HexaSentra ("we", "us") provides an external attack surface management platform. This policy explains what personal data we process, why, and the rights you have. It is written to align with the EU/UK GDPR and comparable regimes.
For account and marketing data, HexaSentra is the data controller. For data processed within your tenant while delivering the service to you, we act as your data processor under the Data Processing Addendum (DPA).
We perform active checks only against assets you have explicitly authorized as in-scope. We do not scan third parties to demonstrate a point, and all testing is non-destructive by design.
We share data only with vetted sub-processors that support the service (hosting, email, payments), under contractual data-protection terms. A current list is available on request. We do not sell personal data.
Where data is transferred outside your region, we rely on appropriate safeguards such as Standard Contractual Clauses.
We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymize it. Scan and evidence data follow your tenant's configured retention.
Subject to law, you may request access, correction, deletion, restriction, portability, or object to processing, and withdraw consent. Contact privacy@hexasentra.com. You may also complain to your supervisory authority.
We apply row-level tenant isolation, encryption in transit, least-privilege access, audit logging, and secret-management controls. No system is perfectly secure, but we work to a high standard and are building toward SOC 2.
HexaSentra — Pune, Maharashtra, India · privacy@hexasentra.com