Last updated: 2026-09-11. Governing law: Israel.
Privacy Policy
This Privacy Policy explains how Eyal Gabay, trading as "EyalSec", a sole proprietor (osek murshe) registered in Israel under no. 211868450, of Yehoshua Stampfer 39, Petah Tikva, Israel ("EyalSec", "we", "us"), handles personal data in connection with the EyalSec / es2 platform, the web dashboard, the agent API, and the EyalSec agents (the es-python runtime, the es-chromium browser, and the es-c, es-cpp, es-rust, es-node, es-solidity, es-bash and es-php agents) (together, the "Service").
It applies to (a) account holders and visitors, for whom we are the controller, and (b) the security-event data our customers send us through those agents, which we process as a processor on the customer's behalf.
Contact for all privacy matters: eyal@eyalsec.com.
1. Who we are and our roles
EyalSec plays two distinct roles:
- Controller: for account, login, and billing data, for transactional email, and for our self-hosted web analytics. We decide why and how this data is processed.
- Processor: for Event Payloads sent by the agents (the fields
where,repr,trace,location,origin). The customer who deploys the agent is the controller of that data; we process it only to provide the Service, under the Data Processing Agreement (/legal/dpa). This Policy describes that processing for transparency, but the customer's own privacy notice governs the underlying personal data.
If your employer or another organization deployed an EyalSec agent on a machine or browser you use, that organization is the controller, not us. Direct your questions and requests to them in the first instance; Section 9 explains what we can and cannot do.
2. What data we collect
(a) Account, login, and billing data (controller). Email address, username, hashed password, two-factor and authentication settings, API keys (stored hashed), access level and capabilities, and billing and transaction records. Payment processing may be handled by a payment provider. If you sign in with Google, where that option is offered, we receive the email address on your Google account and whether Google has verified it; we store no Google password or token.
(b) Web analytics (controller). Self-hosted, anonymous analytics about use of our public pages and dashboard: page views, client performance metrics, JavaScript errors, a hashed visitor identifier, and, only if the operator enables a MaxMind GeoIP database, a coarse country. Analytics can be disabled by the operator and are subject to sampling and a retention window. We do not use third-party advertising or cross-site tracking.
(c) Event Payloads (processor). Security events reported by the EyalSec agents from the customer's own monitored machines, browsers and services.
Important: Event Payloads can contain personal data and secrets. Because the agents observe values as a program runs, an Event Payload can include passwords, tokens, keys, identifiers, the contents of variables, file paths, and other sensitive runtime values drawn from the customer's own processes.
(d) Browsing Data (processor), where es-chromium is deployed. es-chromium reports on pages browsed on the machines the customer monitors. Its Event Payloads can additionally contain:
- page URLs, including any personal data, identifiers, session values or search terms carried in a URL or its query string;
- values present in the page, including values a person typed into it;
- the call site in the page's own code where the value was used;
- an inventory of installed browser extensions (extension identifier, name and version), and an indication of which extension a report is attributed to.
Browsing Data reveals what a person did in a browser. It is the most sensitive category the Service handles. Customers control what they monitor, must have a lawful basis and the required notices and consents in place before deploying es-chromium (Section 7 of the Terms and Section 2 of the AUP), and should minimize the capture of unnecessary sensitive data.
(e) Technical and operational data. Server logs, IP addresses (used for security, IP access control, and abuse prevention), request metadata, and captured server errors.
(f) Communications. Messages you send us through the contact form, pricing enquiries, and support email.
3. Cookies and similar technologies
We use a small number of cookies and none of them are for advertising, profiling or cross-site tracking:
| Cookie | Purpose | Type |
|--------|---------|------|
| Session cookie | Keeps you signed in to the dashboard | Strictly necessary |
| csrftoken | Protects form submissions against cross-site request forgery | Strictly necessary |
Strictly necessary cookies are set without consent because the Service cannot be provided without them; you can block them in your browser, but you will not be able to sign in. Our analytics set no cookie: the visitor identifier in Section 2(b) is computed on our server from a daily-rotating, salted hash of the IP address and browser user agent, and the raw IP address is not stored with it. The analytics are self-hosted and first-party, and the operator can disable them entirely (Section 2(b)). We set no third-party cookies ourselves and we do not sell or share personal data for advertising. Where a CAPTCHA service is enabled on our sign-in, two-factor, password-reset, registration, invitation and contact forms, that provider's script loads on those pages and may set or read the provider's own cookies (Section 5).
