Privacy Policy
Last updated: [PUBLICATION DATE]
This policy explains what Agent-C Security, LLC (“Agent-C,” “we,” “us”) does with information collected through agentcsecurity.com (the “Site”).
We sell security assessments. It would be a poor look to be careless with your data, so we collect as little as we can get away with and we’re specific about what happens to it.
1. The short version
- We collect your email, and — if you request a Checkup — your name and what you tell us about your app.
- We use it to reply to you and, if you asked for it, to send you occasional updates. You can stop that at any time.
- We do not sell or share your information for advertising, and we never will.
- Our analytics are cookieless and aggregate. We can’t identify you from them.
- Your source code is not covered by this policy — see §3, it matters.
2. What we collect
Information you give us:
| Where | What |
|---|---|
| Checkup request / booking form | Your name, email address, information about your application or repository, which tier you’re interested in, and anything else you type into the message field |
| Sample report request | Your email address |
| Platform waitlist | Your email address |
| Email to us | Whatever the message contains, plus your address and any signature block |
Information collected automatically:
- Server logs. Our host records the standard request data every web server sees: IP address, user-agent string, the page requested, referring page, and timestamp. This is used for delivery, security, and abuse prevention, and is retained on a short rolling window by the host.
- Aggregate analytics. Described in §5.
We do not collect: account credentials (there are no accounts), payment card details (no payments happen on the Site), precise geolocation, biometric data, or any special-category / sensitive personal data. We don’t ask for any of it, so please don’t send it.
3. Your source code is not covered by this policy
This is worth stating plainly, because it is the thing our prospective clients most want to know.
This policy covers website visitors. It does not cover the material you provide during an actual engagement — your repository, credentials, architecture, findings, or any report we produce about your system.
That material is governed by the written services agreement and confidentiality terms for that engagement, which are considerably stricter than this page. Access is granted per-engagement, scoped, time-limited, and revoked on completion.
Do not send code, credentials, secrets, or security findings through the Site’s forms or by ordinary email. Those aren’t secure channels. Tell us what you need, and we’ll set up an appropriate one.
4. Why we use it, and on what basis
| Purpose | Basis (UK/EU GDPR terms) |
|---|---|
| Reply to your enquiry, scope and quote work | Steps taken at your request prior to a contract |
| Send the sample report you asked for | Consent |
| Send occasional product updates / waitlist news | Consent — withdrawable at any time |
| Keep the Site available, secure, and free of abuse | Legitimate interests |
| Understand aggregate traffic to improve the Site | Legitimate interests (no personal data involved — see §5) |
| Meet legal, tax, and accounting obligations | Legal obligation |
We do not use your information for automated decision-making or profiling that produces legal or similarly significant effects.
5. Cookies and analytics
The Site sets no cookies of its own, and stores nothing on your device for tracking purposes. There is no advertising pixel, no social widget, no session recording, no heatmap, and no cross-site tracker anywhere on this Site. There is no cookie banner because there is nothing to consent to.
We do measure aggregate traffic — which pages get read and roughly where visitors come from — because we can’t improve the Site blind.
Our analytics is Netlify Analytics, provided by our host, Netlify, Inc. It is server-side and cookieless: it runs no script on your device and stores no cookie or other identifier, does not fingerprint you, does not build a profile, and does not track you across other websites. It is derived from the standard server logs described in §2 and produces counts and trends, not records about individuals. We cannot identify you from it.
Global Privacy Control / Do Not Track. Because we run no cross-site tracking and sell no data, there is nothing for these signals to switch off. We honor them by design rather than by setting.
6. Who else touches your information
We use a small number of service providers. They process data on our instructions and are not permitted to use it for their own purposes:
| Provider | What they do | What they see |
|---|---|---|
| Netlify, Inc. | Hosts and serves the Site | Standard server-log data for every request |
| [FORM / EMAIL PROVIDER] | Delivers form submissions and any email list | What you submit through a form; your email address |
| Netlify Analytics (Netlify, Inc.) | Aggregate traffic measurement, derived from server logs | Aggregate, non-identifying traffic data |
We will also disclose information if we’re legally required to — a valid subpoena, court order, or lawful government request — or where necessary to establish or defend legal claims, or to protect the rights and safety of others. If we ever receive a legal demand for your information, we will notify you unless we are legally prohibited from doing so.
If Agent-C is ever acquired or merged, your information may transfer as part of that transaction. You’d be told before it became subject to a materially different policy.
7. What we don’t do
- We do not sell your personal information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under California law. We have never done so and have no plans to.
- We do not rent, trade, or otherwise make your information available to data brokers, advertisers, or list vendors.
- We do not use your enquiry to build a marketing list without your consent. Asking about a Checkup does not subscribe you to anything.
8. How long we keep it
| Data | Retention |
|---|---|
| Enquiries that don’t become engagements | Up to 24 months, then deleted |
| Enquiries that become engagements | For the engagement, plus the period required by our tax and legal obligations (generally 7 years) |
| Sample-report and waitlist email addresses | Until you unsubscribe or ask us to delete, plus a suppression record so we don’t re-add you |
| Server logs | Short rolling window set by our host |
| Aggregate analytics | Retained as non-identifying aggregates |
9. How we protect it
We keep the number of places your data lives small, use reputable providers, enforce multi-factor authentication on the accounts that hold it, serve the Site over HTTPS, and limit access to those who need it — currently a very short list.
No system is perfectly secure, and we won’t claim ours is. That’s the same honesty we bring to assessments. If a breach affects your personal information, we will notify you and any required regulator without undue delay.
10. Your rights
Wherever you live, you can ask us to:
- Tell you what we hold about you
- Correct anything inaccurate
- Delete it
- Give you a copy in a portable format
- Stop using it for a particular purpose, or object to our legitimate-interests processing
- Unsubscribe from anything we send — every email has a one-click link, and it works
Email privacy@agentcsecurity.com. We’ll respond within 30 days. We won’t charge you, and we won’t treat you differently for asking.
If you’re in California: you have the rights above under the CCPA/CPRA, including the right to know, delete, correct, and opt out of sale or sharing. Since we don’t sell or share, there’s no opt-out to exercise, but the right stands. You may use an authorized agent. We will not discriminate against you for exercising any of these rights.
If you’re in the UK, EU, or EEA: you have the rights above under the UK/EU GDPR, plus the right to withdraw consent at any time and the right to lodge a complaint with your supervisory authority. We are established in the United States, so your data is processed in the US. Where we transfer personal data out of the UK/EEA, we rely on the UK/EU Standard Contractual Clauses with our providers.
11. Children
The Site is for business users and is not directed to anyone under 16. We don’t knowingly collect information from children. If you believe a child has given us information, email privacy@agentcsecurity.com and we’ll delete it.
12. Changes to this policy
If we change this policy we’ll update the “Last updated” date above. If a change is material — a new category of data, a new purpose, a new class of recipient — we’ll say so prominently on the Site, and where the law requires consent, we’ll ask for it rather than assume it.
13. Contact
Agent-C Security, LLC
Nashville, Tennessee
Privacy: privacy@agentcsecurity.com
Security reports: security@agentcsecurity.com
The data controller for the purposes of the UK/EU GDPR is Agent-C Security, LLC.