Privacy Policy

Last updated: January 2025

At ConnectMyAssets, we are committed to protecting your privacy and handling your data responsibly. This Privacy Policy explains how we collect, use, store, and protect your personal and network configuration data.

1. Data Controller

The data controller responsible for your personal data is: [Company Legal Name] [Complete Address] Email: [email protected] Phone: +1 (555) 123-4567 For EU residents, our EU representative is: [EU Representative Details]

2. Data We Collect

Account Information: - Name, email address, phone number - Company name and role - Password (encrypted) - Account preferences and settings Network Configuration Data: - Device configurations and settings - Network topology information - Compliance assessment results - Audit logs and change history Usage Data: - Login timestamps and IP addresses - Feature usage and interaction patterns - Error logs and performance metrics - API calls and integration data Cookies and Tracking: - Session cookies for authentication - Analytics cookies (with your consent) - Preference cookies for language and settings

3. How We Use Your Data

We use your data to: Service Delivery: - Provide network configuration compliance auditing - Generate compliance reports and scoring - Visualize network topology - Authenticate and secure your account Service Improvement: - Analyze usage patterns to improve features - Troubleshoot technical issues - Develop new capabilities - Optimize performance Legal Obligations: - Comply with applicable laws and regulations - Respond to legal requests and prevent fraud - Enforce our Terms of Service - Protect our rights and property Communications: - Send service-related notifications - Provide customer support - Share product updates (with consent) - Respond to your inquiries We do NOT: - Sell your data to third parties - Use your data for purposes other than stated - Share configuration data outside your organization - Access your data without proper authorization

4. Legal Basis for Processing (GDPR)

We process your data based on: Contractual Necessity: - To provide the Service you've subscribed to - To fulfill our obligations under the Terms of Service Legitimate Interest: - To improve and secure our Service - To prevent fraud and abuse - To analyze usage patterns Consent: - For marketing communications - For non-essential cookies - For specific data processing activities Legal Obligation: - To comply with applicable laws - To respond to legal requests

5. Data Sharing and Disclosure

We may share your data with: Service Providers: - Cloud hosting providers (data centers) - Email service providers - Analytics platforms (anonymized data) - Payment processors These providers are contractually bound to protect your data and use it only for specified purposes. Legal Requirements: - Law enforcement agencies (with valid legal request) - Regulatory authorities - Courts and legal proceedings We will notify you of such disclosures unless prohibited by law. Business Transfers: - In case of merger, acquisition, or sale - Your data may be transferred to the new entity - You will be notified of any such changes We do NOT share your network configuration data with any third parties except as necessary to provide the Service or as required by law.

6. Data Retention

We retain your data for as long as necessary to provide the Service and comply with legal obligations: Active Accounts: - Account data: Duration of account plus 30 days - Configuration data: As long as you maintain your subscription - Audit logs: 12 months (configurable) Closed Accounts: - Account data: 90 days after closure - Configuration backups: 30 days after closure - Legal and compliance records: As required by law (typically 5-7 years) You may request deletion of your data at any time, subject to legal retention requirements.

7. Data Security

We implement comprehensive security measures: Technical Measures: - AES-256 encryption for data at rest - TLS 1.3 for data in transit - Multi-factor authentication - Regular security audits and penetration testing - Intrusion detection and prevention systems Organizational Measures: - Access controls and role-based permissions - Employee security training - Confidentiality agreements - Incident response procedures - Regular security reviews Physical Security: - Secure data centers with physical access controls - Redundant infrastructure - Disaster recovery plans Despite these measures, no system is 100% secure. We cannot guarantee absolute security but will notify you promptly of any data breaches.

8. Your Rights (GDPR & Privacy Laws)

You have the following rights: Right to Access: - Request a copy of your personal data - Understand how we process your data Right to Rectification: - Correct inaccurate or incomplete data - Update your account information Right to Erasure ("Right to be Forgotten"): - Request deletion of your data - Subject to legal retention requirements Right to Restriction: - Limit how we process your data - Object to certain processing activities Right to Data Portability: - Receive your data in a structured format - Transfer data to another service Right to Object: - Object to processing based on legitimate interest - Opt-out of marketing communications Right to Withdraw Consent: - Withdraw consent at any time - Does not affect prior processing Right to Lodge a Complaint: - File a complaint with your data protection authority To exercise these rights, contact: [email protected]

9. International Data Transfers

Your data may be processed in countries outside your country of residence. We ensure adequate protection through: Standard Contractual Clauses: - EU-approved data transfer mechanisms - Binding agreements with data processors Adequacy Decisions: - Transfers to countries with adequate data protection Additional Safeguards: - Encryption during transfer - Access controls - Regular compliance audits By using our Service, you consent to these transfers in accordance with applicable laws.

10. Children's Privacy

ConnectMyAssets is not intended for children under 16 years of age. We do not knowingly collect data from children. If you believe we have collected data from a child, please contact us immediately, and we will delete the information.

11. Cookies and Tracking

We use cookies for: Essential Cookies (Always Active): - Authentication and session management - Security features - Service functionality Analytics Cookies (With Consent): - Usage statistics and patterns - Performance monitoring - Feature adoption tracking Preference Cookies (With Consent): - Language selection - Display preferences - Interface customization You can control cookies through: - Our cookie banner (Consent Mode v2 compatible) - Browser settings - Third-party opt-out tools Disabling cookies may affect Service functionality.

12. Third-Party Services

We integrate with third-party services that have their own privacy policies: - Cloud hosting providers - Analytics platforms - Payment processors We are not responsible for their privacy practices. Please review their policies directly.

13. Changes to This Policy

We may update this Privacy Policy to reflect: - Changes in our practices - Legal or regulatory requirements - New features or services We will notify you of material changes via: - Email notification - Prominent notice in the Service - Updated date at the top of this policy Continued use after changes constitutes acceptance of the updated policy.

14. Contact Us

For privacy-related questions or to exercise your rights: Email: [email protected] Address: [Company Address] Data Protection Officer (if applicable): [DPO Contact Information] EU Representative: [EU Representative Contact]