Privacy

Privacy Policy

This Privacy Policy explains how RedSide Security LLC (“RedSide”, “we”, “us” or “our”) collects, uses, discloses and protects personal data in connection with the LeakWatch platform (“Service”). We are committed to protecting the privacy and security of our customers, users and visitors.

1. Scope

This Policy applies to personal data we process when you:

  • Register for and use LeakWatch as an authorized user;
  • Access our website or marketing pages;
  • Communicate with us (for example via email or support channels); or
  • Provide us with information in connection with a commercial relationship.

2. Data we collect

We may collect and process the following categories of personal data:

  • Account information: name, email address, company name, role, telephone number, login credentials and authentication data.
  • li>Usage and log data: IP address, browser type, device identifiers, access times, pages viewed, actions taken within the Service and other technical metadata required for security monitoring and auditing.
  • Search and alert data: email addresses, usernames, domains and related identifiers that you submit to LeakWatch for the purpose of monitoring potential credential or data exposure.
  • Billing and subscription data: subscription plan, invoicing details and payment‑related information processed via our third‑party payment providers.
  • Support and communications: records of communications with our support, sales or customer‑success teams, including associated metadata.

3. How we use personal data

We use personal data for the following purposes:

  • Providing and operating the Service, including user authentication, access control, search execution and delivery of results.
  • Security monitoring and incident detection, including detection of credential exposure, misuse and suspicious activity.
  • Compliance and audit, including maintaining audit logs and evidence to support internal controls, legal obligations and regulatory requirements.
  • Customer support and communication, including responding to enquiries, providing onboarding and training, and sending important service notifications.
  • Service improvement, including analysing usage patterns to improve performance, features and user experience.
  • Legal and regulatory purposes, including managing disputes, enforcing our Terms of Service and protecting our rights, users and the public.

4. Legal bases for processing

Where applicable data protection laws (such as the EU/UK GDPR) require a legal basis, we rely on:

  • Performance of a contract – to provide and administer the Service you have subscribed to;
  • Legitimate interests – for security monitoring, fraud prevention, service improvement and business operations, where our interests are not overridden by your rights;
  • Legal obligations – to comply with applicable laws and regulatory requirements; and
  • Consent – where we rely on your explicit consent, for example for certain marketing communications (which you can withdraw at any time).

5. How we share data

We do not sell personal data. We may share personal data with:

  • Service providers and subprocessors that support the operation of the Service (e.g. hosting, email delivery, customer support tools), under contractual terms that require appropriate safeguards and confidentiality.
  • Authorized customers – for example, exposure findings related to their own accounts, domains or employees.
  • Affiliates within our corporate group, where necessary for operations and support.
  • Authorities or other third parties where required by law, regulation, legal process or to protect the rights, property or safety of RedSide, our customers or others.

6. International data transfers

Depending on your location, personal data may be transferred to and processed in countries outside your jurisdiction, which may have different data‑protection laws. Where required, we implement appropriate safeguards, such as standard contractual clauses or equivalent mechanisms, to protect your data.

7. Data security

We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction, including encryption in transit, access controls, logging and monitoring, and secure development practices. No system is completely secure; we maintain and improve our controls on an ongoing basis.

8. Data retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or as required by law, regulation or contractual obligation. Retention periods may vary depending on the type of data, the nature of our relationship with you and applicable legal requirements.

9. Your rights

Depending on your jurisdiction, you may have certain rights in respect of your personal data, including to:

  • Access, correct or delete your personal data;
  • Object to or restrict specific processing activities;
  • Receive a copy of your data in a portable format; and
  • Withdraw consent where processing is based on consent.

To exercise these rights, please contact us using the details below. We may need to verify your identity before responding.

10. Children’s data

The Service is not directed to children and is intended for use by organisations and authorised professionals. We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us so we can take appropriate steps.

11. Contact

If you have any questions about this Privacy Policy or how we process personal data, please contact:

RedSide Security LLC
Email: [email protected]

12. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date above. We encourage you to review this Policy periodically to stay informed about how we protect your information.

Last updated: 2026-05-18 14:29:48 UTC