Scrubbe Logo

Privacy Policy

This Privacy Policy explains how Scrubbe Inc. collects, uses, stores, and protects personal data in connection with the Scrubbe incident intelligence platform and our marketing presence. We are committed to processing personal data lawfully and transparently, in accordance with the California Consumer Privacy Act (CCPA/CPRA), other applicable U.S. state privacy laws, and applicable data protection law.

Effective Date: 21 May 2025 Last Reviewed: 21 May 2026 Jurisdiction: United States

Overview & Scope

Data you own

Customer incident and telemetry data remains yours. We process it only on your instructions.

CCPA/CPRA Service Provider

Where it lives

Processed and stored in the United States by default. Enterprise residency options available.

U.S. default

How long we keep it

Account data is deleted within 90 days of termination. Audit logs retained for 7 years.

30-day export window

Your rights

Know, correct, delete, opt out of sale/sharing, and non-discrimination — respond within 45 days.

CCPA/CPRA Consumer Rights

Breach notification

We notify affected customers within 72 hours of confirming a breach affecting your personal data.

72-hr notification commitment

No selling of data

We never sell, rent, or trade personal data to third parties for marketing purposes.

No sale or sharing (CCPA)

This Privacy Policy applies to all personal data processed by Scrubbe Inc. in connection with:

  • The Platform: Personal data of Authorized Users who access the Scrubbe incident intelligence platform under a subscription.
  • The Website: Personal data of visitors to www.scrubbe.com, visitors to and any associated marketing pages or documentation portals.
  • Sales & Support: Personal data collected during pre-sales conversations, customer onboarding, technical support engagements, and account management.
  • Customer Data (as processor): Telemetry, alert data, log payloads, and other operational data that Customers submit to the Platform. We process this as a data processor acting on Customer instructions — not as a controller.

This Policy does not govern data processed by third-party services that you may connect to the Platform via Connectors (e.g. PagerDuty, Datadog, AWS). You should review the privacy policies of those services separately.

Controller vs Processor

For personal data in Customer-submitted incident payloads and telemetry, Scrubbe acts as a Data Processor (a "Service Provider" under the CCPA/CPRA) and the Customer is the Data Controller (a "Business" under the CCPA/CPRA).

Our Data Processing Agreement ("DPA") governs that relationship. This Policy primarily describes our activities as a data controller in our own right.

Data Controller

The data controller responsible for personal data processed under this Policy is:

CompanyScrubbe Inc.
JurisdictionUnited States
Websitewww.scrubbe.com
Privacy contactprivacy@scrubbe.com
Primary regulatorsFederal Trade Commission (FTC) for general consumer protection; California Privacy Protection Agency (CPPA) and California Attorney General for CCPA/CPRA enforcement; other state Attorneys General as applicable under their respective state privacy laws.

Data We Collect

We collect personal data in the following categories depending on how you interact with Scrubbe:

CategoryExamplesSource
Account & identityName, work email address, job title, organization name, profile pictureProvided by you or your employer at onboarding
Authentication dataHashed passwords, SSO tokens, MFA state, session tokensGenerated at login; never stored in plaintext
Usage & activityFeature interactions, dashboard views, playbook configurations, incident approvals/rejections, API callsAutomatically collected via platform instrumentation
Audit eventsUser ID, action type, timestamp, IP address, policy version evaluated, outcomeAutomatically generated for every state transition
Device & technicalIP address, browser type and version, operating system, viewport size, time zoneAutomatically collected on web access
CommunicationsSupport tickets, email correspondence, sales call notes, product feedbackProvided by you directly
Connector credentialsAPI keys, OAuth tokens, service account identifiers for third-party integrationsProvided by Customer Authorized Users; stored encrypted
Marketing & websiteName, work email, company, interest area from contact or demo request forms; cookie identifiersProvided by you on the website
Payment dataBilling contact name and email, company name, tax identification number (e.g., EIN or VAT/GST where applicable). Card details are handled exclusively by our payment processor and never stored by Scrubbe.Provided at subscription purchase

We do not knowingly collect special category personal data (health, biometric, racial or ethnic origin, political opinions, etc.) in the normal course of operating the Platform. If any such data appears in Customer-submitted incident payloads, it is processed as Customer Data under the DPA and the Customer is responsible as controller for its lawfulness.

