Privacy Policy
Last updated: June 28, 2026
This Privacy Policy explains how Horus ("Horus", "we", "us") collects, uses, and protects personal data when you visit our website, request a quote, or use the Horus platform. Horus is operated by [Legal entity name], [registered address]. For any privacy question, contact privacy@horusagents.com.
1. Data we collect
- Account & contact data: name, work email, company, and role, provided when you request a quote, are provisioned an account, or are invited to a team.
- Billing data: handled by our payment processor (Stripe). We do not store full card numbers; we receive only the subscription status, seat count, and billing metadata needed to manage your account.
- Platform data: the assets, scan results, findings, and configuration you create inside Horus, stored per-organization and isolated by row-level security.
- Technical data: log and security data (IP address, timestamps, user agent) needed to operate the service securely.
2. How we use it
- To provide, secure, and maintain the platform and your organization's account.
- To process payments and manage your subscription (seats, renewals, invoices).
- To respond to quote requests and support enquiries.
- To comply with legal obligations and protect against abuse.
We do not sell personal data, and we do not use your platform data to train third-party AI models. When AI analysis runs, sensitive identifiers can be pseudonymised before any prompt leaves the perimeter (redaction is on by default).
3. Legal bases (GDPR)
We process personal data on the basis of contract performance (providing the service), legitimate interests (security, service improvement), legal obligation (accounting), and consent where required (e.g. marketing emails you can opt out of at any time).
4. Sub-processors
We rely on a small set of trusted providers that process data on our behalf:
- Supabase: database, authentication, and storage (EU region).
- Stripe: payment processing and subscription management.
- Fly.io: application hosting.
- Cloudflare: web delivery and edge security.
- Resend: transactional email (account and notification emails).
5. Retention
We keep account and platform data for as long as your organization is active. After cancellation, data is retained for a limited grace period so you can reactivate, then deleted or anonymised, except where we must retain records (e.g. invoices) by law.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, portability, or restriction of your personal data, and object to certain processing. To exercise these rights, email privacy@horusagents.com. You also have the right to lodge a complaint with your local data protection authority.
7. Security
Data is encrypted in transit, access is isolated per organization, and the platform follows least-privilege and audit-logging practices. No system is perfectly secure, but protecting your data is core to what we do.
8. Changes
We may update this policy; material changes will be reflected by the "last updated" date above and, where appropriate, notified to account administrators.
This document is a general template and does not constitute legal advice. It should be reviewed by qualified counsel before being relied upon.