Legal
Privacy policy
Revised September 14, 2026.
This Privacy Policy explains how Rapticore Inc. (Rapticore, we, or us) collects, uses, discloses, and protects personal data in connection with our websites, products, and business relationships. It also explains how customer security data is handled, including when AI models are used locally or remotely, and how to contact us about privacy.
Customer Data is used to provide the Services and may be anonymized to improve them. Rapticore does not use Customer Data, prompts, Outputs, or their derivatives, including anonymized derivatives, for Model Training unless a separate agreement expressly authorizes that use. Customer-controlled AI providers may operate under the customer's separate agreement, as explained in Section 6.
1 Scope and our role
1.1 Covered Services. This Policy applies to Rapticore's websites and products made subject to it, including self-service subscriptions, SaaS, customer-hosted software, on-premises and private-cloud deployments, and hybrid configurations. Capabilities may include application and code security; adversarial intelligence, attack surface monitoring, and authorized red teaming; agentic penetration testing and dynamic application security testing; and cloud posture, guardrails, remediation, security operations, and incident-response assistance. Coverage also includes applicable APIs, agents, developer tools, integrations, AI Features, and support. Product names may change. The applicable Order identifies purchased products, editions, entitlements, and deployment options.
1.2 Rapticore's own business data. We determine the purposes and means of processing personal data for activities such as website administration, business inquiries, account administration, billing, and marketing communications. For those activities, we act as a controller or business where those legal terms apply.
1.3 Customer-controlled service data. When an organization uses our Services to process code, logs, inventories, findings, prompts, and other Customer Data on its behalf, it generally determines the purpose and instructions, and we act as processor, service provider, or subprocessor where applicable. The customer's agreement, data processing agreement (DPA), and any business associate agreement (BAA) govern that processing. If your data appears in an organization's security environment, contact that organization first to exercise rights; we will assist it as required and explain our role if you contact us directly. This includes data about the customer's personnel, clients, users, and other affected individuals.
1.4 Contract and notice. This Policy describes our privacy practices and does not form a separate contract or create contractual warranties or remedies beyond those expressly agreed in a signed customer agreement. Statutory privacy, consumer-protection, and other legal rights and duties remain applicable. This notice does not enlarge Rapticore's rights to Customer Data under the Terms of Service, a signed customer agreement, DPA, or BAA. A legally required specific notice may supplement it. Reading this Policy, visiting a website, or ordinary use is not consent to Model Training or optional processing requiring separate consent. A signed agreement may impose additional restrictions or separately authorize processing described here, subject to applicable law and the express training-authorization requirements in Section 6.4.
1.5 Other relationships. Third-party websites and services independently selected by you have their own privacy notices. Employment, applicant, or other special-purpose processing may be governed by a separate notice provided for that relationship; ordinary business correspondence remains covered here where a separate notice does not apply.
1.6 Distributors and resellers. An authorized distributor or reseller identified in your Order or checkout may arrange your purchase, invoice and collect payment, manage the commercial relationship, or provide separately contracted services. It may act independently for information it collects directly through its own customer interactions and for its lawful transaction records; its privacy notice applies to those activities. Section 7.7 explains Rapticore's disclosures to and receipt of information from such partners. When a partner processes information on our or a customer's behalf, the applicable processing role and requirements govern. A commercial relationship does not itself grant access to security findings, source code, prompts, credentials, or other service content.
2 Key terms
Personal data means information that identifies, relates to, describes, or can reasonably be linked to an individual or household, as defined by applicable law. Identifiers, work contact details, IP addresses, and online activity can be personal data. Sensitive personal data means data subject to additional protection under applicable law, which can include account credentials, health information, precise location, government identifiers, or certain private communications.
Customer Data means information supplied, accessed, collected, or generated on a customer's behalf through the Services, including source code, repositories, prompts, files, logs, configurations, asset inventories, credentials, security evidence, support content, and customer-specific findings and Outputs. Customer Data may include personal data even when the purpose of processing is technical or security-related.
Outputs means customer-specific reports, findings, recommendations, generated code, proposed changes, and other results. Model Training means training, pretraining, fine-tuning, retraining, distillation, or otherwise updating a model's learned parameters, weights, or adapters, including through reinforcement learning. Inference means using an existing model to produce a result without those updates.