How we use Data

We use personal data collected as controller for the following purposes:

Service delivery:Provisioning accounts, authenticating users, enforcing role-based access controls, routing notifications, and delivering all platform features within Subscription entitlements.
Security and integrity:Detecting, investigating, and responding to security incidents, abuse, and policy violations. Maintaining the immutable audit trail of all platform actions.
Product improvement:Analyzing aggregated, anonymized usage patterns to prioritize features, improve agent accuracy, and optimize system performance. We do not use individual-level usage data to build personal profiles for advertising.
Customer communications:Sending service notifications, release notes, security advisories, billing communications, and support responses. These are non-optional for account holders.
Marketing:Sending product updates, case studies, webinar invitations, and relevant content to prospects and customers who have opted in. You may withdraw consent at any time.
Legal compliance:Meeting obligations under applicable law, including responding to lawful requests from regulatory authorities.
Business operations:Managing our commercial relationships, processing payments, and maintaining corporate records.

No Automated Decision-Making on You

While the Scrubbe Platform uses AI agents to make automated decisions about operational incidents, we do not use automated decision-making or profiling about individual users or data subjects that produces legal or similarly significant effects, consistent with automated-decision-making protections under applicable U.S. state privacy laws (e.g., Colorado and Connecticut).

Customer & Incident Data

When Customers submit telemetry, alerts, log payloads, and related operational data to the Platform, Scrubbe acts exclusively as a data processor (a "Service Provider" under the CCPA/CPRA, and a "Processor" under other applicable U.S. state privacy laws). This means:

  • We process Customer Data only on documented instructions from the Customer (as set out in the DPA and Order Form).
  • We do not use Customer Data for any purpose other than providing and maintaining the Service, unless required by law.
  • We impose binding confidentiality and data protection obligations on all sub-processors who access Customer Data.
  • We assist Customers in responding to data subject rights requests relating to personal data contained within Customer Data.
  • We maintain records of all processing activities performed on behalf of each Customer tenant.
  • Upon termination, Customer Data is retained for 30 days to allow export and then securely deleted within 90 days, except where law requires longer retention.

Customer Responsibility

Customers are responsible as data controllers for ensuring they have a lawful basis for submitting personal data to the Platform via Connectors. Scrubbe's ingestion pipeline processes all submitted data without inspecting it for personal data at the point of entry — it is the Customer's responsibility to apply appropriate data minimization at source.

Scrubbe maintains a Data Processing Agreement ("DPA") that governs all processor-level processing. Enterprise Customers must execute the DPA prior to submitting personal data to the Platform. Our standard DPA is available at www.scrubbe.com/dpa.

Data Sharing

We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:

Sub-processorsThird-party infrastructure and SaaS providers that process personal data on our behalf to deliver the Service (e.g. cloud hosting, email delivery, error monitoring, payment processing). A current list of sub-processors is maintained at www.scrubbe.com/sub-processors. We notify Customers at least 30 days before adding a new sub-processor.
Professional advisorsLawyers, auditors, and accountants acting in an advisory capacity, subject to professional confidentiality obligations.
Regulatory authoritiesWe may disclose personal data to regulatory or law enforcement authorities where required by applicable law or a valid legal order. We will notify affected Customers where legally permitted to do so.
Business transactionsIn the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred to the successor entity, subject to equivalent privacy protections. We will notify affected individuals before any such transfer takes effect.
With your consentFor any sharing not described above, we will seek your explicit consent before proceeding.

International Transfers

Scrubbe is headquartered in the United States. By default, personal data and Customer Data are processed and stored within the United States.

