Privacy Policy
Effective Date: August 8, 2026 · Version 1.0
This Privacy Policy describes how BreachDuty (operated by Ellis Intelligence LLC, "we", "us") collects, uses, and shares information when you visit breachduty.com or use the Service at app.breachduty.com. It is the same policy published in-app, kept identical across both domains.
1. Scope
Marketing-site visitors; Customer account holders (a company's compliance lead, GC, or authorized representative, or a white-label firm's authorized personnel); client-company users acting under a white-label firm's tenant. No individual consumer who receives a breach notice is ever recorded in the Service (§4) — the Service does not draft, assemble, or send notice content, so it never collects a notice recipient's name or contact information.
BreachDuty is a nested multi-tenant service — a white-label firm is a tenant whose client companies are company-scoped records within it; a direct Customer is a tenant with one company.
2. Information we collect
(a) Directly (account + tenant data):
- Firm / company identity: the Customer's (and, for a white-label firm, each client company's) name, industry, and configuration.
- Contact + account: account email address, name, and role of the authorized account holder.
- Incident metadata: the facts the Customer's team enters about an incident — data classes involved, a narrative, the discovery date, and affected-population counts per state (the counts that thresholds key off).
- Obligation and notice-status data: the computed obligation map (per-jurisdiction triggered/not with cited basis, computed deadline, regulator overlays, status), and, self-reported by the Customer, whether and when a notice was sent for each obligation. The Service does not itself draft, assemble, or send any notice content, and does not collect any notice recipient's name or contact information.
- Billing contact: company billing name and email. Payment details are tokenized via Stripe — we do not store card numbers. Stripe currently runs in TEST mode only.
- Reminder / notification preferences: recipients and thresholds for deadline reminders and statute change-notices.
(b) Automatically: device and connection data, usage data, and the two strictly necessary cookies described in the Cookies and Tracking section (see §7). No advertising, analytics, or preference cookies.
(c) Generated under your tenant: the canonical, tamper-evident events_log audit trail of every incident opened, population set, obligation computed, notice sent (self-reported by the Customer, since the Service does not itself draft, assemble, or send any notice), clock warning, and incident close under your tenant.
3. How we use information
We use the data you provide to:
- Run the incident intake and Obligation Atlas — accept the incident facts and compute the per-jurisdiction obligation map, each obligation shown with its citation.
- Run the deadline clocks — compute each statutory deadline from the statute version in force on the discovery date, and send reminders ahead of each, business-day- and holiday-shifted, firing exactly once.
- Track notice-sent status — record, at the Customer's own report, whether and when a notice was sent for a given obligation. The Service does not draft, assemble, or send any notice content itself (§4).
- Produce the record — write the tamper-evident audit spine, and generate the sealed obligation-map PDF and chain-of-custody export on the Customer's request.
- Send statute change-notices — when a statute is amended, notify affected tenants.
- Authenticate account holders, prevent unauthorized access, process payments, manage subscriptions, communicate about the Service and material changes, run aggregated/de-identified analytics, and comply with legal obligations.
We do not collect, process, or store any individual consumer's name or contact information — no notice recipient is ever entered as a record in the Service.
4. What we do NOT do with your information
- We do not sell personal information. We do not share it for cross-context behavioral advertising.
- We do not provide legal advice or render legal determinations using your data or otherwise — the obligation map is a cited software output for your counsel to confirm.
- We do not share incident, obligation, or notice-status data with third parties for purposes other than providing the Service, except as described in §6 (subprocessors, legal compliance, business transfers).
- We do not use Customer tenant data to train any model or to improve a Service used by other customers.
- We do not draft, assemble, or send any notice content, and we do not collect or store any individual consumer's name or contact information. BreachDuty never submits a notice to a regulator, attorney general, or consumer — the Customer, through its own counsel, originates, drafts, and sends every notice through the Customer's own systems.
- We do not build consumer profiles or offer identity-protection, credit-monitoring, breach-detection, forensic, or scanning services of any kind.
5. The chain-of-custody export — the BreachDuty-specific nuance
Unlike the sibling attestation products, BreachDuty has no public, unauthenticated surface — there is no verification token or public page that discloses any tenant or company data. BreachDuty does not collect or store any individual consumer's name or contact information: the Service does not draft, assemble, or send breach-notification content, so no consumer is ever entered as a record, account holder, or recipient in the Service.
The record is the Customer's to share. The sealed obligation-map PDF and the chain-of-custody export are disclosed to the Customer only. The Customer decides whether, and with whom (its counsel, a regulator, an attorney general, an insurer, an auditor), to share them. Once exported or shared, a copy is the Customer's own.
6. Sharing and disclosure
- Subprocessors: Stripe (billing, currently TEST mode), our email-delivery provider (reminder and statute-change-notice emails), and hosting infrastructure. The current subprocessor list is published at breachduty.com/subprocessors.
