Introduction and scope
This policy covers personal data and organization data processed through bitguardit.com properties, including the client portal (portal.bitguardit.com), staff portal (staff.bitguardit.com), and admin portal (a.bitguardit.com), as well as associated APIs and support channels.
By using BitGuardIT services, you acknowledge that security assessment inherently involves processing technical data about systems you submit for analysis. You should not submit assets or data you are not authorized to assess.
Definitions
- "Personal data" means information relating to an identified or identifiable individual, such as name and email address.
- "Organization data" means information about a customer organization, its assets, scans, findings, subscriptions, and users acting on its behalf.
- "Customer content" means domains, URLs, IP addresses, scan results, findings, reports, tickets, and messages you or your users submit to the platform.
- "Processor" means a third party that processes data on our instructions to provide infrastructure or integrated services.
Information we collect
We collect information necessary to operate a cybersecurity SaaS platform, provide support, and meet legal obligations. Categories include:
Account and organization data
- Name, email address, and account type (client, staff, admin).
- Organization name, slug, and membership relationships.
- Authentication credentials (stored in hashed form), session tokens, and email verification status.
- Role assignments, profile preferences, and notification settings.
- Invitation and onboarding records.
Domain and asset information submitted for scanning
- Asset identifiers (domains, URLs, IP addresses) and display names you register.
- Ownership verification records, authorization scope, approved scan types, and subdomain inclusion settings.
- Verification tokens and DNS TXT validation metadata where used.
- Discovered assets from authorized scans (subdomains, technologies, certificates, and related attack surface data).
Security assessment data
- Scan job configuration, schedules, status, and timelines.
- Findings, severities, risk scores, evidence, and remediation recommendations.
- Vulnerability records, CVE references, and lifecycle status (open, resolved, false positive).
- Monitoring check results, alerts, and continuous monitoring summaries.
- Compliance mapping outputs and assessment records where used.
Scan results and reports
- Generated report files and metadata (type, format, generation time, summary text).
- Executive, compliance, operational, and threat intelligence report contents derived from your organization data.
- Download and access logs associated with report retrieval.
Usage and technical information
- IP address, browser type, device characteristics, and approximate location derived from IP.
- Portal navigation, feature usage, and API request logs needed for security and operations.
- Error diagnostics and performance telemetry.
- Audit log entries for administrative and security-sensitive actions.
Support communications
- Ticket and case subjects, descriptions, priorities, and conversation history.
- Service request details and fulfillment notes.
- Email correspondence with support, security, and privacy teams.
How data is processed and used
We process information for the purposes below based on contractual necessity, legitimate interests in operating a secure SaaS platform, compliance with law, and consent where required.
Providing cybersecurity services
- Executing authorized scans and monitoring checks.
- Enriching findings with threat intelligence providers when enabled.
- Generating reports and dashboard analytics for your organization.
- Delivering human-assisted assessments and consultations when purchased.
Security analysis and threat detection
- Detecting misconfigurations, vulnerabilities, and exposure changes.
- Correlating alerts and prioritizing risk for your workspace.
- Supporting incident response workflows for entitled subscriptions.
Platform improvement
- Diagnosing errors and improving reliability.
- Understanding feature usage to enhance usability and performance.
- Training and tuning detection logic using aggregated or de-identified patterns where feasible.
Fraud prevention
- Verifying asset ownership before scanning.
- Detecting abuse, unauthorized scanning attempts, and account compromise indicators.
- Protecting payment and subscription integrity.
Customer communication
- Service notifications, scan completion alerts, and report readiness messages.
- Billing, subscription, and trial communications.
- Responses to support, privacy, and security inquiries.
Legal obligations
We may process or retain data to comply with applicable law, respond to lawful requests, enforce our agreements, and protect the rights and safety of BitGuardIT, our customers, and the public.
Data retention
We retain data for as long as your organization maintains an active relationship with BitGuardIT or as needed to provide services, resolve disputes, and meet legal requirements. Typical retention considerations:
- Account data — retained while the account is active and for a reasonable period thereafter.
- Scan and finding data — retained according to subscription terms and operational needs; you may export reports before cancellation.
- Billing records — retained as required for tax, accounting, and payment processor rules.
- Audit and security logs — retained for a defined period to support investigations and compliance with internal policies.
Data deletion
You may request deletion of personal data subject to contractual limitations and legal retention requirements. Organization administrators should contact privacy@bitguardit.com with verification of authority. Some security logs and billing records may be retained in anonymized or aggregated form where deletion is not feasible or permitted.
Customer data ownership
You retain ownership of Customer content you submit. BitGuardIT receives a limited license to host, process, and display Customer content solely to provide and improve the services described in your agreement.
Confidentiality of security findings
We treat scan results, findings, and reports as confidential organization data. Access within BitGuardIT is restricted by role and assignment. Staff access to client data is limited to authorized operational needs, assigned cases, and support tickets you initiate, subject to internal access controls and audit logging.
Third-party service providers
We use trusted providers for infrastructure and integrated capabilities, including:
- Cloud hosting and database services for platform operation.
- Payment processors (Stripe, PayPal, M-Pesa) for billing — payment card data is handled on processor systems, not stored by BitGuardIT beyond transaction references.
- Email delivery for notifications and account messages.
- Threat intelligence and enrichment providers when integrations are enabled for scans.
- AI model providers when the AI Assistant or advisory features are used — prompts may include finding context necessary to generate explanations; we configure integrations to minimize unnecessary data transfer.
Providers are bound by contractual confidentiality and security requirements appropriate to their role.
AI-assisted analysis disclosure
When entitled, BitGuardIT may send finding and organizational context to configured AI providers to generate explanations, recommendations, and chat responses. AI output is advisory and may be incomplete or inaccurate; it should be validated before acting. You can review AI feature availability under your subscription entitlements.
Your privacy rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal data, or to object to certain processing. To exercise rights, contact privacy@bitguardit.com. We may need to verify identity and authority before fulfilling requests.
Contact information
Privacy inquiries and data subject requests: privacy@bitguardit.com
General support: support@bitguardit.com
Security concerns: security@bitguardit.com