Privacy Policy

Last Updated:

1. Introduction and Commitment to Privacy

eliSec ("Company," "we," "us," or "our") is committed to protecting your privacy and ensuring you have a positive experience on our platform. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you visit our website, use our mobile applications, and access our services (collectively, the "Platform"). Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Platform.

2. Information We Collect

We may collect information about you in a variety of ways. The information we may collect includes:

2.1 Information You Provide Directly

  • Account Registration: Name, email address, phone number, password, and account preferences
  • Profile Information: Professional background, company affiliation, and job title
  • Financial Data: Billing address, payment method details, and subscription information
  • Communication Data: Messages, inquiries, and feedback you send to our support team
  • Survey and Feedback: Responses to surveys, questionnaires, and feedback forms

2.2 Information Collected Automatically

  • Log Data: IP address, browser type, operating system, referring URL, and pages visited
  • Cookies and Similar Technologies: Information stored through cookies, web beacons, and pixels
  • Device Information: Device ID, device type, manufacturer, and mobile network information
  • Geographic Location: Approximate location based on IP address or GPS data (with consent)
  • Usage Data: Features accessed, search queries, filings viewed, and time spent on Platform
  • Session Data: Information about your interactions and navigation patterns

2.3 Payment Information

  • Credit/Debit Card Data: When processed through Stripe, we do NOT store full card numbers. Stripe securely handles all sensitive payment data.
  • Payment Method Information: Card type, expiration date, and billing address (only if stored by Stripe for recurring billing)
  • Transaction Data: Transaction history, subscription status, and billing records
  • Stripe Tokens: Unique payment tokens generated by Stripe for secure recurring charges

2.3 Information from Third Parties

  • Social Media: If you link your social media accounts, we receive public profile information
  • Third-Party Service Providers: Payment processors, analytics providers, and data brokers
  • Public Records: Publicly available information related to companies and individuals
  • Business Partners: Information shared through affiliate programs or partnerships

Note: We do not knowingly collect personal information from children under 13. If we become aware of such collection, we will immediately delete the information.

3. Use of Your Information

We use the information we collect for various purposes:

  • Account Management: Create, maintain, and manage your user account and profile
  • Service Provision: Deliver the Platform's features and functionality, including SEC filing aggregation, alerts, and analysis
  • Transaction Processing: Process subscription payments, billing, and manage refunds
  • Communication: Send account notifications, service updates, and respond to your inquiries
  • Personalization: Customize your experience and recommend relevant content based on your usage
  • Analytics and Improvement: Analyze usage patterns, identify trends, and improve Platform functionality
  • Security and Fraud Prevention: Detect, prevent, and address fraud, abuse, and security issues
  • Legal Compliance: Comply with applicable laws, regulations, and legal obligations
  • Marketing and Promotion: Send promotional emails, newsletters, and updates (with your consent)
  • Research: Conduct research and analytics to enhance our services and user experience

4. Disclosure and Sharing of Your Information

We may share your information in the following circumstances:

4.1 Third-Party Service Providers

We share information with vendors and service providers who perform services on our behalf, including payment processors, hosting providers, analytics companies, customer support platforms, and email service providers. These providers are contractually obligated to use your information only as necessary to provide services to us.

4.2 Legal Requirements and Compliance

We may disclose your information when required by law, court order, or government request, including responses to subpoenas, warrants, or other legal processes. We will provide notice when legally permissible.

4.3 Protection of Rights and Safety

We may disclose information to protect our legal rights, enforce our Terms of Use, prevent fraud, and protect the safety and security of our Platform, users, and the public.

4.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice if such transfer occurs and your information becomes subject to a different privacy policy.

4.5 Aggregated and De-Identified Information

We may share aggregated or de-identified information that cannot reasonably be used to identify you with third parties for research, marketing, analytics, and other purposes.

4.6 With Your Consent

We may share your information with third parties when you explicitly consent to such sharing, such as connecting your account to third-party applications or services.

5. Stripe Payment Processing

We use Stripe, Inc. ("Stripe") to process all payment transactions on our Platform. When you subscribe or make a payment:

  • Payment Data Handling: Your credit/debit card details are transmitted directly to Stripe using secure encryption. We do NOT store, process, or have access to your full card numbers.
  • Stripe Compliance: Stripe is PCI-DSS Level 1 compliant and handles all sensitive payment data in accordance with industry security standards.
  • Secure Tokens: Stripe generates unique payment tokens that allow us to initiate recurring charges without accessing your actual card information.
  • Billing Information: We store billing address, cardholder name, and last four digits of your card for billing and fraud prevention purposes.
  • Stripe's Privacy Policy: Stripe's collection and use of your payment information is governed by Stripe's Privacy Policy, available at https://stripe.com/privacy
  • Webhook Data: Stripe sends us payment confirmation data (transaction ID, amount, date, status) through secure webhooks for billing records.