- Subprocessor changes: we will notify the Customer's designated account contacts by email (or by in-product notice) at least 30 days before adding or replacing a subprocessor, and will update the current subprocessor list at the same time. Notice is deemed given when sent (or when the in-product notice is first displayed). A Customer may object on reasonable data-protection grounds within 30 days of the date notice is given; if a Customer timely objects, we will not use the new subprocessor to process that Customer's data while we work with the Customer to resolve the objection.
- Legal compliance, business transfers, with consent: standard. We will not share incident, obligation, or notice-status data with third parties beyond subprocessors without your consent, except as required by law.
7. Cookies and tracking
Also published standalone at breachduty.com/cookies (identical text).
The BreachDuty website (breachduty.com)
The Site does not use advertising or analytics cookies and does not load third-party trackers. Because we self-host fonts and front-end assets, your browser does not request resources from third-party servers as a result of visiting the Site.
The BreachDuty application (app.breachduty.com)
The application uses two cookies, both strictly necessary. Neither is used to advertise to you or to follow you across other websites.
- A session cookie, set by the application when you sign in. It keeps you signed in and protects forms against cross-site request forgery. It is removed when your session ends. The application cannot be used while it is blocked.
- A Cloudflare access cookie (
CF_AppSession, and after sign-inCF_Authorization), set by Cloudflare when your browser first reachesapp.breachduty.com— before you sign in. It runs the access-control check that sits in front of the application. Cloudflare provides this service to us as a processor and is listed on our subprocessor page.
We do not set advertising cookies, retargeting or behavioral-tracking pixels, or cross-site tracking cookies of any kind, and we do not integrate with data brokers. We do not set analytics cookies, and we do not set preference or "functional" cookies.
We do count a small number of anonymous events — for example, that a pricing section was viewed or a contact link was clicked. Those counts are kept as day-level totals only. They set no cookie, use no visitor identifier, and record no IP address, device information, or anything else about you.
Your choices. You can block or delete cookies in your browser's settings, and the Site will work normally with every cookie blocked. Blocking the two application cookies means you will not be able to sign in to app.breachduty.com — that is the only thing that stops working.
8. Retention
- Account data: while active, plus a reasonable period for accounting/legal compliance (typically 7 years for business records).
- Tenant incident, obligation, and notice-status data: for the duration of the subscription and available for export at any time during that period; absent an earlier Customer deletion request, retained — including the computed obligation map and notice-sent status history — for twenty-four (24) months after termination to preserve the evidentiary and statutory record-keeping basis for a breach-notification dispute, then deleted within 30 days of the end of that period (or within 30 days of a Customer's written deletion request, if earlier), except as required by law to retain.
- Sealed obligation-map PDFs and chain-of-custody exports: retained while the subscription is active and for twenty-four (24) months after termination for evidentiary and statutory record-keeping purposes, available for Customer export throughout; copies the Customer downloaded before deletion remain the Customer's own records.
- Audit spine (
events_log): retained with the tenant's data for the duration of the subscription and the 24-month post-termination retention period above. - Marketing contacts: until opt-out or deletion request.
- Aggregated, de-identified data: indefinitely.
9. Security
Customer data is stored on encrypted infrastructure (disk-level encryption at rest) and served exclusively over TLS with authenticated, least-privilege access; we operate automated health monitoring, with independent external uptime monitoring on every live brand host. Data uses nested per-tenant, per-company isolation enforced by company-scoping helpers that require both the tenant and company identifiers (no cross-company reads). Every material action writes a tamper-evident events_log row. The application runs behind a Cloudflare Access gate. We do not claim SOC 2, ISO 27001, or any audited certification at this time and will make a report available under NDA if and when one exists. Deadlines are computed from the statute version in force on the discovery date and statute rows are versioned and never overwritten, so the record of what was computed, and against which statute version, is preserved.
10. Your rights
For individuals (under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the UK GDPR, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA"), the Colorado Privacy Act ("CPA"), and other applicable data protection laws):
- Access, portability, correction, deletion, and restriction rights as applicable.
- Email [email protected] to exercise them.
For Colorado residents (CPA): you may exercise the rights described above by contacting [email protected]. We do not sell personal data and do not process it for targeted advertising.
Regarding the tamper-evident record: because the audit spine and sealed record are data-integrity mechanisms, a deletion request affecting an incident's underlying data may be honored on our copy per §8's retention schedule, but cannot retroactively alter a record already exported or shared by the Customer — those copies are the Customer's own, once shared.
11. Children's privacy
The Service is for business account holders and their internal workforce. We do not knowingly collect information from anyone under 13 as an account holder. If we discover such information, we will delete it.
12. Updates
30 days' email notice to the Customer billing contact for material changes. Notice is deemed given when sent; the 30-day period runs from the send date, and failure to read a notice does not extend it. Continued use after the effective date constitutes acceptance of the updated policy.
13. Contact
[email protected] — privacy inquiries, data rights requests
[email protected] — other legal matters