Privacy Statement
Effective date: August 16, 2026 · Last updated: August 16, 2026
Secontinuum Private Limited runs this website and Vynnn, a security operations (SIEM) platform. For your account and billing details, we decide how data is used — we are the controller. For the security logs and telemetry a customer sends into Vynnn, the customer decides — we process that data on their instructions. Security logs can contain personal data (usernames, IP addresses, emails); the customer is responsible for having the right to send them. We use third-party AI models to analyze security data, host in the EU (Stockholm), don’t sell personal data, and don’t use customer security data to train AI models. To exercise privacy rights, email contact@secontinuum.com — or, if your data is inside an employer’s tenant, start with your employer.
1.Who we are and what this covers
This Privacy Statement is issued by Secontinuum Private Limited, a company incorporated under the laws of India with its registered office at B-1204, Block B, 12th Floor, Aparna Cyberlife, Lingampalli, Serilingampally, K.V. Rangareddy, Telangana, India – 500019 (“Secontinuum”, “we”, “us”). Vynnn is a product of Secontinuum.
This statement covers two surfaces, and we describe them separately where they differ:
- Our public websites — www.secontinuum.com and vynnn.com — and the people who visit them or contact us through them.
- The Vynnn service — our multi-tenant, cloud-hosted SIEM and SOC automation platform — and the customers and users who use it.
For all privacy matters, contact contact@secontinuum.com. Dedicated privacy and legal addresses may be introduced later.
Key terms
- “Account Data”
- Data about the customer relationship itself: registration and profile details, billing records, and support communications. Secontinuum is the controller of Account Data.
- “Customer Data”
- Security logs, telemetry, detections, investigations, custom rules, and related content that a customer sends to the Service or authorizes it to collect. The customer is typically the controller; Secontinuum processes it on the customer’s instructions.
- “Service”
- Vynnn, including its consoles, ingest endpoints, host agents, connectors, and APIs.
- “Tenant”
- The isolated environment provisioned for each customer within the Service.
- “User”
- An individual authorized by a customer to use the Service under its Tenant.
- “Subprocessor”
- A third party we engage to process data in connection with providing the Service.
2.Our roles: controller and processor
We act in two different capacities, and your rights route differently depending on which applies:
- Controller of Account Data. We decide how and why we process data about website visitors, sign-ups, billing, and support. For this data, come to us directly.
- Processor of Customer Data. Security telemetry inside a Tenant belongs to the customer, who decides what to collect and how long to keep it. We process it to provide the Service, on the customer’s instructions. For this data, the customer (for example, your employer) is usually the right first point of contact, and we assist them in responding.
A Data Processing Agreement (DPA) reflecting these roles is available on request at contact@secontinuum.com.
3.Whose data we process
- Website visitors and people who contact us (for example through the demo request form);
- Trial and account users — the people who sign up for or administer a Tenant;
- Customer security analysts and other Users working inside a Tenant;
- Customer end-users whose activity appears in ingested logs — employees, contractors, and, at times, attackers whose actions are recorded in security telemetry;
- Vendor and partner contacts.
4.What we collect and why
Website (we are controller)
| Data | Purpose |
|---|---|
| IP address, browser user-agent, pages visited, and analytics events (see Cookies and analytics) | Operating, securing, and improving the website; understanding aggregate usage. |
| Contact and demo-request form fields: name, work email, company, message, and related technical metadata about the submission | Responding to your inquiry and following up about the Service. |
Account and billing (we are controller)
| Data | Purpose |
|---|---|
| Name, work email, password hash, optional avatar, timezone, role, Tenant membership, last login | Providing and securing accounts; authentication and session management. |
| Support tickets and communications | Support, troubleshooting, and service communications. |
| Billing records, handled through a third-party payment processor. We do not store full card numbers. | Invoicing, payment, and accounting obligations. |
Service / Customer Data (we are processor)
| Data | Purpose |
|---|---|
| Security logs and telemetry the customer sends: for example authentication logs, cloud API events, process and command-line records, endpoint alerts, and forwarded events. These can incidentally contain personal data such as IP addresses, hostnames, usernames, file paths, and email addresses that appear in logs. | Threat detection, investigation, and response — the core function of the Service. |
| Detections, investigation notes, verdicts, and AI agent outputs | Presenting, tracking, and resolving security incidents. |
| Connection and configuration material: API keys and agent tokens (stored hashed or as managed secrets), webhook URLs, cloud connector role identifiers, Microsoft tenant and consent tokens, branding assets | Operating the integrations and Tenant configuration the customer sets up. |
Usage and operations
| Data | Purpose |
|---|---|
| Audit logs of administrative and privileged actions | Security, accountability, and abuse response. |
| Health, monitoring, and diagnostic data; backups | Reliability, capacity, disaster recovery. |
5.Legal bases and US privacy disclosures
Where GDPR or similar laws apply, we rely on:
- Contract — providing the Service and website features you request;
- Legitimate interests — securing our Service and customers, preventing fraud and abuse, and keeping the product reliable;
- Consent — where required, for example for non-essential cookies or optional marketing communications;
- Legal obligation — accounting, tax, and responses to lawful requests.
