Privacy Policy
Effective date: June 2026 • Contact: [email protected]
This Privacy Policy explains how VXSec handles information for website visitors, scope checks, diagnostics, cleanup sprints, partner delivery, and related communications. Project-specific agreements may add to or override this policy for a specific engagement.
1. Information We Collect
We collect only what is reasonably needed to respond to inquiries, scope work, deliver services, maintain records, and protect our business.
- Contact information: name, email, company, role, phone number, and information submitted by email, booking tools, or a contact form if one is used.
- Scope check information: systems in use, user counts, tool lists, cloud account context, SaaS stack, AI tool usage, contractor patterns, offboarding concerns, and known cleanup issues.
- Audit and implementation artifacts: screenshots, SaaS exports, cloud exports, AI tool inventories, access lists, admin role lists, audit logs, billing exports, workflow notes, and report drafts.
- Access information: temporary credentials, delegated access details, role assignments, screen-share information, or access instructions provided for a scoped engagement.
- Business records: proposals, statements of work, invoices, payment status, project notes, approvals, and correspondence.
2. How We Use Information
- To respond to inquiries and schedule scope checks.
- To evaluate fit, scope systems, price work, and prepare proposals.
- To deliver fixed-scope diagnostics, access reviews, SaaS/cloud hygiene reviews, AI tool access reviews, implementation sprints, and partner delivery.
- To draft reports, findings tables, implementation roadmaps, approval lists, and documentation.
- To maintain billing, tax, legal, and business records.
- To protect systems, prevent misuse, and comply with applicable obligations.
Client-controlled data remains client data. VXSec does not sell client data or use client data for advertising.
3. AI Tools in Delivery
VXSec builds with AI agents as the engine: they draft, write code, run tests, and prepare documents. Their use is bounded by these rules:
- Never entered into AI tools: credentials, passwords, API keys, tokens, or secrets of any kind; raw tenant exports; audit logs; access lists tied to named individuals; billing exports; and personally identifiable client data. Client-identifying details are removed or generalized before any AI-assisted drafting step.
- Approved services only: AI-assisted drafting runs on commercial services under accounts VXSec controls, with training on submitted content disabled where the provider offers that control. Client data is not used to train models.
- System access only within the written plan: an AI tool touches a client system only when the scope grants that access, with the access listed, logged, and removed at handoff unless VXSec is retained. Verification on real data happens inside the client's environment or on data the client provides for that purpose. Credentials are never placed in prompts.
- Human review: every deliverable is reviewed by VXSec before it is sent, and nothing deploys to a client's production systems without a person approving it.
- Storage: working artifacts and deliverables live in VXSec's own systems under this policy. AI tools are not used as storage.
- Client-specific controls: clients can require stricter handling in the agreement or statement of work, including no AI-assisted processing of their engagement.
4. Sharing and Subprocessors
We share information only as needed to operate the business, deliver the agreed services, or comply with law. This may include scheduling tools, email and document tools, payment processors, cloud storage, security tools, subcontractors, and delivery partners. Examples may include Calendly, Google Workspace, Stripe, cloud hosting or storage providers, and approved project partners.
We do not sell personal information. Subprocessors and partners are expected to handle information only for the purpose of supporting the agreed work.
5. Access, Credentials, and Client Systems
VXSec prefers exports, read-only access, screen share, or least-privilege access where practical. Temporary admin or implementation access may be needed for approved cleanup work. Access should be removed after the engagement or when it is no longer needed unless a project-specific agreement says otherwise.
6. Retention and Deletion
Retention depends on the type of information, project needs, legal requirements, and client instructions.
- Contact and billing records: retained as needed for business, tax, and legal records.
- Reports and project documentation: retained for reference and quality purposes unless deletion is requested or a project agreement sets a different period.
- Temporary access credentials: deleted or revoked after delivery or when no longer needed.
- Exports, screenshots, and audit artifacts: retained only as long as needed for the project, support period, legal record, or agreed follow-up.
You may request deletion of project artifacts by emailing [email protected]. Some records may need to be retained for legal, accounting, dispute, or legitimate business reasons.
7. Security Measures
VXSec uses practical security measures such as access controls, least-privilege access, password management, secure storage, encrypted transport where available, limited access to client artifacts, and removal of temporary access after work is complete. No system or transmission method is perfectly secure, and third-party platforms may have their own limitations.
8. Website Data
The VXSec website does not use advertising pixels or tracking scripts. Server logs or hosting providers may process basic technical information such as IP address, browser, requested page, timestamp, and referrer for security, debugging, and site operation.
9. International Processing
VXSec is based in Ontario, Canada. Some tools, subprocessors, clients, or project partners may process data in Canada, the United States, or other countries depending on the service used.
10. Your Requests
You may contact VXSec to request access, correction, deletion, or information about how your data is handled. We may need to verify identity and confirm authority before acting on requests involving client systems or project artifacts.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be posted on this page. Project-specific agreements may continue to control for active work where they differ from this policy.
12. Contact
For privacy questions, requests, or concerns, contact us at:
VXSec
Ontario, Canada
[email protected]
We will respond to privacy inquiries within 30 days.