4. Purposes and lawful bases (GDPR Arts 6, 13-14)
| Data | Purpose | Lawful basis (GDPR Art. 6) | |------|---------|----------------------------| | Account/login/billing | Create and manage your account; authenticate; provide and bill the Service | Performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting (Art. 6(1)(c)) | | Transactional email | Password reset, invitations, service notices | Performance of a contract; legitimate interests (Art. 6(1)(f)) | | Web analytics | Understand and improve the Service; diagnose errors | Legitimate interests (Art. 6(1)(f)); consent where required | | Event Payloads and Browsing Data | Provide the monitoring and reporting Service to the customer | Processed on the customer's documented instructions as processor; the customer's own lawful basis applies | | Logs / IP / security | Secure the Service, prevent abuse, enforce IP access control | Legitimate interests (Art. 6(1)(f)); legal obligation | | Sanctions and denied-party screening | Comply with export-control and sanctions law | Legal obligation (Art. 6(1)(c)); legitimate interests |
Where we rely on legitimate interests, we have balanced those interests against your rights; you may object (Section 9). Where consent is the basis, you may withdraw it at any time.
5. Recipients and sub-processors
We share personal data with service providers who help us run the Service. Our current
sub-processors are listed at /legal/subprocessors and include Amazon Web Services
(hosting) and Amazon SES (transactional email). Optional GeoIP enrichment uses a MaxMind
database file held on our own server, so no data is sent to MaxMind. Where a CAPTCHA service
(Google reCAPTCHA, Cloudflare Turnstile or hCaptcha) is enabled, its provider receives the IP
address and browser information of visitors to the forms listed in Section 3, to protect
them against automated abuse. We may also disclose data to comply with law, to respond to a
lawful request from a public authority, to enforce our agreements, or to protect rights,
safety and security.
We do not sell personal data, and we do not share it for behavioural advertising. We do not use the content of Event Payloads or Browsing Data for any purpose other than providing the Service to the customer who sent them (Terms, Section 20(c)).
6. International transfers
The Service is hosted on Amazon Web Services in the il-central-1 (Israel) region. Transactional email is delivered through an Amazon SES endpoint in the EU.
Israel benefits from an EU adequacy decision, most recently reaffirmed by the European Commission in January 2024, so transfers of personal data from the EEA to EyalSec in Israel do not require additional safeguards. Where we nonetheless transfer personal data out of the EEA or the UK to a country without an adequacy decision, we rely on appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum, together with any necessary supplementary measures. A copy of the relevant safeguards is available on request at eyal@eyalsec.com. Adequacy decisions are periodically reviewed; if Israel's status changes we will move to the SCCs and update this Policy.
7. Retention
- Account data: kept while your account is active and for a reasonable period afterwards, then deleted, subject to legal retention (for example tax and accounting records, which Israeli law requires us to keep for seven years).
- Event Payloads and Browsing Data: kept until the customer deletes them. Deleting a machine deletes its Events, and deleting the account cascade-deletes all of them. The operator can also set a service-wide event retention window after which events are automatically deleted. Deleted or returned on termination, per the DPA.
- Web analytics: retained for a limited, operator-configurable window (default measured in days) and then deleted by an automated sweeper.
- Security incidents, captured errors and operational records: retained for limited, operator-configurable periods and then automatically deleted.
- Logs: kept for a limited period for security and operational purposes.
- Backups: purged on our standard rotation cycle, so a deleted record can persist in an encrypted backup for a short period after deletion.
8. Security
We use technical and organizational measures appropriate to the risk (GDPR Art. 32),
including encryption in transit (TLS/HTTPS) and encryption at rest, access controls,
hashed passwords and API keys, per-machine credentials, secrets management, IP access
control, and least-privilege practices. Our security measures are described in detail at
/legal/security, which also serves as Annex II to the DPA.
If we become aware of a personal data breach affecting a customer's data, we notify that customer without undue delay (DPA, Section 6(f)). Where we are the controller, we notify affected individuals and the competent supervisory authority as the law requires.
No method of transmission or storage is completely secure; we cannot guarantee absolute
security. To report a suspected vulnerability, see /legal/vulnerability-disclosure.
