10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Start free
All legal documents

Privacy Policy

Effective date: 2026-09-13

In plain language

  • We process metadata and permissions from sources your organization connects, through the read-only scopes you approved — never the contents of your files. We change nothing in those sources unless you turn on Auto-remediate. We do not sell data and we do not train AI models on it.
  • Account data is kept until you delete your account; findings and permission snapshots are kept 24 months by default (your org can configure this); operational logs are kept 90 days.
  • You can export or delete your data yourself from Settings — no support ticket needed.
  • Five subprocessors: Anthropic (AI assistant and summaries), Resend (email), PayPal (billing), RunPod (hosting), Cloudflare (network edge).
  • GDPR and CCPA rights apply; contact [email protected].

1. Who we are and what this covers

This policy explains how Enterprise.Systems ("we") processes personal data on 8200.dev. For account and website data we are the controller. For data inside sources your organization connects ("Customer Source Data"), your organization is the controller and we are its processor under the Data Processing Agreement — your organization’s own privacy notices govern that data.

2. Data we process

We process the following categories:

  • Account data — email address, name, password hash (scrypt; we never store the password itself), organization name, role, and locale; if you use them, your second-factor (TOTP) secret, stored encrypted, and a record of your sign-in sessions (time, IP address, and browser).
  • Customer Source Data — metadata and permission information from connected sources, obtained read-only via the OAuth scopes you approve: resource names and identifiers, sharing settings, permission grants, and the identities of principals holding access (people, service accounts, and AI agents). We do not read or store the contents of your files.
  • Findings — the security findings, explanations, and evidence the platform generates for your organization.
  • Usage and log data — IP address, user agent, timestamps, and an append-only audit trail of actions taken on the platform.
  • Cookies — a small set of first-party cookies for sign-in, security, and your preferences, plus — only if you agree — a partner-referral cookie; the full list is in section 15. We use no advertising, analytics, or cross-site tracking cookies.

3. How we use data

We use data to provide and secure the service: enumerating permissions, generating findings and plain-language explanations, carrying out the remediation actions you armed if you turned on Auto-remediate, authenticating you, sending transactional email, providing support, and meeting legal obligations. We do not sell personal data, we do not show ads, and we do not use Customer Source Data to train AI models.

4. Lawful bases (GDPR)

Where the GDPR applies, we rely on:

  • Performance of a contract (Art. 6(1)(b)) — operating your account and producing findings.
  • Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse, and improving detection quality.
  • Consent (Art. 6(1)(a)) — optional communications; withdrawable at any time.
  • Legal obligation (Art. 6(1)(c)) — accounting, tax, and lawful requests.

5. AI processing

We use large language models through the Anthropic API for three things: (a) the in-product support assistant, which receives the messages you type, exactly as you type them, and, when you are signed in, a short account summary made only of aggregate facts (your plan, how many sources are connected and whether they are healthy, your posture score and grade, how many findings are open and how many are critical, and your team size); (b) executive-summary narratives you ask for, which receive only aggregate figures: your posture score and grade, its trend over the period, finding counts by severity, your peer percentile, plan names, and your most common risk categories as generic category labels with a count (for example “Public link share (link-only): 3”); and (c) translating the interface into additional languages, which sends interface text only. None of these requests contains an identifier from your connected sources: no file, folder or drive names, no user or account names, no email addresses, no paths, no account IDs, and not your organization’s name. We never send file contents or credentials. Under Anthropic’s commercial terms, data submitted via the API is not used to train Anthropic’s models.

6. Subprocessors and sharing

We share personal data only with the subprocessors below, with professional advisers under confidentiality, or where the law requires:

  • Anthropic (USA) — the AI support assistant, executive-summary narratives, and interface translation.
  • Cloudflare (global) — CDN, TLS termination, and DDoS protection.
  • RunPod (USA/EU) — cloud infrastructure hosting the platform.
  • Resend (USA) — transactional email delivery.
  • PayPal (USA) — subscription billing and payment processing.

