- International Data Transfers
- Security Measures
- Your Rights and Choices
- Children's Privacy
- Third-Party Websites and Services
- California Privacy Rights (CCPA)
- Changes to This Privacy Policy
- Cookie Policy
1. Who We Are and How to Contact Us
Retrievy is a Software-as-a-Service company providing a Unified Security Posture Management platform covering Cloud Security Posture Management (CSPM), Identity Security Posture Management (ISPM), and Security Configuration Management (SCM).
| Contact | Details |
|---|---|
| Data Controller | Retrievy |
| General Support | [email protected] |
| Website | retrievy.com |
For data protection requests, please email [email protected] with the subject line "Privacy Request – [Your Name/Organization]." We respond to all privacy inquiries within 30 calendar days.
2. Scope of This Policy
2.1 Covered Individuals. This Privacy Policy applies to:
- Visitors who browse our public website (retrievy.com) without registering;
- Registered Users who create an account and access the platform;
- Authorized Users of a Customer account (e.g., team members added by an organization administrator);
- Prospective Customers who contact us, request a demo, or subscribe to our marketing communications.
2.2 Customer Data. This Privacy Policy does not govern the Customer Data that our Customers submit to the Service (e.g., security scan results, infrastructure telemetry, finding reports). That data is processed on behalf of the Customer acting as a data controller, under the terms of our Data Processing Agreement (DPA). Refer to Section 7 for more details.
2.3 What This Policy Does Not Cover. This Policy does not apply to the practices of third-party providers or cloud platforms (such as Azure, AWS, GCP, OCI, or Cloudflare) that you independently configure and use in connection with the Service. You are responsible for reviewing those providers' privacy policies separately.
3. Information We Collect
We collect the following categories of information, depending on how you interact with the Service:
3.1 Information You Provide Directly
| Category | Examples |
|---|---|
| Account Registration Data | Full name, work email address, company name, role/title, country |
| Billing Information | Credit card details (tokenized, processed by our payment processor), billing address, VAT/tax ID |
| Profile Information | Profile picture, job title, communication preferences |
| Support Communications | Messages, emails, or chat logs sent to our support team |
| Survey and Feedback Data | Responses to satisfaction surveys, feature requests, beta feedback |
| Marketing Data | Email address and preferences when subscribing to newsletters or webinars |
Note: We do not store raw credit card numbers. All payment card data is tokenized by our PCI-DSS compliant payment processor (e.g., Stripe or equivalent).
3.2 Information Collected Automatically
When you visit or use the Service, we automatically collect:
| Category | Examples |
|---|---|
| Usage Data | Pages viewed, features accessed, click paths, search queries within the platform, session duration |
| Device and Browser Data | IP address, browser type and version, operating system, screen resolution, device type |
| Log Data | Server logs recording requests to our infrastructure, timestamps, HTTP status codes, referrer URLs |
| Cookies and Tracking Technologies | See our Cookie Policy for full details |
| Performance Data | Error reports, latency measurements, feature usage telemetry |
3.3 Information Collected from the Windows Agent
If you install the Retrievy Windows Agent on your on-premises infrastructure, the agent collects and transmits to the Service:
- Host Metadata: Hostname, operating system version, agent version, hardware identifiers (anonymized);
- Scan Telemetry: Security scan results in structured JSON format, including CIS control check outcomes, GPO configurations, Active Directory object attributes, and FortiGate configuration snapshots;
- Agent Health Data: Agent process status, scan job completion times, error reports, and connectivity diagnostics.
The Windows Agent does not collect keystrokes, user personal files, email contents, or any data outside the defined security scan scope. All transmissions from the Agent to the Service are encrypted using TLS 1.2 or higher and authenticated via a unique per-tenant API token.