Your card information is never stored on our servers. For questions about how Stripe processes your payment data, please contact Stripe directly or review their privacy documentation.

6. Cookies and Tracking Technologies

We use cookies, web beacons, pixels, and similar tracking technologies to enhance your experience and collect usage data:

  • Essential Cookies: Required for Platform functionality and security
  • Analytics Cookies: Track usage patterns and improve Platform performance
  • Preference Cookies: Remember your settings and preferences
  • Marketing Cookies: Track marketing effectiveness and user behavior

Most browsers allow you to control cookies through settings. However, disabling cookies may impact Platform functionality. We do not respond to Do Not Track signals at this time.

7. Security of Your Information

We implement comprehensive administrative, technical, and physical security measures to protect your personal information:

  • SSL/TLS encryption for data transmitted over the internet
  • Secure data storage with access controls and authentication
  • Regular security audits and vulnerability assessments
  • Employee training on data protection and privacy practices
  • Intrusion detection and prevention systems
  • Firewall protection and network segmentation

Important: No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.

8. Data Retention

We retain your personal information for as long as necessary to:

  • Provide the Platform and services you requested
  • Maintain your account and fulfill our legal obligations
  • Resolve disputes and enforce our agreements
  • Comply with applicable laws and regulations

When information is no longer needed, we securely delete or anonymize it. However, we may retain certain information for legal, regulatory, or business purposes as permitted by law.

9. Your Privacy Rights and Choices

Depending on your location, you may have certain rights regarding your personal information:

8.1 Access and Portability

You have the right to request access to your personal information and, in some cases, receive a copy in a portable format.

8.2 Correction and Update

You may request correction of inaccurate or incomplete information through your account settings or by contacting us.

8.3 Deletion

You may request deletion of your personal information, subject to certain legal and operational exceptions.

8.4 Marketing Communications

You may opt out of promotional emails by clicking the unsubscribe link or adjusting your notification preferences. Note: We will continue to send transactional and service-related communications.

8.5 Cookie Control

You can manage cookie preferences through your browser settings or our cookie consent tool.

To exercise any of these rights, please contact us using the information in Section 12.

10. CCPA and State Privacy Rights

If you are a California resident, under the California Consumer Privacy Act (CCPA), you have the right to:

  • Know what personal information we collect and how we use it
  • Know whether your personal information is sold or shared with third parties
  • Request deletion of your personal information (subject to exceptions)
  • Access and download your personal information
  • Opt out of the sale or sharing of your personal information
  • Be free from discrimination for exercising your CCPA rights
  • Have a consumer rights agent authorized to make requests on your behalf

Similar rights may apply in other states (Colorado, Connecticut, Delaware, Florida, Hawaii, Idaho, Illinois, Indiana, Iowa, Kentucky, Louisiana, Massachusetts, Minnesota, Mississippi, Missouri, Montana, Nebraska, New Hampshire, New Jersey, New York, Ohio, Oregon, Rhode Island, Tennessee, Texas, Utah, Vermont, Virginia, Washington).

To submit a CCPA or state privacy request, contact us at privacy@elisec.net with "Privacy Request" in the subject line. We will respond within 45 days.

11. GDPR and EU Privacy Rights

If you are a resident of the European Union, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

  • Right to access your personal data
  • Right to rectify inaccurate or incomplete data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to lodge complaints with your supervisory authority

We process personal data on the basis of your consent or our legitimate business interests. For data subject requests, contact us at privacy@elisec.net. We will respond within 30 days.

12. International Data Transfers

Your information may be transferred to, stored in, and processed in countries other than your country of residence, including the United States, which may have different data protection laws. By using our Platform, you consent to the transfer of your information to countries outside your country of residence. We implement appropriate safeguards, including standard contractual clauses and adequacy decisions, to protect your information.

13. Third-Party Links and Services

Our Platform may contain links to third-party websites and services. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies before providing any information. Your use of third-party services is governed by their terms and policies, not ours.

14. Contact Us About Your Privacy

If you have questions about this Privacy Policy or your personal information, please contact us at privacy@elisec.net

15. Changes to This Privacy Policy

We reserve the right to modify this Privacy Policy at any time. Any changes will be effective immediately upon posting to the Platform. We will notify you of material changes via email or prominent notice on the Platform. Your continued use of the Platform after changes constitutes acceptance of the modified Privacy Policy.

16. California "Shine the Light" Law

Under California Civil Code Section 1798.83 ("Shine the Light" law), California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. To submit such a request, please contact us at privacy@elisec.net with "Shine the Light Request" in the subject line.