Anonymized Service Data means data derived from Customer Data or operational telemetry that has been processed so it cannot reasonably identify or be linked to an individual or household, or be used to infer information about a particular individual, and meets applicable anonymization or deidentification requirements. Customer identifiers and customer-specific confidential content must also be removed, generalized, or aggregated so the retained information does not reasonably identify the customer or expose its confidential code, credentials, nonpublic vulnerabilities, or identifiable system details. General technical patterns and aggregate service statistics may qualify. Pseudonymization, hashing, tokenization, or partial redaction alone is not sufficient.
3 What we collect and where it comes from
Collection depends on the relationship, purchased features, selected deployment, connected accounts, and data you or your organization provide. We limit processing to information reasonably necessary for the stated purpose. The categories below describe collection and ordinary operational recipients; exceptional disclosures such as legal process or a corporate transaction are explained in Section 7.
| Category | Examples and sources | Ordinary recipient categories |
|---|---|---|
| Identifiers and business contacts | Name, work email, business address, phone, organization, job role, account ID; from you, your employer, account administrators, referrals, events, or lawful business sources | Hosting and communications providers; customer relationship and support providers; your authorized organization administrators; relevant distributors or resellers under Section 7.7 |
| Account and authentication information | Login identifiers, password-verification information, SSO attributes, access roles, authentication events; from registration, identity providers, and account activity | Identity, hosting, security, and support providers where needed; authorized administrators |
| Commercial and billing information | Selected products, subscription and renewal records, invoices, transaction references, billing address, limited payment-method details; from checkout, orders, payment processors, authorized resellers, and account activity | Payment processors, billing and accounting providers, professional advisors; relevant distributors or resellers under Section 7.7 |
| Device and online activity | IP address, browser and operating-system information, device identifiers, pages and features used, timestamps, errors, referring pages, approximate location inferred from IP; from browsers, service logs, cookies, and similar technologies | Hosting, security, and analytics providers, subject to applicable choices and restrictions |
| Communications and support | Inquiries, email correspondence, support tickets, attachments, feedback, diagnostic files; from you and your organization | Communications and support providers; authorized support personnel; customer-authorized partner support under Section 7.7; AI providers only where the disclosed support functionality uses them |
| Customer security content | Source code, repository metadata, application and API data, cloud resource configuration, logs, asset relationships, evidence, reports, remediation changes; from the customer, authorized integrations, agents, and assessments | Hosting and support subprocessors; approved AI providers where enabled; customer-selected integrations and authorized users |
| AI inputs and results | Prompts, selected context, tool results, Outputs, retrieval indexes and embeddings, associated usage and diagnostic records; from enabled AI Features and customer instructions | Approved inference, hosting, and support providers, subject to Section 6; authorized customer users and integrations |
| Sensitive data within authorized workflows | Credentials, access tokens, private communications, or regulated information present in authorized content; from customers and their connected systems | Only authorized providers and recipients necessary for the permitted purpose, subject to the agreement and any required DPA or BAA |
| Security observations and inferences | Vulnerability findings, exposure relationships, suspicious-activity indicators, account-abuse signals, and technical risk scores; derived from authorized assessments, service security operations, and lawfully obtained intelligence | Relevant customer and its authorized recipients; necessary security, hosting, and approved AI providers |
3.1 Third-party and public sources. Business-contact and security information may come from organization administrators, partners, integrations, public internet resources, domain and certificate records, public repositories, and lawfully licensed intelligence sources. Publicly accessible information may still be personal data. We use such information for relevant business communications, authorized security services, and service protection within applicable law; availability does not itself authorize every use. Independently obtained intelligence is not automatically customer-provided data, but customer-specific links and findings remain protected as Customer Data.
3.2 Permissions and sensitive content. A connector's technical permissions may allow access to more information than a particular task needs. The permissions requested and enabled function determine what can be accessed; customers should configure the narrowest appropriate scope. We use credentials to perform authorized access and protect them as sensitive information. We do not need a device's precise location for ordinary website use; if a feature requests precise location or other additional sensitive data, we will provide a specific explanation and obtain required permission. Sensitive information can nevertheless appear in customer-supplied files and logs.
3.3 Payment and support boundaries. Payment providers process payment information in the payment flow; Rapticore ordinarily receives limited billing details, transaction references, and payment status rather than full card credentials. Do not send payment-card security codes or unrelated sensitive information through support or prompts. Customer security content submitted for support stays Customer Data and is not reclassified as unrestricted business-contact information.
3.4 Providing data. You may decline information that is optional, but we may be unable to supply requested functionality without necessary account, payment, connection, or security data. An organization's administrators may have access to your work account, usage, and service content according to their permissions. Your organization's policies also apply to its administration of those records.
