Privacy Policy
Last updated: May 17, 2026
This policy describes how ThreatLynx collects, uses, and protects information when you use our website and platform.
Information we collect
Account information: When you sign in with Google via NextAuth, we receive your name, email address, and profile image as provided by your identity provider.
Form submissions: Demo and trial requests include contact details you provide (name, email, company, and related fields).
Workspace data: When you connect Google Workspace or Microsoft 365, we process application registration information, OAuth permission scope metadata, and user-authorisation records necessary for shadow IT discovery. We do not read, access, or store the content of your emails, files, documents, or messages. We do not sell this data.
Technical data: Standard server logs (IP address, browser type, timestamps) may be collected for security and reliability.
How we use information
To authenticate you and provide access to the ThreatLynx dashboard.
To operate discovery, risk assessment, and governance features you enable.
To respond to demo, trial, and support requests.
To improve the product and maintain security of our services.
Legal basis & retention
We process data based on contract performance, legitimate interest in securing your organization’s SaaS footprint, and consent where required (e.g. marketing follow-up).
We retain data according to your subscription terms and applicable law. You may request deletion of personal data by contacting us.
Sharing & subprocessors
We do not sell personal information. We may use infrastructure providers (hosting, email) that process data on our behalf under contractual safeguards.
Current subprocessors: Resend (US) — transactional email; Stripe (US) — billing and payments; Vercel — web hosting; Neon — database hosting. Customer security telemetry is hosted in Australia (Sydney) as our intended primary region: database and hosting regions are pinned to Australia at deploy time, and residency is confirmed as part of each customer deployment.
Integrations you authorize (Google, Microsoft) are governed by those providers’ terms in addition to this policy.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing.
To exercise these rights, contact privacy@threatlynx.com.au. We will respond within applicable legal timeframes.
Contact
Questions about this policy: privacy@threatlynx.com.au