Privacy Policy
At Triagio, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR/AVG) and other applicable privacy laws.
We act as a Data Controller for your account information and lead data, and as a Data Processor for the vulnerability data you process through our platform.
1. Data We Collect
We only collect what is necessary to provide our services:
- Account Data: Name, email address, organization details (for MSP customers).
- Vulnerability Data: Screenshots, logs, IP addresses, and other technical details processed on your behalf.
- Usage Data: Platform interaction logs for service improvement and security monitoring.
- Lead & Tool Data: When you use our free tools (such as the Security.txt Generator), we may collect your name, email address, domain, scan results, and questionnaire responses — only if you voluntarily provide them.
2. Legal Bases (Art. 6 GDPR)
We process personal data on the following legal grounds:
- Account Data: Performance of a contract (Art. 6(1)(b)) — necessary to provide the agreed SaaS service.
- Vulnerability Data: Performance of a contract (Art. 6(1)(b)) — processed on your behalf under your instructions as Data Processor.
- Usage & Security Logs: Legitimate interest (Art. 6(1)(f)) — to secure the service, detect abuse, and improve platform performance.
- Lead & Tool Data: Consent (Art. 6(1)(a)) — you explicitly consent by checking the privacy checkbox before submitting your details. You may withdraw consent at any time by contacting privacy@triagio.app.
3. How We Use Data
Your data is used solely for:
- Providing and maintaining our SaaS service.
- Communicating about security updates and service changes.
- Improving our platform and ensuring security.
- Sending deployment guides and security.txt expiry reminders to users who opted in via our tools.
- We never sell your data to third parties.
4. Retention Periods
We retain personal data only as long as necessary for the purpose for which it was collected:
- Account Data: Retained for the duration of the contract plus 12 months after termination, unless a longer period is required by law.
- Vulnerability Data: Retained for 90 days after a report is resolved, after which it is permanently deleted. Customers may request earlier deletion.
- Usage & Security Logs: Retained for a maximum of 6 months.
- Lead & Tool Data: Retained for a maximum of 12 months after collection, or until you withdraw consent — whichever comes first.
5. Data Storage & Subprocessors
All data is stored within Europe (EU/EEA and Switzerland):
- Primary storage: Switzerland (Zurich).
- Encrypted backups: Germany (Frankfurt).
Switzerland benefits from an EU adequacy decision, meaning data transfers to Switzerland are treated as equivalent to transfers within the EU/EEA.
We use carefully vetted sub-processors for cloud infrastructure, transactional email, and notification services. An up-to-date list of our sub-processors is available upon request via privacy@triagio.app.
6. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access your personal data.
- Rectify inaccurate data.
- Request erasure ('Right to be forgotten').
- Restrict or object to processing.
- Data portability: You can export your account data via the platform settings, or by submitting a request to privacy@triagio.app. We will provide your data in a structured, commonly used, and machine-readable format (e.g. JSON or CSV).
- Withdraw consent at any time for processing based on consent (e.g. lead data from our tools).
To exercise any of these rights, contact us at: privacy@triagio.app. We will respond within 30 days.
7. Right to Lodge a Complaint
If you believe that your personal data has been processed in violation of the GDPR, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Autoriteit Persoonsgegevens
Website: https://autoriteitpersoonsgegevens.nl
8. Cookies
We use minimal cookies:
- Functional cookies essential for platform operation (e.g., theme preference, language).
- Privacy-friendly analytics for service improvement (no tracking cookies).
9. Privacy Contact
Triagio B.V. is responsible for the processing of personal data as described in this Privacy Policy. The internal privacy officer can be reached at:
Triagio B.V.
KVK 99601869
Kamerikstraat 5, 5045TW Tilburg
Email: privacy@triagio.app
If you have any questions about this Privacy Policy or our data practices, please do not hesitate to contact us.