
Privacy Policy
This Privacy Policy explains how Scrubbe Inc. collects, uses, stores, and protects personal data in connection with the Scrubbe incident intelligence platform and our marketing presence. We are committed to processing personal data lawfully and transparently, in accordance with the California Consumer Privacy Act (CCPA/CPRA), other applicable U.S. state privacy laws, and applicable data protection law.
Overview & Scope
Data you own
Customer incident and telemetry data remains yours. We process it only on your instructions.
CCPA/CPRA Service ProviderWhere it lives
Processed and stored in the United States by default. Enterprise residency options available.
U.S. defaultHow long we keep it
Account data is deleted within 90 days of termination. Audit logs retained for 7 years.
30-day export windowYour rights
Know, correct, delete, opt out of sale/sharing, and non-discrimination — respond within 45 days.
CCPA/CPRA Consumer RightsBreach notification
We notify affected customers within 72 hours of confirming a breach affecting your personal data.
72-hr notification commitmentNo selling of data
We never sell, rent, or trade personal data to third parties for marketing purposes.
No sale or sharing (CCPA)This Privacy Policy applies to all personal data processed by Scrubbe Inc. in connection with:
- ›The Platform: Personal data of Authorized Users who access the Scrubbe incident intelligence platform under a subscription.
- ›The Website: Personal data of visitors to www.scrubbe.com, visitors to and any associated marketing pages or documentation portals.
- ›Sales & Support: Personal data collected during pre-sales conversations, customer onboarding, technical support engagements, and account management.
- ›Customer Data (as processor): Telemetry, alert data, log payloads, and other operational data that Customers submit to the Platform. We process this as a data processor acting on Customer instructions — not as a controller.
This Policy does not govern data processed by third-party services that you may connect to the Platform via Connectors (e.g. PagerDuty, Datadog, AWS). You should review the privacy policies of those services separately.
Controller vs Processor
For personal data in Customer-submitted incident payloads and telemetry, Scrubbe acts as a Data Processor (a "Service Provider" under the CCPA/CPRA) and the Customer is the Data Controller (a "Business" under the CCPA/CPRA).
Our Data Processing Agreement ("DPA") governs that relationship. This Policy primarily describes our activities as a data controller in our own right.
Data Controller
The data controller responsible for personal data processed under this Policy is:
| Company | Scrubbe Inc. |
| Jurisdiction | United States |
| Website | www.scrubbe.com |
| Privacy contact | privacy@scrubbe.com |
| Primary regulators | Federal Trade Commission (FTC) for general consumer protection; California Privacy Protection Agency (CPPA) and California Attorney General for CCPA/CPRA enforcement; other state Attorneys General as applicable under their respective state privacy laws. |
Data We Collect
We collect personal data in the following categories depending on how you interact with Scrubbe:
| Category | Examples | Source |
|---|---|---|
| Account & identity | Name, work email address, job title, organization name, profile picture | Provided by you or your employer at onboarding |
| Authentication data | Hashed passwords, SSO tokens, MFA state, session tokens | Generated at login; never stored in plaintext |
| Usage & activity | Feature interactions, dashboard views, playbook configurations, incident approvals/rejections, API calls | Automatically collected via platform instrumentation |
| Audit events | User ID, action type, timestamp, IP address, policy version evaluated, outcome | Automatically generated for every state transition |
| Device & technical | IP address, browser type and version, operating system, viewport size, time zone | Automatically collected on web access |
| Communications | Support tickets, email correspondence, sales call notes, product feedback | Provided by you directly |
| Connector credentials | API keys, OAuth tokens, service account identifiers for third-party integrations | Provided by Customer Authorized Users; stored encrypted |
| Marketing & website | Name, work email, company, interest area from contact or demo request forms; cookie identifiers | Provided by you on the website |
| Payment data | Billing contact name and email, company name, tax identification number (e.g., EIN or VAT/GST where applicable). Card details are handled exclusively by our payment processor and never stored by Scrubbe. | Provided at subscription purchase |
We do not knowingly collect special category personal data (health, biometric, racial or ethnic origin, political opinions, etc.) in the normal course of operating the Platform. If any such data appears in Customer-submitted incident payloads, it is processed as Customer Data under the DPA and the Customer is responsible as controller for its lawfulness.
