Privacy Policy

Last updated: August 1, 2026

GDPR Compliant

This Privacy Policy complies with the EU General Data Protection Regulation (GDPR). If you are an EU resident, you have specific rights regarding your personal data, which are explained below.

Introduction

TOC Consulting ("we", "us", or "our"), the company operating the KloudSec platform, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our cloud security platform ("Service").

Data Controller: TOC Consulting, 23 Rue de Berne, 75008 Paris, France, is the data controller responsible for your personal data.

Contact: For privacy-related questions or to exercise your data protection rights, email us at hello@kloudsec.io

1. Information We Collect

1.1 Personal Information You Provide

When you register for an account or use the Service, we collect:

  • Account Information: Name, email address, organization name
  • Payment Information: Processed by Stripe (we do not store credit card details)
  • Communications: Messages you send to our support team

1.2 Cloud Infrastructure Data

To provide security scanning services, we collect:

  • Resource Metadata: Configuration details of your cloud resources (for AWS today, e.g. EC2, S3, IAM; GCP and Azure resource metadata will be collected the same way once those integrations launch)
  • Security Findings: Vulnerability and compliance scan results
  • Cloud Account IDs: Used to identify which infrastructure belongs to which customer

Important: We do NOT collect or store:

  • • Cloud credentials, access keys, or secrets
  • • The actual contents of your cloud resources - for example, records inside your databases, objects inside your storage buckets, or files on your servers. We only collect configuration metadata about those resources, never the data stored inside them
  • • Database contents or file contents

1.3 Usage and Technical Data

We automatically collect:

  • User Actions: Platform interactions for audit trails and security monitoring
  • Login Information: Timestamps and IP addresses of account access
  • Device Information: Browser type, operating system (for compatibility)
  • Scan History: Records of when scans were run and their results

1.4 Cookies and Tracking

Current Status: We use minimal cookies - only for authentication.

  • Authentication Cookies: Essential for logging you in and maintaining your session

We do NOT currently use:

  • • Analytics cookies (no Google Analytics, Mixpanel, etc.)
  • • Advertising or tracking cookies
  • • Third-party analytics or error tracking tools

If we introduce analytics or additional cookies in the future, we will update this policy and obtain your consent where required.

2. How We Use Your Information

We use your personal information for the following purposes:

✓ Service Delivery

Provide security scanning, vulnerability detection, and compliance monitoring

✓ Account Management

Create and manage your account, process payments, handle subscriptions

✓ Customer Support

Respond to inquiries, provide technical assistance, troubleshoot issues

✓ Security & Fraud Prevention

Monitor for unauthorized access, detect fraudulent activity, maintain audit logs

✓ Service Improvements

Analyze usage patterns to improve features and user experience

✓ Legal Compliance

Comply with legal obligations, enforce our terms, protect our rights

✓ Communications

Send service updates, security alerts, and account notifications (not marketing)

3. Legal Basis for Processing (GDPR)

For EU users, we process your personal data based on the following legal grounds:

Contract Performance

Processing necessary to provide the Service you signed up for (GDPR Art. 6(1)(b))

Legitimate Interests

Service improvements, security monitoring, and fraud prevention (GDPR Art. 6(1)(f))

Legal Obligation

Compliance with tax laws, financial regulations, and data protection laws (GDPR Art. 6(1)(c))

Consent

Where required for specific processing activities, we obtain your explicit consent (GDPR Art. 6(1)(a))

4. How We Share Your Information

We do NOT sell your personal data. We share data only in limited circumstances:

Service Providers

We use trusted third-party service providers who process data on our behalf:

  • AWS: Cloud infrastructure hosting (EU regions)
  • Stripe: Payment processing (PCI-DSS compliant)

All service providers are contractually obligated to protect your data and use it only for specified purposes.

Legal Requirements

We may disclose data if required by law, court order, or government request, or to protect our legal rights.

Business Transfers

If KloudSec is acquired or merged, your data may be transferred to the acquiring entity (you will be notified).

With Your Consent

We may share data with your explicit consent for specific purposes.

5. Data Storage and International Transfers

Data Location

  • Primary Storage: All user data is stored in EU data centers (AWS EU regions)
  • Data Processing: Some processing may occur in US-based infrastructure for performance optimization
  • Safeguards: All data transfers comply with GDPR requirements, including Standard Contractual Clauses where applicable
  • Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256) regardless of location

6. Data Retention

We retain your data only as long as necessary for the purposes described in this policy.

Retention Periods

  • Active Accounts: Data is retained while your account is active and for the provision of services
  • Account Deletion: Upon request or account deletion, we delete your data immediately
  • Future Soft Delete: We may implement a 30-day "soft delete" period for account recovery, giving you time to restore your account before permanent deletion
  • Legal Requirements: Some data (e.g., invoices, payment records) must be retained for tax and accounting purposes as required by law (typically 7-10 years)
  • Audit Logs: Security audit logs may be retained for up to 2 years for security and compliance purposes

7. Your Data Protection Rights (GDPR)

If you are an EU resident, you have the following rights under GDPR:

Right to Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

Right to Data Portability

Receive your data in a structured, machine-readable format

Right to Object

Object to processing based on legitimate interests or for direct marketing

Right to Restrict Processing

Limit how we use your data under certain circumstances

Right to Withdraw Consent

Withdraw consent for processing based on consent at any time

Right to Complain

Lodge a complaint with your local data protection authority

How to Exercise Your Rights

To exercise any of these rights, please email us at:

hello@kloudsec.io

We will respond to your request within 30 days as required by GDPR. We may request verification of your identity before processing your request.

8. Children's Privacy

KloudSec is not intended for use by children under the age of 18 (or 16 in some EU countries). We do not knowingly collect personal data from children.

If we discover that we have inadvertently collected data from a child, we will delete it immediately. If you believe we have collected data from a child, please contact us at hello@kloudsec.io.

9. Data Security

We implement industry-standard security measures to protect your personal data. For detailed information about our security practices, please see our Security Page.

Key Security Measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Regular security audits and monitoring
  • Access controls and authentication requirements
  • Comprehensive audit logging

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

How we notify you of changes:

  • Post the updated Privacy Policy on this page with a new "Last Updated" date
  • Send email notification for material changes
  • Display a notice in your account dashboard

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.

Contact Us About Privacy

If you have questions or concerns about this Privacy Policy or our data practices:

TOC Consulting

23 Rue de Berne, 75008 Paris, France

Privacy Contact:

hello@kloudsec.io

EU Data Protection Authority:

If you are an EU resident and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local supervisory authority:

France: Commission Nationale de l'Informatique et des Libertés (CNIL) - www.cnil.fr

Last Updated: August 1, 2026

This Privacy Policy is effective immediately for new users and existing users alike.