4 How we use personal data
4.1 Delivering requested Services. We use necessary data to create and administer accounts, authenticate users, fulfill Orders, calculate authorized usage, process payments, provide support, and perform enabled security analysis, assessments, reporting, and authorized remediation. AI processing used for those purposes is subject to Section 6.
4.2 Security and reliability. We use necessary information to detect misuse, secure accounts and infrastructure, investigate incidents, troubleshoot errors, maintain availability, and enforce authorized scope. Customer-specific content used to support or secure a customer's service remains subject to that customer's processing agreement. Reuse for general product improvement remains subject to Section 5.
4.3 Communications. We send transactional messages about accounts, purchases, renewal, security, product changes, and support. We also use business-contact details to respond to requests, organize demonstrations, and send relevant marketing where permitted. Marketing choices are described in Section 12. Declining marketing does not stop messages necessary to administer an active subscription or respond to a security issue. We do not use confidential security findings, source code, or prompts to target advertising.
4.4 Improvement. We may analyze account-level feature usage, website analytics, and operational data to improve usability and reliability, subject to applicable notices, choices, and contractual restrictions. Customer content used for improvement across customers must first qualify as Anonymized Service Data under Section 5. Identifiable website and account data used for ordinary business analytics remains personal data; it is not described as anonymous merely because it is technical. These activities do not authorize Model Training on Customer Data.
4.5 Legal and business administration. We process necessary records to satisfy legal duties, respond to lawful requests, manage contracts and disputes, maintain tax and accounting records, protect legal rights, and evaluate or complete a corporate transaction subject to confidentiality and legal restrictions.
4.6 Limits on new uses. We do not use personal data for a materially different or incompatible purpose without providing required notice and establishing the necessary legal basis or obtaining required consent. An organization's agreement does not replace an individual's consent where the law requires it.
5 Anonymized service improvement
Subject to the customer agreement, applicable law, and any DPA or BAA, we may create and use Anonymized Service Data for service reliability, capacity planning, quality testing, non-training evaluation of AI Features, user-experience improvements, and improvements to detection rules and workflows without Model Training. We may combine qualifying anonymized data from different customers and retain it after the customer relationship ends for those purposes.
We apply reasonable technical and organizational measures designed to prevent identification or reconstruction, consider reasonably available means of linkage, and maintain and use the information in anonymized form. We do not attempt reidentification except for controlled testing solely to validate deidentification where applicable law permits. Recipients are contractually required to follow equivalent restrictions. Aggregation, suppression of small groups, generalization, or other measures are selected according to the data and linkage risk; a numerical threshold alone is not sufficient. Customer-specific domains, IP addresses, code, credentials, uncommon event details, and findings must be removed or transformed as necessary to meet the definition; removing personal names alone is insufficient.
We may publish aggregate service statistics only if they do not identify a customer or reveal confidential information. We may commercialize product improvements and generalized detection rules developed through permitted use of Anonymized Service Data, subject to the customer agreement. This does not authorize selling derived datasets, disclosing Customer Data, or Model Training. If information cannot meet the anonymization standard, it remains subject to the restrictions on Customer Data and personal data. Anonymizing personal data is itself processing that requires the applicable lawful basis and contractual authority.
Anonymization does not create an exception to our no-training commitment. Data derived from Customer Data, including Anonymized Service Data, cannot be used for Model Training unless the separate express agreement described in Section 6.4 authorizes it.
6 AI models and deployment choices
6.1 Local and remote models. AI Features may use local models, remote models, Rapticore-managed providers, customer-connected provider accounts, or more than one model in a workflow. Enabled features can process prompts, selected source code, logs, evidence, tool results, and related context. Remote inference may send that data to the configured provider; it is not necessarily anonymized before inference. Outputs and related processing records can contain personal data and Customer Data.
6.2 SaaS and customer-hosted deployments. In hosted Services, Rapticore and its authorized providers process data needed to operate the purchased functionality. With customer-hosted software, local content may remain in customer-controlled systems, but enabled remote AI, management, telemetry, updates, integrations, license validation, and support can involve outbound connections. On-premises installation or use of a local model does not alone mean that the entire deployment is offline or that no data leaves it. We do not receive data that is not transmitted to us or made accessible through authorized functionality. A disconnected installation does not create permission for us to extract its contents.
