Privacy Policy

Last updated: January 26, 2026

1. Introduction

NETECT INTELLIGENCE CORP. ("Company", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Audit Trail Layer service ("Service").

This policy complies with the General Data Protection Regulation (GDPR) for users in the European Union, the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

2. Data Controller

NETECT INTELLIGENCE CORP. is the data controller for personal data collected through the Service. For privacy inquiries, please use our contact form.

3. Data We Collect

3.1 Account Information

When you create an account, we collect:

  • Email address
  • Name
  • Google account ID (if using Google Sign-In)

3.2 Payment Information

Payment processing is handled by Stripe. We do not store your credit card numbers. We receive from Stripe:

  • Transaction IDs
  • Payment amounts
  • Payment status

3.3 Usage Data

When you use our API, we collect:

  • Request timestamps
  • Payload hashes (not the actual content)
  • API key identifiers
  • Request counts for billing

3.4 Technical Data

For security and service improvement:

  • IP addresses
  • Browser type and version
  • Device information
  • Error logs

4. How We Use Your Data

We use collected data to:

  • Provide and maintain the Service
  • Process payments and billing
  • Send service-related communications
  • Detect and prevent fraud
  • Improve the Service
  • Comply with legal obligations

5. Legal Basis for Processing (GDPR)

We process your data under the following legal bases:

  • Contract: Processing necessary to provide the Service you requested
  • Legitimate Interest: Security, fraud prevention, service improvement
  • Legal Obligation: Tax records, compliance requirements
  • Consent: Marketing communications (if opted in)

6. Data Sharing

We share data with:

  • Stripe: Payment processing
  • Amazon Web Services (AWS): Email delivery (SES), infrastructure hosting
  • Google: OAuth authentication (if used)

We do not sell your personal data. We may disclose data if required by law or to protect our rights.

7. International Transfers

Your data may be transferred to and processed in the United States. For EU users, we rely on Standard Contractual Clauses for lawful data transfers.

8. Data Retention

  • Account data: Until you delete your account
  • Payment records: 7 years (legal requirement)
  • Usage logs: 1 year
  • Technical logs: 90 days

9. Your Rights (GDPR)

If you are in the EU, you have the right to:

  • Access: Request a copy of your data
  • Rectification: Correct inaccurate data
  • Erasure: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Object: Object to certain processing
  • Withdraw Consent: Where processing is based on consent

To exercise these rights, please contact us.

10. Cookies

We use the following cookies:

  • Session cookies: Essential for authentication
  • Preference cookies: Remember your settings (e.g., dark mode)

We do not use third-party advertising cookies. You can control cookies through your browser settings.

11. Security

We implement appropriate technical and organizational measures to protect your data, including:

  • HTTPS encryption for all connections
  • Encrypted database storage
  • Regular security audits
  • Access controls and authentication

12. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect data from children.

13. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via email or through the Service. Continued use after changes constitutes acceptance.

14. Contact

For privacy-related questions or to exercise your rights, please use our contact form.