Privacy

Privacy policy

How we collect, use, and protect your information.

Last updated: June 7, 2026 | Effective February 19, 2026

Our Commitment to Privacy

At Nautillo Pro, we understand that trust is fundamental to our relationship with you. As a cybersecurity platform, we are committed to protecting your privacy and maintaining the highest standards of data security. This Privacy Policy explains how we collect, use, protect, and share your information when you use our attack simulation platform.

If you are evaluating the platform, you can start with a free account and review how your simulation data and evidence are handled before upgrading.

Create a free account and start your first authorized scan.

Information We Collect

Account Information: Name, email address, company details, and billing information when you create an account.

Usage Data: Information about how you use our platform, including simulation history, verified domains, and feature usage.

Technical Data: IP addresses, browser types, device information, and system logs for security and performance monitoring.

Simulation Data: URLs, domain information, and security findings from your authorized simulations (processed and stored securely).

Consent & Authorization Records: Typed authorization statements, intrusive-test consent records, and signed audit logs tied to your account. Optional domain ownership verification records where domain DNS verification has been completed.

AI Interaction Data (optional): Prompts and contextual information supplied to AI-guided features when explicitly enabled on Business plans.

Communication Data: Messages, support tickets, and feedback you send to us.

How We Use Your Information

Provide and improve our attack simulation platform and safety controls.

Process payments and manage your account subscription and billing.

Send important service updates, security alerts, and account notifications.

Provide customer support and respond to your inquiries and requests.

Analyze usage patterns to improve our platform performance and user experience using internal telemetry.

Deliver AI-assisted analysis and recommendations when this feature is enabled, subject to contractual safeguards with sub-processors.

Detect and prevent fraud, abuse, and security threats to our platform.

Comply with legal obligations and enforce our Terms of Service.

Information Security

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Regular security audits and penetration testing are performed on our own infrastructure.

Simulation data is isolated per customer and subject to plan-based retention policies.

We follow industry security best practices and standards.

Access to customer data is restricted to authorized personnel on a need-to-know basis.

We use secure cloud infrastructure with redundancy and backup systems.

Information Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes.

Service Providers: We may share data with trusted third-party providers (payment processors, cloud hosting) under strict data protection agreements.

Analytics Provider: Cloudflare Web Analytics processes limited website usage data on our behalf under data protection terms.

AI Vendors: When AI-guided features are enabled (Business plan), structured prompts and scan metadata are transmitted to OpenAI, Inc. (US) under Standard Contractual Clauses and a data processing agreement. When AI Code Analysis is enabled, JavaScript bundle content from the target application (up to 8,000 characters, truncated) may be included in prompts to detect hardcoded secrets and authorization flaws. Full HTML page responses and API response bodies are not sent to OpenAI. Customer data submitted to OpenAI via our API is not used to train AI models; model training is disabled in our OpenAI account settings, and OpenAI's API usage policy prohibits using API inputs for training by default.

Legal Requirements: We may disclose information when required by law, court order, or to protect our rights and safety.

Business Transfers: In case of merger or acquisition, your information may be transferred to the new entity.

Your Consent: We may share information with your explicit consent for specific purposes.

Anonymized Data: We may use aggregated, anonymized data for research and industry reports.

We do not sell personal information or share it for cross-context behavioral advertising.

Data Retention

Account data is retained for the duration of your active subscription plus 30 days unless you request earlier deletion.

Simulation results: Starter (30 days), Professional (up to 12 months), Business (up to 24 months) in line with our published retention schedule.

Simulation evidence (HTTP captures, payloads): Starter (7 days), Professional (30 days), Business (60 days); uploaded files are purged immediately after analysis.

Audit and consent logs are retained for up to 36 months to comply with legal and contractual obligations.

Billing and transaction records are kept for at least 7 years as required by financial regulations via our payment processor.

Support communications are retained for up to 2 years depending on your plan for service continuity.

System logs are retained between 14 and 60 days depending on plan tier for security monitoring.

Authentication credentials supplied for simulations are encrypted with AES-256-GCM, stored server-side for the duration of the scan only (maximum 24 hours), then automatically and permanently deleted. Credentials are never exposed to the client, never logged, and never included in reports.

You can request deletion of your data at any time by contacting our support team.

Some data may be retained longer if required by legal obligations or legitimate business interests.

Your Rights

Access: Request a copy of the personal information we hold about you.

Correction: Request correction of inaccurate or incomplete personal information.

Deletion: Request deletion of your personal information (subject to legal requirements).

Portability: Request transfer of your data to another service provider in a standard format.

Objection: Object to processing of your personal information for certain purposes.

Restriction: Request restriction of processing in certain circumstances.

Withdraw Consent: Withdraw consent for data processing where consent was the legal basis.

Opt-Out: You may opt out of marketing emails at any time.

Cookies, Local Storage, and Tracking

Necessary Storage: We use cookies, local storage, and session storage required for login, security, and billing functionality.

Cookie-free Analytics: We use Cloudflare Web Analytics to understand website usage. It loads a third-party script and processes IP address, user agent, referrer, page URL, and timestamps in aggregated form.

We do not use advertising pixels or cross-site tracking cookies.

We track usage events internally to improve the platform, never customer content or security data.

Paid plans: We will add in-product opt-out controls for internal telemetry in a future release.

GDPR and International Users

For users in the European Union, we comply with the General Data Protection Regulation (GDPR). Our legal basis for processing your data includes:

  • Contract Performance: Processing necessary to provide our services
  • Legitimate Interest: Improving our services and platform security
  • Legal Compliance: Meeting regulatory and legal requirements
  • Consent: Optional features that require explicit user choice

EU residents can contact our privacy team at support@nautillo.pro for any privacy-related inquiries or to exercise their rights under GDPR.

You also have the right to lodge a complaint with your local supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

A Data Processing Addendum (DPA) incorporating Standard Contractual Clauses is available on our DPA page. Email support@nautillo.pro to request a countersigned copy prior to uploading personal data.

Our Data Processors & Hosting

Personal data (account information, scan results, authentication) is stored and processed through Supabase — a managed database, authentication, and storage provider hosted in the EU (Frankfurt region). Supabase holds its own SOC 2 Type II certification and operates under a GDPR-compliant data processing agreement with us.

The platform frontend is hosted and delivered via Cloudflare (Cloudflare Pages, Workers, CDN, and DNS). Cloudflare Pages serves public assets (HTML, CSS, JavaScript). Cloudflare Workers proxy API requests to Supabase — API traffic (including authentication tokens) transits through Cloudflare infrastructure but no personal data is stored on Cloudflare systems. Cloudflare also provides cookie-free aggregated analytics. Cloudflare operates under Standard Contractual Clauses for EU data transfers.

Nautillo Pro itself has not undergone SOC 2, ISO 27001, or PCI DSS certification. We apply the technical controls described in this policy and our Data Processing Addendum and are working toward formal certification. Personal data will not be transferred outside the EU without appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

California Privacy Rights (CCPA)

If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA. These rights include:

  • Right to Know: Request disclosure of the personal information we collect, use, and share.
  • Right to Delete: Ask us to delete personal information we hold about you, subject to legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out: Direct us not to sell or share your personal information. We do not sell personal data for monetary consideration.
  • Right to Non-Discrimination: Receive equal service and price even if you exercise your privacy rights.

To submit a CCPA request, email support@nautillo.pro with the subject line "CCPA Request". We will verify your identity before fulfilling a request and respond within the timelines required by California law. Authorized agents may submit requests on your behalf when accompanied by a signed permission letter.

You may opt-out of marketing emails at any time by using the unsubscribe link in our communications or contacting support@nautillo.pro.

Contact Us

Privacy Questions

Email: support@nautillo.pro

Response Time: Within 48 hours

Available: Monday – Friday, 9 AM – 6 PM EET/EEST

Mailing Address

NØRTH HŪMAN OÜ
Privacy Department
Harju maakond, Tallinn, Kesklinna linnaosa
Tornimäe tn 5, 10145
Estonia

Policy updates

We may update this Privacy Policy from time to time. We will notify you of any material changes by email and by posting the updated policy on our website. Your continued use of our services after such modifications constitutes acceptance of the updated Privacy Policy.