Skip to content
Securive

Legal

Privacy Policy

What personal data we hold, why, how long for, and what you can require us to do with it.

Version 2026-08-15 · effective 15 August 2026

Draft, pending legal review. This text is modelled on what enterprise backup vendors publish and on what GDPR and CCPA require, and it has not been reviewed by a lawyer. The liability cap, governing law and registered entity are marked in the text and must be set before this is relied upon.

1. Two very different kinds of data

This policy distinguishes between them throughout, because our role and your rights differ:

Account data — the personal data of the people who use the Service: names, work email addresses, phone numbers, IP addresses, and records of what they did in the console. For this we are the controller.

Customer Data — the contents of your backups, which may contain personal data belonging to your own employees, customers or users. For this we are a processor acting on your instructions, and you are the controller. We do not decide what is in it, we do not look inside it, and we process it only to store, replicate and restore it.

2. Account data we collect, and why

Identity and contact details (name, work email, phone, company, role) — to create and administer your account, and to contact you about the Service. Lawful basis: performance of a contract.

Trial request details (company size, infrastructure, partner type) — to evaluate and route the request. Lawful basis: steps taken at your request prior to a contract.

Consent records (what you accepted, when, and the IP address it came from) — to evidence that agreement. Lawful basis: legal obligation and legitimate interest in being able to demonstrate compliance.

Audit logs (sign-ins, privileged actions, backup and restore operations, API calls) — to secure the Service and to give you an account of who did what. Lawful basis: legitimate interest in the security of the Service.

Billing details — to take payment. Card details are handled by our payment processor and are never stored by us.

Marketing preferences, where you have opted in. Lawful basis: consent, withdrawable at any time.

3. Backup metadata

To operate the Service we necessarily process metadata about your backups: machine names, file and volume sizes, timestamps, job outcomes, storage consumption, and the chunk digests used for deduplication.

This metadata can be revealing — a machine name can identify a customer of yours — so it is treated as confidential, held under the same access controls as Customer Data, and is never used for any purpose other than operating and supporting the Service.

4. How long we keep things

Account data: for the life of the account, then 12 months, then deleted.

Customer Data: under the retention policy you configure. On termination, 30 days, then deleted. On trial expiry, 14 days frozen, then deleted.

Consent and contract records: 6 years after the relationship ends, because that is how long we may need to evidence them.

Audit logs: 12 months.

Unverified trial requests: 7 days, then deleted.

Backups of our own systems may hold copies for a further 35 days; deletion requests are honoured across those on the next restore cycle.

5. Where data is stored

Customer Data is stored in the region you select and stays there. Replicas go to a second region you also select. Nothing is relocated for capacity reasons.

Account data is stored in the European Union. Where a sub-processor operates outside it, transfers are made under Standard Contractual Clauses or an adequacy decision.

6. Who else touches it

We use a small number of sub-processors: infrastructure and object-storage providers, an email delivery provider, and a payment processor. A current list is available on request from privacy@securive.net, and we give notice before adding one that processes Customer Data.

We do not sell personal data, and we do not share it for cross-context behavioural advertising — under CCPA terms, we do not "sell" or "share" it.

7. Security

Encryption in transit (TLS) and at rest, with a separate encryption key per tenant.

Backups written to immutable storage for their retention period, so they cannot be altered or deleted early by anyone — including us — before that period elapses.

Role-based access control, including a restore-only role for end clients.

Audit logging of privileged actions.

Staff access on a least-privilege basis, and no routine access to backup contents.

Report a suspected vulnerability to security@securive.net. We do not pursue researchers who act in good faith.

8. Your rights

Where we are the controller (account data), you may ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or provide it in a portable form. You may withdraw marketing consent at any time; withdrawing it does not affect the Service.

If you are in California, you additionally have the rights to know, delete, correct, and to opt out of sale or sharing — noting that we do neither.

Where we are the processor (Customer Data), requests from the people whose data is in your backups must come to you, and we will assist you in answering them.

Contact privacy@securive.net. We respond within one month. You may also complain to your local supervisory authority.

9. Cookies

The console uses a session cookie that is strictly necessary to keep you signed in. The marketing site uses no advertising or cross-site tracking cookies, and analytics — where enabled — records page views and bucketed events with no personal identifiers.

10. Changes

Material changes are notified by email to account administrators before they take effect. The version and effective date are shown at the top of this page.