Privacy Statement

Effective date: August 16, 2026 · Last updated: August 16, 2026

Summary in plain language

Secontinuum Private Limited runs this website and Vynnn, a security operations (SIEM) platform. For your account and billing details, we decide how data is used — we are the controller. For the security logs and telemetry a customer sends into Vynnn, the customer decides — we process that data on their instructions. Security logs can contain personal data (usernames, IP addresses, emails); the customer is responsible for having the right to send them. We use third-party AI models to analyze security data, host in the EU (Stockholm), don’t sell personal data, and don’t use customer security data to train AI models. To exercise privacy rights, email contact@secontinuum.com — or, if your data is inside an employer’s tenant, start with your employer.

1.Who we are and what this covers

This Privacy Statement is issued by Secontinuum Private Limited, a company incorporated under the laws of India with its registered office at B-1204, Block B, 12th Floor, Aparna Cyberlife, Lingampalli, Serilingampally, K.V. Rangareddy, Telangana, India – 500019 (“Secontinuum”, “we”, “us”). Vynnn is a product of Secontinuum.

This statement covers two surfaces, and we describe them separately where they differ:

  • Our public websites — www.secontinuum.com and vynnn.com — and the people who visit them or contact us through them.
  • The Vynnn service — our multi-tenant, cloud-hosted SIEM and SOC automation platform — and the customers and users who use it.

For all privacy matters, contact contact@secontinuum.com. Dedicated privacy and legal addresses may be introduced later.

Key terms

Account Data
Data about the customer relationship itself: registration and profile details, billing records, and support communications. Secontinuum is the controller of Account Data.
Customer Data
Security logs, telemetry, detections, investigations, custom rules, and related content that a customer sends to the Service or authorizes it to collect. The customer is typically the controller; Secontinuum processes it on the customer’s instructions.
Service
Vynnn, including its consoles, ingest endpoints, host agents, connectors, and APIs.
Tenant
The isolated environment provisioned for each customer within the Service.
User
An individual authorized by a customer to use the Service under its Tenant.
Subprocessor
A third party we engage to process data in connection with providing the Service.

2.Our roles: controller and processor

We act in two different capacities, and your rights route differently depending on which applies:

  • Controller of Account Data. We decide how and why we process data about website visitors, sign-ups, billing, and support. For this data, come to us directly.
  • Processor of Customer Data. Security telemetry inside a Tenant belongs to the customer, who decides what to collect and how long to keep it. We process it to provide the Service, on the customer’s instructions. For this data, the customer (for example, your employer) is usually the right first point of contact, and we assist them in responding.

A Data Processing Agreement (DPA) reflecting these roles is available on request at contact@secontinuum.com.

3.Whose data we process

  • Website visitors and people who contact us (for example through the demo request form);
  • Trial and account users — the people who sign up for or administer a Tenant;
  • Customer security analysts and other Users working inside a Tenant;
  • Customer end-users whose activity appears in ingested logs — employees, contractors, and, at times, attackers whose actions are recorded in security telemetry;
  • Vendor and partner contacts.

4.What we collect and why

Website (we are controller)

DataPurpose
IP address, browser user-agent, pages visited, and analytics events (see Cookies and analytics)Operating, securing, and improving the website; understanding aggregate usage.
Contact and demo-request form fields: name, work email, company, message, and related technical metadata about the submissionResponding to your inquiry and following up about the Service.

Account and billing (we are controller)

DataPurpose
Name, work email, password hash, optional avatar, timezone, role, Tenant membership, last loginProviding and securing accounts; authentication and session management.
Support tickets and communicationsSupport, troubleshooting, and service communications.
Billing records, handled through a third-party payment processor. We do not store full card numbers.Invoicing, payment, and accounting obligations.

Service / Customer Data (we are processor)

DataPurpose
Security logs and telemetry the customer sends: for example authentication logs, cloud API events, process and command-line records, endpoint alerts, and forwarded events. These can incidentally contain personal data such as IP addresses, hostnames, usernames, file paths, and email addresses that appear in logs.Threat detection, investigation, and response — the core function of the Service.
Detections, investigation notes, verdicts, and AI agent outputsPresenting, tracking, and resolving security incidents.
Connection and configuration material: API keys and agent tokens (stored hashed or as managed secrets), webhook URLs, cloud connector role identifiers, Microsoft tenant and consent tokens, branding assetsOperating the integrations and Tenant configuration the customer sets up.

Usage and operations

DataPurpose
Audit logs of administrative and privileged actionsSecurity, accountability, and abuse response.
Health, monitoring, and diagnostic data; backupsReliability, capacity, disaster recovery.

6.Where data comes from

  • Directly from you — forms, sign-up, support requests;
  • From your employer or Tenant administrator, who creates and manages accounts;
  • From systems the customer connects — cloud accounts, identity providers, endpoints, and forwarders the customer authorizes;
  • From security telemetry the customer sends to the Service;
  • From our Subprocessors’ operational logs generated while providing the Service.

