Privacy Policy
Effective date: 31 August, 2026
This Privacy Policy explains what personal information DSALTA, Inc. collects, why we collect it, how we use and protect it, who we share it with, and the choices and rights available to you. It applies to our website, platform, integrations and related services.
In short: We collect the information needed to operate the DSALTA platform, secure your account, process payments and improve the Service. We do not sell your personal information. Data you connect through integrations is used only to deliver the compliance features you enable, and you can request access, correction or deletion at any time by writing to hello@dsalta.com.
1. Introduction
DSALTA, Inc. ("DSALTA", "we", "our", "us") operates www.dsalta.com together with the DSALTA platform, dashboards, integrations and related services (collectively, the "Service"). This Privacy Policy governs your visit to our website and use of the Service, and explains how we collect, safeguard and disclose information resulting from that use.
We use your data to provide, secure and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined here, terms used in this Privacy Policy have the same meaning as in our Terms of Service, which together with this Privacy Policy forms your agreement with us.
Where we act as a processor of personal data on behalf of a business customer — for example, personal data contained in evidence, logs or user directories that you connect to the Service — we process that data in accordance with your instructions and the applicable customer agreement or data processing addendum.
2. Definitions
- Service — the www.dsalta.com website and the DSALTA platform and related services operated by DSALTA, Inc.
- Personal Data — data about a living individual who can be identified from that data, or from that data combined with other information in our possession or likely to come into our possession.
- Usage Data — data collected automatically, generated either by the use of the Service or by the Service infrastructure itself (for example, the duration of a page visit).
- Customer Data — data, records, evidence and configurations submitted to, or collected by, the Service by you or on your behalf, including data retrieved from systems you connect.
- Cookies — small files stored on your device (computer or mobile device).
- Data Controller — the natural or legal person who determines the purposes for which, and the manner in which, personal data is processed. For the purposes of this policy, we are the Data Controller of the data described in this policy unless stated otherwise.
- Data Processor (or Service Provider) — any natural or legal person who processes data on behalf of the Data Controller. We use a number of Service Providers to process data more effectively.
- Data Subject — any living individual who is the subject of Personal Data.
- User — the individual using the Service, corresponding to the Data Subject.
3. Information We Collect
We collect several different types of information for the purposes of providing, securing and improving the Service.
3.1 Personal Data
While using the Service, we may ask you to provide certain personally identifiable information that can be used to contact or identify you. This may include, but is not limited to:
- Email address
- First name and last name
- Phone number
- Address, state or province, postal code and city
- Company name, job title and business contact details
- Account credentials and authentication metadata, including multi-factor enrolment status
- Billing contact and transaction records (payment card details are handled by our payment processors, not by us)
- Cookies and Usage Data
We may use your Personal Data to contact you with service notices, newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of marketing communications at any time using the unsubscribe link or by contacting us.
3.2 Usage Data
We may collect information that your browser sends whenever you visit the Service, or that is sent when you access the Service through a mobile device. This Usage Data may include your Internet Protocol (IP) address, browser type and version, the pages of the Service you visit, the time and date of your visit, time spent on those pages, referring pages, unique device identifiers and other diagnostic data.
When you access the Service from a mobile device, Usage Data may also include the type of device, your device's unique identifier, its IP address, your mobile operating system, the type of mobile browser you use and other diagnostic data.
3.3 Customer Data from Connected Systems
Where you connect third-party systems — such as cloud providers, identity providers, code repositories, ticketing tools, HR systems or productivity suites — we access and process data from those systems in order to deliver compliance monitoring, evidence collection and reporting features. That data may include user and group directories, device and configuration states, access logs, policy artefacts and control evidence. We request only the scopes necessary for the features you enable, and you may disconnect an Integration at any time.
3.4 Location Data
We may use and store information about your approximate location, including where derived from your IP address, and more precise location where you give us permission to do so. We use this data to provide and improve features of the Service, and for security purposes such as detecting anomalous sign-in activity. You can enable or disable device location services at any time through your device settings.
3.5 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on the Service and to hold certain information. Cookies are files containing a small amount of data, which may include an anonymous unique identifier, sent to your browser from a website and stored on your device. We also use technologies such as beacons, tags and scripts to collect and track information and to improve and analyse the Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. If you do not accept cookies, some portions of the Service may not function properly.
Examples of cookies we use:
- Session Cookies — required to operate and authenticate your session on the Service.
- Preference Cookies — used to remember your preferences and settings.
- Security Cookies — used for security purposes, including fraud and abuse prevention.
- Analytics Cookies — used to understand how the Service is used so we can improve it.
- Advertising Cookies — used to serve advertisements that may be relevant to you and your interests.