Where we process personal data originating from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, we put an appropriate safeguard in place for the transfer to the United States, including:

  • EU Standard Contractual Clauses (SCCs) for transfers of personal data from the EEA, supplemented by a Transfer Impact Assessment where required.
  • UK International Data Transfer Agreement (IDTA) / UK Addendum for transfers of personal data from the United Kingdom.
  • Other legally recognized transfer mechanisms as they become available or are required under applicable law.

Enterprise Customers requiring data residency in a specific region may request this configuration in their Order Form. We will identify any sub-processors that may necessitate transfers outside that region and provide appropriate documentation.

Transfer Records

You may request a copy of the transfer safeguards applicable to your data by contacting privacy@scrubbe.com. We maintain records of processing activities, including all international transfer mechanisms.

Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law. Our standard retention periods are:

Duration of subscription + 30 days

Account & profile data

Name, work email, role, and access records. Retained for 30 days post-termination to allow export, then permanently deleted.

Duration of subscription + 90 days

Customer incident & telemetry data

All Customer Data processed as a processor, including enriched incident records and agent action logs. Securely deleted within 90 days of contract end, unless law requires longer.

7 years

Audit trail & compliance records

The immutable audit log of all state transitions, approvals, policy evaluations, and action outcomes. Retained for regulatory compliance and legal defensibility.

7 years

Financial & billing records

Invoices, payment records, and associated contact data retained to satisfy applicable U.S. federal and state tax and accounting recordkeeping requirements.

3 years from last contact

Marketing & prospect data

Records of individuals who have expressed interest in Scrubbe but have not become customers. Suppression records (opt-outs) are retained indefinitely.

90 days rolling

Security & access logs

Server access logs, authentication events, and IP address records used for security monitoring and incident investigation.

Security

Scrubbe implements layered technical and organizational security measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include:

Encryption in transit:All data transmitted between clients and the Platform uses TLS 1.2 or higher. Internal service-to-service communication is encrypted.
Encryption at rest:All stored personal data and Customer Data is encrypted using AES-256.
Access controls:Scrubbe personnel access to Customer environments is strictly role-limited, logged, and subject to a least-privilege policy. Access requires multi-factor authentication.
Penetration testing:Annual independent penetration tests and continuous automated vulnerability scanning of the Platform.
Incident response:A documented information security incident response process, including escalation paths and Customer notification procedures.
Sub-processor assessment:All sub-processors handling personal data are assessed for security posture before onboarding and periodically thereafter.
Immutable audit logs:All access to Customer Data by Scrubbe personnel is logged in an append-only audit trail that cannot be modified or deleted.

Breach notification. In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify affected Customers within 72 hours of confirming the breach, providing sufficient information to allow them to fulfill their own notification obligations. Where required by applicable state law, we will also notify affected individuals and state Attorneys General within the timeframes those laws prescribe.

To report a security vulnerability or suspected breach, contact security@scrubbe.com.

Your Rights

Depending on your state of residence, you have some or all of the following rights in relation to personal data we hold about you as controller, under applicable U.S. state privacy laws — including the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and similar laws in Colorado, Connecticut, Virginia, Utah, and other states. These rights apply to our processing of your personal data as a Scrubbe user, website visitor, or contact — not to Customer Data (where rights should be directed to the relevant Customer/controller).

CCPA/CPRA § 1798.100

Right to Know / Access

Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, purposes, and any third parties it was disclosed to.

CCPA/CPRA § 1798.106

Right to Correct

Request correction of inaccurate or incomplete personal data we hold about you.

CCPA/CPRA § 1798.105

Right to Delete

Request deletion of your personal data, subject to legal retention requirements and certain exceptions.

CCPA/CPRA § 1798.121

Right to Limit Sensitive Data

Limit the use and disclosure of sensitive personal information to what is necessary to provide the Service.

CCPA/CPRA § 1798.100

Right to Portability

Receive your personal data in a structured, machine-readable format and transfer it to another controller where technically feasible.

CCPA/CPRA § 1798.120

Right to Opt Out of Sale/Sharing

Direct us not to sell or share your personal information. As noted above, we do not sell or share personal data for cross-context behavioral advertising.

