legal

Privacy Policy

Last updated: 2026-09-11. Governing law: Israel.

Privacy Policy

This Privacy Policy explains how Eyal Gabay, trading as "EyalSec", a sole proprietor (osek murshe) registered in Israel under no. 211868450, of Yehoshua Stampfer 39, Petah Tikva, Israel ("EyalSec", "we", "us"), handles personal data in connection with the EyalSec / es2 platform, the web dashboard, the agent API, and the EyalSec agents (the es-python runtime, the es-chromium browser, and the es-c, es-cpp, es-rust, es-node, es-solidity, es-bash and es-php agents) (together, the "Service").

It applies to (a) account holders and visitors, for whom we are the controller, and (b) the security-event data our customers send us through those agents, which we process as a processor on the customer's behalf.

Contact for all privacy matters: eyal@eyalsec.com.


1. Who we are and our roles

EyalSec plays two distinct roles:

If your employer or another organization deployed an EyalSec agent on a machine or browser you use, that organization is the controller, not us. Direct your questions and requests to them in the first instance; Section 9 explains what we can and cannot do.

2. What data we collect

(a) Account, login, and billing data (controller). Email address, username, hashed password, two-factor and authentication settings, API keys (stored hashed), access level and capabilities, and billing and transaction records. Payment processing may be handled by a payment provider. If you sign in with Google, where that option is offered, we receive the email address on your Google account and whether Google has verified it; we store no Google password or token.

(b) Web analytics (controller). Self-hosted, anonymous analytics about use of our public pages and dashboard: page views, client performance metrics, JavaScript errors, a hashed visitor identifier, and, only if the operator enables a MaxMind GeoIP database, a coarse country. Analytics can be disabled by the operator and are subject to sampling and a retention window. We do not use third-party advertising or cross-site tracking.

(c) Event Payloads (processor). Security events reported by the EyalSec agents from the customer's own monitored machines, browsers and services.

Important: Event Payloads can contain personal data and secrets. Because the agents observe values as a program runs, an Event Payload can include passwords, tokens, keys, identifiers, the contents of variables, file paths, and other sensitive runtime values drawn from the customer's own processes.

(d) Browsing Data (processor), where es-chromium is deployed. es-chromium reports on pages browsed on the machines the customer monitors. Its Event Payloads can additionally contain:

Browsing Data reveals what a person did in a browser. It is the most sensitive category the Service handles. Customers control what they monitor, must have a lawful basis and the required notices and consents in place before deploying es-chromium (Section 7 of the Terms and Section 2 of the AUP), and should minimize the capture of unnecessary sensitive data.

(e) Technical and operational data. Server logs, IP addresses (used for security, IP access control, and abuse prevention), request metadata, and captured server errors.

(f) Communications. Messages you send us through the contact form, pricing enquiries, and support email.

3. Cookies and similar technologies

We use a small number of cookies and none of them are for advertising, profiling or cross-site tracking:

| Cookie | Purpose | Type | |--------|---------|------| | Session cookie | Keeps you signed in to the dashboard | Strictly necessary | | csrftoken | Protects form submissions against cross-site request forgery | Strictly necessary |

Strictly necessary cookies are set without consent because the Service cannot be provided without them; you can block them in your browser, but you will not be able to sign in. Our analytics set no cookie: the visitor identifier in Section 2(b) is computed on our server from a daily-rotating, salted hash of the IP address and browser user agent, and the raw IP address is not stored with it. The analytics are self-hosted and first-party, and the operator can disable them entirely (Section 2(b)). We set no third-party cookies ourselves and we do not sell or share personal data for advertising. Where a CAPTCHA service is enabled on our sign-in, two-factor, password-reset, registration, invitation and contact forms, that provider's script loads on those pages and may set or read the provider's own cookies (Section 5).

4. Purposes and lawful bases (GDPR Arts 6, 13-14)

| Data | Purpose | Lawful basis (GDPR Art. 6) | |------|---------|----------------------------| | Account/login/billing | Create and manage your account; authenticate; provide and bill the Service | Performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting (Art. 6(1)(c)) | | Transactional email | Password reset, invitations, service notices | Performance of a contract; legitimate interests (Art. 6(1)(f)) | | Web analytics | Understand and improve the Service; diagnose errors | Legitimate interests (Art. 6(1)(f)); consent where required | | Event Payloads and Browsing Data | Provide the monitoring and reporting Service to the customer | Processed on the customer's documented instructions as processor; the customer's own lawful basis applies | | Logs / IP / security | Secure the Service, prevent abuse, enforce IP access control | Legitimate interests (Art. 6(1)(f)); legal obligation | | Sanctions and denied-party screening | Comply with export-control and sanctions law | Legal obligation (Art. 6(1)(c)); legitimate interests |

Where we rely on legitimate interests, we have balanced those interests against your rights; you may object (Section 9). Where consent is the basis, you may withdraw it at any time.

