Scope and Applicability
This Privacy Policy applies to all users of the Services, including visitors, customers, prospects, partners, and job applicants. Certain individuals, such as residents of the European Economic Area (“EEA”), United Kingdom, or California, may have additional rights under applicable data protection laws, as described in the regional privacy rights sections below.
Personal Information We Collect
“Personal Information” means information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual. The categories we may collect depend on how you interact with Insight Recon.
A. Information you provide directly
We may collect the following when you interact with us:
- Contact and business information — including name, business email, phone number, company name and role, and mailing or billing address. Collected when you request demos, create an account, download reports, register for events, or contact sales or support.
- Account and service information — including login credentials, user roles and permissions, and support requests and communications.
- Payment and billing information — billing contact details and transaction metadata. Note: Insight Recon does not store full payment card or banking details. Payment processing is handled by third-party processors subject to their own security and privacy obligations.
- Employment and recruiting information — including résumé/CV details, contact information, application materials, interview communications, and feedback.
- Voluntary submissions — including survey responses, product feedback, reviews, and community forum or event participation.
B. Automatically collected information
When you access our Services, we may automatically collect technical and usage information, including IP address, device identifiers, browser type and version, operating system, language and regional settings, pages viewed and actions taken, date/time stamps, referring URLs, and limited email engagement data (opens and link clicks).
This data is used to operate and secure the Services, improve functionality and performance, detect abuse or fraud, and understand usage trends.
C. Information from third parties
We may receive Personal Information from business partners and resellers, marketing and lead-generation providers, publicly available sources, recruiting platforms, and service providers acting on our behalf. We collect such information only where permitted by law and consistent with this Privacy Policy.
How We Use Personal Information
We use Personal Information for legitimate business purposes, including to:
- Provide, operate, and maintain the Services
- Create and manage accounts
- Process transactions and billing
- Deliver reports, findings, and support services
- Respond to inquiries and requests
- Communicate service-related updates
- Improve and develop products and features
- Conduct analytics and research
- Market and promote our Services using only contact information you have provided — never scan results
- Administer events, surveys, and promotions
- Protect against fraud, misuse, or security threats
- Comply with legal, regulatory, and contractual obligations
- Enforce our terms, policies, and agreements
Important: We do not use customer data scanned or analyzed by Insight Recon tools for advertising, marketing profiling, or resale under any circumstances.
Disclosure of Personal Information
We may disclose Personal Information in the following circumstances:
A. Corporate affiliates
Within Breach Point, Inc. and its subsidiaries for legitimate business and operational purposes.
B. Service providers
With trusted third-party vendors who perform services on our behalf, including hosting and infrastructure, payment processing, analytics, marketing and email delivery, customer support, and professional services (legal, accounting, audit). These providers are contractually required to protect Personal Information.
C. Business transactions
In connection with a merger, acquisition, reorganization, sale of assets, or similar corporate transaction.
D. Legal and compliance obligations
Where required to comply with applicable law, regulation, legal process, or government request.
E. With your direction
When you intentionally share information through public forums, reviews, or other interactive features.
Third-Party Services and Links
Our Services may include links to third-party websites or integrations. This Privacy Policy does not apply to those third parties. We are not responsible for their privacy practices or content.
Do Not Track Signals
At this time, we do not respond to browser “Do Not Track” signals, as there is no consistent industry standard.
Security Safeguards
We implement reasonable administrative, technical, and organizational safeguards designed to protect Personal Information from unauthorized access, loss, misuse, or disclosure. No system is completely secure, and we cannot guarantee absolute security.
Data Retention
We retain Personal Information only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Children's Privacy
The Services are intended for business and professional use and are not directed to individuals under the age of 13. We do not knowingly collect Personal Information from children.
Your Rights and Choices
A. Updating or correcting information
You may request updates or corrections to your Personal Information by contacting us at legal@breachpoint.com.
B. Marketing communications
You may opt out of marketing emails at any time by using the unsubscribe link in any marketing email. Transactional or service-related communications may still be sent.
California Privacy Rights
California residents may have rights under applicable state law, including the right to:
- Know what Personal Information we collect and disclose
- Request deletion of Personal Information (subject to legal exceptions)
- Not be discriminated against for exercising privacy rights
We do not sell Personal Information. Requests may be submitted to legal@breachpoint.com.
European Economic Area and UK Rights
Where applicable, we comply with the GDPR and related laws. Individuals in the EEA or United Kingdom may have rights to access, correct, delete, restrict, or object to the processing of their Personal Information, as well as the right to data portability. To exercise these rights, contact us at legal@breachpoint.com.
Changes to This Privacy Policy
We may update this Privacy Policy periodically. Updates become effective when posted. Continued use of the Services after changes are posted indicates acceptance of the revised Policy.