How we use Data
We use personal data collected as controller for the following purposes:
| Service delivery: | Provisioning accounts, authenticating users, enforcing role-based access controls, routing notifications, and delivering all platform features within Subscription entitlements. |
| Security and integrity: | Detecting, investigating, and responding to security incidents, abuse, and policy violations. Maintaining the immutable audit trail of all platform actions. |
| Product improvement: | Analyzing aggregated, anonymized usage patterns to prioritize features, improve agent accuracy, and optimize system performance. We do not use individual-level usage data to build personal profiles for advertising. |
| Customer communications: | Sending service notifications, release notes, security advisories, billing communications, and support responses. These are non-optional for account holders. |
| Marketing: | Sending product updates, case studies, webinar invitations, and relevant content to prospects and customers who have opted in. You may withdraw consent at any time. |
| Legal compliance: | Meeting obligations under applicable law, including responding to lawful requests from regulatory authorities. |
| Business operations: | Managing our commercial relationships, processing payments, and maintaining corporate records. |
No Automated Decision-Making on You
While the Scrubbe Platform uses AI agents to make automated decisions about operational incidents, we do not use automated decision-making or profiling about individual users or data subjects that produces legal or similarly significant effects, consistent with automated-decision-making protections under applicable U.S. state privacy laws (e.g., Colorado and Connecticut).
Customer & Incident Data
When Customers submit telemetry, alerts, log payloads, and related operational data to the Platform, Scrubbe acts exclusively as a data processor (a "Service Provider" under the CCPA/CPRA, and a "Processor" under other applicable U.S. state privacy laws). This means:
- ›We process Customer Data only on documented instructions from the Customer (as set out in the DPA and Order Form).
- ›We do not use Customer Data for any purpose other than providing and maintaining the Service, unless required by law.
- ›We impose binding confidentiality and data protection obligations on all sub-processors who access Customer Data.
- ›We assist Customers in responding to data subject rights requests relating to personal data contained within Customer Data.
- ›We maintain records of all processing activities performed on behalf of each Customer tenant.
- ›Upon termination, Customer Data is retained for 30 days to allow export and then securely deleted within 90 days, except where law requires longer retention.
Customer Responsibility
Customers are responsible as data controllers for ensuring they have a lawful basis for submitting personal data to the Platform via Connectors. Scrubbe's ingestion pipeline processes all submitted data without inspecting it for personal data at the point of entry — it is the Customer's responsibility to apply appropriate data minimization at source.
Scrubbe maintains a Data Processing Agreement ("DPA") that governs all processor-level processing. Enterprise Customers must execute the DPA prior to submitting personal data to the Platform. Our standard DPA is available at www.scrubbe.com/dpa.
Data Sharing
We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:
| Sub-processors | Third-party infrastructure and SaaS providers that process personal data on our behalf to deliver the Service (e.g. cloud hosting, email delivery, error monitoring, payment processing). A current list of sub-processors is maintained at www.scrubbe.com/sub-processors. We notify Customers at least 30 days before adding a new sub-processor. |
| Professional advisors | Lawyers, auditors, and accountants acting in an advisory capacity, subject to professional confidentiality obligations. |
| Regulatory authorities | We may disclose personal data to regulatory or law enforcement authorities where required by applicable law or a valid legal order. We will notify affected Customers where legally permitted to do so. |
| Business transactions | In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the successor entity, subject to equivalent privacy protections. We will notify affected individuals before any such transfer takes effect. |
| With your consent | For any sharing not described above, we will seek your explicit consent before proceeding. |
International Transfers
Scrubbe is headquartered in the United States. By default, personal data and Customer Data are processed and stored within the United States.
Where we process personal data originating from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, we put an appropriate safeguard in place for the transfer to the United States, including:
- ›EU Standard Contractual Clauses (SCCs) for transfers of personal data from the EEA, supplemented by a Transfer Impact Assessment where required.
- ›UK International Data Transfer Agreement (IDTA) / UK Addendum for transfers of personal data from the United Kingdom.
- ›Other legally recognized transfer mechanisms as they become available or are required under applicable law.
Enterprise Customers requiring data residency in a specific region may request this configuration in their Order Form. We will identify any sub-processors that may necessitate transfers outside that region and provide appropriate documentation.
Transfer Records
You may request a copy of the transfer safeguards applicable to your data by contacting privacy@scrubbe.com. We maintain records of processing activities, including all international transfer mechanisms.
Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law. Our standard retention periods are:
Duration of subscription + 30 days
Account & profile data
Name, work email, role, and access records. Retained for 30 days post-termination to allow export, then permanently deleted.
Duration of subscription + 90 days
Customer incident & telemetry data
All Customer Data processed as a processor, including enriched incident records and agent action logs. Securely deleted within 90 days of contract end, unless law requires longer.
7 years
Audit trail & compliance records
The immutable audit log of all state transitions, approvals, policy evaluations, and action outcomes. Retained for regulatory compliance and legal defensibility.
7 years
Financial & billing records
Invoices, payment records, and associated contact data retained to satisfy applicable U.S. federal and state tax and accounting recordkeeping requirements.
3 years from last contact
Marketing & prospect data
Records of individuals who have expressed interest in Scrubbe but have not become customers. Suppression records (opt-outs) are retained indefinitely.
90 days rolling
Security & access logs
Server access logs, authentication events, and IP address records used for security monitoring and incident investigation.
Security
Scrubbe implements layered technical and organizational security measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include:
| Encryption in transit: | All data transmitted between clients and the Platform uses TLS 1.2 or higher. Internal service-to-service communication is encrypted. |
| Encryption at rest: | All stored personal data and Customer Data is encrypted using AES-256. |
| Access controls: | Scrubbe personnel access to Customer environments is strictly role-limited, logged, and subject to a least-privilege policy. Access requires multi-factor authentication. |
| Penetration testing: | Annual independent penetration tests and continuous automated vulnerability scanning of the Platform. |
| Incident response: | A documented information security incident response process, including escalation paths and Customer notification procedures. |
| Sub-processor assessment: | All sub-processors handling personal data are assessed for security posture before onboarding and periodically thereafter. |
| Immutable audit logs: | All access to Customer Data by Scrubbe personnel is logged in an append-only audit trail that cannot be modified or deleted. |
Breach notification. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify affected Customers within 72 hours of confirming the breach, providing sufficient information to allow them to fulfill their own notification obligations. Where required by applicable state law, we will also notify affected individuals and state Attorneys General within the timeframes those laws prescribe.
To report a security vulnerability or suspected breach, contact security@scrubbe.com.
Your Rights
Depending on your state of residence, you have some or all of the following rights in relation to personal data we hold about you as controller, under applicable U.S. state privacy laws — including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and similar laws in Colorado, Connecticut, Virginia, Utah, and other states. These rights apply to our processing of your personal data as a Scrubbe user, website visitor, or contact — not to Customer Data (where rights should be directed to the relevant Customer/controller).
CCPA/CPRA § 1798.100
Right to Know / Access
Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, purposes, and any third parties it was disclosed to.
CCPA/CPRA § 1798.106
Right to Correct
Request correction of inaccurate or incomplete personal data we hold about you.
CCPA/CPRA § 1798.105
Right to Delete
Request deletion of your personal data, subject to legal retention requirements and certain exceptions.
CCPA/CPRA § 1798.121
Right to Limit Sensitive Data
Limit the use and disclosure of sensitive personal information to what is necessary to provide the Service.
CCPA/CPRA § 1798.100
Right to Portability
Receive your personal data in a structured, machine-readable format and transfer it to another controller where technically feasible.
CCPA/CPRA § 1798.120
Right to Opt Out of Sale/Sharing
Direct us not to sell or share your personal information. As noted above, we do not sell or share personal data for cross-context behavioral advertising.
CCPA/CPRA § 1798.125
Right to Non-Discrimination
We will not deny goods or services, charge a different price, or provide a different level of service because you exercised a privacy right.
State AG / FTC
Right to Lodge a Complaint
Lodge a complaint with the California Privacy Protection Agency (CPPA), your state Attorney General, the Federal Trade Commission (FTC), or your local supervisory authority if you believe we have infringed your rights.
To exercise any right, submit a request to privacy@scrubbe.com. We will respond within 45 days (extendable by a further 45 days for complex requests, with notice). We may need to verify your identity before processing the request, and may require a higher level of verification for delete or correct requests. Rights requests are free of charge, though we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests. You may designate an authorized agent to submit a request on your behalf.
Children's Privacy
The Scrubbe Platform and website are directed exclusively at business users and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
If you believe that a child has provided personal data to Scrubbe, please contact privacy@scrubbe.com and we will take prompt steps to delete the relevant data.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or new features. When we make material changes, we will:
- ›Notify account holders by email to the primary registered address at least 30 days before the changes take effect.
- ›Display a prominent notice within the Platform and on the Scrubbe website.
- ›Update the "Last updated" date at the top of this Policy.
- ›Maintain a version history so you can review what has changed.
Your continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the changes. If you do not accept material changes, you may exercise your right to erasure or account closure by contacting privacy@scrubbe.com.
For non-material changes (such as clarifications, typographical corrections, or descriptions of existing practices), we will update the Policy without prior notice.
Contacts & Notices
For legal notices under these Terms, or to report a potential breach of these Terms, please contact Scrubbe's legal team using the details below. Notices sent by email are deemed received on the next business day. Notices sent by certified mail to the registered address are deemed received three business days after mailing.
Legal enquiries
legal@scrubbe.comSecurity & data incidents
security@scrubbe.comGeneral enquiries
p.ifediora@scrubbe.comCompany
Scrubbe Inc.
Website
www.scrubbe.comCookie preferences
We use essential cookies to keep Scrubbe secure and functional. You can choose whether to allow analytics, preferences, and marketing cookies, and update your choices at any time.
Essential cookies
Required for security, session continuity, consent state, and core site functionality. These are always on.
Analytics cookies
Help us understand usage patterns so we can improve product pages, onboarding paths, and documentation quality.
Preference cookies
Remember selected settings such as region, UI preferences, and previously chosen site options.
Marketing cookies
Enable campaign measurement and more relevant follow-up communications across trusted channels.
Your choices are stored locally in this browser and can be updated at any time from the cookie settings button.
