Privacy Policy
This Privacy Policy explains how IRU Shield may collect, use, disclose, store, and protect personal and device-related information in connection with service delivery and cybersecurity operations.
1. Information we may collect
- Account information such as name, email, organization, role, and billing contact details.
- Device and agent data such as hostname, operating system, agent version, IP address, crash logs, and scan results.
- Threat intelligence and security telemetry such as file hashes, behavioral indicators, suspicious process data, and alert metadata.
- Usage and diagnostic information such as dashboard interactions, performance metrics, and support records.
2. How we use information
- To authenticate users and manage subscriptions.
- To operate scans, updates, policies, detections, and response workflows.
- To improve threat models, reduce abuse, and strengthen service reliability.
- To provide support, report incidents, process billing, and fulfill legal obligations.
3. Legal bases and enterprise context
Depending on jurisdiction and deployment model, processing may be based on contract performance, legitimate interests, compliance obligations, security interests, or other lawful grounds. In enterprise settings, customer organizations may act as controllers for certain managed endpoint data.
4. Data sharing
IRU Shield does not sell personal data. We may share information with service providers, infrastructure partners, payment providers, analytics processors, support vendors, or legal authorities where necessary for lawful service delivery, incident response, or compliance.
5. Retention and security
Data is retained only as long as reasonably required for service functionality, security operations, business records, dispute resolution, or legal obligations. Retention windows may vary across account data, alerts, telemetry, logs, backups, and support records. IRU Shield uses technical and organizational safeguards intended to protect data from unauthorized access, alteration, loss, and misuse.
6. User rights
Subject to applicable law, users may have rights to request access, correction, deletion, restriction, objection, or portability relating to personal data. Enterprise-managed users may be redirected to their organization administrator where the organization controls certain data handling decisions.