Skip to main content
Legal

Privacy & Data Collection Policy

Last Updated: September 1, 2026

1. Introduction

SunTzu Security Labs ("SunTzu," "we," "our," or "us") is committed to protecting the privacy, confidentiality, and security of client and visitor information. This Privacy & Data Collection Policy explains how information is handled when you use our website, services, security assessment platforms, and related communications.

Our operational philosophy is based on minimal data collection, secure handling practices, and limiting retention to what is reasonably necessary for providing cybersecurity services and maintaining an active client relationship.

We do not sell personal information, marketing data, scan results, or client information to third parties.

2. Scope

This policy applies to:

  • Visitors to our website
  • Prospective clients
  • Existing clients
  • Authorized users of SunTzu systems and portals
  • Individuals communicating with SunTzu Security Labs

This policy applies to information collected through:

  • Our website
  • Client intake forms
  • Security assessment activities
  • Authorized scanning and reporting services
  • Email and support communications
  • Client portals and hosted platforms

3. Information We Collect

SunTzu Security Labs follows a data minimization approach.

We may collect only the information reasonably necessary to:

  • Provide requested services
  • Verify authorization for security assessments
  • Communicate with clients
  • Generate reports
  • Meet legal or contractual obligations
  • Maintain system security and auditability

Contact Information

  • Name
  • Company name
  • Business email address
  • Business phone number
  • Billing or contract contact details

Technical Information

  • Authorized target domains
  • IP addresses
  • Hostnames
  • DNS records
  • TLS/SSL certificate information
  • Publicly exposed services and metadata
  • Security scan findings
  • Security assessment artifacts and logs

Website Information

Our website may collect limited technical information such as:

  • Browser type
  • Device type
  • IP address
  • Referring pages
  • Basic access logs

This information is used solely for:

  • Website security
  • Operational troubleshooting
  • Abuse prevention
  • Performance monitoring

We do not use invasive behavioral tracking technologies or sell visitor analytics data.

4. HIPAA Considerations

The public website is not intended to receive Protected Health Information (PHI), and use of the website does not establish a HIPAA-regulated service relationship.

Unless explicitly agreed in a signed engagement:

  • Clients should avoid transmitting Protected Health Information (PHI) through public website forms or unsecured email

If regulated data is required for service delivery, scope, safeguards, and contractual requirements must be reviewed before any data is transmitted.

5. GDPR Principles

Where the General Data Protection Regulation (GDPR) applies, contractual scope and data-handling obligations are reviewed for the engagement. The public website follows these privacy principles:

Data Minimization

We collect only the information necessary to provide requested services.

Purpose Limitation

Information is used only for:

  • Service delivery
  • Security operations
  • Legal compliance
  • Contractual obligations

Limited Retention

We do not retain client data indefinitely.

Access & Correction

Where legally applicable, individuals may request:

  • Access to their personal data
  • Correction of inaccurate information
  • Deletion of eligible information

Lawful Basis

Processing activities are generally based on:

  • Contractual necessity
  • Legitimate interest in cybersecurity operations
  • Legal obligations where applicable

6. Data Retention

SunTzu Security Labs believes cybersecurity is a relationship-based service, not a permanent data warehousing business.

Our retention philosophy is:

  • Retain only what is operationally necessary
  • Reduce long-term exposure risk
  • Minimize unnecessary storage of sensitive findings

Active Clients

For active engagements and ongoing service relationships, relevant assessment data and reporting artifacts may be retained to:

  • Support trend analysis
  • Track remediation progress
  • Provide historical comparisons
  • Improve security posture over time

Inactive Clients

When a client relationship becomes inactive:

  • Data may be securely archived or deleted according to operational retention schedules
  • Non-essential artifacts may be purged
  • Raw scan data may be deleted before summarized reporting data

Retention periods may vary depending on:

  • Contractual obligations
  • Legal requirements
  • Compliance requirements
  • Incident preservation needs

Clients may request specific retention handling requirements through written agreement.

7. Security Measures

SunTzu Security Labs uses reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction.

Security measures may include:

  • Encryption of stored data where appropriate
  • Encryption in transit
  • Access controls
  • Authentication controls
  • Audit logging
  • Segmented infrastructure
  • Principle of least privilege
  • Controlled authorization workflows
  • Restricted access to assessment artifacts

No internet-connected system can be guaranteed completely secure. However, we strive to apply industry-aligned security practices appropriate to the nature of the services provided.

8. Authorized Security Assessments

SunTzu Security Labs performs security assessments only against systems for which authorization has been granted.

Clients may be required to:

  • Sign Letters of Authorization (LOAs)
  • Execute Statements of Work (SOWs)
  • Confirm authorized target scope
  • Provide proof of authority where appropriate

Unauthorized scanning requests may be rejected.

9. Third-Party Services

We may utilize reputable third-party providers for:

  • Cloud hosting
  • Infrastructure services
  • Communication services
  • Security tooling

These providers are selected based on operational and security considerations.

SunTzu Security Labs does not sell client or visitor data to advertisers, brokers, or marketing networks.

10. Cookies & Tracking

The launch website does not intentionally set advertising cookies or require an account. Hosting and security providers may process standard request metadata needed to deliver and protect the site.

If site functionality changes, limited technologies may be used for:

  • Site functionality
  • Security controls
  • Performance optimization

We do not intentionally use invasive cross-site behavioral advertising technologies.

Visitors may configure browser settings to limit cookies where technically feasible.

11. International Users

If you access our services from outside the United States, you understand that information may be processed in the United States or other jurisdictions where our infrastructure or providers operate.

Where applicable, reasonable safeguards will be applied to support lawful international processing requirements.

12. Children's Privacy

SunTzu Security Labs services are intended for businesses and professional users and are not directed toward children under 13 years of age.

We do not knowingly collect personal information from children.

13. Changes to This Policy

We may update this Privacy & Data Collection Policy periodically to reflect:

  • Legal changes
  • Operational changes
  • Security improvements
  • Service updates

Updated versions will be posted on this page with a revised effective date.

14. Contact Information

For privacy, compliance, or data handling inquiries, contact:

SunTzu Security Labs

Email: security@suntzusecuritylabs.com

Website: suntzusecuritylabs.com

15. Compliance Cooperation

Engagement-specific compliance requirements are reviewed before work begins. Depending on scope and legal review, supporting documentation may include:

  • Non-Disclosure Agreements (NDAs)
  • Data Processing Agreements (DPAs)
  • Security questionnaires
  • Vendor risk assessments
  • Related compliance documentation as appropriate to the engagement

Privacy obligations vary by location, relationship, and data involved. Contact us with questions about your specific requirements. For specific questions about how your data is handled, please contact our security team.