Privacy Policy

How BITS Blackrock IT Solutions LLC collects, uses, and protects personal data in connection with the SekuRad platform.

BITS Blackrock IT Solutions LLC · Last updated 2026-07-17

1.Who we are

BITS Blackrock IT Solutions LLC (“we”, “us”) operates the SekuRad security-operations platform. For personal data processed to run our business and website, we act as the data controller. For the data a customer’s users enter into the platform, the customer is the controller and we act as a processor under our Data Processing Agreement.

Registered office: 8 Ali Basha Zolfakar Street, Alexandria, Egypt. Registration: Commercial Register CR 191183 · Unified No. 1777619972 (Egypt). Questions: privacy@sekurad.com.

2.What we collect

  • Account data — name, work email, organisation, role, and authentication identifiers (via our identity provider).
  • Customer content — the operational data your team enters (incidents, sites, personnel, assessments, documents). We process this on your instruction as a processor.
  • Usage & technical data — log data, IP address, device/browser, and audit events, used for security, debugging, and abuse prevention.
  • Communications — messages you send us (e.g. a demo request or support ticket).

We do not sell personal data, and we do not use customer content to train AI models.

3.Why we process it (legal bases)

  • To provide the platform and fulfil our contract with your organisation (performance of a contract).
  • To secure the service, prevent abuse, and keep an audit trail (legitimate interests / legal obligation).
  • To communicate with you about the service (contract / legitimate interests).
  • Where required, on the basis of your consent — which you may withdraw at any time.

Under the GCC PDPL and EU GDPR, we rely on the equivalent lawful bases and honour the data-subject rights described below.

4.Sub-processors

We use vetted third parties to run the service. Each is bound by data-protection terms:

ProviderPurposeLocation
Hetzner Online GmbHApplication hosting & deliveryGermany (EU)
Supabase (PostgreSQL)Primary database & file storageEU
Clerk Inc.Authentication & identityUSA (SCCs)
OpenAIAI assistant (Keva) — features you opt intoUSA (SCCs, no training on your data)
AnthropicAI assistant (Keva) — features you opt intoUSA (SCCs, no training on your data)
ResendTransactional & alert emailUSA (SCCs)
LemonSqueezyBilling & payment processingUSA (SCCs)
Sentry (Functional Software, Inc.)Error & performance monitoring (PII disabled)USA (SCCs)

International transfers are covered by Standard Contractual Clauses or an equivalent safeguard.

5.Cookies

We use only strictly necessary cookies: authentication and session cookies set by our identity provider, and security cookies that protect the service. We do not use advertising, analytics, or cross-site tracking cookies on our public pages, which is why you see no cookie banner. If that ever changes, we will ask for consent first.

6.How long we keep it

We retain customer content for the life of your subscription and delete or return it within 30 days of termination, unless a longer period is legally required. Logs and audit records are retained for a limited period for security and compliance.

7.Your rights

  • Access, correct, or delete your personal data.
  • Object to or restrict certain processing, and request portability.
  • Withdraw consent where processing is based on it.
  • Lodge a complaint with your supervisory authority.

If your data lives in a customer’s workspace, please raise the request with that organisation; we will assist them as their processor. Otherwise contact privacy@sekurad.com.

8.Security

We apply tenant isolation at the database level, encryption in transit and at rest, least-privilege access, and full audit logging. See our Security & Trust page for detail.

9.Changes

We may update this policy; material changes will be notified in-app or by email. Continued use after the effective date constitutes acceptance.