Privacy policy¶
Last updated: 2026-05-03
TODO: review by counsel before sending to any customer or publishing publicly. This policy describes Secruna's handling of personal data. It must be reviewed by a CEE- qualified privacy lawyer (Polish + at least one further CEE jurisdiction) before publication.
1. Who we are¶
Secruna sp. z o.o. (controller entity name pending — TODO
confirm with founder) is a Polish-incorporated SaaS provider
of EU AI Act compliance tooling. Secruna operates the service
available at app.secruna.com and the API at api.secruna.com.
Contact: TODO legal@secruna.com (alias to be configured).
2. Scope¶
This policy applies to:
- Visitors to our marketing site (
secruna.com). - Users of the Secruna platform (
app.secruna.com,api.secruna.com) operating under their employer's tenant. - Recipients of transactional emails from us.
It does not apply to AI systems we discover within a customer's environment via a connector — those are governed by the customer's own privacy notices to its employees and end-users, supplemented by the Data Processing Agreement.
3. Personal data we process and why¶
3.1 As controller (about visitors and prospects)¶
| Data | Source | Purpose | Legal basis |
|---|---|---|---|
| Email address | You give it to us via contact form, email, or sign-up | Reply to your enquiry; account creation | Performance of contract / pre-contract steps (Art 6(1)(b)) |
| Name, job title, company | You give it to us | Sales context, account creation | Pre-contract steps |
Cookie data on secruna.com |
Browser | Strict-necessary only by default; analytics cookies require consent banner (consent banner deployment is in P0 of our roadmap; until then we do not set non-essential cookies) | Consent (Art 6(1)(a)) when applicable |
3.2 As processor (about our customers' users)¶
When your employer onboards your team to Secruna, we process the following on behalf of that employer (the controller):
- Microsoft Entra ID identifier, email, and display name (for authentication).
- IP address and user-agent (for rate limiting and audit).
- Audit-log entries for actions you perform inside the platform.
The full list, retention windows, and security controls are documented in the DPA template. Your employer is the data controller for these activities; please contact your employer's data protection officer for rights requests.
3.3 As processor (about systems we discover)¶
The connectors documented under connectors/
read management-plane metadata about your employer's AI systems.
The categories of data and the legal basis are governed by the
DPA between Secruna and your employer, not by this policy.
4. Cookies¶
secruna.com and app.secruna.com use the following cookies:
| Cookie | Purpose | Type | Lifetime |
|---|---|---|---|
rekognise_session |
Authenticates a logged-in user | Strictly necessary | 24h sliding |
| (CSRF tokens — Next.js framework cookies) | Security | Strictly necessary | Session |
We do not currently use analytics or marketing cookies on the
authenticated platform. The marketing site secruna.com will
deploy a consent banner before any analytics tracking is added
(this is a tracked roadmap item, not a future ambition).
5. Sharing and subprocessors¶
5.1 Subprocessors¶
We use the third parties listed at subprocessors.md to operate the service. Each is bound by contract to use personal data only for the agreed purpose and to apply security measures equivalent to ours.
5.2 Disclosure to law enforcement¶
We disclose personal data in response to legal process only when:
- We are compelled by a court order or other binding legal instrument from a competent authority;
- The order has been reviewed for legality by counsel;
- Where lawful and not prohibited by the issuing authority, we notify the affected controller in advance.
We publish an annual transparency report counting such requests (planned, P2).
5.3 Sale of data¶
We do not sell personal data. We do not engage in cross-context behavioural advertising.
6. International transfers¶
The service is hosted in the EU (Azure Sweden Central). Personal data is transferred outside the EEA only to the subprocessors listed under subprocessors.md, under the Standard Contractual Clauses (EU 2021/914) with appropriate supplementary measures. Copies are available on request.
7. Retention¶
Retention periods are documented in data-retention.md. Summary:
- Authentication and account data — lifetime of the tenant + 30 days grace.
- Audit log entries — 7 years (matches AI Act Article 12 + GDPR Article 30).
- System artefacts — 90 days post-disconnect of source connector.
- Marketing leads (visitor to prospect) — until you ask us to delete, or 24 months of inactivity, whichever comes first.
8. Your rights¶
You have the right to:
- Access (Art 15) the personal data we hold about you.
- Rectify (Art 16) inaccurate data.
- Erase (Art 17) data we no longer need to retain.
- Restrict (Art 18) processing in defined circumstances.
- Receive a portable copy (Art 20) of structured data you have given us.
- Object (Art 21) to processing based on legitimate interest (Secruna does not currently rely on this basis).
- Not be subject (Art 22) to a decision based solely on automated processing producing legal or similarly significant effects on you.
- Withdraw consent (Art 7) at any time where processing is based on consent.
- Lodge a complaint with the Polish data protection authority (Urząd Ochrony Danych Osobowych — UODO) or with the supervisory authority of your habitual residence.
To exercise any of these rights, email legal@secruna.com (TODO:
configure alias) with proof of identity.
We respond to verifiable requests within 30 calendar days.
When you exercise a right concerning processing performed by Secruna as a processor on behalf of your employer, we forward your request to your employer per Article 28(3)(e) GDPR — they are the controller and must respond.
9. Security¶
A summary of our technical and organisational measures appears in §6 of the DPA template. In short:
- TLS 1.2+ everywhere; encryption at rest with AES-256.
- Secrets in Azure Key Vault.
- Microsoft Entra ID OIDC for authentication, RLS for tenant isolation, 2-eyes for impersonation.
- Single-region (Sweden Central) with documented manual DR (RTO ≈ 6h).
- 7-year audit log, 30-day app-log retention.
We have not yet completed SOC 2 or ISO 27001 audits; we disclose this honestly and intend to attest to SOC 2 Type 1 during the post-MVP period (see public roadmap).
10. Children¶
We do not knowingly process personal data of individuals under the age of 16. The service is targeted at enterprise compliance teams.
11. Changes to this policy¶
When we materially change this policy, we will:
- Update the Last updated date.
- Email account-owner contacts at every active tenant.
- Post a banner notice in
app.secruna.comfor 30 days.
Trivial corrections (typos, link fixes) ship without notice.
12. Contact¶
- Privacy questions / rights requests: TODO
legal@secruna.com - Security disclosures: TODO
security@secruna.com - General support: TODO
support@secruna.com
Postal address: TODO insert registered Polish entity address when finalised.
TODO: review by counsel before sending to any customer or publishing publicly.