For residents of California and similar US states: we do not sell personal information, and we do not share it for cross-context behavioral advertising. The categories we collect are described in Section 4; rights and how to exercise them are in Section 13. As an Indian company, we also have regard to India’s Digital Personal Data Protection Act, 2023, as it applies.
6.Where data comes from
- Directly from you — forms, sign-up, support requests;
- From your employer or Tenant administrator, who creates and manages accounts;
- From systems the customer connects — cloud accounts, identity providers, endpoints, and forwarders the customer authorizes;
- From security telemetry the customer sends to the Service;
- From our Subprocessors’ operational logs generated while providing the Service.
7.AI processing
Vynnn’s SOC agents use a third-party AI model provider to verify detections, investigate incidents, recommend remediation, and support onboarding tasks such as identifying personal data present in logs. This means relevant Customer Data — telemetry excerpts, detections, and analyst context — can be sent to that provider as a Subprocessor, and that content may include personal data the customer ingested.
We do not use Customer Data — security logs, telemetry, detections, or investigation content — to train AI models. We may use operational data about our own agents’ behavior (actions taken, playbook outcomes, performance and feedback signals) to improve the Service.
10.International transfers
The Service is hosted in the EU (Stockholm). Some Subprocessors, including our AI model provider, may process data outside the EEA or India. Where personal data is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses.
11.Retention and deletion
- Account Data is kept while the account is active and for a reasonable period after closure for security, billing, and legal obligations.
- Security telemetry is retained per the customer’s plan and configuration, then deleted or archived. Expired detections may become unavailable in the console.
- Backups exist for a shorter, overlapping window and expire on their normal cycle.
On termination of a customer agreement, Customer Data is deleted or returned as described in our Terms of Service, except for backups and legal holds.
12.Security
We protect data with multi-tenant isolation (per-tenant application data and tenant-scoped event stores), encryption in transit (TLS), role-based access control, audit logging of privileged actions, managed secrets storage, and least-privilege access within our infrastructure. Platform staff may access Tenants only for operations, support, and abuse or security response.
No system is perfectly secure, and we do not promise absolute security. We do not currently hold SOC 2, ISO 27001, or similar certifications; we are actively working toward SOC 2 and other compliance certifications.
13.Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict the personal data we hold about you, to object to certain processing, and to withdraw consent where processing is based on consent. We do not discriminate against you for exercising them.
- For Account Data (your profile, billing, support history): email contact@secontinuum.com. We may need to verify your identity, and we respond within the timelines required by applicable law.
- For data inside a customer’s Tenant (for example, your activity appearing in your employer’s security logs): the customer is typically the controller, so contact your employer’s or organization’s administrator first. If a request reaches us directly, we will refer it to the relevant customer and assist them in responding.
Tenant administrators control their own Users — they can update profiles, change roles, and remove accounts directly in the console.
14.Children’s data
Our websites and the Service are for business use by people aged 18 and over. We do not knowingly collect data from children, and we do not offer accounts to them. Note that security telemetry ingested by a customer reflects activity on the customer’s systems; the customer is responsible for what its systems record.
15.Automated decision-making
Vynnn’s AI analyses and recommended remediations are assistive: they inform human analysts and administrators, who remain responsible for decisions and actions. We do not make solely automated decisions that produce legal or similarly significant effects about individuals — including a customer’s end-users — and the Service is not designed to be used that way (for example, for employment decisions).
16.Changes to this statement
We may update this statement from time to time. The “Last updated” date at the top shows the current version. For material changes we will give notice via the website and/or email before the new version takes effect.
17.Complaints and supervisory authorities
If you believe we have processed your personal data unlawfully, please contact us first at contact@secontinuum.com so we can try to resolve it. You may also have the right to lodge a complaint with a data protection authority in your place of residence or work — for example, a supervisory authority in an EEA member state, or the Data Protection Board of India once operational.
18.Contact
Secontinuum Private Limited
B-1204, Block B, 12th Floor, Aparna Cyberlife,
Lingampalli, Serilingampally, K.V. Rangareddy,
Telangana, India – 500019
Privacy, support, and legal: contact@secontinuum.com