legal

Privacy Policy

Last updated: 2026-07-17. Governing law: Israel.

Privacy Policy

This Privacy Policy explains how EyalSec, of Yehoshua Stampfer 39, Petah Tikva, Israel ("EyalSec", "we", "us"), handles personal data in connection with the EyalSec / es2 platform, the web dashboard, the agent API, and the es-python interpreter (the "Service").

It applies to (a) account holders and visitors, for whom we are the controller, and (b) the security-event data our customers send us through es-python, which we process as a processor on the customer's behalf.


1. Who we are and our roles

EyalSec plays two distinct roles:

Contact: eyal@eyalsec.com.

2. What data we collect

(a) Account, login, and billing data (controller). Email address, username, hashed password, two-factor/authentication settings, API keys (hashed), plan/role, and billing/transaction records (payment processing may be handled by a payment provider).

(b) Web analytics (controller). Self-hosted, anonymous analytics about use of our public pages and dashboard, e.g., page views, client metrics, JavaScript errors, a hashed visitor identifier, and (only if the operator enables a MaxMind GeoIP database) a coarse country. Analytics can be disabled by the operator and are subject to sampling and a retention window.

(c) Event Payloads (processor). Security events reported by es-python from the customer's own monitored machines. Important: Event Payloads can contain personal data and secrets (for example passwords, tokens, keys, or other sensitive runtime values) extracted from the customer's process memory. Customers control what they monitor and should minimize the capture of unnecessary sensitive data (see the DPA and the Acceptable Use Policy).

(d) Technical/operational data. Server logs, IP addresses (used for security, IP access-control, and abuse prevention), and similar metadata.

3. Purposes and lawful bases (GDPR Arts 6, 13–14)

| Data | Purpose | Lawful basis (GDPR Art. 6) | |------|---------|----------------------------| | Account/login/billing | Create and manage your account; authenticate; provide and bill the Service | Performance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) | | Transactional email (via Amazon SES) | Password reset, invitations, service notices | Performance of a contract; legitimate interests (Art. 6(1)(f)) | | Web analytics | Understand and improve the Service; diagnose errors | Legitimate interests (Art. 6(1)(f)); consent where required | | Event Payloads | Provide the monitoring/reporting Service to the customer | Processed on the customer's documented instructions as processor; the customer's own lawful basis applies | | Logs / IP / security | Secure the Service, prevent abuse, enforce IP access control | Legitimate interests (Art. 6(1)(f)); legal obligation |

Where we rely on legitimate interests, we have balanced those interests against your rights. You may object (Section 8). Where consent is the basis, you may withdraw it at any time.

4. Recipients and sub-processors

We share personal data with service providers who help us run the Service. Our current sub-processors are listed at /legal/subprocessors and include Amazon Web Services (hosting), Amazon SES (transactional email), and, only if the operator enables it, MaxMind (GeoIP). We may also disclose data to comply with law, enforce our agreements, or protect rights, safety, and security. We do not sell personal data.

5. International transfers

The Service is hosted on Amazon Web Services in the il-central-1 (Israel) region. Personal data may be processed in, or transferred to, countries outside the EEA or the UK. Where we transfer personal data out of the EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum for UK transfers), together with any necessary supplementary measures. Israel benefits from an EU adequacy decision. A copy of the relevant safeguards is available on request at eyal@eyalsec.com.

6. Retention

7. Security

We use technical and organizational measures appropriate to the risk (GDPR Art. 32), including encryption in transit (TLS/HTTPS) and encryption at rest for hosted data (AWS-managed encryption of the underlying EBS storage), access controls, hashed passwords and API keys, secrets management, IP access control, and least-privilege practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

8. Your rights

Subject to applicable law, you have the right to access, rectify, erase ("right to be forgotten"), restrict or object to processing, and port your personal data, and to withdraw consent where processing is based on consent. In particular:

For Event Payloads, we act as a processor: please direct data-subject requests to the relevant customer (controller); we will assist the customer as required by the DPA.

9. GDPR Articles 13–14 disclosures

In addition to the above, EU/EEA data subjects are informed that: the controller is EyalSec (for account/analytics) or the customer (for Event Payloads); processing is for the purposes and on the bases in Section 3; recipients are in Section 4; transfers and safeguards are in Section 5; retention is in Section 6; you have the rights in Section 8; you may lodge a complaint with a supervisory authority (Section 11); and provision of account data is necessary to enter into and perform the contract. We do not use the personal data described here for solely automated decision-making with legal or similarly significant effects.

10. Israel Privacy Protection Law

For data subjects and processing in Israel, we comply with the Privacy Protection Law, 5741-1981 and its regulations (including the Privacy Protection (Data Security) Regulations, 5777-2017). We also account for the modernization introduced by Amendment 13 (2024/2025), which strengthens definitions (including expanded "personal information" and sensitive-data concepts), enforcement, and accountability obligations of the Israeli Privacy Protection Authority (PPA). Israeli residents may exercise their rights of access and correction and may contact the PPA.

11. Complaints and supervisory authorities

You may contact us first at eyal@eyalsec.com. You also have the right to lodge a complaint with a supervisory authority:

12. US privacy notice (CCPA / CPRA and other state laws)

For California residents (and, by analogy, residents of other US states with comparable laws):

13. Children

The Service is not directed to children, and we do not knowingly collect personal data from children below the age of digital consent in your jurisdiction. If you believe a child has provided us personal data, contact us and we will delete it.

14. Changes

We may update this Policy. We will post the updated version and, for material changes, give reasonable notice. The "Last updated" date above will change accordingly.

EyalSec Pricing Docs Security Login Start free