Enterprise Legal & Compliance Notice

Privacy Policy

Comprehensive data privacy standards, regulatory compliance, and telemetry protection for OnDuty Security.

Effective / Last Updated: July 16, 2026

1. Introduction & Scope

Thank you for accessing the OnDuty Security platform, website, and related enterprise cloud security services (collectively, the “Service”) offered by OnDuty Security, Inc. (“we”, “us”, “our”, or “OnDuty Security”). This Privacy Policy sets out the comprehensive basis on which any personal information we collect from you, or that you or your organization provide to us, will be processed, secured, and maintained.

We encourage you to read this Privacy Policy carefully to understand our practices regarding your personal data and how we safeguard workload telemetry across multi-cloud environments.

2. Information We Collect

OnDuty Security collects information that identifies individuals or that may, with reasonable effort, identify individuals (“Personal Information”), together with data you or your organization choose to submit or connect for scanning:

Account & Identity Data

We collect your name, email address, organization details, and authentication credentials (usernames and cryptographic tokens) when you create an account or workspace.

Customer-Submitted Data

When you connect a repository, cloud account, or domain, we collect and process the data needed to perform the scans you request: source code and repository contents and metadata, cloud configuration and resource metadata, domain-scan targets, and the resulting scan findings. Scan results may surface credentials, secrets, or other sensitive material present in your own code or cloud environment. We treat such material as your confidential data, and you are responsible for what you choose to connect to the Service.

Usage Analytics & Aggregated Information

We collect usage analytics (e.g., browser type, OS version, pages visited, and feature interactions) via analytics providers such as PostHog, along with aggregated, de-identified performance metrics. De-identified data is used to improve the Service.

3. How We Collect Information

Direct & Customer Provided

Information is collected directly when you register for an account, configure cloud connector credentials, interact with AI On-Call assistants, or request customer support. In enterprise deployments, your organization’s administrative lead may provision your account by supplying essential directory details.

Automated Telemetry & Cookies

When accessing OnDuty Security, our servers automatically log standard network parameters including IP addresses, timestamps, API request latencies, and device identifiers. We utilize standard session and persistent cookies to maintain secure authentication states and customize user preferences. You may manage cookie settings through your browser controls.

4. Use of Collected Information

We utilize collected data strictly for providing, auditing, securing, and enhancing our enterprise cloud security platform:

  • Real-time zero-day vulnerability matching against NVD/CVE registries
  • Building cloud asset inventory and identity posture dependency graphs
  • Automating incident triage and notification routing via AI workflows
  • Verifying compliance against CIS, SOC 2, HIPAA, and ISO benchmarks
  • Sending essential transactional notices, security alerts, and invoices
  • Detecting and preventing unauthorized access, abuse, and cyber threats

5. Data Sharing & Subprocessors

OnDuty Security never sells personal information or customer data. We share data only with service providers (subprocessors) that help us operate the Service, such as cloud hosting and edge infrastructure providers (e.g., Cloudflare, AWS, GCP), product analytics providers (e.g., PostHog), and third-party AI/LLM providers that process data under their commercial terms to power AI-assisted features.

We require our subprocessors to protect data consistent with this Privacy Policy and applicable law. A current list of subprocessors is available on request at privacy@onduty.ai. We may also disclose data if legally required to comply with judicial subpoenas, court orders, or regulatory inquiries.

6. California CCPA Privacy Rights

For residents of California, we support the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) to the extent they apply to us. Over the past twelve (12) months, we have collected identifiers, commercial interaction records, and electronic network activity strictly for operational business purposes. We respond to verified requests within the timelines required by applicable law.

Your Rights Under California Law:
  • •Right to Know: You may request disclosure of the specific pieces and categories of personal information collected, sources, and business purposes.
  • •Right to Delete: You may request complete deletion of your personal records from our active systems and subprocessor databases.
  • •Non-Discrimination: We guarantee equal service quality and pricing when you exercise any privacy rights.

7. European Union GDPR Rights & International Transfers

For residents of the European Economic Area (EEA), OnDuty Security processes personal data on the lawful bases of legitimate interests (operating and securing the Service), performance of a contract, and, where applicable, consent.

Where Your Data Is Processed: Personal data and customer data are processed primarily in the United States and in other locations where our infrastructure and service providers operate. Where required by applicable law, international transfers of EEA personal data rely on European Commission-approved Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms.

You have rights to access, rectify, restrict processing of, delete, or request portability of your personal data. To exercise your GDPR rights, email privacy@onduty.ai.

8. Data Security, Storage & Retention

We implement commercially reasonable administrative and technical safeguards appropriate to our size and stage, including industry-standard encryption of data in transit and at rest.

Personal data and customer data are retained for the active lifespan of your account or subscription plus an administrative grace period. Upon account termination or verified deletion requests, we delete active records typically within thirty (30) days, with residual copies in backups removed in accordance with our backup rotation schedules.

No Guarantee of Security: No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal data, we will notify you and applicable regulators as required by applicable law.

Children: The Service is not directed to, and may not be used by, anyone under eighteen (18) years of age, and we do not knowingly collect personal information from children.

9. Governing Law & Dispute Resolution

This Privacy Policy and all related security disputes are governed by the laws of the State of Delaware, United States, without regard to conflict of law principles. Any legal proceedings shall be brought exclusively in the state or federal courts located in Delaware.

We reserve the right to periodically update this policy to reflect evolving legal and technical standards. Material modifications will be communicated via platform notifications or direct email.

Questions about your privacy or CCPA/GDPR compliance?

If you have inquiries regarding subject access requests, telemetry audits, or contractual data processing agreements, our legal and security operations team is ready to assist.

privacy@onduty.ai