4. How We Use Your Information
DSALTA uses the information it collects for the following purposes:
- To provide, operate and maintain the Service
- To authenticate users and secure accounts, and to detect, prevent and investigate fraud, abuse and security incidents
- To notify you about changes to the Service
- To allow you to participate in interactive features when you choose to do so
- To provide customer support and respond to your requests
- To gather analysis and insight so that we can improve the Service
- To monitor usage of the Service and to detect, prevent and address technical issues
- To carry out our obligations and enforce our rights arising from any contract between you and us, including billing and collection
- To send you account and subscription notices, including renewal, expiry and invoicing communications
- To provide news, special offers and general information about goods, services and events similar to those you have purchased or enquired about, unless you have opted out
- To comply with legal obligations and respond to lawful requests from public authorities
- For any other purpose disclosed at the time you provide the information, or with your consent
5. Legal Bases for Processing
Where data protection law requires a legal basis for processing, we rely on the following:
- Performance of a contract — to provide the Service, administer your account and process payments.
- Legitimate interests — to secure and improve the Service, prevent abuse, and conduct limited business communications, where those interests are not overridden by your rights.
- Consent — for optional cookies, marketing communications and certain location features. You may withdraw consent at any time.
- Legal obligation — where processing is necessary for us to comply with applicable law.
6. Retention of Data
We retain Personal Data only for as long as necessary for the purposes set out in this Privacy Policy. We retain and use Personal Data to the extent needed to comply with our legal obligations, resolve disputes, and enforce our agreements and policies.
We also retain Usage Data for internal analysis. Usage Data is generally retained for a shorter period, except where it is used to strengthen security or improve the functionality of the Service, or where we are legally required to retain it for longer. Customer Data is retained for the duration of your subscription and deleted in accordance with our retention practices following termination, unless retention is required by law.
7. Transfer of Data
Your information, including Personal Data, may be transferred to and maintained on servers located outside of your state, province, country or other governmental jurisdiction, where data protection laws may differ from those in your jurisdiction.
If you are located outside the United States and choose to provide information to us, please note that we transfer data, including Personal Data, to the United States and process it there. Your submission of such information represents your agreement to that transfer.
Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland, we implement appropriate safeguards, such as Standard Contractual Clauses, together with technical and organisational measures. DSALTA takes all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy, and no transfer will take place to an organisation or country without adequate controls in place.
8. Disclosure of Data
We may disclose personal information that we collect or that you provide in the following circumstances:
- Service Providers. To vendors and subprocessors who perform services on our behalf, such as hosting, analytics, payment processing, communications and customer support, under contractual confidentiality and security obligations.
- Law enforcement and legal requirements. Where required to do so by law, or in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
- Business transactions. If we or our subsidiaries are involved in a merger, acquisition, financing or asset sale, your Personal Data may be transferred, subject to this Privacy Policy.
- Protection of rights. Where we believe disclosure is necessary or appropriate to protect the rights, property or safety of DSALTA, our customers or others, or to enforce our agreements.
- Other cases. To display your company's logo as a customer reference on our website, and in any other case with your consent.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising in a manner requiring an opt-out under applicable law beyond the cookie choices described in this policy.
9. Security of Data
The security of your data is important to us. We maintain administrative, technical and organisational safeguards designed to protect personal information against unauthorised access, disclosure, alteration and destruction, including encryption in transit, access controls, least-privilege administration, logging and regular review of our security practices.
No method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security. If we become aware of a breach affecting your personal information, we will notify you and the relevant authorities where required by applicable law.
10. Your Rights Under the GDPR
If you are a resident of the European Union (EU) or European Economic Area (EEA), you have certain data protection rights under the GDPR — see EU GDPR Regulation (2016/679). We aim to take reasonable steps to allow you to correct, amend, delete or limit the use of your Personal Data.
If you wish to know what Personal Data we hold about you, or you want it removed from our systems, please email hello@dsalta.com. In certain circumstances you have the following rights:
- The right to access, update or delete the information we hold about you
- The right of rectification, if information about you is inaccurate or incomplete
- The right to object to our processing of your Personal Data
- The right of restriction, to request that we restrict the processing of your personal information
- The right to data portability, to receive a copy of your Personal Data in a structured, machine-readable and commonly used format
- The right to withdraw consent at any time where we rely on your consent to process your personal information
We may ask you to verify your identity before responding to such requests, and we may be unable to provide the Service without certain necessary data. You also have the right to complain to a Data Protection Authority about our collection and use of your Personal Data; for more information, contact your local data protection authority in the EEA.
11. Your Rights Under U.S. State Privacy Laws
Depending on your state of residence, you may have the right to know what personal information we collect and how it is used and disclosed, to request access to or a copy of that information, to request correction or deletion, and to be free from discrimination for exercising these rights. We do not sell personal information, and we do not use or disclose sensitive personal information for purposes other than those permitted by applicable law.
To exercise any of these rights, contact hello@dsalta.com. We will verify your request before responding, and you may use an authorised agent where permitted by law.
