Skip to main content

Legal

Privacy Policy

What we collect, why, and what you can do about it.

This is a first draft

It reflects our real data practices today, but it has not yet had a full legal review or formal sign-off.

What we collect

  • Account and contact details you give us directly.
  • Metadata read from the accounts you connect, read-only, never the secret values themselves.
  • Usage data about how you use RunAssured (pages visited, actions taken), for running and improving the service.

Why we collect it

To run the assessment, produce your reports, and, once you move onto the service, to operate your app: monitor it, respond to incidents, and keep the evidence a serious buyer or regulator will ask for.

Where your data lives

Held in the EU (Ireland), with monitoring data on Datadog’s EU site. See the Trust Centre for the full detail.

Visit the Trust Centre →

Who we share it with

The subprocessors who help us run the service are listed, with what they do and where, in the Trust Centre.

Visit the Trust Centre →

How long we keep it

For as long as your account is active, plus whatever UK and EU law requires us to retain afterwards for tax, audit or dispute purposes.

Your rights

Under UK GDPR you can ask to see, correct, export or delete the personal data we hold about you. Email privacy@criticalcloud.ai to ask.

Contact

Questions about this policy: privacy@criticalcloud.ai.

Email privacy@criticalcloud.ai