We disclose required connections and data categories through deployment information and distinguish mandatory operational or licensing information from optional improvement telemetry. Remote support access requires customer authorization. We maintain routing and access controls designed to enforce supported customer configuration and express egress, regional, and local-only commitments in components we control. Customers manage controls in their own components. An agreed local-only route does not permit remote fallback; we may pause or disable the feature when no permitted route is available. A route outside an express restriction requires the applicable customer authorization or contractual amendment.
6.3 Rapticore-managed AI providers. Before routing Customer Data, we make available the relevant provider or processing arrangement, categories sent, material retention or human-review conditions, and available regional restrictions through the Order, Documentation, provider information, or configuration flow. Providers engaged by Rapticore to process Customer Data on its behalf are subject to applicable subprocessor arrangements, including confidentiality, permitted-purpose, security, and no-training restrictions. Provider changes must preserve agreed protections and follow applicable notice and objection procedures.
For managed routes, we select and configure providers under binding written terms that restrict Model Training on Customer Data, prompts, and Outputs, consistent with Section 6.4. These may be applicable accepted provider terms rather than individually negotiated agreements. A managed route without the required restrictions is not enabled absent the separate authorization described in Section 6.4. A no-training restriction is different from a zero-retention promise: a provider may retain limited data for disclosed, permitted security or abuse monitoring consistent with the applicable agreement. Where authorized human review is part of processing or support, access must be limited and protected. We do not promise universal zero retention, a particular model vendor, or no human access unless expressly agreed.
6.4 No Model Training without separate authorization. Rapticore does not use Customer Data, prompts, Outputs, customer-related account, usage, or support data, or derivatives of any of them, including anonymized derivatives, for Model Training of Rapticore or third-party models unless a separate written agreement expressly permits it. The agreement must be signed or separately affirmatively accepted by an authorized customer representative and identify the data, permitted training purposes, model or provider scope, retention, and any withdrawal terms or limits. A negotiated Order may provide that authorization only if it specifically overrides the Terms' no-training provision. General service-improvement language, policy updates, ordinary use, feedback submission, and preselected settings are insufficient. Additional legally required permissions must also be obtained.
If a separate authorized training arrangement applies, the specific agreement and any legally required notice explain it. We do not claim that deleting an account can remove information already incorporated into model weights; any authorized arrangement must address those practical limits before training occurs. Without that arrangement, the prohibition applies. It includes customer-related operational telemetry, redacted support content, free or trial usage, and synthetic derivatives of Customer Data. It does not prohibit training on independently developed Rapticore laboratory data, independently obtained public or licensed information for which training rights and a lawful basis exist, or synthetic data created without the prohibited data as a source. A voluntary training program requires the separate express agreement and any additional legally required permissions.
6.5 Inference and retrieval are still processing. Inference, temporary context handling, customer-specific embeddings, retrieval indexes, and evaluation without parameter updates may support enabled Services. These are not permission to train models or build a shared customer-content knowledge base. Customer-specific stores, caches, prompts, logs, and results remain subject to applicable permitted-purpose, security, retention, and deletion requirements. We maintain logical separation and access controls designed to prevent one customer's content from being disclosed through another customer's prompts, retrieval indexes, memory, or results. Calling a use evaluation, synthetic-data generation, feedback, or improvement does not avoid the Model Training restriction.
6.6 Customer-connected models and accounts. If a customer independently provides a model, endpoint, API key, or provider account, that customer manages its provider agreement, retention and training settings, permissions, location, and provider charges. Its provider may apply different data practices under that separate agreement. Rapticore cannot guarantee those independent terms, but remains responsible for its own handling and routing and does not enable provider training or use that connection to train models on Customer Data without the required separate authorization. Supplying an API key does not alone determine the legal processing roles. Customers should include these providers in their own privacy notices and required agreements.
6.7 AI results and decisions. Security findings and generated content can be incomplete or incorrect and may involve automated analysis of technical or account activity. These features are designed to assist security work and authorized technical actions. They are not offered as a basis for determining an individual's employment, credit, insurance, housing, or similar eligibility. If we undertake legally regulated automated decision-making about individuals in our own capacity, we will provide the disclosures and rights required for that processing. Customers remain responsible for lawful decisions they make using the Services, including notices and human review where required.
7 When we disclose data
7.1 Service providers. We disclose necessary information to providers of hosting, infrastructure, security, authentication, communications, support, billing, analytics, and approved AI processing. They are bound to appropriate restrictions for their role. Rapticore-managed subprocessors receive Customer Data only for the contracted purpose; independent payment or other providers may have their own legal obligations and notices for their independent activities. Information about relevant provider categories, processing arrangements, and available safeguards may be requested at privacy@rapticore.com. Customer-specific subprocessor information and change notices are provided as required by the applicable agreement and law; confidential provider contracts or sensitive security details may be withheld or appropriately redacted where permitted. Any contractual right to notice of new subprocessors remains in effect.
