10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Start free
All legal documents

Privacy Policy

Effective date: 2026-06-12

In plain language

  • We process metadata and permissions from sources your organization connects — read-only, scoped to what you approved. We do not sell data and we do not train AI models on it.
  • Account data is kept until you delete your account; findings and permission snapshots are kept 24 months by default (your org can configure this); operational logs are kept 90 days.
  • You can export or delete your data yourself from Settings — no support ticket needed.
  • Five subprocessors: Anthropic (AI analysis), Cloudflare (CDN), RunPod (hosting), Resend (email, once active), PayPal (billing).
  • GDPR and CCPA rights apply; contact [email protected].

1. Who we are and what this covers

This policy explains how Enterprise.Systems ("we") processes personal data on 8200.dev. For account and website data we are the controller. For data inside sources your organization connects ("Customer Source Data"), your organization is the controller and we are its processor under the Data Processing Agreement — your organization’s own privacy notices govern that data.

2. Data we process

We process the following categories:

  • Account data — email address, name, password hash, organization name, role, and locale.
  • Customer Source Data — metadata and permission information from connected sources, obtained read-only via the OAuth scopes you approve: resource names and identifiers, sharing settings, permission grants, and the identities of principals holding access (people, service accounts, and AI agents). We do not read or store the contents of your files.
  • Findings — the security findings, explanations, and evidence the platform generates for your organization.
  • Usage and log data — IP address, user agent, timestamps, and an append-only audit trail of actions taken on the platform.
  • Cookies — session cookies required for sign-in. We use no advertising or cross-site tracking cookies.

3. How we use data

We use data to provide and secure the service: enumerating permissions, generating findings and plain-language explanations, authenticating you, sending transactional email (when email delivery is active), providing support, and meeting legal obligations. We do not sell personal data, we do not show ads, and we do not use Customer Source Data to train AI models.

4. Lawful bases (GDPR)

Where the GDPR applies, we rely on:

  • Performance of a contract (Art. 6(1)(b)) — operating your account and producing findings.
  • Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse, and improving detection quality.
  • Consent (Art. 6(1)(a)) — optional communications; withdrawable at any time.
  • Legal obligation (Art. 6(1)(c)) — accounting, tax, and lawful requests.

5. AI processing

Some analysis is performed with large language models via the Anthropic API. We send only the metadata needed for the specific analysis. Under Anthropic’s commercial terms, data submitted via the API is not used to train Anthropic’s models.

6. Subprocessors and sharing

We share personal data only with the subprocessors below, with professional advisers under confidentiality, or where the law requires:

  • Anthropic (USA) — AI analysis of metadata.
  • Cloudflare (global) — CDN, TLS termination, and DDoS protection.
  • RunPod (USA/EU) — cloud infrastructure hosting the platform.
  • Resend (USA) — transactional email delivery, once email features are active.
  • PayPal (USA) — subscription billing and payment processing.

We update this list here; organizations with a DPA receive advance notice of additions per the DPA.

7. Retention

We keep data no longer than needed:

  • Account data — for the life of your account. Account deletion has a 7-day grace period, after which data is permanently purged.
  • Findings and permission snapshots — 24 months by default, or the period your organization configures.
  • Operational and audit logs — 90 days.
  • Deleting your account also deletes organizations you solely own, including their connectors (stored credentials are destroyed immediately), snapshots, and findings.

8. Your rights

Under the GDPR and similar laws you have the right of access, rectification, erasure, portability, restriction of processing, and objection, and the right not to be subject to solely automated decisions with legal effect (the platform makes none about you). Export and erasure are self-serve: Settings → Export my data / Delete my account. For anything else, write to [email protected] — we respond within 30 days. You may also lodge a complaint with your supervisory authority.

9. International transfers

We are based in Israel, which holds an EU adequacy decision; infrastructure runs in the regions listed under Subprocessors. Where personal data is transferred from the EEA/UK to countries without adequacy, we rely on the European Commission’s Standard Contractual Clauses (SCCs) and equivalent UK safeguards, plus supplementary technical measures (encryption in transit and at rest).

10. California (CCPA/CPRA)

We do not sell or share personal information as defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. California residents have the rights to know, correct, delete, and not be discriminated against for exercising them — use the self-serve tools in Settings or [email protected].

11. Security

Data is encrypted in transit (TLS) and stored credentials are encrypted at rest (AES-256-GCM). Source access is read-only and least-privilege. Every platform action is written to an append-only audit log. We notify affected organizations of personal-data breaches without undue delay, consistent with GDPR Articles 33–34.

12. Children

The platform is a B2B service and not directed at children. We do not knowingly process data of anyone under 16 as an account holder.

13. Changes to this policy

We will post changes here and update the effective date; material changes are notified to account owners in advance.

14. Google API Services

8200.dev's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

15. Contact and data protection officer

For product support and general enquiries, contact [email protected]. Privacy and data-protection contact (including for the DPO function): [email protected].