Privacy Policy

Your privacy is our priority. Learn how DataSecure protects and handles your information.

Last updated: September 15, 2025

Introduction

Cortex Security S.A. ("DataSecure") operates the DataSecure RDR platform for ransomware detection and response. This Privacy Policy explains how we handle your information when you use our services.

Information We Collect

We collect information you provide directly, including account details (name, email, company), payment information, and communications with our team. Our platform automatically collects security telemetry for ransomware detection, system performance metrics, usage patterns, and technical information like IP addresses and device identifiers.

How We Use Your Information

Your information enables us to deliver our security services, detect and respond to ransomware threats, provide customer support, send critical security alerts, improve our detection algorithms, and comply with legal requirements.

Data Security

We protect your data using AES-256 encryption at rest and TLS 1.3 in transit, enforce multi-factor authentication and role-based access controls, maintain 24/7 security monitoring, and host exclusively in SOC 2 Type II certified EU data centers in Luxembourg and Germany.

Data Retention

Account data is retained during your subscription plus 30 days after termination. Security telemetry is kept for 90 days for threat analysis. All data is securely deleted after retention periods expire, except where legally required.

Information Sharing

We never sell your personal information. We share data only with essential service providers under strict confidentiality agreements, when legally required, to prevent imminent security threats, or during business transfers with prior notice.

Your Rights

Under GDPR, you have the right to:

  • Access and receive copies of your personal data
  • Correct inaccurate information
  • Request deletion of your data
  • Port your data to other services
  • Object to or restrict certain processing

EU Data Processing

All data processing and storage occurs within the European Union. We do not transfer personal data outside the EU without appropriate safeguards.

Cookies

We use only essential cookies for authentication, security, and preferences. No third-party tracking or advertising cookies are used.

Updates to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email or platform notifications.

Contact Us

For privacy inquiries or to exercise your rights:

Data Protection Officer
Cortex Security S.A.
Email: contact@datasecure.ai
123 Cybersecurity Avenue, L-1234 Luxembourg

You may also contact the Luxembourg National Commission for Data Protection (CNPD) at cnpd.public.lu.