Privacy Policy

Your privacy is important to us. This policy explains how we handle your data.

Effective
25th September 2026
Last updated
25th September 2026
On this page
01

Who we are

Shubham Raut, an individual doing business as SwaSec ("SwaSec," "we," "us"), based in Pune, Maharashtra, India, operates the SwaSec at swasec.com.

This policy explains what personal data we collect when you use the tool, why, who we share it with, and what rights you have. Questions or rights requests: hello@swasec.com.

02

What this covers

This covers the assessment tool itself: the organization profile intake, the questionnaire, the results dashboard, the report email gate, and the Security Posture Card. Cookies are covered separately in our Cookie Policy. General site use is covered by our Terms of Use.

03

What we collect

Organization profile data

Company name, industry, employee count range, operating regions, whether you develop or deploy AI, current certifications held.

Assessment responses

Your maturity-level answer per question, plus "I don't know" and "Not Applicable" flags.

Session identifier

A token stored in your browser and against your assessment record, so you can resume later.

Report gate data

Work email, full name, job title, and the timestamp of your consent, collected only if you request the detailed report.

Usage and analytics data

Via PostHog (EU Cloud, hosted in Frankfurt, Germany): pages viewed, funnel events, approximate device and browser, approximate location.

Anything you send us directly

Support or feedback correspondence.

We do not currently collect any payment information, since the assessment and report are free. If we introduce paid services, this policy will be updated before any payment data is collected.

04

Why we use it

  • Run the assessment, calculate scores, generate the report and posture card
  • Let you resume an in-progress assessment
  • Understand drop-off points and improve the tool, at an aggregate level
  • Send the report and, only with opt-in consent, follow-up compliance emails
  • Follow up personally if you request a consultation
  • Produce anonymized, aggregated benchmarking statistics, no individual company is identifiable
  • If you start an assessment but do not complete it or request the report, we may use the organization information you provided to research your company and contact you about our services, for up to 6 months. See Section 8 for retention and your right to object at any time.
06

Who we share it with

We do not sell your data.

Supabase

Database and file storage

Tokyo, Japan

PostHog

Product analytics

EU Cloud, Frankfurt, Germany

Resend

Transactional email, sends the report

US company, sending region North Virginia (US), account data stored in the US, covered by Resend's Standard Contractual Clauses and participation in the EU-U.S. Data Privacy Framework.

US, North Virginia

Future CRM

Only if and when we introduce automated follow-up sequences, and only for consented leads.

07

International transfers

Supabase stores data in Japan, which the European Commission has formally recognized as providing an adequate level of data protection, so data originating in the EU can move there without additional safeguards. Our analytics provider stores EU visitor data in Frankfurt, Germany, inside the EU, so no international transfer occurs for that data. Our email provider, Resend, is US-based, transfers to the US are covered by their pre-signed Data Processing Agreement, which relies on Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.

08

How long we keep it

Assessment started, no report requested

Kept up to 6 months. During this period we may use the organization information to research your company and reach out, as described in Section 4. After 6 months, deleted or anonymized.

Report requested (lead data)

Kept until you unsubscribe or ask us to delete it, or automatically after 24 months with no interaction (open, click, or reply) on either side, whichever comes first.

Anonymized aggregate statistics

Kept indefinitely. Once genuinely anonymized, meaning no session ID, IP address, or company name attached, this data no longer identifies anyone and isn't subject to a retention limit.

09

Security

Encryption in transit and at rest via Supabase, database access restricted by row-level security scoped to session tokens. In the event of a breach affecting personal data, we will notify affected users and the relevant regulator within the timeframe required by applicable law.

10

Your rights

EU/EEA/UK (GDPR)

Access, correction, deletion, restriction, portability, objection, withdraw consent, complain to your local supervisory authority.

India (DPDP Act, 2023)

Access a summary of your data, correct or erase it, nominate someone to act on your behalf if you die or become incapacitated, file a grievance with us and then with the Data Protection Board of India if unresolved.

California

Ability to know what we hold and request deletion. We don't sell or share personal information for cross-context behavioral advertising.

To exercise any of these, email hello@swasec.com.

11

Children

Not directed at anyone under 18. We don't knowingly collect their data.

12

Cookies

Non-essential cookies, including analytics, only load after you consent via our cookie banner. See our Cookie Policy for details and how to manage your preferences.

13

Changes

Posted here with an updated date. Material changes trigger an email to report-gate leads.

14

Contact

Shubham Raut, doing business as SwaSec

Pune, Maharashtra, India

hello@swasec.com