Privacy Policy
This Privacy Policy explains how SecOps ("SecOps", "we", "us") handles personal data in connection with the SecOps platform and related services (the "Service"). SecOps operates as a processor of Customer Data on behalf of partners, and as a controller of the limited account data needed to run the Service.
1. Data we process
We process: account data (name, work email, role, and hashed credentials); session and security data (session tokens, audit events, IP address, and login activity); and Customer Data that partners connect to the Service, including Vision One credentials and the security telemetry retrieved through them. We do not sell personal data.
2. How we use data
We use data to authenticate users, provide dashboards, reporting, and ticketing, maintain tenant isolation, keep a tamper-evident audit trail, secure and troubleshoot the Service, and meet legal obligations. We process Customer Data only to provide the Service and on the documented instructions of the partner.
3. Regional isolation and residency
SecOps runs as fully isolated regional deployments (for example EU, US, APAC, India, and Middle East). A partner's data lives entirely within a single region, and no personal data flows between regions. This design supports data-residency and sovereignty requirements.
4. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), hashing of passwords, encryption of sensitive secrets at rest, non-bypassable tenant-scoped data access, and append-only audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
5. Data retention
We retain account and Customer Data for as long as an account is active or as needed to provide the Service, and thereafter as required for legitimate business or legal purposes. Partners may request deletion of Customer Data subject to those obligations.
6. Sub-processors
We may use vetted third parties (for example regional infrastructure and, where enabled, email delivery providers) to help operate the Service. Such sub-processors are bound by obligations consistent with this Policy.
7. Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object or request portability. Because much of the data is processed on behalf of a partner, we will direct qualifying requests to the relevant partner (controller) and assist as required.
8. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the Service or by other reasonable means, and the "last updated" date above will change.
9. Contact
For privacy questions or to exercise a right, contact your SecOps administrator or the privacy contact published for your region.
See also: Terms of Service.