Legal
Privacy Policy
Draft template — pending review by counsel. Placeholders in [brackets] must be completed and this document validated by a licensed attorney (including CCPA/CPRA and any state-specific requirements) before it is relied upon.
Last updated: [DATE]
Who we are
[Glober Security legal entity name], [City, State], United States ("Glober").
What we collect
- Account data — email and authentication data.
- Assessment inputs — domains, connected repositories, and engagement details you provide.
- Findings — the results of assessments (the vulnerability, location, and fix).
- Usage & log data — standard technical logs, including IP address, for security and rate-limiting.
What we do not collect / store
We do not store your source code — scans run in isolated, ephemeral environments that are deleted after each run. We do not store raw breach credentials; we store only the finding. We do not sell your personal information, and we do not train AI models on your code.
How we use it
To provide, secure, and improve the Services; to communicate with you (including monitoring alerts you enable); and to comply with law.
Subprocessors
We use service providers to operate the Services, including cloud hosting, database/authentication, and a US-based AI model provider that processes assessment text under commercial terms (no training on your data). A current list is available in our Trust Center or on request.
Retention
We retain findings and account data for as long as your account is active or as needed to provide the Services, then delete or de-identify per our retention policy. [Specify periods.]
Your rights
Depending on your jurisdiction (including California under the CCPA/CPRA), you may have rights to access, delete, correct, or port your personal information, and to opt out of certain processing. To exercise them, contact info@glober-security.com. We do not sell or "share" personal information as defined by the CCPA/CPRA.
Security
We use encryption in transit, tenant isolation (row-level security), server-side secret handling, and least-privilege access. See our Trust Center.
Changes
We may update this policy; material changes will be posted here with an updated date.