Scope
This Privacy Policy applies to information Torchsec Technologies, LLC ("Torchsec," "we," "us") collects through torchsec.com, through direct communications with prospects and clients, and through the systems we operate on behalf of our managed-service clients under a signed Master Services Agreement (MSA).
Data we process on behalf of a client — endpoint telemetry, SIEM events, identity logs, and similar — is governed by that client's MSA and our Data Processing Addendum, not this public-facing policy. This page covers the information we collect about visitors, prospects, and client administrative contacts.
Information we collect
Information you provide
- Contact forms & assessments. Name, business email, company, phone, and whatever you write in the message field when you reach out or request a free security assessment.
- Client onboarding. Billing contacts, authorized administrator details, and technical points of contact needed to deliver services.
- Support communications. Emails, tickets, and call notes when you contact Sales & Support.
Information collected automatically
- Log data. IP address, user-agent, referrer, requested URL, and timestamp — kept for security monitoring and abuse prevention.
- Visitor identification. For security and business-development purposes, we use third-party services (such as ipinfo.io and Dealfront/Leadfeeder) to identify the organization or network associated with a visitor's IP address, and we may notify our team of business-network visits. This identifies companies and approximate locations — not individuals — is not used for advertising, and may set cookies for the website-visitor analytics. You can opt out of cookies as described under Cookies & tracking.
- Site analytics. With your consent, we use product analytics (PostHog) to understand which pages and features are useful and to improve the site. This may capture page views, clicks, approximate location (from IP), and device/browser details. We do not build advertising profiles, do not sell this data, and you can decline (see Cookies & tracking).
- Cookies. A strictly-necessary set to operate the site, plus optional analytics cookies that load only after you accept (see Cookies & tracking).
Client portal (Singular)
If you have an account on our client portal at singular.torchsec.com, we record the following while you are signed in. This is authenticated, first-party operational logging — it is strictly necessary to run a secure portal, so it is not covered by the site's optional analytics consent, and it is never used for advertising or sold.
- Account details. Your name, email address, job title, and the client organization your account is authorized to see.
- Sign-in events. The time of each successful sign-in, the IP address it came from, and whether multi-factor authentication was used. Retained for 24 hours.
- Session activity. While the portal is open in front of you, it sends a periodic heartbeat so our team can see who is currently working in the portal. That heartbeat records the screen you are on (for example "Tickets" or "Backups"), your browser and operating system, your IP address, when your session began, and when you were last active. This record expires roughly five minutes after your last activity and is not retained as a history.
- Administrative actions. Actions taken in the portal — creating or changing tickets, changing user access, exporting data — are written to an audit log with the acting account and IP address. Retained for 90 days.
We use this to operate and support the portal, to help you when you contact us about something you were doing in it, and to detect unauthorized access to your account. If you would like to know what we currently hold about your portal account, ask us using the details under Contact us.
Information from third parties
- Publicly-available business information when we're researching a prospective client (company name, industry, size).
- Information passed to us by partners with your consent — for example, when you start a security assessment through a partner tool.
How we use your information
We use the information above for a narrow set of purposes:
- Respond to inquiries and deliver the assessments, proposals, or support you've asked for.
- Deliver contracted services — monitoring, incident response, compliance engineering, IT operations.
- Operate and secure the site, including detecting abuse and fraud.
- Improve our services using aggregate, de-identified usage data.
- Comply with legal obligations, enforce our contracts, and protect our legal rights.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
Data retention
We keep information only as long as we need it for the purpose we collected it, plus a reasonable period to meet legal, tax, and contractual obligations. Typical retention periods:
- Sales and prospect contact forms: up to 24 months from last interaction.
- Client administrative records: duration of the relationship plus 7 years.
- Security and access logs: 12 months rolling, longer where required by framework (e.g., HIPAA, CMMC).
- Client portal: live session activity expires about 5 minutes after you stop using it; sign-in events 24 hours; the portal audit log 90 days.
- Billing records: 7 years for tax and audit purposes.
How we protect information
We eat our own cooking. The same controls we build for clients — MFA, least-privilege access, endpoint protection, encrypted-in-transit and at-rest data, 24/7 monitoring, documented incident response — we apply to our own systems.
No system is perfectly secure. We'll notify affected clients and, where required, regulators and individuals without undue delay if we discover a breach of personal information we hold.
Your rights & choices
Depending on where you live, you may have the right to:
- Access a copy of the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete information, subject to legal and contractual retention requirements.
- Restrict or object to certain processing.
- Opt out of marketing emails (use the unsubscribe link in any message).
- Lodge a complaint with a data protection authority in your jurisdiction.
To exercise any of these, email privacy@torchsec.com. We'll verify your identity before acting and respond within 30 days (or as required by applicable law).
California residents (CCPA/CPRA)
California residents have additional rights, including the right to know the categories of personal information we collect and the right to non-discrimination for exercising privacy rights. We do not sell personal information and do not share it for cross-context behavioral advertising.
Children's privacy
Torchsec's services are sold to businesses, not individuals. The site is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@torchsec.com and we'll delete it.
Changes to this policy
We'll update this policy as our practices evolve. Material changes will be posted here with a new "Last updated" date; for significant changes affecting client data, we'll also notify your designated administrative contact.
Contact us
Questions, requests, or concerns about this policy can go to our privacy team: