Privacy Policy

Last updated: June 2026

1. Who we are

SecuritComply is a compliance management platform operated by SecuritAI Technologies Ltd., a company incorporated in Canada with its principal place of business in Toronto, Ontario. References to "we", "us", or "our" in this policy mean SecuritAI Technologies Ltd. acting through the SecuritComply service.

If you have questions about this policy, contact us at [email protected].

2. Definitions

  • Service means the SecuritComply website, dashboard, and API at securitcomply.com.
  • Account means a registered user or organization account on the Service.
  • Compliance Data means the controls, evidence, risk assessments, policies, vendor records, and other compliance information you upload or create within the Service.
  • Personal Data means information relating to an identified or identifiable individual, as defined under PIPEDA and applicable Canadian privacy law.
  • You means the individual accessing the Service or the organization on whose behalf they act.

3. Data we collect

Account information

When you create an account we collect your name, email address, organization name, and role. This is used to operate your account and communicate with you about the Service.

Compliance Data

The controls, evidence files, risk registers, vendor records, incident reports, and other compliance content you enter into the Service are stored on your behalf. This data belongs to you. We process it only to provide the Service and do not use it for any other purpose.

Usage and technical data

We collect standard server logs including IP address, browser type, device type, pages visited, and timestamps. This information is used to operate, secure, and improve the Service.

Cookies

We use essential session cookies to keep you signed in. We may use analytics cookies to understand aggregate usage patterns. We do not use advertising or cross-site tracking cookies.

4. How we use your data

  • To provide and operate the SecuritComply Service
  • To manage your account and authenticate your sessions
  • To respond to support requests
  • To send product updates and notices related to your account (you may opt out of marketing messages at any time)
  • To monitor for security incidents and prevent fraud
  • To comply with applicable law

We do not sell your Personal Data or Compliance Data to third parties. We do not use your Compliance Data to train any machine learning model.

5. AI Virtual CISO feature

The SecuritComply platform includes an AI Virtual CISO feature that uses a large language model to answer compliance questions. When you use this feature, your queries are sent to a third-party AI provider (currently Anthropic) over an encrypted connection. We do not permit our AI provider to train on your queries. Queries are not stored beyond what is needed to return a response. Do not include sensitive personal information in queries to the AI Virtual CISO.

6. Data sharing

We share your data only in the following circumstances:

  • Service providers — infrastructure, email delivery, and monitoring tools we use to operate the Service, bound by data processing agreements.
  • Marketplace professionals — if you engage an auditor or vCISO through the SecuritComply Marketplace, they receive access to the Compliance Data you explicitly share with them through the auditor portal.
  • Legal requirements — when required by law, court order, or to protect the rights and safety of our users or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, with notice provided to you.

7. Data residency

All Compliance Data and Personal Data is stored on infrastructure located in Canada. We do not transfer your data outside of Canada except where you explicitly direct us to (for example, when using the AI Virtual CISO feature, which routes queries to Anthropic servers). Anthropic operates under standard contractual protections consistent with applicable privacy law.

8. Data retention

We retain your account information and Compliance Data for as long as your account is active. If you close your account, we will delete or anonymize your data within 90 days unless a longer retention period is required by law. Server logs are retained for up to 12 months.

9. Security

We use industry-standard controls to protect your data, including encryption in transit (TLS), encryption at rest, access controls, and regular security reviews. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

10. Your rights

Under PIPEDA and applicable Canadian privacy law, you have the right to:

  • Access the Personal Data we hold about you
  • Correct inaccurate Personal Data
  • Request deletion of your Personal Data, subject to legal retention requirements
  • Withdraw consent to optional processing (such as marketing emails)
  • Lodge a complaint with the Office of the Privacy Commissioner of Canada

To exercise these rights, email [email protected]. We will respond within 30 days.

11. Children

The Service is not directed to individuals under 16. We do not knowingly collect Personal Data from anyone under 16. If you believe we have inadvertently done so, contact us and we will delete it promptly.

12. Third-party links

The Service may contain links to third-party websites, including our Marketplace. We are not responsible for the privacy practices of those sites and encourage you to review their policies.

13. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and notify account holders by email at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.

14. Contact

SecuritAI Technologies Ltd.
Toronto, Ontario, Canada
[email protected]
1 (647) 948-6768