Two quite different things arrive at our door. One is a small administrative record that lets us invoice you and reach a human being; the other is whatever your protected systems produce, which belongs to you and merely sits in our keeping. This document treats them apart, because running the two together is how a vendor ends up quietly monetizing the second.
Section IWhat reaches us
| Account | Your name, a work email address, and the organization. Those are what provisioning needs, and what lets a person reach you when something breaks at an awkward hour. |
|---|---|
| Billing | Subscription records, invoices, receipts. The card is handled start to finish by Stripe; what comes back to us is the last four digits and a pass or a decline. |
| Service metadata | Which endpoints, servers, company files, tenants, and mailboxes sit in scope, together with agent check-ins, job outcomes, and detection history. |
| Protected content | The backed-up material itself, plus the forensic detail hanging off a security finding. Encrypted with 256-bit AES where it rests and protected while it moves. Yours by title, ours only to hold. |
| Site logs | Ordinary web server entries: address, timestamp, page requested. No profiling of the visitor, and no advertising pixels. |
Section IIThe narrow list of uses
- Provisioning the protection, operating it, invoicing it, and answering for it.
- Telling you when a job keeps failing, when an endpoint looks compromised, and when the account needs a decision only you can make.
- Meeting the obligations that tax, accounting, and the law place on us.
That is the extent of it. Personal information is not for sale here. Protected content is never mined, sampled, benchmarked, or fed to a model in training. The only thing it exists for is being handed back.
Section IIIOther hands
Only those processors the service genuinely needs. Stripe takes payment; the security and backup platforms each Article page names, along with the cloud storage sitting beneath them, hold the data they protect; and a mail provider carries receipts, alerts, and the sign-in links. All of them act on our instruction and hold no separate purpose in your data.
If a court order or a subpoena arrives, we do what the law genuinely requires and nothing broader, and we tell you about it unless telling you is itself forbidden.
Section IVRetention
Protected content is held for exactly as long as the line you bought says: 28 days of file versions on one line, seven years of Exchange mail on another, unrestricted history on directory configuration. When a subscription ends, that content is destroyed on whatever deprovisioning timetable the platform holding it runs.
Detection and case history stays available while the account is open, so that a later investigation has something to work from. Records of the account and of the billing are held for the period tax and accounting rules oblige.
Section VWhat you can require of us
California residents, along with residents of a lengthening list of other places, may by statute inspect, correct, copy, or erase what a business records about them personally. Write from the account address and we honor whichever of those you are entitled to.
Erasure of an account is final, and so is erasure of the protected content inside it. We confirm in writing before anything is destroyed.
Section VIWhere to write
Fortify 24x7 · support@constitutioncomputing.com