Legal
Privacy Policy
This policy explains what personal data Preventio collects, why, and the rights you have over it.
1. Who we are
Preventio is operated by Fred ("Fred", trading as Preventio, "we", "us"), which is the data controller for the personal data described in this notice.
Preventio operates preventio.live, an event security intelligence platform that produces threat assessments, OSINT reviews and operational risk briefings for public events.
For questions about this policy or your data, contact us via the contact page at preventio.live/contact.
2. Data we collect
Account data: email address and authentication identifiers when you register or sign in (including via Google sign-in).
Briefing data: the event information you enter to generate a briefing, and the briefings you save to your account.
Contact data: name, work email, organization and message content submitted through our contact and sales forms.
Subscription data: the plan you purchase, subscription status, renewal dates and the transaction/customer identifiers we receive back from Paddle. Card details are never collected or stored by us — they are handled directly by Paddle.
Technical data: standard server logs (IP address, browser type, timestamps) used for security, abuse prevention and rate limiting.
3. How we use data
To provide the service: authenticate you, generate, store and display your briefings, and operate shared read-only report links you explicitly create.
To respond to inquiries and sales requests you send us.
To secure the platform: prevent spam, abuse and unauthorized access.
We do not sell personal data and do not use your briefing content for advertising.
Briefing content submitted via the OpenAI API is not used to train AI models. OpenAI's API data usage policy excludes API inputs and outputs from model training by default.
4. Shared report links
When you use the Share action, the briefing content is stored with a random, non-guessable token and becomes viewable by anyone holding that link, without login. You control what you share; treat the link as confidential.
5. Legal basis and retention
We process data to perform the service you request (contract), for our legitimate interest in securing and improving the platform, and — for optional communications — on your consent.
Account and briefing data are retained while your account is active. Contact submissions are retained as long as needed to handle the request and for a reasonable follow-up period. You may request deletion at any time.
6. Who we share data with
Payments and Merchant of Record: Paddle.com Market Limited acts as reseller and Merchant of Record for all orders. Paddle receives the data needed to process your purchase (name, billing email, billing address/country, payment details, purchase and tax information) and processes it for payment, fraud prevention, invoicing, subscription management and tax compliance. See Paddle's own privacy notice at paddle.com/legal/privacy.
Service providers and subprocessors: hosting, database, authentication, email delivery and AI-processing providers used to run the platform and generate analytical content.
Professional advisers (legal, accounting) and public authorities where we are required to disclose by law.
Data may be processed outside your country; where required, appropriate safeguards such as standard contractual clauses are applied. We do not sell personal data.
7. Your rights
Depending on your jurisdiction (including the GDPR in the EU/EEA), you may have the right to access, rectify, erase, restrict or port your personal data, and to object to processing. To exercise these rights, contact us at preventio.live/contact.
8. Security
We apply appropriate technical and organisational measures, including encryption in transit and at rest, access controls and row-level authorisation on stored data.
9. Changes
We may update this policy from time to time. Material changes will be signposted on this page. Last updated: September 2026.