7.2 Your organization and selected recipients. We disclose data to authorized administrators and users, and to integrations or recipients selected by the customer, within its permissions. For example, an enabled workflow may deliver a finding to a ticketing system or send a code change to a repository. A customer may separately share its reports with an auditor, advisor, or client. Those customer-directed disclosures are governed by its instructions and responsibilities.
7.3 Professional advisors and corporate transactions. Necessary information may be disclosed to legal, accounting, insurance, and other professional advisors under appropriate duties. Information may also be disclosed in evaluating or completing a financing, merger, reorganization, sale of relevant assets, or similar transaction, subject to confidentiality and applicable law. A successor's use remains subject to applicable privacy obligations and the customer agreement; a transaction does not create new training rights.
7.4 Legal and protective disclosures. We may disclose information when required by law or valid legal process, or where legally permitted and reasonably necessary to address fraud, a security threat, or a threat to rights or safety. We limit disclosure to the relevant purpose and provide customer or individual notice when legally required or contractually promised and not prohibited by law.
7.5 Public content and permission. If you choose to post in an expressly public forum or separately approve a testimonial or case study, the content you authorize may become public. Ordinary service uploads, prompts, assessment results, support tickets, and security evidence are confidential, not public posts. We do not publish identifiable customer findings without separate authorization except where legally required. Organizational names and logos may be used as permitted by the applicable customer agreement; this does not authorize publishing an individual's identity or image, confidential findings, or an endorsement without separate permission.
7.6 Sale and advertising sharing. We do not sell personal data or share it for cross-context behavioral advertising, as those terms are defined by applicable California law. We do not disclose customer content to advertisers or use it to build advertising profiles. We limit the exchanges described in Section 7.7 to arrangements consistent with these restrictions. Any future change to a practice requiring additional notice, choices, or consent must satisfy those requirements before it begins and cannot override contractual restrictions on Customer Data.
7.7 Distributors and resellers. Where your purchase or authorized support involves an identified distributor or reseller, we may exchange information reasonably necessary to arrange and administer that relationship: relevant business contact details, customer and account identifiers, purchased products, subscription dates, metered usage totals, invoice and payment status, refunds and credits, and relevant commercial support correspondence. We may receive corresponding order, collection, renewal, and support records from the partner. We use organization-level identifiers and totals without individual user details where those suffice. We do not provide access to records of unrelated customers merely because a partner resells our products.
We disclose information for the identified purchase, authorized support, and related lawful accounting, tax, security, or dispute needs. We do not provide it for unrelated prospecting, advertising profiles, sale, cross-context behavioral advertising, or Model Training. Before disclosure, we establish the required lawful basis and any binding recipient restrictions required by applicable law or our customer agreement. Where required, those arrangements address permitted purposes, confidentiality, security, retention, onward disclosure, rights requests, compliance oversight, and stopping or remedying unauthorized use. We restrict or suspend disclosures where the applicable requirements cannot be met. When a partner processes data on our or a customer's behalf, we require the instructions and written protections applicable to that role. We remain responsible for our own disclosure decisions and legal obligations; this Policy does not guarantee an independent partner's conduct or itself amend its agreement.
A partner may separately determine how to handle information it collects independently and its lawful transaction records, subject to its own notice, agreements, and law. This does not expand Rapticore's purposes for disclosure. Partners acting independently handle rights requests for their own records; we handle requests concerning our processing and provide legally required assistance. Billing or reconciliation does not itself authorize disclosure of source code, prompts, credentials, vulnerability evidence, or other detailed security content. That access requires a separately authorized support or service workflow, appropriate permissions, and any required processing agreement. Contact privacy@rapticore.com about our processing or for help identifying the responsible party.
8 Cookies and similar technologies
We use cookies or comparable browser storage to maintain sessions, secure logins, remember relevant preferences, and support website or service functionality. Website and usage measurement may also use cookies or similar technologies, subject to applicable consent requirements and choices. Cookie identifiers and analytics records can be personal data; we do not describe them as inherently anonymous.
