Privacy Policy
Version 1 · Effective September 3, 2026
This policy explains how Vantaura Security LLC (“Vantaura”, “we”) handles personal information across our public website (vantaurasecurity.com) and our customer portal (where customers manage their account, licenses, billing, and support). Where your organization has signed a Data Processing Addendum with us, that addendum governs the personal data it covers and controls on any conflict.
What this policy does not cover — and why it matters: the RelentLens product is self-hosted. Customers run it entirely within their own environments. The Software initiates no outbound connection to Vantaura and enforces its license offline, so your operational data — the prompts, documents, telemetry, and findings RelentLens processes — never reaches us. We only handle the limited information below.
Information we collect
From the website:
- Contact form: your name, work email, company, and message — only what you type.
- Cookieless analytics: privacy-friendly, aggregate usage statistics. No cookies, no personal profiles, no cross-site tracking.
- Security & operational logs: standard request metadata (such as IP address and user agent) that our host keeps to operate and protect the site.
From the customer portal:
- Account & identity: the name, email, and organization associated with your access, received through the sign-in method configured for your organization (single sign-on, or a one-time code sent to your work email).
- Billing records: subscription, cluster, invoice, and payment-status information. Card and bank details are handled by Stripe — we do not store full payment-card numbers.
- License & cluster metadata: the non-sensitive identifiers you provide to issue a license (such as a cluster identifier and certificate fingerprint), edition, and license status.
- Support tickets & attachments: the content of tickets you open and any support bundles or ops files you choose to upload. Please include only what is necessary and redact where practical.
How we use it
- To respond to your inquiries and communicate with you.
- To provide, administer, and secure the customer portal, licenses, and downloads.
- To process subscriptions, invoicing, and payments.
- To provide customer support.
- To operate, protect, and improve our website and services.
- To comply with legal obligations and enforce our agreements.
If you contact us about RelentLens, we may follow up about your request and, occasionally, about product updates. Every such email includes an unsubscribe link, and you can opt out at any time by replying or emailing us; opting out does not affect service or support messages tied to your account.
We do not use your information for advertising, and we do not sell or rent it. We do not “sell” or “share” personal information, or use it for targeted advertising or profiling, as those terms are defined in U.S. state privacy laws.
Legal bases (where the GDPR or UK GDPR applies): performance of a contract or steps at your request before entering one (portal, licenses, support, billing); our legitimate interests in operating, securing, and improving our website and services and in following up on business inquiries; compliance with legal obligations; and, where we ask for it, your consent.
Who processes it
We use a small, fixed set of service providers that process information on our behalf, under contracts that restrict their use of it to the service they provide us. By category:
- Hosting, content delivery, security, and cookieless analytics for the website and portal, including the databases and object storage behind the portal (e.g., Cloudflare).
- Customer-relationship management, which stores your website contact request so we can follow up.
- Payment processing, invoicing, and sales-tax calculation. Card and bank details go directly to the payment processor.
- Business email and productivity tools for our correspondence with you.
We update this section when the providers we rely on change. Beyond these processors, we disclose personal information only where the law requires it, to protect our rights, safety, or property, or as part of a merger, acquisition, or sale of our business (in which case this policy continues to apply until you are told otherwise).
International transfers
Vantaura is based in the United States and processes information there. If you are outside the United States, your information is transferred to and processed in the United States. Where personal data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred, we rely on recognized transfer mechanisms such as the European Commission’s Standard Contractual Clauses and our providers’ participation in the EU-U.S. Data Privacy Framework.
How long we keep it
- Website contact requests: kept for up to 24 months after our last contact with you, unless a customer relationship follows.
- Portal account & billing records: kept for the life of the account and as long as required for legal, tax, and records-retention purposes.
- Support ticket attachments: automatically deleted 360 days after a ticket is resolved or closed.
- Audit and security logs: retained for our legal and records-retention period.
On account closure, we deactivate access and delete or return records in accordance with the above; certain audit records are retained where the law requires.
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, to withdraw consent where processing is based on it, and to appeal a decision we make on a request. To exercise these rights, email contact@vantaurasecurity.com. We may need to verify your identity before acting on a request, and an authorized agent may act for you where the law allows. We will respond within the time the applicable law requires, and we will not discriminate against you for exercising your rights. If you are in the EEA, the UK, or Switzerland, you may also lodge a complaint with your local data-protection authority.
Where personal information reaches us through a customer’s use of the portal (for example, a colleague added to your organization’s account), we act on that customer’s instructions; please direct requests to your organization first, and we will support them.
Cookies & tracking
Our analytics are cookieless. We use only strictly necessary cookies and local state for security and to operate the site and portal (for example, our hosting provider’s security checks, the anti-abuse challenge on the contact form, and your portal sign-in session). We do not use advertising or cross-site tracking cookies. Because we do not track visitors across sites, there is nothing for a browser “Do Not Track” or Global Privacy Control signal to switch off; we treat such signals as an opt-out request in any case.
Children
Our website and product are intended for businesses and are not directed to children under 18. We do not knowingly collect personal information from children; if you believe a child has provided us information, contact us and we will delete it.
Security
We protect personal information with encryption in transit and at rest, strict access controls, tenant isolation, least-privilege credentials, and audit logging. No method of transmission or storage is perfectly secure, but we work to protect your information and to disclose incidents as required by law. To report a security concern, see our security page.
Changes to this policy
We may update this policy from time to time. Each version carries its effective date above; for material changes we will provide a more prominent notice where appropriate, such as a note on the website or an email to portal account holders.
Contact
Questions or requests about this policy or your information: contact@vantaurasecurity.com. Legal notices: legal@vantaurasecurity.com. Vantaura Security LLC, Texas, USA.