Your privacy is important to us. This Privacy Policy tells you the types of information we collect about you when you visit our website or use our services, how we use that information, and when we may share your information. This Privacy Policy may change from time to time, so please check this policy regularly.

KeyLocker BV (doing business as SecretHub) is registered at the Dutch Chamber of Commerce, number 60796324. We are located at Molengraaffsingel 10, 2629 JD Delft in The Netherlands.


Information we collect

To operate our website and service, we have to collect some personal information from you. Collecting personal information is not the goal of our business. Therefore, we limit collection to that which helps us to run, sell and improve our website and services.

Data we collect when you sign up for an individual user account

When you sign up for a new account on our service, we ask for the following personal information:

  • Your name
  • Your email address
  • A chosen username

We need your email address to provide services to you and use it to verify your account ownership in case you contact us.

We use your name and email address to help you with your onboarding experience and inform you of product updates or other service messages if needed. You can always unsubscribe from these kinds of communications. Information how to unsubscribe from mailings is provided in each message.

Your username is used as a means for other users to identify you on our platform. You have the freedom to choose a fictitious username (as long as another user has not yet taken it).

Data we collect when you use our services

When you use our service, we collect the IP addresses of the machines from which you use the service for recording an audit trail of your action (which is part of the provided service) and diagnosis of service problems. Such information can also be used to help secure our services and systems and to investigate abuse or technical issues affecting our services or their security.

Data we collect when you make a purchase

Purchasing a license can only be done as a business entity. When making a purchase, we collect the following data:

  • The company’s payment details
  • The company’s billing address
  • An email address for billing purposes

These details are used strictly to maintain our relationship with you with respect to the ordered services such as for billing purposes.

We use a certified third party payment service provider (Stripe Inc.) for processing payment details. Our systems only have access to a minimum set of details of the payment methods (e.g., last 4 digits of credit card and expiration date). We do not store full payment details such as credit card numbers on our own systems.

Other

When you visit our website or use our service, we may randomly collect anonymized data about your usage of the website and our product. The purpose of gathering this information is to improve the user experience for our website and service.

Cookies

We use cookies on our website. Using cookies is a way for us to make sure that our website is continuously improved and meets your needs. In order for us to do this, we place functional cookies to make our website function and analytical cookies to analyze how our website and services are being used. We do not use cookies for tracking you across third party websites.

Please view our Cookie Policy for more details on how we use cookies.

Your rights

In accordance with European Law, you have the following rights concerning the personal information we collect of you:

  • You can ask us to provide you with a copy of the data we have collected from you.
  • You can ask us to restrict or stop processing data we have collected from you.
  • You can ask us to correct any mistakes in the data we have collected from you.
  • You can ask us to erase any data we have collected of you that we have no good reason for processing.
  • You can withdraw your consent for processing your personal information.

It may not always be possible to continue providing our services when you request us to stop processing information or withdraw your consent. If this is the case, we will advise you of this when you make your request.

Furthermore, note that we may not always be able to comply with your requests, for example, because of legal obligations. If this is the case, you will be notified of this in response to your request.

Data retention

We will only retain your personal data for as long as necessary to fulfil the purposes for which we collected it, including to comply with our legal, accounting, or reporting requirements. Our retention of your data allows us to continue to provide you with services without interruption.

In some circumstances, we may anonymize your personal data (so that it can no longer be associated with you) for analytical, research, and statistical purposes and help us improve our products and services, in which case we may use this information indefinitely without further notice to you.

Data protection

We are committed to securing your personal data and have taken steps in this regard. To prevent unauthorized people or parties from accessing your data, we have put in place a range of technical and organizational measures to safeguard and secure the information we process from you.

Sharing information with Third Parties

We need the help of third parties to be able to offer you our website and services. Where necessary, we will share your information with our service providers. We have concluded agreements with our service providers to ensure their processing practices are compliant with applicable European data protection laws.

If our business (or a part of our business) is sold or integrated with another business, your details will be disclosed to our advisers and any prospective purchaser’s adviser and will be passed to the new owners of the business.

International transfers

Some information you send us and or use on our website or service may be shared with other third parties outside the European Economic Area (EEA). To protect the data that is transferred outside of the EEA, we have implemented appropriate safeguards.

Data processed by means of SecretHub

With respect to the secrets and other information you may upload and process by means of the SecretHub Application (“End User Data” as also defined in our Terms of Service), the following applies in addition and deviation of the above:

  • Our services are not intended to be used to manage or process personal data. Should incidental to the provision of SecretHub any personal data be processed by End User by means of SecretHub, End User shall ensure this occurs in accordance with applicable laws and that all consents that may be required from the relevant individuals for such processing are obtained.
  • The processing of End User Data is never outsourced by us and never provided to any third party except as per your instruction or if it is required to be disclosed to a competent governmental or regulatory authority. Please note we do not have a copy of the encryption master keys used to encrypt the secrets you process by means of SecretHub so we cannot be forced to disclose those master keys to any third party.

Contacting us

If you have any questions, comments, or requests regarding our Privacy Policy, you can address these to info@secrethub.io.

This policy was last updated on December 17 2020