3.4 Information from Third Parties
We may receive information about you from:
- Cloud Authentication Providers: If you register or log in via a social/SSO provider (e.g., Microsoft, Google), we receive your name, email address, and profile picture as authorized by that provider;
- Payment Processors: Transaction confirmation, billing status, and fraud signals from our payment provider;
- Analytics (Self-Hosted): Retrievy uses Plausible Analytics, self-hosted on our own infrastructure. No data is shared with any third-party analytics provider. See our Cookie Policy for details.
4. How We Collect Information
We collect information through the following means:
- Direct Submission: Forms, registration flows, support tickets, and survey responses;
- Automated Technologies: Cookies, web beacons, server-side logs, and the Windows Agent (see Section 3.3);
- Third-Party Integrations: OAuth-based authentication providers, payment processors, and analytics platforms;
- API Usage: When you interact with the Retrievy API, we log request metadata (endpoint, timestamp, IP, response status) to ensure security and proper operation.
5. How We Use Your Information
We use the information we collect for the following purposes:
5.1 Service Delivery
- To create, manage, and authenticate your account;
- To provision and manage your Tenant environment and associated database;
- To process security scan data submitted through Retrievy's cloud scanning engine and the Windows Agent;
- To generate Findings, posture scores, Hardening Kanban items, and PDF reports;
- To send transactional emails (account creation, scan completion, scan failure alerts, exception approvals).
5.2 Billing and Payments
- To process Subscription purchases and renewals;
- To manage invoicing, refunds (where applicable), and payment disputes;
- To detect and prevent fraudulent transactions.
5.3 Platform Improvement
- To analyze usage patterns to improve existing features and inform new feature development;
- To diagnose and resolve bugs, performance issues, and security vulnerabilities;
- To conduct internal research and analytics (using aggregated, de-identified data only).
5.4 Communication
- To send service-related notifications (account alerts, security events, maintenance windows);
- To respond to support inquiries and feedback;
- To send marketing and promotional communications, where you have given consent or where permitted by applicable law (you may opt out at any time).
5.5 Safety, Security, and Legal Compliance
- To detect, investigate, and prevent fraudulent activity, abuse, and security threats;
- To enforce our Terms of Service and other legal agreements;
- To comply with applicable laws, court orders, and regulatory requirements;
- To protect the rights, property, or safety of the Company, our users, or the public.
5.6 Aggregate Insights
We may use de-identified, aggregated statistical data (e.g., "X% of organizations fail CIS Control 1.1 on first scan") for benchmarking research, marketing materials, and public reports. This data will never be traceable to any individual Customer or user.
6. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, the following legal bases apply to our processing activities under the General Data Protection Regulation (GDPR) and applicable national laws:
| Processing Purpose | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b) GDPR) |
| Service delivery (scanning, reporting, Kanban) | Contract performance (Art. 6(1)(b) GDPR) |
| Billing and payments | Contract performance (Art. 6(1)(b) GDPR) |
| Fraud detection and security | Legitimate interests (Art. 6(1)(f) GDPR) — securing the platform |
| Legal compliance and regulatory requests | Legal obligation (Art. 6(1)(c) GDPR) |
| Analytics and platform improvement | Legitimate interests (Art. 6(1)(f) GDPR) — improving service quality |
| Marketing communications (existing customers) | Legitimate interests (Art. 6(1)(f) GDPR) |
| Marketing communications (opt-in) | Consent (Art. 6(1)(a) GDPR) |
| Sharing with sub-processors | Contract performance / Legitimate interests |
Where processing is based on legitimate interests, you have the right to object. See Section 12 for how to exercise this right.
7. Customer Data and Tenant Isolation
7.1 We Are a Data Processor for Customer Data. When Customers submit security scan results, infrastructure data, and related operational data to the Service, the Customer is the data controller and Retrievy acts as a data processor under applicable data protection law. Our processing of Customer Data on behalf of Customers is governed by our Data Processing Agreement (DPA), which forms part of the agreement with business Customers.
7.2 Database-per-Tenant Architecture. Each Customer's Tenant is provisioned with a dedicated PostgreSQL database. Customer Data is never stored in a shared schema and is never accessible to other Tenants. This architectural guarantee is a core design principle of the Retrievy platform.
