Legal

Privacy Policy

How IOthreat collects, uses, and protects your information.

1. Who we are

IOthreat (“IOthreat,” “we,” “us”) provides AI-assisted compliance remediation and related security services. This Privacy Policy explains how we handle personal information in connection with our website and Services. For privacy questions, contact hello@iothreat.com.

2. Information we collect

Information you provide. When you submit our contact form or correspond with us, we collect your name, work email, company (optional), and the contents of your message.

Information from using the Services. If you become a customer and connect the Services to your systems, we process the configuration and findings needed to propose remediations, on the access basis you set. We do not seek to collect more than is necessary to deliver the Services.

Technical information. Our hosting and infrastructure providers may automatically log basic technical data (such as IP address, browser type, and request time) for security and reliability.

3. How we use information

We use information to respond to your enquiries; provide, operate, and improve the Services; communicate with you about your account or request; maintain security and prevent abuse; and comply with legal obligations.

4. Legal bases

Where the GDPR or similar laws apply, we rely on: your consent; the performance of a contract with you; our legitimate interests in operating and securing the Services; and compliance with legal obligations.

5. How we share information

We do not sell your personal information. We share it only with:

  • Service providers (sub-processors) who help us run the Services — including our application and hosting platform (Base44) and our transactional email provider (Resend) — under agreements that require appropriate protection.
  • Legal and safety recipients, where required by law or to protect rights, safety, and the integrity of the Services.
  • Successors, in connection with a merger, acquisition, or asset transfer, subject to this Policy.

6. Data retention

We keep personal information only as long as needed for the purposes described here — for example, to respond to and follow up on your enquiry, meet legal requirements, and resolve disputes — after which we delete or anonymize it.

7. Security

Security is central to what we do. We apply administrative, technical, and organizational measures appropriate to the risk, and hold service providers to comparable standards. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to issues. To report a vulnerability, see our security policy.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email hello@iothreat.com. You may also have the right to complain to your local data protection authority.

9. International transfers

We and our service providers may process information in countries other than yours. Where required, we use appropriate safeguards for such transfers.

10. Cookies

Our website uses only the cookies and similar technologies necessary to operate reliably and securely. We do not use them to build advertising profiles.

11. Children

The Services are intended for businesses and are not directed to children. We do not knowingly collect personal information from children.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be reflected by updating the effective date above.

13. Contact

Questions or requests about your privacy? Email hello@iothreat.com.