Respawn Privacy Policy
v1.0.0
January 4, 2025
Privacy Policy
Effective Date: July 22, 2026 Last Updated: July 22, 2026
This Privacy Policy describes how Immune Security Inc., a Delaware corporation doing business as Respawn ("Respawn," "we," "us," or "our"), collects, uses, and shares personal information when you visit respawnit.com (the "Site"), use the Respawn platform (the "Service"), or otherwise interact with us.
1. Two Roles: Our Data vs. Customer Environment Data
Respawn handles information in two distinct capacities, and it matters which one applies:
As a business (controller). For the Site, sales and marketing, billing, and the accounts of our customers' authorized users, Respawn decides how and why personal information is used. This Privacy Policy governs that information.
As a service provider (processor). The Service connects — agentlessly and read-only by default — to our customers' cloud environments to map infrastructure, test availability and recovery, and route remediations. Information obtained from a customer's environment ("Customer Environment Data"), which is primarily infrastructure metadata such as configurations, dependencies, service topology, and test results but may incidentally include personal information contained in those environments, is processed on the customer's behalf and under its instructions, as set out in our Terms of Service and the applicable customer agreement. If your personal information appears in a customer's environment, the customer is the controller — please direct requests about it to that organization; we will support our customer in responding as required.
2. Information We Collect
Information you provide. Name, work email, company, title, and phone number when you book a demo, contact us, subscribe to updates, or register for an account; the contents of messages you send us; and billing details when you purchase the Service (payment card details are collected and processed by our payment processor, Stripe — we do not store full card numbers).
Information collected automatically. When you visit the Site or use the Service, we and our providers collect log and usage data such as IP address, browser and device type, pages viewed, referring pages, and actions taken in the product, using cookies and similar technologies. See Section 7 (Cookies).
Information from integrations and third parties. If a customer connects workplace tools (for example Slack, Microsoft Teams, or a ticketing system) to route findings and fixes, we process the identifiers needed to deliver those notifications (such as workspace, channel, and user handles). We may also receive business contact information from publicly available sources or partners for sales outreach.
3. How We Use Information
We use personal information to provide, operate, secure, and support the Site and the Service; to set up and administer accounts; to respond to inquiries and schedule demos; to send invoices and process payments; to send service communications and, where permitted, marketing communications (you can opt out at any time); to analyze and improve the Site and the Service; to protect against fraud, abuse, and security threats; and to comply with legal obligations. Where laws such as the GDPR apply, we rely on the legal bases of contract performance, legitimate interests (such as securing and improving the Service and reaching business prospects), consent where required, and legal compliance.
4. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share personal information only with: service providers and subprocessors who help us run the business and the Service (such as cloud hosting and infrastructure providers, Stripe for payments and invoicing, communications and scheduling tools, and analytics providers), bound by contractual confidentiality and data-protection obligations; integration providers you or your organization choose to connect (such as Slack or Microsoft Teams), per your configuration; professional advisors (lawyers, accountants, insurers) under confidentiality obligations; authorities where required by law, subpoena, or legal process, or to protect rights, safety, and the integrity of the Service; and a successor entity in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy.
5. Data Retention
We retain personal information for as long as needed for the purposes described above: account information for the life of the account and a reasonable period thereafter; billing records as required by tax and accounting law; and marketing contact data until you opt out or it becomes stale. Customer Environment Data is retained as specified in the applicable customer agreement and is deleted or returned following termination in accordance with our Terms of Service, except for copies in routine backups or as required by law.
6. Security
We protect personal information and Customer Environment Data with industry-standard administrative, technical, and organizational safeguards, including encryption in transit and at rest, least-privilege access controls, and logging and monitoring. Read-only, scoped access is the default posture for customer environment connections. No method of transmission or storage is completely secure; if we learn of a breach affecting your personal information, we will notify you and regulators as required by law.
7. Cookies and Analytics
The Site uses cookies and similar technologies that are strictly necessary for it to function, plus analytics cookies that help us understand how the Site is used. You can control cookies through your browser settings; disabling some cookies may affect Site functionality. Where required by law, we request consent before setting non-essential cookies.
8. Your Rights and Choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. If you are in the European Economic Area or the United Kingdom, these rights arise under the GDPR/UK GDPR, and you may also lodge a complaint with your supervisory authority. If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) gives you similar rights, including the right to know, delete, and correct, and the right not to be discriminated against for exercising them; we do not sell or share personal information as those terms are defined by the CCPA. To exercise any right, contact us at support@respawnit.com — we will verify your request and respond within the timeframe required by applicable law. To opt out of marketing email, use the unsubscribe link in any message or contact us at the same address.
9. International Transfers
We are based in the United States, and information we collect is processed in the United States and in other countries where our service providers operate. Where required, we use appropriate safeguards for cross-border transfers, such as the European Commission's Standard Contractual Clauses.
10. Children
The Site and the Service are for business use and are not directed to children under 16. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version on this page with a revised "Last Updated" date and, for material changes, provide additional notice as required by law.
12. Contact Us
Immune Security Inc. (d/b/a Respawn) 2261 Market Street STE 69202 San Francisco, CA 94114 support@respawnit.com

