Skip to main content

Last updated: April 17, 2026 · Effective: April 17, 2026

Privacy Policy

What personal information we collect, how it is used and shared, and the rights you can exercise over it.

Anhui Reallysec Information Technology Ltd. (“Reallysec”, “we”, “us”, or “our”) operates reallysec.com and provides managed cybersecurity services. This Privacy Policy (“Policy”) describes how we collect, use, share, and protect personal information when you visit our website or engage our services. We comply with the Personal Information Protection Law (PIPL), Data Security Law, and Cybersecurity Law of the People’s Republic of China, as well as the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable international regulations.

01

Information We Collect

We collect personal information only when necessary and on a lawful basis. Depending on how you interact with us, we may collect the following categories:

Information you provide:

  • Contact information: When you submit a contact form or inquiry, we collect your name, email, company, phone number, and message content.
  • Service engagement data: After signing a service agreement, you may authorize us to access systems, credentials, network configurations, logs, and security artifacts strictly for delivering the agreed-upon services.
  • Account information: If you register for a partner or client portal, we collect authentication information required for access.
02

Information Automatically Collected

When you visit our website, for security and operational purposes we automatically collect:

  • IP address, browser type and version, operating system, device identifiers
  • Access timestamps, pages viewed, time on page, click behavior, referring URL
  • Cookie identifiers and similar technologies (see Section 8)
  • Request pattern data used for threat detection and abuse prevention
03

Account and Payment Information

If you create a console account we store your email address, name, hashed password, organisation, and — where you enable it — two-factor authentication settings. Signing in with Google or GitHub gives us the profile fields those providers release, and no password.

Payments are processed by Stripe. Card numbers are entered on Stripe's own hosted fields and are never transmitted to or stored on our systems. What we receive back and retain is the transaction record: amount, currency, status, the card brand and last four digits, and the Stripe identifiers needed to issue a refund or manage a subscription.

We keep, for as long as the account exists:

  • Order and subscription history, including invoices, for the period tax law requires us to retain records
  • Which licences were issued to the account and their current state
  • Email delivery records for messages we sent you about your account, so we can prove a licence or renewal notice was sent
04

Licence Activation and Telemetry

Licensed software contacts our licence server to activate and then periodically to confirm it is still licensed. This is how licence enforcement works, and it is described here because the data involved can identify a machine and, indirectly, a person.

The purpose is limited to licence enforcement, support, and detecting abuse. We do not collect the content of your systems — not your logs, not your search queries, not your data, not the results the software produces.

Each activation and heartbeat records:

  • A hardware fingerprint derived from machine identifiers, used to bind a licence to a deployment and to enforce the node count
  • The IP address the request came from, and the time of the request
  • The product, edition, version and licence identifier
  • Whether the check succeeded, and why it failed if it did not

For customers in the EU and UK, our legal basis is performance of the contract (the licence cannot be enforced without it) and our legitimate interest in preventing licence abuse. Heartbeat records are pruned on a rolling basis and are not retained indefinitely; activation records are kept for the life of the licence, because the licence is defined by them.

05

How We Use Information

We process your personal information only for specified, lawful, and necessary purposes:

  • Respond to inquiries and deliver the services you request
  • Operate, maintain, and improve our website and services
  • Communicate about service status, important notices, and security alerts
  • Send product updates and marketing communications with your consent (you can unsubscribe at any time)
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations, respond to judicial or regulatory requests, and protect our and others’ lawful rights
07

Sharing and Disclosure

We do not sell your personal information. We share data only in the following circumstances:

  • Service providers: We share data with vetted processors under data processing agreements, including cloud hosting (Vercel), email delivery (Resend), messaging notifications (Feishu), authentication, and analytics services
  • Group affiliates: Where necessary and consistent with this Policy, with Reallysec global affiliates in London, Melbourne, and Silicon Valley
  • Legal requirements: When required by law, court order, or lawful government request
  • Business transfers: In a merger, acquisition, or asset sale, the successor entity will inherit the obligations of this Policy
  • Rights protection: Where necessary to protect our or others’ rights, safety, and property
08

Service Providers We Use

We use a small number of processors to run the service. Each receives only what it needs for its function, under a data processing agreement, and none of them is permitted to use your data for their own purposes.