CCPA/CPRA § 1798.125

Right to Non-Discrimination

We will not deny goods or services, charge a different price, or provide a different level of service because you exercised a privacy right.

State AG / FTC

Right to Lodge a Complaint

Lodge a complaint with the California Privacy Protection Agency (CPPA), your state Attorney General, the Federal Trade Commission (FTC), or your local supervisory authority if you believe we have infringed your rights.

To exercise any right, submit a request to privacy@scrubbe.com. We will respond within 45 days (extendable by a further 45 days for complex requests, with notice). We may need to verify your identity before processing the request, and may require a higher level of verification for delete or correct requests. Rights requests are free of charge, though we may charge a reasonable fee for manifestly unfounded, excessive, or repetitive requests. You may designate an authorized agent to submit a request on your behalf.

Cookies & Tracking

We use cookies and similar tracking technologies on www.scrubbe.com and the Platform. Detailed information about the cookies we use, their purpose, and how to manage your preferences is set out in our Cookie Policy. A summary:

CategoryPurposeConsent required?
EssentialSession management, authentication, security, load balancing. Without these the Platform cannot function.No — lawful basis: contract
AnalyticsAggregated anonymized usage statistics to understand how the Platform and website are used. We use privacy-preserving analytics that do not fingerprint individuals.Yes — consent required
FunctionalRemembering your preferences (theme, language, dashboard layout) to improve your experience.No — consent required
MarketingTracking visits from marketing campaigns to measure effectiveness. Not used for third-party ad targeting.No — consent required

You can manage your cookie preferences at any time via the cookie preference center, accessible from the footer of any Scrubbe website page — including the "Do Not Sell or Share My Personal Information" control required under the CCPA/CPRA. You may also control cookies through your browser settings or by enabling the Global Privacy Control (GPC), though disabling Essential cookies will impair Platform functionality.

Children's Privacy

The Scrubbe Platform and website are directed exclusively at business users and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.

If you believe that a child has provided personal data to Scrubbe, please contact privacy@scrubbe.com and we will take prompt steps to delete the relevant data.

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or new features. When we make material changes, we will:

  • Notify account holders by email to the primary registered address at least 30 days before the changes take effect.
  • Display a prominent notice within the Platform and on the Scrubbe website.
  • Update the "Last updated" date at the top of this Policy.
  • Maintain a version history so you can review what has changed.

Your continued use of the Platform after the effective date of an updated Policy constitutes acceptance of the changes. If you do not accept material changes, you may exercise your right to erasure or account closure by contacting privacy@scrubbe.com.

For non-material changes (such as clarifications, typographical corrections, or descriptions of existing practices), we will update the Policy without prior notice.

Contacts & Notices

For legal notices under these Terms, or to report a potential breach of these Terms, please contact Scrubbe's legal team using the details below. Notices sent by email are deemed received on the next business day. Notices sent by certified mail to the registered address are deemed received three business days after mailing.

Legal enquiries

legal@scrubbe.com

Security & data incidents

security@scrubbe.com

General enquiries

p.ifediora@scrubbe.com

Company

Scrubbe Inc.

Document reference: TOS-2025-v1.0Effective: 21 May 2025Last reviewed: 21 May 2026Jurisdiction: United StatesCompany: Scrubbe Inc.

Cookie preferences

We use essential cookies to keep Scrubbe secure and functional. You can choose whether to allow analytics, preferences, and marketing cookies, and update your choices at any time.

Essential cookies

Required for security, session continuity, consent state, and core site functionality. These are always on.

Always active

Analytics cookies

Help us understand usage patterns so we can improve product pages, onboarding paths, and documentation quality.

Allow analytics

Preference cookies

Remember selected settings such as region, UI preferences, and previously chosen site options.

Remember preferences

Marketing cookies

Enable campaign measurement and more relevant follow-up communications across trusted channels.

Allow marketing

Your choices are stored locally in this browser and can be updated at any time from the cookie settings button.