Legal

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Zairen collects, uses, and protects information when you use our website and platform.

Information we collect

We collect account details you provide, such as your name, work email, and company. When you connect tools to the platform, we process the configuration and evidence data needed to assess your controls. We also collect basic usage and device information to operate and improve the service.

How we use information

We use information to provide and secure the service, map controls and evidence across frameworks, communicate with you, and meet our legal obligations. We do not sell personal information.

How we share information

We share information with vetted subprocessors that help us run the service, and where required by law or to protect rights and safety. A current list of subprocessors is available on request.

Data security

We apply administrative, technical, and organizational safeguards designed to protect information in line with the standards we help customers meet, including ISO 27001, SOC 2, and PCI DSS.

Data retention

We retain information for as long as needed to provide the service and to satisfy legal, audit, and reporting requirements, after which it is deleted or anonymized.

International transfers

Where information is transferred across borders, we use appropriate safeguards consistent with applicable data protection laws.

Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict the processing of your personal information. To exercise these rights, contact us using the details below.

Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with a revised date.

Contact

Questions about this policy can be sent to privacy@zairen.co.