Current processors:

  • Stripe — payment processing, subscription billing and refunds
  • Cloudflare — bot protection on public forms, and network-level protection
  • Our email delivery provider — licence delivery, verification, password reset and renewal notices
  • Our hosting provider — the servers this service runs on

We will publish an updated list before adding a processor that handles personal data in a materially different way. If you need the current list in writing for your own compliance records, ask us and we will send it.

09

International Data Transfers

Reallysec operates globally from Hefei, London, Melbourne, and Silicon Valley. Your personal information may be processed outside your country of residence.

For transfers of personal information from China to overseas, we complete the security assessments, standard contract filings, or personal information protection certifications required under Article 38 of the PIPL. For transfers from the European Economic Area, we use EU Standard Contractual Clauses (SCCs) along with any necessary supplementary measures.

10

Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described, considering processing purpose, legal obligations, and reasonable business needs:

  • Contact form submissions: 24 months from submission, unless business engagement continues
  • Service engagement records: as specified in the Service Agreement, typically 3–7 years post-project for audit, compliance, and dispute resolution
  • Website access logs: up to 12 months
  • Longer retention applies where required by law. After expiry, data is promptly deleted or anonymized
11

Your Rights

Under PIPL, GDPR, and other applicable laws, you have the following rights regarding your personal information:

  • Right to be informed and to decide: understand how we process your information, restrict or object to processing
  • Right of access and copy: obtain a copy of your personal information
  • Right to rectification: correct inaccurate or incomplete data
  • Right to erasure (right to be forgotten): request deletion subject to legal conditions
  • Right to data portability: receive data in a structured, commonly used, machine-readable format
  • Right to withdraw consent: for consent-based processing, at any time
  • Right to complain: lodge complaints with your local data protection authority (e.g., UK ICO, EU DPAs, China CAC)
12

Cookies and Tracking Technologies

We use the following categories of cookies:

  • Strictly necessary cookies: required for basic site functionality (language preference, theme, security tokens); no consent required
  • Functional cookies: remember your choices and enhance usability
  • Analytics cookies: help us understand site usage to improve the experience (we favor privacy-friendly analytics solutions)
13

Data Security

As a cybersecurity company, we protect client data to standards significantly higher than industry average. We hold ISO/IEC 27001:2022 and ISO 9001:2015 certifications; our core experts hold CISM, OSCP, and other international credentials.

Technical and organizational measures include:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Least-privilege access controls, multi-factor authentication (MFA), privileged account auditing
  • 24/7 SOC monitoring and intrusion detection
  • Regular penetration testing, red team exercises, and third-party security audits
  • Formal incident response process with regular tabletop drills
  • Security awareness training and strict confidentiality obligations for all staff

No system can guarantee absolute security. In the event of a personal information breach, we will notify affected users and regulators in accordance with applicable law.

14

Children’s Privacy

Our website and services are directed at business users and not intended for children under 14 (in China) or other ages applicable under local law. We do not knowingly collect information from minors. If you believe a minor has provided us personal information, please contact us and we will promptly delete it upon verification.

15

Third-Party Links

Our website may contain links to third-party sites or services we do not control. This Policy does not apply to those sites. Please review their privacy policies before providing any information.

16

Changes to This Policy

We may update this Policy to reflect changes in our business, legal environment, or technology. Material changes will be announced through the website, email, or other reasonable means, and the “Last Updated” date at the top will be revised. Continued use of our services after such changes constitutes acceptance.

Contact Us

For questions about this Policy or to exercise your rights, contact us:

Anhui Reallysec Information Technology Ltd.
Privacy Inquiries: privacy@reallysec.com
Data Protection Officer (DPO): dpo@reallysec.com
Contact Page: https://reallysec.com/contact

We will respond to your request within 15 business days (or within the period required by applicable law).

Related policies