Anhui Reallysec Information Technology Ltd. (“Reallysec”, “we”, “us”, or “our”) operates reallysec.com and provides managed cybersecurity services. This Privacy Policy (“Policy”) describes how we collect, use, share, and protect personal information when you visit our website or engage our services. We comply with the Personal Information Protection Law (PIPL), Data Security Law, and Cybersecurity Law of the People’s Republic of China, as well as the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable international regulations.
Information We Collect
We collect personal information only when necessary and on a lawful basis. Depending on how you interact with us, we may collect the following categories:
Information you provide:
- Contact information: When you submit a contact form or inquiry, we collect your name, email, company, phone number, and message content.
- Service engagement data: After signing a service agreement, you may authorize us to access systems, credentials, network configurations, logs, and security artifacts strictly for delivering the agreed-upon services.
- Account information: If you register for a partner or client portal, we collect authentication information required for access.
Information Automatically Collected
When you visit our website, for security and operational purposes we automatically collect:
- IP address, browser type and version, operating system, device identifiers
- Access timestamps, pages viewed, time on page, click behavior, referring URL
- Cookie identifiers and similar technologies (see Section 8)
- Request pattern data used for threat detection and abuse prevention
Account and Payment Information
If you create a console account we store your email address, name, hashed password, organisation, and — where you enable it — two-factor authentication settings. Signing in with Google or GitHub gives us the profile fields those providers release, and no password.
Payments are processed by Stripe. Card numbers are entered on Stripe's own hosted fields and are never transmitted to or stored on our systems. What we receive back and retain is the transaction record: amount, currency, status, the card brand and last four digits, and the Stripe identifiers needed to issue a refund or manage a subscription.
We keep, for as long as the account exists:
- Order and subscription history, including invoices, for the period tax law requires us to retain records
- Which licences were issued to the account and their current state
- Email delivery records for messages we sent you about your account, so we can prove a licence or renewal notice was sent
Licence Activation and Telemetry
Licensed software contacts our licence server to activate and then periodically to confirm it is still licensed. This is how licence enforcement works, and it is described here because the data involved can identify a machine and, indirectly, a person.
The purpose is limited to licence enforcement, support, and detecting abuse. We do not collect the content of your systems — not your logs, not your search queries, not your data, not the results the software produces.
Each activation and heartbeat records:
- A hardware fingerprint derived from machine identifiers, used to bind a licence to a deployment and to enforce the node count
- The IP address the request came from, and the time of the request
- The product, edition, version and licence identifier
- Whether the check succeeded, and why it failed if it did not
For customers in the EU and UK, our legal basis is performance of the contract (the licence cannot be enforced without it) and our legitimate interest in preventing licence abuse. Heartbeat records are pruned on a rolling basis and are not retained indefinitely; activation records are kept for the life of the licence, because the licence is defined by them.
How We Use Information
We process your personal information only for specified, lawful, and necessary purposes:
- Respond to inquiries and deliver the services you request
- Operate, maintain, and improve our website and services
- Communicate about service status, important notices, and security alerts
- Send product updates and marketing communications with your consent (you can unsubscribe at any time)
- Detect and prevent fraud, abuse, and security threats
- Comply with legal obligations, respond to judicial or regulatory requests, and protect our and others’ lawful rights
Legal Bases for Processing
Depending on your jurisdiction, we rely on the following legal bases:
- Your consent (for marketing communications and non-essential cookies)
- Contract performance (to deliver services you have requested)
- Legal obligation (for tax, audit, and regulatory recordkeeping)
- Legitimate interests (website security, fraud prevention, service improvement), where such interests do not override your fundamental rights
Service Providers We Use
We use a small number of processors to run the service. Each receives only what it needs for its function, under a data processing agreement, and none of them is permitted to use your data for their own purposes.
Current processors:
- Stripe — payment processing, subscription billing and refunds
- Cloudflare — bot protection on public forms, and network-level protection
- Our email delivery provider — licence delivery, verification, password reset and renewal notices
- Our hosting provider — the servers this service runs on
We will publish an updated list before adding a processor that handles personal data in a materially different way. If you need the current list in writing for your own compliance records, ask us and we will send it.
International Data Transfers
Reallysec operates globally from Hefei, London, Melbourne, and Silicon Valley. Your personal information may be processed outside your country of residence.
For transfers of personal information from China to overseas, we complete the security assessments, standard contract filings, or personal information protection certifications required under Article 38 of the PIPL. For transfers from the European Economic Area, we use EU Standard Contractual Clauses (SCCs) along with any necessary supplementary measures.
Data Retention
We retain personal information only for as long as necessary to fulfill the purposes described, considering processing purpose, legal obligations, and reasonable business needs:
- Contact form submissions: 24 months from submission, unless business engagement continues
- Service engagement records: as specified in the Service Agreement, typically 3–7 years post-project for audit, compliance, and dispute resolution
- Website access logs: up to 12 months
- Longer retention applies where required by law. After expiry, data is promptly deleted or anonymized
Your Rights
Under PIPL, GDPR, and other applicable laws, you have the following rights regarding your personal information:
- Right to be informed and to decide: understand how we process your information, restrict or object to processing
- Right of access and copy: obtain a copy of your personal information
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure (right to be forgotten): request deletion subject to legal conditions
- Right to data portability: receive data in a structured, commonly used, machine-readable format
- Right to withdraw consent: for consent-based processing, at any time
- Right to complain: lodge complaints with your local data protection authority (e.g., UK ICO, EU DPAs, China CAC)
Data Security
As a cybersecurity company, we protect client data to standards significantly higher than industry average. We hold ISO/IEC 27001:2022 and ISO 9001:2015 certifications; our core experts hold CISM, OSCP, and other international credentials.
Technical and organizational measures include:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Least-privilege access controls, multi-factor authentication (MFA), privileged account auditing
- 24/7 SOC monitoring and intrusion detection
- Regular penetration testing, red team exercises, and third-party security audits
- Formal incident response process with regular tabletop drills
- Security awareness training and strict confidentiality obligations for all staff
No system can guarantee absolute security. In the event of a personal information breach, we will notify affected users and regulators in accordance with applicable law.
Children’s Privacy
Our website and services are directed at business users and not intended for children under 14 (in China) or other ages applicable under local law. We do not knowingly collect information from minors. If you believe a minor has provided us personal information, please contact us and we will promptly delete it upon verification.
Third-Party Links
Our website may contain links to third-party sites or services we do not control. This Policy does not apply to those sites. Please review their privacy policies before providing any information.
Changes to This Policy
We may update this Policy to reflect changes in our business, legal environment, or technology. Material changes will be announced through the website, email, or other reasonable means, and the “Last Updated” date at the top will be revised. Continued use of our services after such changes constitutes acceptance.
Contact Us
Anhui Reallysec Information Technology Ltd.
Privacy Inquiries: privacy@reallysec.com
Data Protection Officer (DPO): dpo@reallysec.com
Contact Page: https://reallysec.com/contact
We will respond to your request within 15 business days (or within the period required by applicable law).
Related policies