Privacy

Privacy Policy

Effective Date:

1. Introduction

WASViking LLC ("WASViking", "we", "our", or "us") is committed to protecting the privacy of its users and customers. This Privacy Policy describes how we collect, use, store, share, and safeguard personal and technical data when you access or use our web application security services, platform, website, or interact with us.

This policy applies to:

  • The WASViking platform (SaaS web application, API, CLI)
  • Our public websites and customer support channels
  • Communications and emails with you

By using our services, you agree to the collection and use of information in accordance with this policy.

1.1 Definitions

"Customer Content" refers to the information the customer submits to the platform for security analysis. Depending on the features used, this includes: domains, IP addresses, URLs, APIs, and certificates; mobile application packages (such as APK and IPA files) uploaded for Mobile Security Assessment, which may contain embedded secrets; software bills of materials (SBOM) and dependency inventories; credentials and session material the customer provides or records for authenticated scanning; integration credentials for services the customer connects (such as issue trackers, chat tools, cloud providers, and identity providers); identity and directory information synchronized from the customer's identity provider; endpoint telemetry generated by the AI Guardian module, as described in the AI Guardian Browser Extension Privacy Policy; and technical metadata produced by scans, such as open ports, headers, TLS configurations, vulnerability indicators, evidence captures, and screenshots of scanned assets.

Depending on the features used (including Exposure Intelligence), Customer Content or related analysis may involve identifiers such as email addresses, usernames, or other data elements that could be considered personal data under applicable laws.

2. Information We Collect

We may collect the following categories of data:

a) Information You Provide to Us

  • Name, email address, company name
  • Billing information (if applicable)
  • Authentication credentials (e.g., passwords, API tokens)
  • Support messages, feedback, or requests

b) Information Collected Automatically

  • IP address, device type, browser type
  • Access logs and activity within the platform
  • Timestamps of logins, scans, report generation
  • Usage metadata (e.g., scan type, number of assets)

c) Scan and Security Data (Customer Content)

  • Targets submitted by you (e.g., domains, IPs, APIs)
  • Security headers, certificate metadata, open ports
  • HTTP/TLS responses, vulnerability indicators
  • Logs and payloads related to scan activity

d) Exposure Intelligence Data

  • Data obtained from publicly available sources or third-party datasets related to security incidents
  • Identifiers such as email addresses, usernames, or associated metadata
  • Credential exposure indicators and related risk signals

This data is processed strictly for legitimate security purposes, including risk identification, threat analysis, and exposure monitoring, and is limited to domains and assets under the Customer’s control.

Note: You are responsible for ensuring that you have a valid legal basis to monitor and process such data in accordance with applicable data protection and privacy laws.

3. How We Use Your Information

We use your data to:

  • Provide and maintain the WASViking service
  • Authenticate users and manage access
  • Generate vulnerability and certificate reports
  • Detect abuse and prevent unauthorized scans
  • Communicate with you (e.g., updates, alerts, support)
  • Improve and secure our platform

We do not use your scan data for marketing or unrelated analytics.

Some analysis features are assisted by a third-party artificial intelligence provider listed on our Subprocessors page. Content sent to that provider is limited to what the feature needs, and voluntary data sharing for model training is disabled on our account. These features are part of how certain platform modules work.

If you are located in the EU or UK, we process your data based on:

  • Contractual necessity: to provide our services
  • Legitimate interest: to ensure platform security and prevent abuse
  • Legal obligation: when required by law
  • Consent: for specific features or communications, where applicable

If you are located in Brazil, we process personal data under the legal bases permitted by the Brazilian General Data Protection Law (LGPD – Law No. 13,709/2018), including:

  • Consent provided by the user (when applicable);
  • Fulfillment of contract or pre-contractual measures;
  • Legitimate interest in ensuring platform security and performance;
  • Compliance with legal or regulatory obligations.

If you are a California resident, WASViking complies with the California Consumer Privacy Act (CCPA – Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act (CPRA). We do not sell or share personal data as those terms are defined by the CCPA. You have the right to know, correct, delete, and opt out of certain data uses as defined by the CCPA.

5. Data Sharing and Disclosure

We do not sell or rent your personal data.

