Legal
Privacy Policy
How IOthreat collects, uses, and protects your information.
Effective date: 28 July 2026
1. Who we are
IOthreat (“IOthreat,” “we,” “us”) provides AI-assisted compliance remediation and related security services. This Privacy Policy explains how we handle personal information in connection with our website and Services. For privacy questions, contact hello@iothreat.com.
2. Information we collect
Information you provide. When you submit our contact form or correspond with us, we collect your name, work email, company (optional), and the contents of your message.
Information from using the Services. If you become a customer and connect the Services to your systems, we process the configuration and findings needed to propose remediations, on the access basis you set. We do not seek to collect more than is necessary to deliver the Services.
Technical information. Our hosting and infrastructure providers may automatically log basic technical data (such as IP address, browser type, and request time) for security and reliability.
3. How we use information
We use information to respond to your enquiries; provide, operate, and improve the Services; communicate with you about your account or request; maintain security and prevent abuse; and comply with legal obligations.
4. Legal bases
Where the GDPR or similar laws apply, we rely on: your consent; the performance of a contract with you; our legitimate interests in operating and securing the Services; and compliance with legal obligations.
5. How we share information
We do not sell your personal information. We share it only with:
- Service providers (sub-processors) who help us run the Services — including our application and hosting platform (Base44) and our transactional email provider (Resend) — under agreements that require appropriate protection.
- Legal and safety recipients, where required by law or to protect rights, safety, and the integrity of the Services.
- Successors, in connection with a merger, acquisition, or asset transfer, subject to this Policy.
6. Data retention
We keep personal information only as long as needed for the purposes described here — for example, to respond to and follow up on your enquiry, meet legal requirements, and resolve disputes — after which we delete or anonymize it.
7. Security
Security is central to what we do. We apply administrative, technical, and organizational measures appropriate to the risk, and hold service providers to comparable standards. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to issues. To report a vulnerability, see our security policy.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email hello@iothreat.com. You may also have the right to complain to your local data protection authority.
9. International transfers
We and our service providers may process information in countries other than yours. Where required, we use appropriate safeguards for such transfers.
10. Cookies
Our website uses only the cookies and similar technologies necessary to operate reliably and securely. We do not use them to build advertising profiles.
11. Children
The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected by updating the effective date above.
13. Contact
Questions or requests about your privacy? Email hello@iothreat.com.