Your privacy choices.
One page for every jurisdiction: what rights you have, what we do and do not do with personal data, and exactly how to exercise a request.
01 · Summary
- We do not sell personal information and do not share it for cross-context behavioral advertising — so there is no "Do Not Sell or Share" toggle to flip; the opt-out is permanently on by construction.
- We honor Global Privacy Control (GPC) signals. Because we do not sell or share, a GPC signal changes nothing about how your data is handled — it is already treated that way.
- We do not use personal data for automated decisions that produce legal or similarly significant effects, and we do not profile visitors.
- All rights requests go to privacy@securityvault.io and are answered within 30 days or sooner where law requires.
02 · United States (CCPA/CPRA and state privacy laws)
If you are a resident of California or another US state with a comprehensive privacy law (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others), you have the right to:
- Know / access — the categories and specific pieces of personal information we hold about you, the sources, purposes, and disclosures.
- Delete — request deletion, subject to legal retention obligations (for example, billing records).
- Correct — fix inaccurate personal information.
- Portability — receive your data in a usable format.
- Opt out of sale/sharing and targeted advertising — not applicable in practice: we do not sell, share, or use personal information for targeted advertising, and this is a binding commitment in our privacy notice.
- Limit use of sensitive personal information — we do not collect sensitive personal information on this site.
- Non-discrimination — exercising any right never affects pricing or service quality.
Notice at collection (California)
Categories collected: identifiers (name, work email) and professional information (employer, role) — only when you submit a form; internet activity (server logs for security). Purposes: responding to you, providing the service, security. Retention: per the schedule in the privacy notice. Sold or shared: none.
03 · EU / UK / EEA (GDPR)
Under the EU/UK GDPR you may access, rectify, erase, or port your personal data; restrict or object to processing (including any processing based on legitimate interest); and withdraw consent at any time without affecting prior processing. Legal bases per purpose are listed in the privacy notice.
You may also lodge a complaint with your national supervisory authority. No EU or UK representative has been appointed yet; contact details for the privacy office are in the privacy notice and can be contacted directly under Article 27.
04 · India — Digital Personal Data Protection Act, 2023
For Data Principals in India, SecurityVault Systems Private Limited acts as a Data Fiduciary for personal data collected through this website and as a Data Processor for customer tenant data. Under the DPDP Act you have the right to:
- Access — a summary of your personal data being processed and the processing activities.
- Correction and erasure — update, complete, or erase personal data you provided.
- Grievance redressal — a readily available means to raise a grievance, answered within the statutory period.
- Nominate — designate another individual to exercise your rights in the event of death or incapacity.
- Withdraw consent — as easily as it was given; withdrawal stops the processing that relied on it.
Grievance Officer (India)
Grievance Officer, SecurityVault Systems Private Limited
grievance@securityvault.io
We acknowledge grievances within 72 hours and resolve them within 30 days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
We do not process the personal data of children under 18 in India, do not undertake tracking or behavioral monitoring of children, and do not serve targeted advertising to anyone.
05 · How to exercise a request
- Emailprivacy@securityvault.io from the address your request concerns, stating the right you want to exercise and your jurisdiction.
- Verification — we verify requests against the email address and account records on file; we ask for additional proof only when strictly needed and never request government ID for routine requests.
- Authorized agents (California) — agents may submit on your behalf with signed permission; we will confirm directly with you.
- Timeline — acknowledgment within 72 hours; substantive response within 30 days (45 with notice, where the law allows an extension).
- No fee — requests are free unless manifestly unfounded or excessive, in which case we explain before anything is charged.
06 · Appeals
If we decline a request in whole or part, we explain why and how to appeal. Reply to our decision or write to privacy@securityvault.io with the subject "Appeal"; a person not involved in the original decision reviews it within 30 days. You may also contact your supervisory authority (EU/UK), state attorney general (US), or the Data Protection Board of India at any time.