Skip to main content

Last updated: 18 July 2026

Privacy Policy

Techbunk Limited operates Secuvon. This policy describes the data the application handles and distinguishes product defaults from choices made by the operator of a particular deployment.

1. Data we process

  • Account and team data, including names, email addresses, roles, and authentication records.
  • Agent configuration, scan requests, model responses, findings, reports, and audit events.
  • Provider credentials supplied for scanning, encrypted before database storage.
  • Contact-form submissions and support correspondence.
  • Billing identifiers and subscription status when Stripe billing is enabled; Secuvon does not store full card details.
  • Operational data such as IP-derived security records, request identifiers, timestamps, and error logs.

2. Why we process it

We process data to provide the service, secure accounts, run requested assessments, generate evidence and reports, administer subscriptions, answer enquiries, prevent abuse, and meet applicable legal obligations. The applicable legal basis depends on the activity and may include contract, legitimate interests, consent, or legal obligation.

3. Deployment location and providers

Secuvon does not promise one universal hosting region. In self-hosted deployments, the customer controls the infrastructure and region. In a managed deployment, location and subprocessors are the ones stated in the signed order or DPA. Selecting an external model provider sends the prompts required for a scan to that provider under the customer's provider account and terms.

Depending on configuration, service providers can include the hosting operator, Stripe for billing, the selected email provider, monitoring services, and the AI providers selected by the customer. We do not sell personal data.

4. Retention

The application ships with the following defaults. Organisation-level settings, a signed contract, legal holds, and backup retention may alter the effective period.

Scans and generated reports365 days
Encrypted finding evidence90 days
Guardian runtime events90 days
Audit logs2,555 days (approximately seven years)

Account deletion removes or anonymises account-linked data, while records that must be kept for security, dispute, tax, or legal purposes may be retained for the applicable period.

5. Security

Secuvon provides encrypted credential storage, scoped access controls, audit logging, secure-cookie support, SSRF protections, and deployment checks that require HTTPS and database TLS in staging and production. Operators remain responsible for their infrastructure, secrets, access policies, monitoring, and offsite backups. No online service can promise absolute security.

6. Your choices and rights

Depending on applicable law, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data, and to complain to the competent supervisory authority. The dashboard includes data export and account deletion controls.

Submit privacy or security requests through the contact form. We may need to verify identity before acting on a request. Secuvon does not claim that a statutory Data Protection Officer has been appointed.

7. Changes

We may update this policy when the product, deployment, providers, or legal requirements change. Material changes will be shown here with a new effective date. This policy is product information, not legal advice to customers about their own processing activities.