7.3 No Use of Customer Data for External Purposes. We will not:
- Use Customer Data to train machine learning or AI models for any purpose other than serving that specific Customer;
- Share Customer Data with other Customers;
- Sell Customer Data to any third party;
- Use Customer Data for our own commercial advertising or benchmarking without explicit written consent and full anonymization.
7.4 Customer Data Requests. Customers may request export or deletion of their Customer Data at any time in accordance with our Terms of Service. Data export is available in standard machine-readable formats. Upon termination, data is permanently deleted from active systems within 30 days and from backups within 90 days.
8. Data Sharing and Disclosure
We do not sell your personal information. We may share your information in the following circumstances:
8.1 Sub-Processors and Service Providers
We engage trusted third-party companies to assist in operating our platform. All sub-processors are bound by data protection agreements and are restricted from using your data for any purpose other than providing services to us.
Our current sub-processors include categories such as:
| Category | Purpose |
|---|---|
| Cloud Infrastructure (e.g., AWS, Azure) | Hosting the platform, database storage, backups |
| Payment Processor (e.g., Stripe) | Billing, invoicing, subscription management |
| Email Service Provider | Transactional and marketing emails |
| Error Tracking / Monitoring | Platform reliability and bug detection |
| Analytics Platform | Aggregated usage analytics (no raw Customer Data) |
A complete, up-to-date list of sub-processors is available upon written request to [email protected].
8.2 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or when we believe in good faith that disclosure is necessary to:
- comply with a legal obligation;
- protect and defend the rights or property of Retrievy;
- prevent or investigate possible wrongdoing in connection with the Service;
- protect the personal safety of users of the Service or the public.
Where legally permissible, we will notify you before complying with such a request.
8.3 Business Transfers
In the event of a merger, acquisition, reorganization, asset sale, or bankruptcy, your information may be transferred to a successor entity. We will provide notice via email or a prominent notice on our website before your data becomes subject to a materially different privacy policy.
8.4 With Your Consent
We may share your information for any other purpose not described herein with your prior explicit consent.
8.5 Aggregated or De-Identified Data
We may share aggregated, anonymized data (which cannot reasonably be used to identify you) with partners, researchers, or in public reports without restriction.
9. Data Retention
We retain your information for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| Account and registration data | Duration of account + 3 years after termination |
| Billing and transaction records | 7 years (legal/tax compliance requirement) |
| Customer Data (Tenant DB) | Duration of Subscription + 30 days post-termination (then deleted from active systems); backups purged within 90 days |
| Support communications | 3 years from resolution |
| Server and security logs | 12 months |
| Marketing data | Until opt-out, then 30 days to process |
| Audit trails and access logs | 24 months |
When data is no longer required, we use secure deletion methods appropriate to the storage medium (cryptographic erasure for cloud storage, secure wipe for physical media).
10. International Data Transfers
Retrievy operates globally. Your information may be transferred to and processed in countries outside your country of residence, including countries that may not have the same level of data protection as your home country.
When we transfer personal data from the EEA, UK, or Switzerland to countries without an EU adequacy decision, we rely on appropriate transfer mechanisms, including:
- Standard Contractual Clauses (SCCs): As approved by the European Commission;
- UK International Data Transfer Agreements (IDTAs): For transfers from the United Kingdom;
- Binding Corporate Rules: Where applicable.
You may request a copy of the applicable transfer safeguards by contacting [email protected].