We may share information with:

  • Cloud infrastructure providers (e.g., AWS) for secure hosting
  • Authorized partners, such as resellers and managed security service providers, where they administer your subscription or environment under an agreement with you; partner access to customer environments is logged by the platform
  • Law enforcement or regulators if legally required
  • Vendors or contractors who support operations (under NDA and DPA)

6. Data Retention and Deletion

  • Scan data is retained while it is needed to provide the service and allow customers to access reports. Certain modules apply plan-based retention windows described in your plan documentation.
  • You may delete targets, mobile assessments, and monitored domains, together with their associated data, from your account dashboard, subject to the deletion controls of your plan.
  • You may request deletion of your organization's data at [email protected]. Upon a verified request, WASViking deletes Customer Data from active systems in accordance with its documented deletion procedures. Limited records may be retained where reasonably necessary for security, fraud prevention, audit integrity, legal compliance, or the establishment, exercise, or defense of legal claims. Residual copies may remain in encrypted backups until they expire through the normal backup retention cycle.
  • Organization account closure. An organization administrator with billing authority can close the organization's account from the portal (User, then Privacy & Data). Confirmation requires a code from an authenticator app and a one-time code sent by e-mail. The account is suspended at once and remains readable for a 60-day reversible window, during which the closure can be cancelled from the same page and the organization's data can be exported. When the window ends, WASViking erases the organization's Customer Data from its active systems, closes the organization's user accounts and delivers a completion record stating the number of records removed. Records required by law survive the erasure for their mandated period only: billing records (7 years), accepted terms and the audit evidence needed for legal claims and fraud prevention (5 years), and the record of the closure itself. Copies held in encrypted backups expire within 7 days on our rotation schedule and are not restored into production; if a backup is restored for disaster recovery within that window, the erased data is deleted again from the restored system. The procedure is described at docs.wasviking.com/security/account-closure-and-data-erasure/.
  • Logs related to abusive or unauthorized activity may be retained for security reasons, limited to the minimum necessary period.

7. Security of Your Information

We implement strong security measures including:

  • TLS 1.2+ encryption in transit
  • Encryption at rest for customer data stored in our managed database platforms
  • Application-level encryption of stored credentials, tokens, and secrets
  • Role-based access control and principle of least privilege
  • Use of the WASViking platform to test our own services
  • Monitoring for abuse and anomalies

8. Your Rights (GDPR/CCPA)

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict certain data uses
  • Request data portability (where applicable)
  • Lodge a complaint with a supervisory authority

If you are located in Brazil, you may also exercise the following rights under the LGPD:

  • Confirmation of the existence of data processing;
  • Access to your personal data;
  • Correction of incomplete, inaccurate or outdated data;
  • Anonymization, blocking, or deletion of unnecessary or excessive data;
  • Data portability to another provider;
  • Revocation of consent and information about its consequences.

To exercise your rights, contact us at: [email protected]

Data Protection Officer (Encarregado de Proteção de Dados, LGPD Art. 41): [email protected]

9. International Data Transfers

WASViking LLC is based in the United States. Personal data may therefore be transferred to and processed in the United States and in other locations in which WASViking's authorized service providers operate.

For personal data subject to the GDPR, WASViking uses applicable international-transfer mechanisms recognized under European data protection law, such as the European Commission Standard Contractual Clauses.

For personal data subject to the Brazilian LGPD, international transfers are conducted in accordance with Article 33 of the LGPD and applicable ANPD regulations, including Resolution CD/ANPD No. 19/2024. Where ANPD Standard Contractual Clauses are used as the applicable transfer mechanism, they are incorporated in accordance with the requirements established by the ANPD.

Additional information about international transfers and subprocessors is available in our Data Processing Agreement and Subprocessors documentation.

10. Cookies and Tracking Technologies

Our marketing website uses a consent banner for non-essential cookies. The platform itself uses only cookies that are strictly necessary for authentication, security, and preferences. Some pages rely on third-party services, such as Google reCAPTCHA on authentication pages, which may process your IP address. See our Cookies Policy for details. We do not use third-party advertising cookies.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Effective Date.” We encourage you to review this page periodically.

12. Contact Us

For any questions or requests regarding this Privacy Policy, contact us at:
WASViking LLC
Orlando, FL, USA
[email protected]

Questions about security or privacy?

Write to the team that owns the answer. Security reviews, data subject requests and contract questions each have a direct address.

Evaluating WASViking? Talk to our team and we will bring the right people to the call.