12. Your Rights Under CalOPPA
CalOPPA was the first state law in the United States to require commercial websites and online services to post a privacy policy — see California Online Privacy Protection Act (CalOPPA). In accordance with CalOPPA:
- Users can visit our site anonymously
- Our Privacy Policy link includes the word "Privacy" and can easily be found on the home page of our website
- Users are notified of any privacy policy changes on this Privacy Policy page
- Users can change their personal information by emailing us at hello@dsalta.com
Our policy on "Do Not Track" signals: we honour Do Not Track signals and do not track, plant cookies or serve advertising when a Do Not Track browser mechanism is in place. You can enable or disable Do Not Track in the preferences or settings page of your browser.
13. Service Providers
We may employ third-party companies and individuals to facilitate the Service, provide the Service on our behalf, perform Service-related tasks, or assist us in analysing how the Service is used. These third parties have access to your Personal Data only to perform those tasks on our behalf and are contractually obligated not to disclose or use it for any other purpose.
14. Analytics
We may use third-party Service Providers to monitor and analyse the use of the Service.
Google Analytics
Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service, and this data may be shared with other Google services. Google may use the collected data to contextualise and personalise the advertising of its own advertising network.
For more information on the privacy practices of Google, please see the Google Privacy Policy. We also encourage you to review Google's guide for safeguarding your data in Analytics.
Firebase
Firebase is an analytics service provided by Google Inc. You may opt out of certain Firebase features through your device settings, including your advertising settings, or by following the instructions provided by Google in their Privacy Policy. For more information on what type of information Firebase collects, please see the Google Privacy Policy.
Mixpanel
Mixpanel is provided by Mixpanel Inc. You can prevent Mixpanel from using your information for analytics purposes by opting out at Mixpanel Opt-Out. For more information on what type of information Mixpanel collects, please see the Mixpanel Terms of Use.
15. CI/CD Tools
We may use third-party Service Providers to automate the development process of the Service.
GitHub
GitHub is provided by GitHub, Inc. and is a development platform used to host and review code, manage projects and build software. For more information on what data GitHub collects, for what purpose, and how the protection of that data is ensured, please see the GitHub Privacy Statement.
GitLab CI/CD
GitLab CI (Continuous Integration) is part of GitLab and builds and tests software whenever a developer pushes code. GitLab CD (Continuous Deployment) places code changes into production. For more information on what data GitLab CI/CD collects, for what purpose, and how the protection of that data is ensured, please see the GitLab Privacy Policy.
16. Behavioural Remarketing
DSALTA uses remarketing services to advertise on third-party websites after you have visited the Service. We and our third-party vendors use cookies to inform, optimise and serve advertising based on your past visits to the Service.
Google Ads
Google Ads remarketing is provided by Google Inc. You can opt out of Google Analytics for Display Advertising and customise Google Display Network ads through the Google Ads Settings page. Google also recommends installing the Google Analytics Opt-out Browser Add-on, which allows visitors to prevent their data from being collected and used by Google Analytics. For more information on the privacy practices of Google, please see the Google Privacy Policy.
X (formerly Twitter)
X remarketing is provided by X Corp. You can opt out of interest-based advertising by following their instructions for opting out of interest-based ads. You can learn more about their privacy practices in the X Privacy Policy.
17. Payments
We may provide paid products and services within the Service. In that case, we use third-party payment processors. We do not store or collect your payment card details; that information is provided directly to our payment processors, whose use of your personal information is governed by their own privacy policies. These processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, a joint effort of brands including Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
The payment processors we work with are:
- Stripe — Stripe Privacy Policy
18. Links to Other Sites
The Service may contain links to sites that are not operated by us. If you click a third-party link, you will be directed to that third party's site, and we strongly advise you to review the privacy policy of every site you visit. We have no control over, and assume no responsibility for, the content, privacy policies or practices of any third-party sites or services.
19. Children's Privacy
The Service is not intended for use by children under the age of 13 ("Children"). We do not knowingly collect personally identifiable information from Children under 13. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.
20. Google API Services and Limited Use
DSALTA's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google Workspace APIs is not used, transferred, or sold to develop, improve, or train generalized or foundational AI/ML models.
Where the Service connects to your Google account or Google Workspace environment, we request only the minimum scopes necessary to deliver the compliance monitoring features you have enabled. Data accessed through those scopes is used solely to provide and secure user-facing features of the Service, to comply with applicable law, and to investigate abuse or security incidents. We do not transfer such data to third parties except as necessary to provide the Service, for security purposes, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you. Human review of Google user data is limited to cases where you have given affirmative consent, where required for security or legal purposes, or where the data has been aggregated and anonymized.
You may revoke DSALTA's access to your Google data at any time through your Google account permissions page or by contacting us at hello@dsalta.com. Upon revocation or termination, we will delete Google user data in accordance with our retention practices, except where retention is required by law.
21. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page, and we will let you know via email and/or a prominent notice on the Service prior to material changes becoming effective, and update the effective date at the top of this page.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
22. Contact Us
If you have any questions, requests or complaints about this Privacy Policy or our handling of your personal information, please contact us:
- By email: hello@dsalta.com
- By visiting our website: www.dsalta.com
Google API Services User Data Policy
DSALTA’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google Workspace APIs is not used, transferred, or sold to develop, improve, or train generalized or foundational AI/ML models.