11. Security Measures
We take the protection of your information seriously and implement the following security measures:
| Measure | Description |
|---|---|
| Encryption at Rest | AES-256 encryption for all database contents and stored files |
| Encryption in Transit | TLS 1.2+ for all data transmissions, including Windows Agent communications |
| Database Isolation | Dedicated per-tenant PostgreSQL databases; no shared schemas |
| Access Controls | Role-based access control (RBAC) within the platform; principle of least privilege for internal staff |
| Authentication | Token-based API authentication; multi-factor authentication (MFA) available for platform users |
| Audit Logging | All administrative and security-relevant actions are logged with user, timestamp, and IP address |
| Vulnerability Management | Regular security reviews and dependency auditing |
| Incident Response | Documented breach response procedures; affected parties notified within 72 hours of discovery, as required by GDPR |
No security system is impenetrable. While we work diligently to protect your information, we cannot guarantee that unauthorized third parties will never be able to defeat our security measures. In the event of a security breach involving your personal data, we will notify you as required by applicable law.
12. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, contact [email protected].
12.1 Rights Under GDPR (EEA/UK/Switzerland Residents)
| Right | Description |
|---|---|
| Right of Access | Request a copy of the personal data we hold about you |
| Right to Rectification | Request correction of inaccurate or incomplete personal data |
| Right to Erasure ("Right to be Forgotten") | Request deletion of your personal data, subject to legal retention requirements |
| Right to Restriction of Processing | Request that we limit how we use your data in certain circumstances |
| Right to Data Portability | Receive your personal data in a structured, machine-readable format |
| Right to Object | Object to processing based on legitimate interests, including direct marketing |
| Rights Related to Automated Decision-Making | Request human review of any decision made about you solely by automated means |
| Right to Withdraw Consent | Withdraw your consent at any time where processing is based on consent |
| Right to Lodge a Complaint | File a complaint with your local data protection authority |
We will respond to all verifiable requests within 30 calendar days (extendable by a further 60 days for complex requests, with notice).
12.2 Marketing Communications
You may opt out of marketing emails at any time by:
- Clicking the "Unsubscribe" link in any marketing email;
- Updating your notification preferences in your account settings;
- Emailing us at [email protected].
Opting out of marketing emails does not affect transactional communications (e.g., scan result notifications, billing alerts, security warnings), which are essential to the operation of your account.
12.3 Cookies
You may manage your cookie preferences through our Cookie Consent banner or your browser settings. See our Cookie Policy for full details.
12.4 Account Deletion
You may request deletion of your account and associated personal data by contacting [email protected]. Account deletion is subject to the data retention periods described in Section 9.
13. Children's Privacy
The Service is not directed to children under the age of sixteen (16) (or such higher minimum age as required by applicable law in the relevant jurisdiction). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact [email protected] and we will promptly take steps to delete such information.
14. Third-Party Websites and Services
The Service may contain links to third-party websites or services, including Microsoft Azure documentation, CIS Benchmarks resources, and cloud provider portals. This Privacy Policy does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access.
15. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we shared it;
- Right to Delete: Request deletion of your personal information, subject to certain exceptions;
- Right to Correct: Request correction of inaccurate personal information;
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. If this changes, we will update this Policy and provide opt-out mechanisms;
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a California privacy rights request, email [email protected] with the subject line "California Privacy Request."
Categories of personal information collected in the last 12 months: Identifiers (name, email, IP address), commercial information (billing records), internet/electronic activity (usage data, log data), and inferences drawn from usage data to understand platform preferences.
We do not sell personal information as defined under the CCPA/CPRA.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:
- Update the "Last Updated" date at the top of this document;
- Post the revised Policy at retrievy.com/privacy-policy;
- Send a notification to the email address associated with your account at least 14 days before the effective date of the changes.
Your continued use of the Service after the effective date constitutes your acceptance of the updated Policy. We encourage you to review this Policy periodically.
17. Cookie Policy
For detailed information about how we use cookies and tracking technologies, please see our dedicated Cookie Policy.
This Privacy Policy was prepared in accordance with the requirements of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the UK GDPR, the Brazilian General Data Protection Law (LGPD — Lei Geral de Proteção de Dados, Law No. 13,709/2018), and other applicable international privacy regulations.
Last reviewed: April 15, 2026
© 2026 Retrievy. All rights reserved.