Skip to content
← Back to home

Last updated:

Privacy Policy

1. Introduction

Konzern AI DOO ("we," "us," or "our") operates the QubeAuditor platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

2. Data Controller

The data controller responsible for your personal data is:

Konzern AI DOO

Contact: [email protected]

3. Information We Collect

We collect the following types of information:

  • Account Information: Name, email address, company name, and other contact details you provide when registering or contacting us.
  • Usage Data: Information about how you interact with the Service, including log data, IP address, browser type, and pages visited.
  • Scan Metadata: When you use QubeAuditor to assess Kubernetes clusters, Azure container services, AWS ECS estates or cloud accounts, we process scan results, findings, control results and configuration metadata. We do not access or store your application data, secrets, or customer data.

4. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve the Service
  • Process transactions and send related information
  • Respond to your comments, questions, and requests
  • Send technical notices, updates, security alerts, and support messages
  • Monitor and analyze trends, usage, and activities in connection with the Service
  • Detect, investigate, and prevent fraudulent transactions and other illegal activities

5. Deployment Model and Data Location

In the primary operating model, the QubeAuditor control plane, evidence store and generated artifacts run inside the customer environment or a deployment the customer controls. In that model, scan results and evidence remain under the customer's control and are not transferred to us except where the customer engages us to operate the deployment on its behalf.

Where an optional AI-assisted remediation feature is enabled for a customer, prompts are processed by a platform-managed model provider in an EU region. Secrets, credentials, environment values, full manifests and raw scanner payloads are excluded from those requests by design. The feature is disabled for a customer unless it has been explicitly enabled.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Data transmitted between your systems and our Service is encrypted in transit using TLS. Stored integration secrets, including SMTP and webhook credentials, are encrypted at rest. Given the security-sensitive nature of our Service, we adhere to industry best practices for infrastructure security.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you the Service. Scan results and audit findings are retained according to your agreement and can be deleted upon request. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

8. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your personal data
  • Object to or restrict certain processing activities
  • Request data portability
  • Withdraw consent at any time

To exercise these rights, please contact us at [email protected].

9. Cookies and Tracking Technologies

This website stores your language and theme preference in your browser's local storage so the site behaves consistently between visits. These values stay in your browser and are not used to track you across sites. Our contact form uses Cloudflare Turnstile to distinguish humans from automated submissions.

Where you use the QubeAuditor platform itself, a session cookie is required to keep you signed in. Some features of the Service will not function without it.

10. Third-Party Services

We may employ third-party companies and individuals to facilitate our Service, provide the Service on our behalf, or assist us in analyzing how our Service is used. These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

11. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at [email protected].