7.AI processing

Vynnn’s SOC agents use a third-party AI model provider to verify detections, investigate incidents, recommend remediation, and support onboarding tasks such as identifying personal data present in logs. This means relevant Customer Data — telemetry excerpts, detections, and analyst context — can be sent to that provider as a Subprocessor, and that content may include personal data the customer ingested.

We do not use Customer Data — security logs, telemetry, detections, or investigation content — to train AI models. We may use operational data about our own agents’ behavior (actions taken, playbook outcomes, performance and feedback signals) to improve the Service.

8.Cookies and analytics

Marketing website

www.secontinuum.com uses Google Analytics 4 to measure aggregate site usage (pages viewed, approximate location, device and browser type). The site does not currently show a cookie consent banner; a consent mechanism for visitors in regions that require one is under review. You can refuse analytics by blocking cookies in your browser, using a content blocker, or installing Google’s Analytics opt-out browser add-on.

Product (SOC console)

The Vynnn console does not use third-party marketing or analytics trackers. It uses only technical storage needed to run the application — session tokens are stored in your browser’s local storage and can be revoked by signing out or by a Tenant administrator.

9.How we share data

We share personal data only as needed to run the Service and our business:

  • Our cloud hosting provider — hosting and storage, primary region in the EU (Stockholm);
  • Our AI model provider — AI processing as described in Section 7;
  • Other service providers that support our business, such as email, billing, and support tooling. An up-to-date list of Subprocessors is available on request at contact@secontinuum.com;
  • Professional advisors (lawyers, accountants, auditors) under confidentiality;
  • Public authorities, where required by applicable law or valid legal process;
  • A successor entity in connection with a merger, acquisition, or asset sale, with notice where required.

We do not sell Customer Data or personal data. Customers can also direct the Service to send data outward themselves — for example to webhook URLs they configure — and are responsible for those destinations.

10.International transfers

The Service is hosted in the EU (Stockholm). Some Subprocessors, including our AI model provider, may process data outside the EEA or India. Where personal data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses.

11.Retention and deletion

  • Account Data is kept while the account is active and for a reasonable period after closure for security, billing, and legal obligations.
  • Security telemetry is retained per the customer’s plan and configuration, then deleted or archived. Expired detections may become unavailable in the console.
  • Backups exist for a shorter, overlapping window and expire on their normal cycle.

On termination of a customer agreement, Customer Data is deleted or returned as described in our Terms of Service, except for backups and legal holds.

12.Security

We protect data with multi-tenant isolation (per-tenant application data and tenant-scoped event stores), encryption in transit (TLS), role-based access control, audit logging of privileged actions, managed secrets storage, and least-privilege access within our infrastructure. Platform staff may access Tenants only for operations, support, and abuse or security response.

No system is perfectly secure, and we do not promise absolute security. We do not currently hold SOC 2, ISO 27001, or similar certifications; we are actively working toward SOC 2 and other compliance certifications.

13.Your rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict the personal data we hold about you, to object to certain processing, and to withdraw consent where processing is based on consent. We do not discriminate against you for exercising them.

  • For Account Data (your profile, billing, support history): email contact@secontinuum.com. We may need to verify your identity, and we respond within the timelines required by applicable law.
  • For data inside a customer’s Tenant (for example, your activity appearing in your employer’s security logs): the customer is typically the controller, so contact your employer’s or organization’s administrator first. If a request reaches us directly, we will refer it to the relevant customer and assist them in responding.

Tenant administrators control their own Users — they can update profiles, change roles, and remove accounts directly in the console.

14.Children’s data

Our websites and the Service are for business use by people aged 18 and over. We do not knowingly collect data from children, and we do not offer accounts to them. Note that security telemetry ingested by a customer reflects activity on the customer’s systems; the customer is responsible for what its systems record.

15.Automated decision-making

Vynnn’s AI analyses and recommended remediations are assistive: they inform human analysts and administrators, who remain responsible for decisions and actions. We do not make solely automated decisions that produce legal or similarly significant effects about individuals — including a customer’s end-users — and the Service is not designed to be used that way (for example, for employment decisions).

16.Changes to this statement

We may update this statement from time to time. The “Last updated” date at the top shows the current version. For material changes we will give notice via the website and/or email before the new version takes effect.

17.Complaints and supervisory authorities

If you believe we have processed your personal data unlawfully, please contact us first at contact@secontinuum.com so we can try to resolve it. You may also have the right to lodge a complaint with a data protection authority in your place of residence or work — for example, a supervisory authority in an EEA member state, or the Data Protection Board of India once operational.

18.Contact

Secontinuum Private Limited
B-1204, Block B, 12th Floor, Aparna Cyberlife,
Lingampalli, Serilingampally, K.V. Rangareddy,
Telangana, India – 500019

Privacy, support, and legal: contact@secontinuum.com