5. Recipients and sub-processors

We share personal data with service providers who help us run the Service. Our current sub-processors are listed at /legal/subprocessors and include Amazon Web Services (hosting) and Amazon SES (transactional email). Optional GeoIP enrichment uses a MaxMind database file held on our own server, so no data is sent to MaxMind. Where a CAPTCHA service (Google reCAPTCHA, Cloudflare Turnstile or hCaptcha) is enabled, its provider receives the IP address and browser information of visitors to the forms listed in Section 3, to protect them against automated abuse. We may also disclose data to comply with law, to respond to a lawful request from a public authority, to enforce our agreements, or to protect rights, safety and security.

We do not sell personal data, and we do not share it for behavioural advertising. We do not use the content of Event Payloads or Browsing Data for any purpose other than providing the Service to the customer who sent them (Terms, Section 20(c)).

6. International transfers

The Service is hosted on Amazon Web Services in the il-central-1 (Israel) region. Transactional email is delivered through an Amazon SES endpoint in the EU.

Israel benefits from an EU adequacy decision, most recently reaffirmed by the European Commission in January 2024, so transfers of personal data from the EEA to EyalSec in Israel do not require additional safeguards. Where we nonetheless transfer personal data out of the EEA or the UK to a country without an adequacy decision, we rely on appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) and, for UK transfers, the UK International Data Transfer Addendum, together with any necessary supplementary measures. A copy of the relevant safeguards is available on request at eyal@eyalsec.com. Adequacy decisions are periodically reviewed; if Israel's status changes we will move to the SCCs and update this Policy.

7. Retention

8. Security

We use technical and organizational measures appropriate to the risk (GDPR Art. 32), including encryption in transit (TLS/HTTPS) and encryption at rest, access controls, hashed passwords and API keys, per-machine credentials, secrets management, IP access control, and least-privilege practices. Our security measures are described in detail at /legal/security, which also serves as Annex II to the DPA.

If we become aware of a personal data breach affecting a customer's data, we notify that customer without undue delay (DPA, Section 6(f)). Where we are the controller, we notify affected individuals and the competent supervisory authority as the law requires.

No method of transmission or storage is completely secure; we cannot guarantee absolute security. To report a suspected vulnerability, see /legal/vulnerability-disclosure.

9. Your rights

Subject to applicable law, you have the right to access, rectify, erase ("right to be forgotten"), restrict or object to processing, and port your personal data, and to withdraw consent where processing is based on consent. In particular:

For Event Payloads and Browsing Data we act as a processor. If you are an individual whose data appears in them (for example an employee of one of our customers), please direct your request to the customer who deployed the agent; they are the controller and they hold the context needed to answer you. If you contact us, we will refer you to them and will assist them as the DPA requires. We will not disclose a customer's event data to a third party who asks for it.

10. GDPR Articles 13-14 disclosures and EU/UK representation

EU/EEA data subjects are informed that: the controller is EyalSec (for account, analytics and communications) or the customer (for Event Payloads and Browsing Data); processing is for the purposes and on the bases in Section 4; recipients are in Section 5; transfers and safeguards are in Section 6; retention is in Section 7; your rights are in Section 9; you may lodge a complaint with a supervisory authority (Section 12); and provision of account data is necessary to enter into and perform the contract. We do not use the personal data described here for solely automated decision-making with legal or similarly significant effects, and we do not carry out profiling of visitors or account holders.

Representatives. EyalSec is established in Israel and has no establishment in the EEA or the UK. Where GDPR Article 27 or UK GDPR Article 27 requires us to designate a representative in the Union or the United Kingdom, we will designate one and publish the contact details on this page. Until a representative is published, contact us directly at eyal@eyalsec.com; this does not affect your right to complain to your own supervisory authority.

11. Israel Privacy Protection Law

For data subjects and processing in Israel, we comply with the Privacy Protection Law, 5741-1981 and its regulations, including the Privacy Protection (Data Security) Regulations, 5777-2017.

Amendment 13 to the Privacy Protection Law took effect on 14 August 2025. It expands the definition of personal information (to cover, among other things, online identifiers, IP addresses and location data), introduces an "especially sensitive information" category, strengthens the enforcement and administrative-fine powers of the Israeli Privacy Protection Authority (PPA), adds database notification obligations, and requires the appointment of a Data Protection Officer in defined cases, including for databases whose principal activity is monitoring. We assess our obligations under Amendment 13 on an ongoing basis, including whether a DPO appointment and a database notification are required for the Service, and will publish the DPO's contact details here if one is appointed.

Israeli residents may exercise their rights of access and correction under the Law and may contact the PPA.

12. Complaints and supervisory authorities

Please contact us first at eyal@eyalsec.com; we would rather fix a problem than have you escalate it. You also have the right to lodge a complaint with a supervisory authority:

13. US privacy notice (CCPA / CPRA and other state laws)

For California residents, and by analogy residents of other US states with comparable laws:

14. Children

The Service is a business security tool, is not directed to children, and we do not knowingly collect personal data from children below the age of digital consent in your jurisdiction. If you believe a child has provided us personal data, contact us and we will delete it.

15. Changes

We may update this Policy. We will post the updated version and, for material changes, give reasonable notice. The "Last updated" date above will change accordingly.

EyalSec Pricing Docs Security Login Book a live demo