Privacy policy
How Sicurs collects, uses and protects information. Last updated .
Template notice: this policy is a starting structure for the Sicurs foundation. Have a qualified lawyer review and adapt it to your jurisdiction, entity and actual data practices before you publish.
1. What we collect
We collect three kinds of information:
- Account information you give us: name, email address, company name and billing details.
- Content you create in the workspace: projects, briefs, drafts, notes, files and reports.
- Technical information collected automatically: IP address, browser and device type, pages viewed, and timestamps.
2. How we use it
We use information to provide and secure the service, process payments, respond to support requests, send service notices, and improve the product through aggregated usage analysis. We do not sell personal information, and we do not use your workspace content for advertising.
3. Legal basis for processing
Where the GDPR applies, we process personal data under the following bases: performance of a contract (providing the service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (optional marketing email), and legal obligation (tax and accounting records).
4. When we share information
We share data only with service providers who help us operate — cloud hosting, payment processing, email delivery and error monitoring — under contracts that limit their use of it. We may also disclose information where required by law, or as part of a merger or acquisition, in which case we will notify you before your data becomes subject to a different policy.
5. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and to remember your theme preference, which is stored locally in your browser. Analytics cookies, where used, are set only with your consent and can be withdrawn at any time from the cookie settings link in the footer.
6. How long we keep it
Account and content data is retained while your account is active. After deletion, workspace content is removed from live systems within 30 days and from backups within 90 days. Invoicing records are kept for the period required by tax law.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete or port your data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Email privacy@sicurs.com and we will respond within 30 days.
8. Security
Data is encrypted in transit with TLS and at rest. Access to production systems is limited to staff who need it, protected by multi-factor authentication and logged. No system is perfectly secure, so we also maintain an incident response process and will notify affected users and regulators where required.
9. Children
Sicurs is a business tool and is not directed at anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us information, contact us and we will delete it.
10. Changes to this policy
We will post any changes on this page and update the date above. If a change materially affects how we handle your information, we will email account owners before it takes effect.
11. Contact
Questions about this policy: privacy@sicurs.com. Add your registered company name, address and data protection contact here before launch. You can also use the contact form.