Section 1
Information We Collect
1.1 Information You Provide
- Account Information
- Name, email address, phone number, organization details, and job title
- Authentication Data
- Login credentials, security questions, and multi-factor authentication information
- Payment Information
- Billing details and payment method information (processed securely through third-party payment processors)
- Communication Data
- Support requests, feedback, and correspondence with our team
1.2 Information Automatically Collected
- Usage Data
- Feature usage, access times, pages viewed, and interaction patterns
- Device Information
- IP address, browser type, operating system, and device identifiers
- Log Data
- System logs, error reports, and security event logs
- Cookies & Tracking
- Session cookies, analytics cookies, and preference settings
1.3 Investigation & Intelligence Data
- Query Data
- Search queries, investigation parameters, and analysis requests
- Intelligence Reports
- Generated reports, analytics, and threat intelligence data
- Case Data
- Investigation files, evidence metadata, and case management information
Section 2
How We Use Your Information
We use the collected information for the following purposes:
- Service Delivery
- To provide, maintain, and improve our cybersecurity intelligence services
- Security & Authentication
- To verify your identity and protect against unauthorized access
- Threat Intelligence
- To generate intelligence reports, conduct analyses, and provide investigation support
- Communication
- To respond to inquiries, provide support, and send service updates
- Compliance
- To comply with legal obligations, law enforcement requests, and regulatory requirements
- Analytics & Improvement
- To analyze usage patterns and enhance our platform functionality
- Billing & Payments
- To process transactions and manage subscriptions
Section 3
Data Security
We implement industry-leading security measures to protect your information:
- Encryption
- End-to-end encryption for data in transit and at rest using AES-256 and TLS 1.3
- Access Controls
- Multi-factor authentication, role-based access control, and principle of least privilege
- Infrastructure Security
- Secure cloud hosting, regular security audits, and penetration testing
- Monitoring
- 24/7 security monitoring, intrusion detection, and incident response protocols
- Data Segregation
- Logical separation of client data with strict isolation policies
- Backup & Recovery
- Regular encrypted backups with disaster recovery procedures
While we implement robust security measures, no system is completely secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.
Section 4
Data Sharing & Disclosure
4.1 We Do Not Sell Your Data
HornetStrike does not sell, rent, or trade your personal information to third parties for marketing purposes.
4.2 When We Share Information
We may share your information only in the following limited circumstances:
- Service Providers
- Trusted third-party vendors who assist with hosting, analytics, and payment processing (under strict confidentiality agreements)
- Legal Compliance
- When required by law, court order, or government request
- Law Enforcement
- To comply with valid legal processes from authorized agencies
- Business Transfers
- In connection with a merger, acquisition, or sale of assets (with continued privacy protection)
- With Your Consent
- When you explicitly authorize data sharing
- Security Purposes
- To prevent fraud, protect our systems, or respond to security incidents
Section 5
Data Retention
We retain your information for as long as necessary to:
- Provide our services and maintain your account
- Comply with legal obligations and regulatory requirements
- Resolve disputes and enforce our agreements
- Maintain security and prevent fraud
Retention periods vary by data type:
- Account Data
- Retained while your account is active plus applicable legal retention periods
- Investigation Data
- Retained according to case requirements and legal obligations
- Log Data
- Typically retained for 12-24 months for security and audit purposes
- Backup Data
- May persist in backup systems for up to 90 days after deletion
Section 6
Your Privacy Rights
Depending on your jurisdiction, you may have the following rights:
- Access
- Request a copy of the personal information we hold about you
- Correction
- Request correction of inaccurate or incomplete information
- Deletion
- Request deletion of your personal information (subject to legal retention requirements)
- Portability
- Request your data in a structured, machine-readable format
- Restriction
- Request limitation of processing in certain circumstances
- Objection
- Object to processing based on legitimate interests
- Withdraw Consent
- Withdraw consent for processing where consent was given
- Note
- Some rights may be limited by legal obligations to retain certain data for law enforcement, regulatory compliance, or security purposes.
Section 7
International Data Transfers
HornetStrike is based in South Africa. Your information may be transferred to and processed in South Africa or other countries where we or our service providers operate.
We ensure appropriate safeguards are in place for international transfers, including:
- Standard contractual clauses approved by relevant authorities
- Adequacy decisions by data protection authorities
- Compliance with applicable data protection frameworks
Section 8
Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete such information.
Section 9
Cookies & Tracking Technologies
We use cookies and similar technologies to:
- Maintain your session and preferences
- Analyze usage patterns and improve our services
- Enhance security and prevent fraud
- Remember your settings and customizations
You can control cookies through your browser settings, but disabling certain cookies may limit functionality.
Section 10
Third-Party Links
Our services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
Section 11
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this policy
- Sending you an email notification (for significant changes)
- Displaying a prominent notice on our platform
Your continued use of our services after changes constitutes acceptance of the updated policy.
Section 12
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- HornetStrike Cyber Intelligence
We aim to respond to all privacy-related inquiries within 30 days.