We update this list here; organizations with a DPA receive advance notice of additions per the DPA.

7. Retention

We keep data no longer than needed:

  • Account data — for the life of your account. Account deletion has a 7-day grace period, after which data is permanently purged.
  • Findings and permission snapshots — 24 months by default, or the period your organization configures.
  • Operational and audit logs — 90 days.
  • Deleting your account also deletes organizations you solely own, including their connectors (stored credentials are destroyed immediately), snapshots, and findings.

8. Your rights

Under the GDPR and similar laws you have the right of access, rectification, erasure, portability, restriction of processing, and objection, and the right not to be subject to solely automated decisions with legal effect (the platform makes none about you). Export and erasure are self-serve: Settings → Export my data / Delete my account. For anything else, write to [email protected] — we respond within 30 days. You may also lodge a complaint with your supervisory authority.

9. International transfers

We are based in Israel, which holds an EU adequacy decision; infrastructure runs in the regions listed under Subprocessors. Where personal data is transferred from the EEA/UK to countries without adequacy, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and equivalent UK safeguards, plus supplementary technical measures (encryption in transit and at rest).

10. California (CCPA/CPRA)

We do not sell or share personal information as defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. California residents have the rights to know, correct, delete, and not be discriminated against for exercising them — use the self-serve tools in Settings or [email protected].

11. Security

Data is encrypted in transit (TLS) and stored credentials are encrypted at rest (AES-256-GCM). Monitoring access to your sources is read-only and least-privilege; write access exists only if you turn on Auto-remediate and grant it separately, and you can revoke it at any time. Passwords are stored only as salted scrypt hashes. Every platform action is written to an append-only audit log. We notify affected organizations of personal-data breaches without undue delay, consistent with GDPR Articles 33–34.

12. Children

The platform is a B2B service and not directed at children. We do not knowingly process data of anyone under 16 as an account holder.

13. Changes to this policy

We post changes here and update the effective date at the top of this page; a change takes effect on that date.

14. Google API Services

8200.dev's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

We do not use any raw or derived Google Workspace user data to develop, improve, or train generalized artificial-intelligence or machine-learning models, and we do not transfer such data to third-party AI or ML tools or services for training purposes. Large-language-model analysis on the platform (via the Anthropic API) is inference-only, and under Anthropic’s commercial terms data submitted through the API is never used to train Anthropic’s models.

15. Cookies

We set only the first-party cookies below. None is used for advertising, analytics, or tracking you across other sites. All of them are strictly necessary or remember a choice you made — except es8200_ref, which is set only with your consent.

  • authjs.session-token — keeps you signed in; ends when you sign out or after 30 days without use.
  • authjs.csrf-token and authjs.callback-url — protect the sign-in form and return you to the page you came from; they last for the browser session.
  • authjs.pkce.code_verifier, authjs.state, and authjs.nonce — protect a Google sign-in until it completes; 15 minutes.
  • mfa_trust — remembers a device you chose to trust after a second-factor check; 30 days; set only if you choose it.
  • active_org — remembers which of your organizations you are viewing; 1 year.
  • NEXT_LOCALE — remembers your language; 1 year.
  • es8200_plan — remembers the plan you picked on the pricing page so that sign-up can take you to checkout; 24 hours.
  • es8200_ref — category “Partner referral”, optional: set only if you accept it in the banner shown when you arrive through a partner’s link. It records the referral code so the partner gets their commission if you subscribe; 90 days.

In production the sign-in cookies carry the __Secure- prefix and are HttpOnly and Secure. Your light or dark theme choice is kept in your browser’s local storage, not in a cookie, and is never sent to us. You can delete cookies in your browser at any time; without the sign-in cookies you cannot stay signed in.

16. Contact and data protection officer

For product support and general enquiries, contact [email protected]. Privacy and data-protection contact (including for the DPO function): [email protected].