Privacy Policy
This Privacy Policy explains how SuperTools (“SuperTools,” “we,” “us,” “our”) collects, uses, discloses, and protects information in connection with the SuperTools platform (the “Service”), an AI-powered autonomous offensive security and penetration testing platform.
This Policy covers information about our business contacts and Customer personnel who use the Service (“you”). It does notprimarily govern the Target data, source code, and vulnerability Findings that Customer submits for scanning — that data is addressed separately in Section 4 below and in our Terms of Service, since it is processed on behalf of Customer rather than collected from you as an individual.
1. Information We Collect
a) Information you provide directly
- Contact and lead information: full name, company name, WhatsApp/phone number, business email, and country, submitted through our contact/demo request form.
- Account information: name, email, company, and role, when you register for or are added to a Customer account.
- Communications: messages sent via our AI Pentester Chat, support requests, and correspondence with our team.
b) Information collected through use of the Service
- Usage data: log-in times, feature usage, pages visited on our marketing site, browser/device type, IP address.
- Cookies and similar technologies: see Section 8.
c) Customer Data submitted for security assessments
This is the most sensitive category we process, and includes, where applicable:
- Target identifiers (domains, IP ranges, application URLs);
- Source code and configuration files submitted via the CLI;
- VPN configuration files (OpenVPN
.ovpn/ WireGuard.conf) used to reach internal network Targets; - Mobile application packages (APKs) and Windows binaries submitted for analysis;
- Scan results, vulnerability Findings, proof-of-concept evidence, and CVSS/CWE-mapped reports.
We process this Customer Data as a service provider/processor acting on Customer’s instructions to deliver the Service — not for our own independent marketing purposes.
2. How We Use Information
We use the information above to:
- Provide, operate, and secure the Service, including running Scans and generating reports;
- Respond to contact/demo requests and manage the sales and onboarding process;
- Authenticate users and maintain account security;
- Improve detection accuracy and reduce false positives, using de-identified and aggregated data where possible;
- Communicate service updates, security notices, and (where you’ve consented) product news;
- Comply with legal obligations, enforce our Terms of Service, and investigate suspected unauthorized or unlawful use (see Terms of Service, Section 4).
We do not use Customer’s Target data, source code, or vulnerability Findings to train models shared across customers, or sell it, without explicit written agreement.
3. Legal Bases for Processing
Where applicable data protection law requires a legal basis (e.g., under GDPR or similar frameworks), we rely on: performance of a contract with Customer, our legitimate interests in operating and securing the Service, your consent (e.g., for marketing communications or optional cookies), and compliance with legal obligations.
4. Data Ownership, Confidentiality, and No Third-Party Sale of Scan Data
- Findings, Target data, and related scan artifacts are securely processed and stored on SuperTools servers as necessary to deliver the Service.
- We do not share Customer scan data or Findings with third parties, except: (a) sub-processors who host our infrastructure under confidentiality and security obligations equivalent to this Policy (e.g., cloud hosting providers); (b) a third-party integration Customer explicitly enables (e.g., Jira), in which case that third party’s own terms apply to data sent to it; or (c) where required by law, regulation, or valid legal process.
- All Findings are encrypted at rest and in transit and are accessible only to Customer’s authorized team members and the SuperTools personnel who need access to operate or support the Service.
5. How We Share Information
We may share the categories of information described in Section 1(a)/(b) with:
- Service providers who support hosting, analytics, customer support, or billing, under contractual confidentiality and data protection obligations;
- Professional advisors (legal, accounting) as needed;
- Authorities, where required to comply with law, respond to lawful requests, or protect rights, safety, or property — including where we reasonably suspect Customer has submitted a Target without proper authorization (see Terms of Service, Section 4);
- A successor entity, in connection with a merger, acquisition, or asset sale, subject to this Policy or a materially similar one.
We do not sell personal information as that term is defined under applicable law.
6. Data Security
We apply technical and organizational measures appropriate to the sensitivity of vulnerability and Target data, including encryption of Findings, role-based access controls restricting data to authorized Customer team members, rate-limited and scoped execution of Agents, audit logging of scan activity, and a kill switch to halt active testing. No system is completely secure; we maintain incident response procedures and will notify affected Customers of a confirmed data breach affecting their data without undue delay and in accordance with applicable law.
7. Data Retention
- Account and contact information is retained for as long as your account is active, plus a reasonable period thereafter for legal, tax, or dispute-resolution purposes.
- Scan data and Findings are retained on SuperTools servers to support your ongoing dashboard, historical reporting, and compliance audit trail, for the duration of your subscription plus 12 months, or until you request earlier deletion.
- Purchased, unused scan credits do not expire, but we may archive associated historical scan data after 24 months of account inactivity; contact us to request earlier deletion.
8. Cookies and Similar Technologies
Our marketing website and Service dashboard may use cookies or similar technologies for authentication, session management, and (where consented) analytics. You can control cookies through your browser settings; disabling essential cookies may affect Service functionality.
9. International Data Transfers and Data Residency
We primarily serve enterprise clients across Southeast Asia. Scan data is stored on servers located in Indonesia. If data is transferred across borders (e.g., to sub-processors in another country), we take steps required by applicable law to protect it, such as standard contractual clauses or equivalent safeguards where required.
10. Your Rights
Depending on applicable law (which may include Indonesia’s Personal Data Protection Law, Singapore’s PDPA, GDPR, or other regional frameworks), you may have rights to:
- Access, correct, or request deletion of your personal information;
- Object to or restrict certain processing;
- Withdraw consent for marketing communications at any time;
- Request a copy of your data in a portable format;
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at admin@supertool.web.id. Note that Target scan data and Findings submitted by an organization are generally controlled by that organization (your employer/Customer); individual requests regarding that data may need to go through your organization’s account administrator.
11. Children's Privacy
The Service is intended for business use by enterprise security teams and is not directed at individuals under 18. We do not knowingly collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email at least 15 days before taking effect, and the “Last Updated” date above will be revised accordingly.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact:
SuperTools
Tangerang, Banten, Indonesia
Email: admin@supertool.web.id