Essential technologies are used only to the extent needed for requested functionality, security, or another applicable exemption. Where consent is legally required for optional analytics or preferences, we obtain it before activating those technologies, and provide a way to refuse and later change the choice. Information shown with the choice must identify the applicable purposes and providers. A preference is not essential merely because it benefits our business.
You can also use browser controls to remove or block cookies. Blocking necessary cookies may prevent login or break requested functionality; rejecting optional technologies does not remove access to features that do not depend on them. To ask about website technologies or exercise privacy choices, contact privacy@rapticore.com. Email is not a substitute for prior consent where prior consent is required.
Privacy signals. We honor legally recognized opt-out preference signals, including Global Privacy Control, as required by applicable law. Those signals are distinct from older Do Not Track browser requests, for which there is no uniform implementation standard. We do not promise a separate response to every legacy Do Not Track setting, but this does not limit our obligation to honor legally recognized signals. Because we do not sell or share personal data for cross-context behavioral advertising, an opt-out signal does not enable or permit any such use.
9 Retention and deletion
We retain personal data only for as long as reasonably necessary for the disclosed purpose, the applicable customer instructions and agreement, and legal requirements. Relevant criteria include the duration of the relationship, the type and sensitivity of information, security and support needs, contractual commitments, accounting and tax duties, limitation periods, and whether the purpose can be met with less or no personal data. Retention for legal claims or security evidence is limited to the necessary records, purpose, and period, subject to the applicable agreement and law.
| Record type | Retention approach |
|---|---|
| Account and business-contact records | For the relationship and a limited period needed for administration, relevant communications, or legal purposes; reviewed for deletion when no longer needed |
| Billing and contract records | For the applicable accounting, tax, evidentiary, and contractual period; access limited to those purposes |
| Marketing contacts and choices | Until withdrawal or objection, loss of relevance, or the end of a lawful retention period; a minimal suppression record may remain to honor an opt-out |
| Website analytics and security logs | According to the stated purpose and applicable configuration, with shorter retention where detailed records are no longer necessary |
| Customer Data and customer-specific AI records | During the service period under customer settings and the agreement, followed by the export and deletion process below |
| Properly anonymized service information | May be retained for the permitted service-improvement purposes; it remains excluded from Model Training without separate authorization |
9.1 Hosted Customer Data after the service ends. Export rights, formats, fees, and conditions are governed by the customer agreement. Unless a DPA, BAA, mandatory law, or agreed Order requires different handling, our Terms provide a 30-day period after expiry or termination to request an export from paid hosted Services, followed by deletion from active service systems within 30 days. Residual backups are deleted or irreversibly overwritten within 90 additional days, or sooner if required. This default permits up to 150 days after termination for final backup deletion. It does not override earlier individual-rights deadlines or a different binding agreement. A shorter free, trial, or beta export window applies only if disclosed before use; otherwise the 30-day window applies. Payment conditions for ordinary export do not delay legally required access, return, or deletion.
Pending deletion, backups remain protected, excluded from ordinary use, and accessible only for necessary recovery, security, or legal purposes. Deletion instructions are reapplied to restored copies. Deletion covers associated customer-specific embeddings, retrieval indexes, AI caches, and logs under our control; we require our managed subprocessors to meet applicable deletion obligations. We may retain limited records for legal obligations, actual or reasonably anticipated disputes, and necessary security or compliance evidence only as permitted by the governing agreement and law. Retained records are restricted to those purposes and excluded from Model Training and general product improvement. Customers may request earlier deletion where supported by the agreement or law.
9.2 Local and independent provider data. Customers control retention and deletion in their own infrastructure and independently procured provider accounts. Rapticore cannot remotely erase an inaccessible local copy or independently held provider record. We remain responsible for copies we receive through authorized support, telemetry, or other processing. Deleting an integration or uninstalling software does not automatically delete all provider copies or cancel a subscription.
9.3 Individual requests. A request about personal data we control is assessed under the applicable rights process in Section 12. Legal retention exceptions do not authorize continued marketing, Model Training, or general reuse. Where data has been properly anonymized so that we cannot reasonably associate it with an individual, we do not reidentify it merely to fulfill a request.
10 Security and regulated information
We maintain reasonable administrative, technical, and physical safeguards appropriate to the data and processing, including controls for access, confidential handling, and service security. Specific contractual safeguards, audit rights, data locations, and incident obligations are set out in the applicable customer agreement, security schedule, DPA, or BAA. No internet service or security measure guarantees absolute protection.
