Privacy Policy
Last updated: January 10, 2026
Rehashly, Inc. ("Rehashly," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Vigilfield security analytics platform and related services (the "Service"). Please read this policy carefully to understand our practices regarding your information.
1. Information We Collect
1.1 Account Information
When you create an account or organization, we collect information you provide directly, including:
- Name and email address
- Organization name and billing information
- Account credentials
- Contact preferences
1.2 Customer Data
In the course of providing the Service, we process security log data that you configure the Service to extract from your AWS environment ("Customer Data"). Customer Data may include:
- AWS CloudTrail logs
- VPC Flow Logs
- S3 Access Logs
- Route 53 DNS Resolver logs
- Custom log sources you configure
Customer Data is processed solely to provide the Service and is encrypted using customer-managed KMS keys where configured. We do not access, use, or share Customer Data except as necessary to provide, maintain, and improve the Service, or as required by law.
1.3 Usage Information
We automatically collect information about how you interact with the Service, including:
- Queries executed and their metadata (not the underlying data)
- Features accessed and actions performed
- Performance and error data
- Browser type, operating system, and device information
- IP addresses and approximate location
- Timestamps and session duration
1.4 Cookies and Similar Technologies
We use cookies and similar tracking technologies to maintain sessions, remember preferences, and analyze usage patterns. You can control cookies through your browser settings, but disabling certain cookies may affect the functionality of the Service.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process transactions and send related information
- Send administrative information, such as updates and security alerts
- Respond to your comments, questions, and requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent or unauthorized activities
- Personalize and improve the Service
- Comply with legal obligations
3. How We Share Your Information
We do not sell your personal information. We may share information in the following circumstances:
3.1 Service Providers
We share information with third-party service providers who perform services on our behalf, such as payment processing, data hosting (AWS), email delivery, and analytics. These providers are bound by contractual obligations to protect your information.
3.2 Legal Requirements
We may disclose information if required to do so by law or in response to valid legal requests, such as subpoenas, court orders, or government requests.
3.3 Business Transfers
In connection with any merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
3.4 With Your Consent
We may share information with third parties when you have given us your consent to do so.
4. Data Security
We implement technical and organizational measures designed to protect your information, including:
- Encryption of data at rest using customer-managed AWS KMS keys
- Encryption of data in transit using TLS 1.2 or higher
- Dedicated, isolated storage for each customer
- Role-based access controls
- Regular security assessments and monitoring
- Employee security training
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy. Specifically:
- Account information is retained while your account is active and for a reasonable period thereafter
- Customer Data is retained according to your configured retention settings
- Usage information is retained for up to 24 months for analytics purposes
- After account termination, we delete your data within 90 days unless required by law to retain it
6. Your Rights and Choices
6.1 Access and Portability
You can access and export your account information and Customer Data through the Service dashboard. You may also request a copy of your personal information by contacting us.
6.2 Correction
You can update your account information through your account settings. If you believe any information we have about you is inaccurate, you may contact us to request corrections.
6.3 Deletion
You can request deletion of your account and associated data by contacting us. Some information may be retained as required by law or for legitimate business purposes.
6.4 Marketing Communications
You can opt out of marketing communications by clicking the unsubscribe link in any marketing email or by updating your communication preferences in your account settings.
7. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information we collect, use, disclose, and sell
- The right to request deletion of your personal information
- The right to opt out of the sale of your personal information (we do not sell personal information)
- The right to non-discrimination for exercising your CCPA rights
To exercise these rights, please contact us at privacy@vigilfield.com.
8. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including:
- The right to access your personal data
- The right to rectification of inaccurate personal data
- The right to erasure ("right to be forgotten")
- The right to restrict processing
- The right to data portability
- The right to object to processing
- Rights related to automated decision-making
Our legal bases for processing include: performance of a contract, legitimate interests, compliance with legal obligations, and consent where applicable.
9. International Data Transfers
Your information may be transferred to and processed in the United States and other countries where our service providers operate. When we transfer data internationally, we use appropriate safeguards, including Standard Contractual Clauses approved by the European Commission, where required.
10. Children's Privacy
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will delete that information promptly.
11. Third-Party Links
The Service may contain links to third-party websites and services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party services you access.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of the Service after such changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
Rehashly, Inc.
Email: privacy@vigilfield.com