Last updated: 2026-07-17. Governing law: Israel.
Privacy Policy
This Privacy Policy explains how EyalSec, of Yehoshua Stampfer 39, Petah Tikva, Israel ("EyalSec", "we", "us"), handles personal data in connection with the EyalSec / es2 platform, the web dashboard, the agent API, and the es-python interpreter (the "Service").
It applies to (a) account holders and visitors, for whom we are the controller, and (b) the security-event data our customers send us through es-python, which we process as a processor on the customer's behalf.
1. Who we are and our roles
EyalSec plays two distinct roles:
- Controller: for account, login, and billing data, for transactional email, and for our self-hosted web analytics. We decide why and how this data is processed.
- Processor: for Event Payloads sent by es-python (the fields
where,repr,trace,location,origin). The customer who deploys es-python is the controller of that data; we process it only to provide the Service, under the Data Processing Agreement (/legal/dpa). This Policy describes that processing for transparency, but the customer's own privacy notice governs the underlying personal data.
Contact: eyal@eyalsec.com.
2. What data we collect
(a) Account, login, and billing data (controller). Email address, username, hashed password, two-factor/authentication settings, API keys (hashed), plan/role, and billing/transaction records (payment processing may be handled by a payment provider).
(b) Web analytics (controller). Self-hosted, anonymous analytics about use of our public pages and dashboard, e.g., page views, client metrics, JavaScript errors, a hashed visitor identifier, and (only if the operator enables a MaxMind GeoIP database) a coarse country. Analytics can be disabled by the operator and are subject to sampling and a retention window.
(c) Event Payloads (processor). Security events reported by es-python from the customer's own monitored machines. Important: Event Payloads can contain personal data and secrets (for example passwords, tokens, keys, or other sensitive runtime values) extracted from the customer's process memory. Customers control what they monitor and should minimize the capture of unnecessary sensitive data (see the DPA and the Acceptable Use Policy).
(d) Technical/operational data. Server logs, IP addresses (used for security, IP access-control, and abuse prevention), and similar metadata.
3. Purposes and lawful bases (GDPR Arts 6, 13–14)
| Data | Purpose | Lawful basis (GDPR Art. 6) | |------|---------|----------------------------| | Account/login/billing | Create and manage your account; authenticate; provide and bill the Service | Performance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) | | Transactional email (via Amazon SES) | Password reset, invitations, service notices | Performance of a contract; legitimate interests (Art. 6(1)(f)) | | Web analytics | Understand and improve the Service; diagnose errors | Legitimate interests (Art. 6(1)(f)); consent where required | | Event Payloads | Provide the monitoring/reporting Service to the customer | Processed on the customer's documented instructions as processor; the customer's own lawful basis applies | | Logs / IP / security | Secure the Service, prevent abuse, enforce IP access control | Legitimate interests (Art. 6(1)(f)); legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object (Section 8). Where consent is the basis, you may withdraw it at any time.
4. Recipients and sub-processors
We share personal data with service providers who help us run the Service. Our current
sub-processors are listed at /legal/subprocessors and include Amazon Web
Services (hosting), Amazon SES (transactional email), and, only if the operator enables it,
MaxMind (GeoIP). We may also disclose data to comply with law, enforce our agreements, or
protect rights, safety, and security. We do not sell personal data.
5. International transfers
The Service is hosted on Amazon Web Services in the il-central-1 (Israel) region. Personal data may be processed in, or transferred to, countries outside the EEA or the UK. Where we transfer personal data out of the EEA or UK to a country without an adequacy decision, we rely on appropriate safeguards, primarily the European Commission's Standard Contractual Clauses (SCCs) (and the UK International Data Transfer Addendum for UK transfers), together with any necessary supplementary measures. Israel benefits from an EU adequacy decision. A copy of the relevant safeguards is available on request at eyal@eyalsec.com.
6. Retention
- Account data: kept while your account is active and for a reasonable period afterwards, then deleted, subject to legal retention (e.g., tax records).
- Event Payloads: retained per the customer's configuration and the DPA; deleted or returned on termination, and cascade-deleted when the customer deletes their account.
- Web analytics: retained for a limited, configurable window (operator-set retention, e.g., a default measured in days) and then deleted by an automated sweeper.
- Logs: kept for a limited period for security and operational purposes.
7. Security
We use technical and organizational measures appropriate to the risk (GDPR Art. 32), including encryption in transit (TLS/HTTPS) and encryption at rest for hosted data (AWS-managed encryption of the underlying EBS storage), access controls, hashed passwords and API keys, secrets management, IP access control, and least-privilege practices. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase ("right to be forgotten"), restrict or object to processing, and port your personal data, and to withdraw consent where processing is based on consent. In particular:
- Self-serve erasure. You can delete your account and all associated data from Settings; this cascade-deletes your machines, Events, and filters.
- To exercise other rights, contact eyal@eyalsec.com. We will respond within the time required by law (generally one month under the GDPR).
For Event Payloads, we act as a processor: please direct data-subject requests to the relevant customer (controller); we will assist the customer as required by the DPA.
9. GDPR Articles 13–14 disclosures
In addition to the above, EU/EEA data subjects are informed that: the controller is EyalSec (for account/analytics) or the customer (for Event Payloads); processing is for the purposes and on the bases in Section 3; recipients are in Section 4; transfers and safeguards are in Section 5; retention is in Section 6; you have the rights in Section 8; you may lodge a complaint with a supervisory authority (Section 11); and provision of account data is necessary to enter into and perform the contract. We do not use the personal data described here for solely automated decision-making with legal or similarly significant effects.
10. Israel Privacy Protection Law
For data subjects and processing in Israel, we comply with the Privacy Protection Law, 5741-1981 and its regulations (including the Privacy Protection (Data Security) Regulations, 5777-2017). We also account for the modernization introduced by Amendment 13 (2024/2025), which strengthens definitions (including expanded "personal information" and sensitive-data concepts), enforcement, and accountability obligations of the Israeli Privacy Protection Authority (PPA). Israeli residents may exercise their rights of access and correction and may contact the PPA.
11. Complaints and supervisory authorities
You may contact us first at eyal@eyalsec.com. You also have the right to lodge a complaint with a supervisory authority:
- EU/EEA: the data protection authority of your country of residence or work, or where the alleged infringement occurred.
- UK: the Information Commissioner's Office (ICO).
- Israel: the Privacy Protection Authority (PPA).
12. US privacy notice (CCPA / CPRA and other state laws)
For California residents (and, by analogy, residents of other US states with comparable laws):
- Categories of personal information we collect: identifiers (email, username, IP), account/commercial information (plan, transactions), internet/usage activity (analytics), and, for Event Payloads we process on a customer's behalf, potentially other categories depending on what the customer monitors.
- Purposes: as described in Section 3.
- We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes that would trigger a right to limit beyond providing the Service.
- Your rights: to know/access, delete, correct, and opt out of sale/sharing (we do not sell or share), and not to be discriminated against for exercising these rights. Exercise them via eyal@eyalsec.com or, for account data, via Settings.
- For Event Payloads, we act as a service provider to the customer (business) and process the data only as permitted by our contract.
13. Children
The Service is not directed to children, and we do not knowingly collect personal data from children below the age of digital consent in your jurisdiction. If you believe a child has provided us personal data, contact us and we will delete it.
14. Changes
We may update this Policy. We will post the updated version and, for material changes, give reasonable notice. The "Last updated" date above will change accordingly.