We notify customers of security incidents as required by the applicable customer agreement and law. Under our Terms, notification follows awareness of a security breach compromising Customer Data in systems controlled by us or our subprocessors, without undue delay. We promptly assess credible indications of a potential breach and do not wait for final forensic confirmation, identification of every affected record, or completion of a risk-of-harm assessment before giving required notice. Earlier triggers, broader definitions, or other requirements imposed by law, a DPA, or a BAA control. We provide reasonably available information and take reasonable containment and remediation measures within our control. Notification does not wait for completion of the investigation and is not an admission of liability. We also make individual or regulatory notifications where required for our role. Customers maintain safeguards for their own systems, access permissions, backups, and selected models.
Protected health information may be sent to Rapticore-managed components only where Rapticore expressly supports the use and any required BAA is in place. Other specially regulated content requires a supported arrangement and necessary agreements. On-premises hosting and encryption do not alone settle whether legal duties apply. Accidental receipt of regulated information does not waive duties that arise under applicable law.
11 International processing
Rapticore is based in the United States. Depending on the deployment, authorized support, and selected providers, personal data may be processed in the United States or other locations identified in applicable processing information. Countries may provide different legal protections. Customer-hosted storage in one country does not by itself establish the location of remote inference, backup, telemetry, or support access.
For components we control, we maintain controls designed to enforce express geographic and provider restrictions under the applicable customer agreement. When applicable law requires a safeguard for an international transfer, we use a valid mechanism before the transfer, such as applicable standard contractual clauses, an approved UK transfer mechanism, or a legally recognized adequacy decision, together with additional measures where required. This Policy does not claim certification under a privacy framework or unrestricted authority for international transfers. You may request information about relevant safeguards or a copy, subject to necessary redactions, at privacy@rapticore.com.
12 Your choices and privacy rights
12.1 How to contact us and verify a request. Send privacy questions and requests to privacy@rapticore.com, or write to Rapticore Inc., 2227 Derby Street, Berkeley, CA 94705. Describe the right you wish to exercise and provide information reasonably necessary to locate the relevant records. Do not include passwords, API keys, health records, or government identification in an initial request. We may require authentication through an existing account or additional information proportionate to the sensitivity of the request and disclosure risk, as permitted by law. We may decline or limit a request when identity or authority cannot be adequately verified, explaining the outcome and available alternatives where required. We do not require creation of a new account to exercise a right where prohibited, and do not require verification for an opt-out where the law prohibits it. Verification information is used and retained only as permitted for verification and legally required records.
12.2 Available rights. Depending on your location, our role, and applicable law, you may have rights to confirm processing; access or obtain a portable copy; correct inaccurate information; delete information; restrict processing; object to processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive data; or exercise rights concerning qualifying automated decisions. These rights have legal conditions and exceptions. Withdrawing consent does not affect the lawfulness of processing already based on it. We do not discriminate or retaliate for exercising protected rights.
12.3 Marketing and account controls. You can unsubscribe from marketing using the link in a message or by contacting us. We retain a minimal suppression record where needed to respect the choice. Where available, you may update profile information, adjust optional telemetry, change AI configurations, or disconnect integrations through account controls. Organization-level choices may require an administrator. Canceling a subscription is handled separately through the account cancellation method, the authorized reseller channel identified in your Order, or support@rapticore.com; a privacy request does not automatically cancel billing, and cancellation alone does not eliminate legally retained records.
12.4 Requests concerning an organization's data. When we process your information solely for a customer, that organization normally determines the response. We will forward or direct the request appropriately, subject to law and our agreement, and assist the customer with its obligations. We will not disclose another organization's confidential records to an unauthorized requester. We separately address any information we process as a controller or business.
12.5 Responses and appeals. We respond within the applicable legal deadline and explain any lawful denial or extension. We generally do not charge for a request; a fee or refusal is considered only where law permits and with the required explanation. Where applicable law provides an appeal, email privacy@rapticore.com with the subject Privacy Appeal and identify the decision. We will review and respond within the required period and provide any required information about contacting the relevant regulator. You may complain to an appropriate privacy or consumer-protection authority without first contacting us.
13 Additional information for California and other US residents
13.1 California rights. Where the CCPA as amended applies to our processing, California residents may request the categories and specific pieces of personal information collected, categories of sources, purposes, and categories of recipients; request deletion or correction; opt out of sale or sharing; and limit uses of sensitive personal information where the law provides that right. We do not sell or share personal information for cross-context behavioral advertising. We use sensitive personal information for necessary service, security, and other legally permitted limited purposes, not to infer unrelated sensitive characteristics about individuals. Sections 3, 4, 7, and 9 explain categories, purposes, recipients, and retention criteria.
