Effective: August 31, 2026 · Last reviewed: August 31, 2026 · Calculated Ventures, LLC
We receive information directly from users and customer administrators, automatically from use of the Service, and from service providers such as payment, hosting, authentication, email, and infrastructure providers that support the Service.
We use information to provide, process, secure, maintain, troubleshoot, support, bill for, and improve the Service; create and administer accounts; communicate about transactions and service changes; investigate misuse or security incidents; enforce agreements; protect rights and safety; and comply with applicable law. We do not materially expand the purposes for which Customer Content is used without updating this Policy or obtaining additional agreement when required.
Vulnerability scan data can reveal hostnames, addresses, software versions, findings, vulnerabilities, and other sensitive system details. Upload only data you are authorized to process. Sanitize demonstrations and sales examples when practical. Do not upload classified information, CUI, export-controlled technical data, credentials, private keys, PHI, payment-card data, malware samples, or other prohibited/high-risk data unless we expressly authorize that data type in writing for the specific environment.
For Customer Content submitted by or for a business customer, the customer is responsible for determining that it has lawful authority to collect, upload, and direct processing of that content. Calculated Ventures processes Customer Content to provide the Service and for the limited operational purposes described in this Policy and the Terms. For account, billing, security, support, and business-administration information that Calculated Ventures determines how to use, Calculated Ventures may act as an independent business or controller as defined by applicable law. If a particular privacy law requires a separate data-processing agreement for your intended use, contact us before submitting the covered data.
We may disclose information to service providers that support hosting, infrastructure, authentication, payment, email, analytics/security logging, or customer support; to authorized administrators of your organization; at your direction; in connection with a merger, financing, acquisition, or sale of assets; or when reasonably necessary to comply with law, legal process, security obligations, or protection of rights and safety. Service providers are expected to use information only for the services they provide to us and to protect it appropriately.
We do not sell Customer Content or generated customer outputs for advertising. We do not use Customer Content to train generalized public or third-party AI models unless the customer expressly agrees in writing. If these practices change, this Policy must be updated before the changed use begins.
The Service may use session, authentication, security, and preference technologies needed to operate accounts and protect the Service. If we add nonessential advertising or cross-site tracking technologies, we will update this Policy and provide any consent or opt-out mechanism required by applicable law.
We retain information only for as long as reasonably necessary for the purpose collected, to provide and secure the Service, maintain business and security records, comply with law or contract, resolve disputes, and enforce agreements. Customer Content should not be treated as a permanent archive. You may request deletion of Customer Content or account information, subject to identity verification, technical limitations, backup cycles, legal holds, and lawful retention requirements.
We use administrative, technical, and organizational safeguards designed to protect information in light of the nature of the data and the Service. No method of transmission, storage, or security control can guarantee absolute security. You are responsible for protecting your credentials and for using the Service only for data types appropriate to the environment.
If we determine that a security incident involving information processed through the Service requires notice under applicable law or a binding contract, we will provide the required notice to affected customers, individuals, or authorities in the manner and timeframe required. Customers remain responsible for any separate notice or reporting duties that apply to their systems, contracts, or uploaded data.
The Service is operated primarily from the United States. If you access it from another country, information may be processed and stored in the United States or other locations used by our service providers. If your intended use requires GDPR, UK GDPR, data-localization, government-sovereignty, or another special cross-border data regime, contact us before uploading covered data so that the parties can determine whether the Service and any required contractual safeguards are appropriate.
Depending on where you live and which privacy laws apply, you may have rights to request access, correction, deletion, or information about certain processing. Submit requests to inquiry@calculatedit.com. We may need to verify identity or authority and may deny or limit a request where law permits or requires retention.
The Service is a business cybersecurity tool and is not directed to children under 18. We do not knowingly seek personal information from children through the Service.
We may update this Policy as the Service, vendors, or legal requirements change. The effective date above will be revised when we do. Material changes will be communicated through the Service, email, or another reasonable method when appropriate.
Privacy questions or requests: inquiry@calculatedit.com.