Privacy Policy

Last updated: June 2025

1. Information We Collect

We collect information you voluntarily provide when contacting us, requesting services, or subscribing to our newsletter. This includes name, email address, company name, and application URLs submitted for assessment. We do not collect data beyond what is necessary for service delivery.

2. How We Use Your Information

Your information is used exclusively to: (a) Deliver requested security assessment services, (b) Communicate about engagements and deliverables, (c) Send security advisories if you opt in, (d) Improve our services. We never sell, rent, or share your data with third parties for marketing purposes.

3. Data Security

As a cybersecurity firm, we practice what we preach. All client data is encrypted at rest (AES-256) and in transit (TLS 1.3). Access is restricted on a need-to-know basis. We maintain audit logs of all data access.

4. Data Retention

Engagement data is retained for the duration of the engagement plus 12 months for re-test purposes. After this period, all data is securely deleted. You may request earlier deletion at any time.

5. Your Rights

You have the right to: access your personal data, request correction of inaccurate data, request deletion of your data, withdraw consent at any time. To exercise these rights, contact privacy@aritaro.com.

6. Cookies

Our website uses only essential cookies required for functionality. We do not use tracking cookies or third-party analytics that identify individual users.

7. Changes

We may update this policy periodically. Changes will be posted on this page with an updated "Last Updated" date.

8. Contact

For privacy-related inquiries: privacy@aritaro.com