Effective Date: 08 Aug 2026 · Version: 2026-08-08
Loquen Lab LLC is the data controller for processing described herein.
Privacy inquiries: [email protected]
Legal / compliance: [email protected]
We may process the following categories (depending on your interactions):
| Category | Examples | Required? |
|---|---|---|
| Account Identifiers | Internal user ID, username, auth provider ID | Yes (core usage) |
| Contact | Email (if provided by identity provider) | Conditional |
| Technical / Usage | IP address, timestamps, user agent, logs, feature flags, error traces | Yes (security & diagnostics) |
| Billing | Subscription plan, payment status, transaction metadata (no full payment card PAN stored) | Conditional (if using paid plan) |
| API / Scan Data | OpenAPI specs, base URLs, credentials metadata, scan results, security findings, Trust Page data | Conditional (if using scanning features) |
| Credentials | API keys, tokens, and secrets used to authenticate scans — encrypted at rest (AES-256), never logged in plaintext | Conditional |
| AI Prompt / Output | Text submitted to AI-assisted triage/interpretation + generated analysis (may undergo transient logging) | Conditional |
| Booking / Demo | Name, email, chosen time slot and timezone when you book a demo | Conditional |
| Support / Feedback | Tickets, emails, form submissions, session notes | Conditional |
Sensitive categories (e.g., government IDs, health data) are neither required nor intentionally collected. Do not submit them.
| Purpose | Legal Basis |
|---|---|
| Provide core Platform features | Contract necessity |
| Account & session security | Legitimate interest / Contract |
| Billing & subscriptions | Contract necessity |
| Abuse, fraud & moderation controls | Legitimate interest |
| Analytics & performance tuning (aggregate) | Legitimate interest (minimal / pseudonymized) |
| Legal compliance & enforcement | Legal obligation / Legitimate interest |
| AI analysis & recommendations | Contract necessity / Legitimate interest |
| User communications & support | Contract necessity / Legitimate interest |
| Marketing (if opted-in) | Consent |
Where required by data protection laws we rely on: performance of contract, legitimate interest (balanced test maintained), legal obligation, or consent (for optional communications). We avoid relying on consent when another lawful basis is more appropriate.
We keep personal data only for as long as needed:
| Data Type | Retention | Notes |
|---|---|---|
| Account & profile | Life of account + short grace (≤90 days) | Basic identifiers |
| Logs (standard) | 30–180 days | Security, diagnostics, aggregated thereafter |
| Scan results & findings | Life of account + ≤90 days | Needed for Trust Page history |
| Credentials | Until deleted by user or account termination | Encrypted at rest (AES-256) |
| Billing records | 7–10 years (jurisdictional accounting) | Required for audit |
| AI prompts/output logs | ≤30 days (service improvement / abuse) | May be aggregated earlier |
| Booking / demo data | Until deleted by user or retention policy | Booking confirmation + reminders |
| Backups | Rolling cycles (e.g., 30–60 days) | Encrypted at rest |
Upon expiry we delete or irreversibly anonymize.
Controls include: transport encryption (TLS), role-based access, least privilege, audit logging, anomaly detection, secret management (AES-256 encryption for credentials), routine patching, segregated environments, encryption at rest for key data stores, and sandboxed scanning with strict pacing and request caps. No system is perfectly secure; report suspected issues to [email protected].
Credentials you provide for scans are encrypted at rest and never logged in plaintext. You are responsible for only providing credentials you are authorized to use and for keeping them accurate. We are not liable for unauthorized access to your Target APIs caused by your credentials, their exposure, or misconfiguration on your side.
We do NOT sell personal data. We may share with:
Public Trust Page: if you enable the public certificate for an organisation, the organisation name, overall status, and aggregate scan data (open/fixed counts, last scan, statement) become publicly visible at the certificate URL and via our embed widgets. Do not enable it if you do not want this information public. You are responsible for how you present and share the certificate.
Third parties are bound by contractual obligations (data processing agreements) where required.
Where data moves outside your jurisdiction we implement appropriate safeguards (e.g., Standard Contractual Clauses, transfer risk assessments). Additional measures (encryption / pseudonymization) may be applied.
AI features may analyze scan findings and produce triage, severity suggestions, and interpretations. We do not use your private scan data to publicly train models without consent. Limited human review may occur for abuse detection or quality evaluation under confidentiality obligations. No solely automated decision produces legal or similarly significant effects without recourse. The deterministic core scanner remains the source of truth.
We primarily rely on essential session tokens and minimal local storage for preference or anti-abuse markers. Non-essential marketing / tracking cookies are not currently deployed. If adopted, a separate consent banner will describe categories and preferences.
Rights may include: access, rectification, erasure, restriction, objection, portability, withdrawal of consent (prospective), complaint to supervisory authority, opt-out of certain processing.
Exercise via [email protected] (we may need to verify identity). Responses typically within 30 days.
The Platform is not directed to children under 16 (or lower age defined locally). We do not knowingly collect such data. If you believe a child provided information, contact us for removal.
External links or plugins operate under their own policies; review them separately. We disclaim responsibility for third-party practices.
We maintain incident response playbooks. In the event of a breach impacting personal data, we will notify affected users and/or authorities in accordance with applicable law (content: nature, categories, mitigation steps, contact).
We may aggregate or anonymize data for statistical insights (performance metrics, adoption trends). Such information no longer constitutes personal data.
Transactional or security emails (e.g., password reset, booking confirmation, policy acceptance, moderation) are mandatory. Optional marketing requires prior consent and includes an opt-out mechanism.
If required (e.g., CCPA / CPRA), additional disclosures (categories sold/shared = none, right to limit use of sensitive information = not applicable presently) may be published as an Addendum.
Revisions will carry a new “Effective Date”. Material changes may trigger re-acceptance. Maintain awareness by checking periodically.
Loquen Lab LLC
418 Broadway STE N, Albany
Albany County, New York 12207 USA
Privacy & data rights: [email protected]
Security: [email protected]
Legal notices: [email protected]
By continuing to use the Platform you acknowledge you have read and understood this Privacy Policy.