What we collect, why, how long we keep it, and how to exercise your rights over it.
ORTAL TECH ("PROSENTRIQ", "we", "us") is the data controller for personal data processed through the prosentriq.com website and the PROSENTRIQ Detection API (api.prosentriq.com), and the data processor for security telemetry your PROSENTRIQ agent generates on infrastructure you control (see Section 4). Contact our privacy team at [email protected].
| Data | Source | Why |
|---|---|---|
| Email address | You, at signup | Account identification, billing, service and security notices |
| API key (stored hashed) | Generated at signup | Authenticating requests to the Detection API |
| Billing details | You, via our payment processor | Processing subscription payments (card numbers are held by our payment processor, never by us directly) |
| IP address of requests to our website/API | Automatically, from connections | Security (rate limiting, abuse prevention), diagnosing faults |
| Support correspondence | You, when you email us | Responding to your request |
We do not collect hardware or device identifiers, and account authentication is by API key alone — there is no device-binding or hardware-ID check anywhere in PROSENTRIQ.
When installed on your infrastructure, the PROSENTRIQ agent processes network and process-behavior data locally, on your own systems, to perform baselining, scoring, and enforcement. Only the following is transmitted off your infrastructure, to the Threat Hub:
This telemetry is anonymized at the point of transmission — it is not linked back to your account identity in the shared Threat Hub dataset. We do not transmit file contents, kernel memory dumps, your proprietary code, or user network traffic logs. For this category of data, we act as a data processor on your behalf where it may contain personal data originating from your own users/traffic (e.g., an attacker's IP address); you remain the controller for data your own systems process.
Covered in full in the separate Cookie Policy, which is part of this Privacy Policy by reference.
We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.
If personal data is transferred outside the UK or EEA, we rely on an adequacy decision or appropriate safeguards (such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses) with the recipient.
Under the UK GDPR and EU GDPR, you have the right to:
To exercise any of these rights, email [email protected]. We aim to respond within one month, as required by law. We may need to verify your identity before acting on a request.
API keys are stored hashed, never in plaintext. Account recovery emails your new key directly rather than displaying it in an API response, when SMTP delivery is configured. See the Security & Compliance page for more, and [email protected] to report a vulnerability.
The Service is intended for business and professional use and is not directed at children. We do not knowingly collect personal data from anyone under 16.
We'll update the "Last updated" date above whenever this policy changes, and notify you by email for material changes affecting how we use previously-collected data.