9. Your rights
Subject to applicable law, you have the right to access, rectify, erase ("right to be forgotten"), restrict or object to processing, and port your personal data, and to withdraw consent where processing is based on consent. In particular:
- Self-serve erasure. You can delete your account and all associated data from Settings; this cascade-deletes your machines, Events and filters, and is irreversible.
- Export. You can export your Events from the dashboard and the API.
- To exercise other rights, contact eyal@eyalsec.com. We will respond within the time required by law (generally one month under the GDPR). We may need to verify your identity.
- Exercising a right is free; we may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.
For Event Payloads and Browsing Data we act as a processor. If you are an individual whose data appears in them (for example an employee of one of our customers), please direct your request to the customer who deployed the agent; they are the controller and they hold the context needed to answer you. If you contact us, we will refer you to them and will assist them as the DPA requires. We will not disclose a customer's event data to a third party who asks for it.
10. GDPR Articles 13-14 disclosures and EU/UK representation
EU/EEA data subjects are informed that: the controller is EyalSec (for account, analytics and communications) or the customer (for Event Payloads and Browsing Data); processing is for the purposes and on the bases in Section 4; recipients are in Section 5; transfers and safeguards are in Section 6; retention is in Section 7; your rights are in Section 9; you may lodge a complaint with a supervisory authority (Section 12); and provision of account data is necessary to enter into and perform the contract. We do not use the personal data described here for solely automated decision-making with legal or similarly significant effects, and we do not carry out profiling of visitors or account holders.
Representatives. EyalSec is established in Israel and has no establishment in the EEA or the UK. Where GDPR Article 27 or UK GDPR Article 27 requires us to designate a representative in the Union or the United Kingdom, we will designate one and publish the contact details on this page. Until a representative is published, contact us directly at eyal@eyalsec.com; this does not affect your right to complain to your own supervisory authority.
11. Israel Privacy Protection Law
For data subjects and processing in Israel, we comply with the Privacy Protection Law, 5741-1981 and its regulations, including the Privacy Protection (Data Security) Regulations, 5777-2017.
Amendment 13 to the Privacy Protection Law took effect on 14 August 2025. It expands the definition of personal information (to cover, among other things, online identifiers, IP addresses and location data), introduces an "especially sensitive information" category, strengthens the enforcement and administrative-fine powers of the Israeli Privacy Protection Authority (PPA), adds database notification obligations, and requires the appointment of a Data Protection Officer in defined cases, including for databases whose principal activity is monitoring. We assess our obligations under Amendment 13 on an ongoing basis, including whether a DPO appointment and a database notification are required for the Service, and will publish the DPO's contact details here if one is appointed.
Israeli residents may exercise their rights of access and correction under the Law and may contact the PPA.
12. Complaints and supervisory authorities
Please contact us first at eyal@eyalsec.com; we would rather fix a problem than have you escalate it. You also have the right to lodge a complaint with a supervisory authority:
- EU/EEA: the data protection authority of your country of residence or work, or where the alleged infringement occurred.
- UK: the Information Commissioner's Office (ICO).
- Israel: the Privacy Protection Authority (PPA).
13. US privacy notice (CCPA / CPRA and other state laws)
For California residents, and by analogy residents of other US states with comparable laws:
- Categories of personal information we collect: identifiers (email, username, IP), account and commercial information (plan, transactions), internet and usage activity (analytics), and, for Event Payloads and Browsing Data we process on a customer's behalf, potentially other categories, including internet activity and sensitive personal information, depending on what the customer monitors.
- Purposes: as described in Section 4. Sources: you, your use of the Service, and our customers' agents. Retention: as described in Section 7.
- We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes that would trigger a right to limit beyond providing the Service.
- Your rights: to know and access, delete, correct, opt out of sale or sharing (we do neither), limit use of sensitive personal information, and not be discriminated against for exercising these rights. Exercise them via eyal@eyalsec.com or, for account data, via Settings. You may use an authorized agent.
- For Event Payloads and Browsing Data we act as a service provider to the customer (business) and process the data only as permitted by our contract with them.
14. Children
The Service is a business security tool, is not directed to children, and we do not knowingly collect personal data from children below the age of digital consent in your jurisdiction. If you believe a child has provided us personal data, contact us and we will delete it.
15. Changes
We may update this Policy. We will post the updated version and, for material changes, give reasonable notice. The "Last updated" date above will change accordingly.