Privacy Policy
Last updated: August 1, 2026
GDPR Compliant
This Privacy Policy complies with the EU General Data Protection Regulation (GDPR). If you are an EU resident, you have specific rights regarding your personal data, which are explained below.
Introduction
TOC Consulting ("we", "us", or "our"), the company operating the KloudSec platform, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our cloud security platform ("Service").
Data Controller: TOC Consulting, 23 Rue de Berne, 75008 Paris, France, is the data controller responsible for your personal data.
Contact: For privacy-related questions or to exercise your data protection rights, email us at hello@kloudsec.io
1. Information We Collect
1.1 Personal Information You Provide
When you register for an account or use the Service, we collect:
- •Account Information: Name, email address, organization name
- •Payment Information: Processed by Stripe (we do not store credit card details)
- •Communications: Messages you send to our support team
1.2 Cloud Infrastructure Data
To provide security scanning services, we collect:
- •Resource Metadata: Configuration details of your cloud resources (for AWS today, e.g. EC2, S3, IAM; GCP and Azure resource metadata will be collected the same way once those integrations launch)
- •Security Findings: Vulnerability and compliance scan results
- •Cloud Account IDs: Used to identify which infrastructure belongs to which customer
Important: We do NOT collect or store:
- • Cloud credentials, access keys, or secrets
- • The actual contents of your cloud resources - for example, records inside your databases, objects inside your storage buckets, or files on your servers. We only collect configuration metadata about those resources, never the data stored inside them
- • Database contents or file contents
1.3 Usage and Technical Data
We automatically collect:
- •User Actions: Platform interactions for audit trails and security monitoring
- •Login Information: Timestamps and IP addresses of account access
- •Device Information: Browser type, operating system (for compatibility)
- •Scan History: Records of when scans were run and their results
1.4 Cookies and Tracking
Current Status: We use minimal cookies - only for authentication.
- Authentication Cookies: Essential for logging you in and maintaining your session
We do NOT currently use:
- • Analytics cookies (no Google Analytics, Mixpanel, etc.)
- • Advertising or tracking cookies
- • Third-party analytics or error tracking tools
If we introduce analytics or additional cookies in the future, we will update this policy and obtain your consent where required.
2. How We Use Your Information
We use your personal information for the following purposes:
✓ Service Delivery
Provide security scanning, vulnerability detection, and compliance monitoring
✓ Account Management
Create and manage your account, process payments, handle subscriptions
✓ Customer Support
Respond to inquiries, provide technical assistance, troubleshoot issues
✓ Security & Fraud Prevention
Monitor for unauthorized access, detect fraudulent activity, maintain audit logs
✓ Service Improvements
Analyze usage patterns to improve features and user experience
✓ Legal Compliance
Comply with legal obligations, enforce our terms, protect our rights
✓ Communications
Send service updates, security alerts, and account notifications (not marketing)
3. Legal Basis for Processing (GDPR)
For EU users, we process your personal data based on the following legal grounds:
Contract Performance
Processing necessary to provide the Service you signed up for (GDPR Art. 6(1)(b))
Legitimate Interests
Service improvements, security monitoring, and fraud prevention (GDPR Art. 6(1)(f))
Legal Obligation
Compliance with tax laws, financial regulations, and data protection laws (GDPR Art. 6(1)(c))
Consent
Where required for specific processing activities, we obtain your explicit consent (GDPR Art. 6(1)(a))
4. How We Share Your Information
We do NOT sell your personal data. We share data only in limited circumstances:
Service Providers
We use trusted third-party service providers who process data on our behalf:
- • AWS: Cloud infrastructure hosting (EU regions)
- • Stripe: Payment processing (PCI-DSS compliant)
All service providers are contractually obligated to protect your data and use it only for specified purposes.
Legal Requirements
We may disclose data if required by law, court order, or government request, or to protect our legal rights.
Business Transfers
If KloudSec is acquired or merged, your data may be transferred to the acquiring entity (you will be notified).
With Your Consent
We may share data with your explicit consent for specific purposes.
5. Data Storage and International Transfers
Data Location
- Primary Storage: All user data is stored in EU data centers (AWS EU regions)
- Data Processing: Some processing may occur in US-based infrastructure for performance optimization
- Safeguards: All data transfers comply with GDPR requirements, including Standard Contractual Clauses where applicable
- Encryption: Data is encrypted in transit (TLS 1.3) and at rest (AES-256) regardless of location
6. Data Retention
We retain your data only as long as necessary for the purposes described in this policy.
Retention Periods
- •Active Accounts: Data is retained while your account is active and for the provision of services
- •Account Deletion: Upon request or account deletion, we delete your data immediately
- •Future Soft Delete: We may implement a 30-day "soft delete" period for account recovery, giving you time to restore your account before permanent deletion
- •Legal Requirements: Some data (e.g., invoices, payment records) must be retained for tax and accounting purposes as required by law (typically 7-10 years)
- •Audit Logs: Security audit logs may be retained for up to 2 years for security and compliance purposes
7. Your Data Protection Rights (GDPR)
If you are an EU resident, you have the following rights under GDPR:
Right to Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
Right to Data Portability
Receive your data in a structured, machine-readable format
Right to Object
Object to processing based on legitimate interests or for direct marketing
Right to Restrict Processing
Limit how we use your data under certain circumstances
Right to Withdraw Consent
Withdraw consent for processing based on consent at any time
Right to Complain
Lodge a complaint with your local data protection authority
How to Exercise Your Rights
To exercise any of these rights, please email us at:
We will respond to your request within 30 days as required by GDPR. We may request verification of your identity before processing your request.
8. Children's Privacy
KloudSec is not intended for use by children under the age of 18 (or 16 in some EU countries). We do not knowingly collect personal data from children.
If we discover that we have inadvertently collected data from a child, we will delete it immediately. If you believe we have collected data from a child, please contact us at hello@kloudsec.io.
9. Data Security
We implement industry-standard security measures to protect your personal data. For detailed information about our security practices, please see our Security Page.
Key Security Measures:
- •TLS 1.3 encryption for all data in transit
- •AES-256 encryption for data at rest
- •Regular security audits and monitoring
- •Access controls and authentication requirements
- •Comprehensive audit logging
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
How we notify you of changes:
- Post the updated Privacy Policy on this page with a new "Last Updated" date
- Send email notification for material changes
- Display a notice in your account dashboard
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
Contact Us About Privacy
If you have questions or concerns about this Privacy Policy or our data practices:
TOC Consulting
23 Rue de Berne, 75008 Paris, France
Privacy Contact:
EU Data Protection Authority:
If you are an EU resident and believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your local supervisory authority:
France: Commission Nationale de l'Informatique et des Libertés (CNIL) - www.cnil.fr
Last Updated: August 1, 2026
This Privacy Policy is effective immediately for new users and existing users alike.