13.2 California request process. Submit requests through the email or postal contact in Section 12. We acknowledge requests to know, delete, or correct within 10 business days and generally respond within 45 calendar days; when law permits an extension, we explain it and respond within the additional permitted period. Different and shorter timelines can apply to opt-outs and other choices. Access disclosures generally cover the preceding 12 months. You may request a longer period for information collected on or after January 1, 2022, subject to applicable law and its impossibility or disproportionate-effort exceptions. This does not require us to retain information beyond an otherwise lawful retention period. An authorized agent may act for you with the required permission or legal authority. We may verify the agent's authority and your identity as allowed by law, but do not require identity verification for an opt-out where it is prohibited.
13.3 Additional California disclosures. California residents may ask whether personal information has been disclosed to third parties for their own direct marketing under California's Shine the Light law. We do not disclose personal information for that purpose. We do not knowingly sell or share personal information of individuals under 16. You may use a recognized opt-out signal as described in Section 8. The right to exercise privacy choices is not waived by accepting our Terms or this Policy.
13.4 Other US state rights. Residents of other states may have comparable rights, including portability, an appeal, information about certain recipients, or an opt-out of targeted advertising or qualifying profiling. Applicability depends on the law, the processing, and any relevant exemption. Contact us under Section 12 and identify your state if helpful. We apply any required universal opt-out mechanism and will explain available rights and appeal procedures without requiring you to choose a statute first.
14 Additional information for the EEA the UK and Switzerland
Where applicable data-protection law requires a lawful basis for our controller activities, the basis depends on the specific purpose. We do not rely on a single blanket consent for all processing.
| Purpose | Applicable basis where available |
|---|---|
| Providing a service requested by an individual, including a sole proprietor who contracts with us | Performance of that contract or steps requested before entering it |
| Business account administration and communications with an organization's representatives | Our legitimate interests in operating the business relationship, subject to balancing against individual rights |
| Protecting accounts, investigating abuse, and maintaining service reliability | Necessary and proportionate legitimate interests in service and information security, or a specific legal obligation where applicable |
| Tax, accounting, and legally required records or disclosures | Compliance with the applicable legal obligation |
| Optional tracking and marketing where consent is required | Consent, which may be withdrawn; otherwise a permitted basis for lawful business marketing subject to objection |
| Appropriate website and business analytics | A documented legitimate interest where permitted, with separate consent for device access where required; this does not authorize reuse of customer content or Model Training |
For Customer Data processed on behalf of an organization, the organization determines its lawful basis and instructions; we process under the applicable agreement. Sensitive-category or criminal-offense data requires additional conditions where applicable law requires them. A general legitimate interest or a BAA alone does not replace those conditions.
You may have rights of access, correction, erasure, restriction, portability, objection, and withdrawal of consent, as applicable. You may object at any time to direct marketing and to processing based on legitimate interests on grounds relating to your situation. We generally respond to requests within one month, with a permitted extension of up to two further months for complexity or volume and notice during the initial month. Swiss timelines and requirements apply where relevant. You may complain to the competent supervisory authority in your place of residence, work, or alleged infringement. Contact privacy@rapticore.com to exercise rights or obtain relevant transfer and contact information.
15 Children
The Services are directed to adults and organizations, and account holders must be at least 18. We do not knowingly collect children's personal data through direct registration or marketing. An organization's authorized security content can nevertheless contain information about individuals of different ages; that processing remains subject to its instructions, applicable law, and required protections. If you believe a child has directly submitted personal data to us inappropriately, contact privacy@rapticore.com so we can assess and address it. An age restriction does not remove duties for information actually received.
16 Changes and contact
We may update this Policy to reflect lawful changes in our practices or requirements and will state the effective date. For material changes, we will provide appropriate notice, such as email to account contacts or a prominent service notice, before the change takes effect where required. We will obtain consent when legally required. Changes to processing practices remain subject to applicable law, required notices and choices, and the terms governing information already collected. Changes to contractual data rights require a valid amendment or authorization under the customer agreement. Model Training on the data described in Section 6.4 continues to require the separate express agreement specified there; a Policy update alone is insufficient.
For privacy questions, rights requests, or information about processing providers and safeguards, contact privacy@rapticore.com or Rapticore Inc., 2227 Derby Street, Berkeley, CA 94705. For account support, billing, or subscription cancellation, contact support@rapticore.com.