Privacy Policy
Last updated: June 2025
1. Information We Collect
We collect information you voluntarily provide when contacting us, requesting services, or subscribing to our newsletter. This includes name, email address, company name, and application URLs submitted for assessment. We do not collect data beyond what is necessary for service delivery.
2. How We Use Your Information
Your information is used exclusively to: (a) Deliver requested security assessment services, (b) Communicate about engagements and deliverables, (c) Send security advisories if you opt in, (d) Improve our services. We never sell, rent, or share your data with third parties for marketing purposes.
3. Data Security
As a cybersecurity firm, we practice what we preach. All client data is encrypted at rest (AES-256) and in transit (TLS 1.3). Access is restricted on a need-to-know basis. We maintain audit logs of all data access.
4. Data Retention
Engagement data is retained for the duration of the engagement plus 12 months for re-test purposes. After this period, all data is securely deleted. You may request earlier deletion at any time.
5. Your Rights
You have the right to: access your personal data, request correction of inaccurate data, request deletion of your data, withdraw consent at any time. To exercise these rights, contact privacy@aritaro.com.
6. Cookies
Our website uses only essential cookies required for functionality. We do not use tracking cookies or third-party analytics that identify individual users.
7. Changes
We may update this policy periodically. Changes will be posted on this page with an updated "Last Updated" date.
8. Contact
For privacy-related inquiries: privacy@aritaro.com